Symmetric keys (AES/HMAC/3DES) don't have KeyPairs or attestation certs — routing them through doSoftwareKeyGen crashes with "Unsupported algorithm: 32". Skip the software path entirely and let the real HAL handle them. Also adds CTR block mode, RSA_PKCS1_1_5_SIGN cipher padding, and RSA_PSS signature padding to JcaAlgorithmMapper.