// the find
trussed-dev/trussed
Modern Cryptographic Firmware
Trussed is a Rust firmware framework for cryptographic hardware (security keys, HSM-ish embedded devices) that abstracts crypto mechanisms, secure storage, and client/service communication behind a trait-based API. It's aimed at embedded/firmware developers building authenticators or secure elements, not application developers looking for a crypto library.
The mechanism list is genuinely broad for an embedded target — P256/P384/P521, Ed25519/X25519, AES-GCM, ChaCha8Poly1305, HMAC variants, TOTP — and it's organized as pluggable backends rather than one monolithic crypto blob. The client/service split (core/src/client vs src/service) with an interchange-based IPC model is a sane way to isolate crypto operations from application code on constrained hardware. It's a real production lineage: this is the crypto core behind Nitrokey/Solo devices, not a toy project, and the workspace is split into core/derive/main crates with its own CHANGELOGs, suggesting actual API discipline despite instability.
The README explicitly says 'Very much WIP, unstable APIs' — anyone depending on this needs to pin exact versions and expect breaking changes, which the README doesn't soften. There's no top-level architecture doc in the tree beyond API docs and a tutorial repo, so understanding how backends, stores, and the derive macros fit together requires reading source, not docs. Filesystem/counter/cert/key stores are abstracted but the README gives zero guidance on writing a new backend for unsupported hardware, which is presumably the main reason someone would clone this instead of using the compiled firmware directly. No fuzzing or side-channel testing mentioned anywhere for a project whose entire purpose is being attack-resistant crypto firmware.