[Cryptech Tech] CryptoStick

Russ Housley housley at vigilsec.com
Thu Jul 3 16:46:44 UTC 2014


https://www.crypto-stick.com/en/introduction

I just learned about this.  They claim:
-- 100% Open Source software and hardware; open interfaces for easy integration
-- Firmware updates can be applied easily
-- The installed firmware can be exported to allow verifying its correctness and absence of backdoors.
-- All development tools are available as open source and for free

The hardware seems to be very different.  They have incorporated:
-- A PCB with an Atmel AT32 microprocessor which stores the firmware, AES working keys (encrypted by the master key), and configurations.
-- A MicroSD card as mass storage. Class 10 is preferred for maxium speed.
-- The OpenPGP (smart) Card is PIN-protected and stores the AES master key and RSA keys. Special features will become standard in the next OpenPGP Card version.

What can we learn from their effort?

Russ


More information about the Tech mailing list