A single-purpose device
Built on a Raspberry Pi Pico 2 (RP2350). It is not a general keystore or a smart card — v1 holds exactly one key, the SSH user CA, and exposes a handful of semantic operations: report identity, return the CA public key, and issue an SSH user certificate under policy. A separate provisioning workflow for persistent CA identity is in development.
Split into two worlds
The RP2350's Arm TrustZone-M is used to separate the code that touches the key from the code that talks to the host. The Secure world holds the key, re-validates every request field on its own copy, checks policy, and performs the Ed25519 signature. The Non-secure world does USB and message framing only, holds no secrets, and can reach the Secure world only through a thin, typed gateway. A memory-safety bug in the USB or parsing code cannot reach key material.
Standard cryptography
Signing, hashing and random-number generation use a pinned build of a well-known verified cryptography library (HACL). The on-die hardware RNG is run through standard health tests and conditioning before seeding an HMAC-DRBG. Consistent with the rest of the project: no invented cryptography.
Its own clock
The production design includes a battery-backed real-time clock inside a sealed enclosure, providing a time source independent of the host. The prototype RTC has passed hardware bring-up; trusted time is not yet implemented. Certificate validity is designed to be bounded by the time the device holds, plus a monotonic floor it will not go behind — not by whatever clock value the host sends.
Sealed, with one way in
The production device is designed to ship sealed, exposing only USB and a status LED — no debug header, no boot-override, no re-key path once locked. The host link is a framed binary protocol (VNHSM/1) over a USB vendor interface, one request in flight at a time.