I theory you could install some kind of TPM-like device to every hardware that signs the data with key generated by manufacturer. Should be designed in such a way that it is very easy to break it when trying to tamper with it