DEVICE MANUFACTURERS
Every device an authority anchor
UniKey's signing key lives in the device's hardware root of trust and never leaves it. Device makers provision that authority anchor, and every action the owner takes from the device can carry proof that they authorized it.
THE PROBLEM TODAY
Credentials stand in for permission
Credentials leave the device
Passwords, tokens and codes travel over the network, where they are intercepted, stored and stolen.
Provisioning trust
Enrolling a new device, or transferring ownership of one, relies on the same weak credentials.
Lost or compromised devices
Without per-device authority, revoking one device often means resetting everything.
WITH UNIKEY
Actions that carry a Trust Packet
Each one is signed by the party with the authority to take it, and verified before it executes.
-
Provision an anchor
A key pair is created in the Secure Enclave at setup and its public key is published for verifiers.
-
Sign for the owner
Payments, approvals and changes are signed on the device after the owner confirms them.
-
Transfer ownership
A new owner is enrolled with a packet from the old one, recorded on the ledger.
-
Revoke a device
The issuer revokes one device's anchor, keeping the blast radius to that device.
{
"action": "provision_device",
"subject": "device-7f3a91@oem.example",
"signer": "oem.example",
"audience": "provisioning@oem.example",
"params": {
"model": "X12",
"enclave": "secure-element",
"key_validity_days": 90
},
"expires_at": "2026-10-05T14:05:00Z"
}
Illustrative. The verifier looks up the signer's public key in DNS, checks the Ed25519 signature, refuses a packet it has seen before or one past its expiry, and only then lets the action run.
DEMO VIDEOS
Shape what comes next
UniKey is in active conversations in this industry. Founding partners receive preferential terms on the commercial layer.
MORE INDUSTRIES