| ▲ | Hackbraten 2 days ago | |||||||
> For a big enough production run, you'd likely ship an HSM to the factory I figure that the factory is exactly the adversary in the whole threat model? So why give them the keys to the castle so they can moonlight their own genuine batch? | ||||||||
| ▲ | NBJack a day ago | parent [-] | |||||||
A few ways, if I understand them correctly. On-site people you employ (if you can afford it) auditing the process, connectivity to the HSM to record every key assigned (makes it easy to trace duplicated keys to their origin), and ideally assigning these keys at the very last possible step after the rest is assembled (to minimize 'defective' parts wandering off and being assembled elsewhere). | ||||||||
| ||||||||