SECDSA Lab

Sole control without trusting the WSCA — detect compromise, don’t bury it in firmware.

Slide deck Glossary

Wallet

User device · NCH + PIN

Wallets
Account
Activated no
Y deleted
Seq SN 0
Token key none

Blinds Y before it leaves the phone. Provider never learns raw Y.

WSCA

Software container · not firmware

PIN counter PC 0
Lockout τ 5
Blocked no
Trust boundary An attacker who owns this process can reset PC or skip auth. That is expected. Security does not stop here.

Simulate compromise

HSM / WSCD

backend · —

Every key use is logged. Monitoring trusts this log, not the WSCA.

    Monitor

    Annex F · independent axis

    Run after honest traffic or an attack.

    Inputs: Transaction Records + HSM audit. No secrets. Reproducible by any third party.

    Transaction records

      Execution windows × HSM audit

      Windows are [TS_S, TS_E]. User-key marks outside a window = Alg 40 alarm.

      execution window blinding user key orphan Alg40 / excess Alg39

      Compact wallet log

      Open judge view →

      Figure 7: keep ASN‖TS_E‖T₁‖T₂‖T₃‖Sig locally (~196 B). Full Tr stays at the provider; dispute rehydrates and checks hashes.

      Protocol story