Applied Cryptography and Key Management Questions

Selecting and applying cryptographic primitives correctly: symmetric and asymmetric encryption, hashing, digital signatures, key derivation, secure random number generation, and public key infrastructure. Covers key lifecycle management, key exchange and distribution, choosing appropriate algorithms for a given constraint set including resource-constrained environments, and the forward-looking side of algorithm lifecycle: cryptographic agility and algorithm-migration strategy, forward secrecy, and the post-quantum cryptography transition and planning upgrades without breaking existing data or interoperability. The applied-crypto engineering layer, distinct from compliance-driven crypto standards.

HardSystem Design
46 practiced

Design a scalable PKI and key-management solution for 10 million IoT devices, many with intermittent connectivity and limited TPM/HSM capability. Address secure provisioning, key storage choices, rotation, revocation strategies where CRL/OCSP don't fit well, OTA updates, and how you'd bootstrap a root of trust.

HardTechnical
28 practiced

Design a remote-attestation and secure firmware-update pipeline for a fleet of HSM-like devices or secure elements. Include boot-chain verification, signed firmware images, an attestation protocol to verify device state, rollback protection, an emergency-revocation path, and a safe staged rollout with recovery if a firmware push goes wrong.

HardSystem Design
29 practiced

Design a key-management service to provision, authenticate, and rotate cryptographic keys for a fleet of intermittently-connected, low-power IoT devices (from tens of thousands to hundreds of millions of units). Cover manufacturing provisioning (pre-seeded identities), initial bootstrap, use of TPMs or secure elements where available, over-the-air key updates for devices offline for months, and how you handle revocation or compromise at that scale.

HardTechnical
32 practiced

Design a secure, post-quantum-ready code-signing and firmware-update architecture for highly constrained embedded devices (think 32KB RAM, a slow CPU, limited flash). Walk through your signature-scheme selection, verifier performance in the bootloader, how you handle storage and transmission of larger PQ signatures, and your strategy for backward compatibility with legacy devices in the field.

HardTechnical
27 practiced

Design a secure key-derivation and device-authentication scheme for resource-constrained IoT devices that have low-quality entropy at manufacturing time and may be provisioned offline. The scheme needs to prevent device cloning, provide a durable device identity, and support firmware updates while minimizing long-term secret disclosure. Describe your provisioning, storage, and update flows and the trade-offs involved.

That is every published Applied Cryptography and Key Management question for Embedded Developer so far. Browse the other topics in this category, or practice this one interactively.