Tamperproof devices and backdoors

Hadmut Danisch hadmut at danisch.de
Fri May 25 17:10:23 EDT 2001

On Fri, May 25, 2001 at 09:34:20AM +0800, Enzo Michelangeli wrote:
> On another mailing list, someone posted an interesting question: how to
> ascertain that a tamperproof device (e.g., a smartcard) contains no hidden
> backdoors?

What about this:

Don't use a tamperproof _device_. 

Use a device consisting of n tamperproof modules instead.
Have the device built in a way such that someone needs
to tamper with at least m, 1 < m <=n, modules to be successful.

(Simple example: Use a chain of encryption modules from 
distinct manufacturers...)


