Tech & AI News
Hacker News

Has anybody seen my keys? A key-hierarchy strategy for rack-level security

The design adds a rack-level Trust Quorum that splits a rack secret into N shares using Shamir secret sharing, storing each share unencrypted on a sled’s M.2 drive and distributing them via authenticated sprockets sessions. An attacker must acquire at least K shares—requiring K whole sleds and successful boot—to reconstruct the secret, which derives encryption keys for U.2 devices and rack-level root certificates. Future work will seal the shares with the RoT, limiting decryption to sled boot and raising the compromise barrier.