Уровень 0 · материалов: 2
В кластер входят документы, посвященные реализации и безопасности функции неизвлекаемости ключей в аппаратных токенах, и не входят документы о самостоятельном создании дешевых устройств безопасности.
Общие признаки: криптографические ключи, аппаратные токены безопасности, защита от извлечения ключей, взаимодействие ПО и оборудования
Группа выше: Многофакторная и беспарольная аутентификация
Смысл: The main idea is that hardware tokens marketed as 'non-extractable' do not provide security if the accompanying software (CSP) treats them as simple removable drives. True non-extractability requires a specific synergy between hardware applets and specialized cryptographic provider software.
Tokens with 'non-extractable' keys can still have their keys stolen if used with standard software that treats them as simple storage devices rather than Functional Key Carriers.
Смысл: The main idea is that Tensor's software intentionally disables the use of non-extractable hardware keys during certificate generation, which the author suspects is a mechanism to illicitly obtain clients' private keys.
The author suspects the Tensor CA of potentially stealing clients' private keys by using software that intentionally disables secure hardware token generation and requires a mandatory internet connection.