3 ms·
This looks like a nice piece of work but worth noting that as it uses a stock RP2040 Pico board any hardening against physical attacks will be done purely in so
by gchadwick 3y ago
This looks like a nice piece of work but worth noting that as it uses a stock RP2040 Pico board any hardening against physical attacks will be done purely in software so cloning the HSM entirely or extracting keys may not be too complex for an attacker. Hardening against physical attackers and significant resistance against them is normally seen as a key component of an HSM.
Indeed from a very quick glance at the source, it's using the mbedtls library (from arm) and I think this is an unmasked implementation. This means key extraction, if you have physical access to the device, will be trivial.