Skip to main content

SimpleGo Security Architecture - Hardware Class 3

Hardware Class 3 - Overview and Architecture ("Vault")

Status: Coming soon Hardware: Custom PCB Model 3 "Vault" (STM32U5A9 + ATECC608B + OPTIGA Trust M + SE050)


What is Hardware Class 3?

Hardware Class 3 represents the maximum achievable hardware security for a dedicated messaging device. It distributes cryptographic trust across three secure elements from three independent semiconductor manufacturers in three different countries:

Secure ElementManufacturerCountryCertification
ATECC608BMicrochip TechnologyUSACC EAL5+
OPTIGA Trust MInfineon TechnologiesGermanyCC EAL6+
SE050NXP SemiconductorsNetherlandsCC EAL6+

The core principle: even if one manufacturer has a hidden backdoor, even if one chip has an undiscovered side-channel vulnerability (as demonstrated by the Eucleak attack on Infineon SLE78 in 2024), the complete key cannot be reconstructed from a single compromised element. This triple-vendor approach has no known precedent in any commercial, military, or academic device.

Additional physical security features planned for Model 3 include active tamper mesh on the PCB, light sensors for enclosure breach detection, a supercapacitor for sub-100ns RAM zeroization on power loss, temperature monitoring, and three physical kill switches (WiFi/BLE, LoRa, LTE).

This documentation will be published when Hardware Class 3 PCB design begins.


Planned Documentation

#DocumentDescription
01Overview and ArchitectureThis document - triple-SE model, threat model, physical security
02Triple-Vendor Key SplittingKey distribution across three SEs, threshold schemes, recovery
03ATECC608B Deep DiveSlot config, ECDH in hardware, attestation
04OPTIGA Trust M Deep DiveShielded Connection, platform integrity, lifecycle management
05SE050 Deep DiveAPDU commands, applet architecture, IoT attestation
06STM32U5A9 SecurityTrustZone, OTFDEC, active tamper pins, RDP Level 2
07Physical Tamper DetectionMesh design, sensor integration, zeroization response
08Duress PIN and Dead Man's SwitchEmergency key destruction, configurable timeouts
09Supply Chain SecurityComponent authentication, anti-counterfeit measures
10Comparison: Class 1 vs Class 2 vs Class 3Complete feature matrix across all hardware classes

SimpleGo - IT and More Systems, Recklinghausen AGPL-3.0 (Software) | CERN-OHL-W-2.0 (Hardware)