DEVICE MANUFACTURERS

Every device an authority anchor

UniKey's signing key lives in the device's hardware root of trust and never leaves it. Device makers provision that authority anchor, and every action the owner takes from the device can carry proof that they authorized it.

THE PROBLEM TODAY

Credentials stand in for permission

Credentials leave the device

Passwords, tokens and codes travel over the network, where they are intercepted, stored and stolen.

Provisioning trust

Enrolling a new device, or transferring ownership of one, relies on the same weak credentials.

Lost or compromised devices

Without per-device authority, revoking one device often means resetting everything.

WITH UNIKEY

Actions that carry a Trust Packet

Each one is signed by the party with the authority to take it, and verified before it executes.

  • Provision an anchor

    A key pair is created in the Secure Enclave at setup and its public key is published for verifiers.

  • Sign for the owner

    Payments, approvals and changes are signed on the device after the owner confirms them.

  • Transfer ownership

    A new owner is enrolled with a packet from the old one, recorded on the ledger.

  • Revoke a device

    The issuer revokes one device's anchor, keeping the blast radius to that device.

Example Trust Packet provision_device
{
  "action": "provision_device",
  "subject": "device-7f3a91@oem.example",
  "signer": "oem.example",
  "audience": "provisioning@oem.example",
  "params": {
    "model": "X12",
    "enclave": "secure-element",
    "key_validity_days": 90
  },
  "expires_at": "2026-10-05T14:05:00Z"
}

Illustrative. The verifier looks up the signer's public key in DNS, checks the Ed25519 signature, refuses a packet it has seen before or one past its expiry, and only then lets the action run.

DEMO VIDEOS

Shape what comes next

UniKey is in active conversations in this industry. Founding partners receive preferential terms on the commercial layer.