UBIQS

Identity you can't copy

Certificates, API keys, and tokens are data — and data gets copied. The only machine identity that holds under pressure is one derived from the physics of the silicon itself, not assigned by an authority you have to trust.

Share LinkedIn X Email

Almost every machine identity in use today is, underneath, a piece of data: an API key, a certificate, a bearer token, a set of model credentials. It sits in memory, in a config file, in a secrets manager, in an environment variable. And data — however carefully guarded — can be read, extracted, or replayed by anything that reaches it. An identity that lives in software inherits every attack that lives in software.

There's a second, quieter assumption baked into that model. Conventional identity depends on a certificate authority — a trusted party that generates a key, assigns it to a device, and vouches for it afterward. Security then rests on two hopes: that you can trust the authority not to be compromised or coerced, and that the assigned secret stays secret for the entire life of the device. Both are bets. Neither is physics.

Derived, not assigned

The UBIQS difference is a property of where the identity comes from. It is derived from a physical property of the specific silicon — not a credential that was stored, provisioned, or handed down. There is no issuing event, no assignment step, and no third party to trust or to compromise. The device does not hold its identity the way a wallet holds a card; the identity is a consequence of what the device physically is.

That single change cascades. Because nothing was stored, there is no secret store — nothing sitting in memory or flash waiting to be found, and therefore nothing to steal, clone, or replay. And because the root of trust is derived from the hardware, it moves off the plane where breaches happen: off the software and firmware layer where credential theft, key exfiltration, and supply-chain compromise actually occur.

An identity you can steal was never really an identity — it was a password with better branding. The only identity worth the name is one there is no copy of to take.

The reason it earns the word "unclonable" is precise, and it's worth stating carefully. An invasive attempt to extract the structure that the identity is derived from disturbs the very property being read. The act of trying to copy it changes it. So there is no clean copy to walk away with — only a failed one. It isn't that the identity is hardened against copying and might hold; it is that the identity is structurally unavailable to copy. It fails closed by construction, not by policy.

Authenticity is not authorization

It helps to separate two questions that conventional systems tend to blur. The first is authenticity: is this genuinely this device? That is a question physics can answer, because the identity is bound to the hardware and cannot be presented by an impostor. The second is authorization: is this device approved for this use? That is a question of policy — and it should belong to the owner of the infrastructure, not to an external certificate authority that assigned a secret and now effectively decides who is who.

Keeping these apart matters. When authenticity comes from physics and authorization stays with the owner, you no longer have to trust a third party to vouch for who a machine is, and you no longer inherit the blast radius of that third party being compromised. The device proves it is genuine on its own terms; you decide what a genuine device is allowed to do.

The foundation everything else stands on

An identity that can't be copied is not a feature — it's the ground floor. A signed receipt for every execution is only as trustworthy as the identity that signs it. A verifiable provenance record means nothing if the thing it describes can be impersonated. Accountability, in the end, requires that there be exactly one genuine "who" to hold accountable.

That is why UBIQS starts here. Get the identity right — derived from physics, unavailable to copy, owned by you rather than assigned to you — and receipts, provenance, and accountability become things you can build on rather than things you have to keep hoping are true.

Keep reading

Related

Building on an identity you can actually trust?

We're talking with teams that need machine identity rooted in physics, not assigned by an authority.