PlatformsFaststream SiliconFaststream RadioFaststream VisionConnected EdgeFaststream SecureMobility & Rail
ProductsSemiconductor IPWireless & RANEdge & GatewaysTracking & IdentificationSoftware & FrameworksConnected Systems
TechnologyRTL to GDSIIVerification methodologyDFT and silicon testLow-power designMixed-signal integrationDesign enablement5G protocol stackWireless and RF architectureBaseband and low PHYForward error correctionControl and data planeHigh-speed interfacesFirmware and bootSilicon root of trustSoftware-defined vehicleAutomotive OTAFunctional safety
AIAI Engineering ServicesEdge AI & Embedded MLComputer Vision EngineeringSensor Fusion & PerceptionAI Silicon & AccelerationMLOps for DevicesAI Visual InspectionPredictive MaintenanceDriver MonitoringVideo Analytics & Safety
SolutionsSemiconductorIndustrial AIConnected ProductsAsset TrackingAutomotive & MobilitySmart InfrastructureSecure IdentityWireless & SatelliteSmart WashroomsFuel ManagementSmart BuildingsWorker SafetyEnergy MonitoringSmart AgricultureSmart CityAutonomous PlatformsAssembly AutomationLiDAR Rail SafetyHardware Wallet
IndustriesSemiconductorTelecommunicationsIndustrial & ManufacturingAutomotive & MobilityTransportation & RailAerospace & DefenceHealthcare & MedicalEnergy & UtilitiesOil & GasRetailConsumer ElectronicsMedia & EntertainmentSmart Infrastructure & IoT
ServicesSystem Integration overviewASIC & SoC DesignFPGA DesignFPGA-to-ASIC ConversionAnalog, Mixed-Signal & RFHardware & High-Speed PCBEmbedded SoftwareCloud, OTA & Device ManagementManufacturing TransitionHow we engage
InsightCase StudiesKnowledge CenterWhite PapersGlossaryNewsletterResources & Support
CompanyAbout FaststreamEngineering ExcellenceLeadership & OrganisationHow We EngageQuality & ComplianceStandards & EcosystemPartners & EcosystemTrust CentreLocations & DeliveryNewsroom & MediaCareers
ContactStart a projectHow we engage
Talk to an engineer
SOLUTION

The screen is the security boundary. Everything else is supporting detail.

A hardware wallet exists so a private key never touches a networked machine. That part is well understood. The part that decides whether a device is actually safe is narrower: can the person holding it see, on hardware they trust, exactly what they are about to authorise — and refuse. A device that signs what the host asks without showing it has moved the key and kept the vulnerability.

Secure elementOn-device keygenTrusted displayTamper evidenceVerified firmware
What each layer defends against
Supply chain attestationProves at first use the device is genuine and unprovisionedTamper evidenceInterference during transit or handling becomes detectableVerified firmwareSignature checked from an immutable first stage before execu…Secure elementKey storage, cryptographic operation, physical attack resist…On-device key generationThe key never existed anywhere else, so it cannot have leakedTrusted display and confirmationThe holder sees the real transaction and can refuse itThe top and bottom are the ones vendors skip. The middle is the one they name.
WHAT GETS MEASURED

Six properties, and what each one is actually defending against.

Each maps to a specific attack. A device that has five of the six has a named weakness, not a smaller amount of security.

Sensing set
SignalHow What it changes
Key generation on the deviceEntropy sourced and keys derived in the secure element, never importedA key generated elsewhere existed elsewhere — on a machine, in a process, in someone's memory
Keys never leaveSigning happens inside the boundary; the key is not exported under any commandExtraction through the host interface, malware on the connected computer
Trusted display and confirmationAddress and amount rendered by the device, physically confirmedThe host showing one transaction while requesting the signature for another
Verified firmwareSignature checked from an immutable first stage before executionSubstituted or modified firmware that behaves correctly until it does not
Tamper evidenceEnclosure and package designed so interference is detectableInterception in transit, or a device returned to a user after handling
Supply chain attestationThe device proves at first use that it is genuine and unprovisionedA counterfeit or pre-initialised unit substituted before it reaches the owner
WHAT IS ACTUALLY HARD

Not the sensors.

