2 ms·
Thanks, I think I understand now. The chip verifies the update using the public key present in the blob. But before doing so, it checks the public key against s
by taway2012 13y ago
Thanks, I think I understand now. The chip verifies the update using the public key present in the blob. But before doing so, it checks the public key against some whitelist of valid public keys.
The private key used to sign the blob is never present on the chip. Interesting. Seems pretty secure to me, and more secure than a straight-up HMAC.
Thanks for answering my questions. I know a little about symmetric crypto, and your explanation has been very useful to expand my knowledge.