
- Of cargo thefts target electronics: the most-stolen commodity
- 22%
- (Overhaul)
- Suspect counterfeit electronic parts found in the US defence supply chain
- 1M+
- (US Senate Armed Services Committee)
- Cargo theft losses in 2025 up 60% year on year
- $725M
- (Verisk CargoNet)
- Usable devices in a stolen Factory to Field shipment
- 0
- (Cavero Secure)
The Problem
The manufacturing process does not imply trust
A device passes through many hands before it's switched on
Contract manufacturers, distributors, integrators, installers, logistics and storage: every link in the supply chain is a chance for hardware to be substituted, cloned or tampered with, and by the time a device reaches the field, there is often no way to prove where it has really been. Certificate-based identity was never built for this. It is brittle at scale; it depends on infrastructure a dormant device cannot reach, and the post-quantum certificates that will replace today's are far larger than the classical ones, putting them out of reach of the very hardware that needs protecting the longest.
The Solution
CDA Collaborative Device Activation
Collaborative Device Activation means a device cannot bring itself into service alone.
In-field activation can occur only through Collaborative Device Activation (CDA). A quorum grants trust, verifies it cryptographically, and then re-proves it for the device's entire working life. In CDA, a device coming online in the field must be vouched for by a quorum of already-trusted devices randomly drawn at activation time. No single credential can be stolen, no single point of compromise exists, and subverting enough devices to compromise the process is infeasible.
The Fit
How does this work?
Your security team defines the policy centrally, including the quorum pool size and how many devices must agree to activate it. A secure orchestration platform at headquarters manages everything. Once activated, the device continuously re-verifies its identity and trust using CaveroCore™. CaveroCore™ delivers two capabilities: CaveroKEX™, a unique PQC key exchange algorithm for constrained devices. CaveroCTX™, providing continuous and mutual trust between endpoints. CaveroCore™ is crypto-agile and can use either ECDH or ML-KEM in place of CaveroKEX™ keys to establish trust, as required. Thanks to its lightweight nature, CaveroCore™ can be deployed on in-field devices via OTA updates.