The sensing is the solved part. These are what determine whether the deployment is still running in year three.

01

Blind signing is the whole problem

If the device renders what the host tells it to render, the trusted display is decorative. The device must parse the transaction itself and present its actual effect — which means understanding the payload rather than relaying a description of it. Complex contract interactions make this genuinely difficult, and it is where real devices differ most.

02

A secure element is a component, not an architecture

Certified secure elements provide key storage, cryptographic operation and physical attack resistance. They do not decide what gets signed, what the user sees, or how firmware is verified. Most of the security-relevant design sits outside the part everyone names in the datasheet.

03

Recovery is the largest attack surface

A seed that can restore the wallet can steal it. Generation, display, backup guidance and the restore path have to be designed together, and the honest engineering position is that most real-world losses are recovery failures rather than device compromise.

04

Supply chain, not just the device

A wallet can be intercepted, opened, modified and repackaged. Tamper-evident construction and an attestation the owner can check at first use are the defence — and the check has to be simple enough that a non-technical owner performs it.

05

Physical attack resistance is a scale, not a state

Certified elements resist a defined class of attack for a defined effort. Against an unbounded laboratory attack with physical possession, the correct claim is tamper-evident, not tamper-proof. Any vendor claiming otherwise is describing marketing rather than a threat model.

06

It does not defend against a coerced owner

No device protects a key from someone who compels its holder to use it. Passphrase and duress features change the shape of that problem without removing it, and saying so plainly is part of specifying the product honestly.

APPLICATIONS

Where this engineering applies.

The same discipline, wherever a key must not leave the hardware holding it.

SELF-CUSTODY

Cold wallets

Air-gapped or interface-connected devices holding keys for digital assets, with a trusted display and physical confirmation.

ENTERPRISE KEYS

Signing and credential devices

Code signing, document signing and administrative credentials where the key must not exist on a networked machine.

DEVICE IDENTITY

Industrial and infrastructure

Hardware-anchored identity for equipment that must prove what it is across a supply chain.

AUTHENTICATION

Security keys and tokens

Phishing-resistant authentication where the credential is bound to the hardware and cannot be copied to a second device.

WHERE THIS APPLIES

Industries this serves.

COMMON QUESTIONS

What engineers ask before they call.

01

What makes a hardware wallet secure?

Not the secure element alone. Keys generated on the device and never exported, firmware verified from an immutable first stage, tamper-evident construction, an attestation the owner can check at first use — and above all a trusted display that renders the actual transaction so the holder can refuse it.

02

What is blind signing and why does it matter?

Signing a payload the device cannot interpret and therefore cannot show meaningfully. If the device renders whatever the host describes rather than parsing the transaction itself, the trusted display provides no protection — which makes payload parsing one of the hardest and most security-relevant parts of the design.

03

Is a hardware wallet tamper-proof?

No, and that word should be treated as a warning sign. Certified secure elements resist a defined class of physical attack for a defined effort. Against an unbounded laboratory attack with physical possession, the accurate claim is tamper-evident.

04

What is the most common way people actually lose funds?

Recovery failures rather than device compromise — a seed lost, stored insecurely, or entered into something that captured it. Generation, backup guidance and the restore path deserve as much design attention as the cryptography.

05

Can Faststream build a secure key device end to end?

Secure hardware architecture, secure element integration, verified boot, firmware, enclosure and tamper evidence, provisioning and manufacturing transition. Mechanism-level detail and threat modelling are discussed under a non-disclosure agreement.

KEEP READING

Related work.

BUILD WITH FASTSTREAM

Bring us the difficult part.

Tell us the specification, the constraint and the deadline. Programmes that cross silicon, radio, embedded and AI are where Faststream is strongest.