TrustKey

 

Definition

TrustKey is the immutable, non-exportable cryptographic identity used across all users, devices, workloads, and services in Forge.

 

Why It Matters

Passwords, tokens, cookies, OAuth grants, and certificates can all be replayed or stolen. TrustKey eliminates replay and impersonation by anchoring identity to hardware or derived roots.

 

How It Works

TrustKey signs DTL packets, VTZ operations, trust validations, session creation, and identity assertions. It can never be exported, copied, or cloned, ensuring identity cannot be hijacked.

 

Related Terms

UTA, DTL, TrustLock, TrustOps, VTZ

 

FAQ

Q: Is it exportable?

A: No—by design.

Q: Does it require TPM?

A: Preferred but optional.

Q: Can attackers steal it?

A: No—TrustKey never leaves its secure root.