Quantum-resistant cryptography, deterministic scanning, and runtime integrity protection.
vollcrypt-shield-embedded is an independent, zero-allocation #![no_std]
integrity-state library for long-lived embedded devices. It does not depend on
Wave, an operating system, a network stack, or another Vollcrypt package.
The current foundation provides:
The application supplies component identifiers, digests, monotonic counters, persistent storage, notifications, and an ML-DSA-65 implementation through the documented traits. A software counter or key stored in the same writable trust domain as monitored firmware is a weak trust root. Cortex-M33 deployments should place counters and signing behind TrustZone-M or a secure element.
This crate does not implement a bootloader, flash driver, network isolation, device shutdown, or remote fleet control. Commercial centralized fleet management is described publicly but implemented in a separate private repository.
Licensed under GPL-3.0-only OR LicenseRef-Commercial.