Blog


Exploring the future of security — From Hardware Root of Trust to End-to-End Quantum-Safe Protection.


[Insight & Thought Leadership]PAZI & Device Identity: Why Devices Have to Prove Themselves

BH Kang
10 Jul 2026

body-image-en-1200.png

You can steal an ID card. You can't steal an existence.

Picture an immigration checkpoint at an airport. A passport is an excellent government-issued credential, but no officer waves someone through on the passport alone. They compare the photo against the face in front of them, scan fingerprints, and increasingly check the iris. The reason is simple: a passport can be forged or stolen, but a living face and fingerprint cannot. An ID and an existence are two different things.

For decades, devices in digital systems have been the equivalent of travelers checked by passport only. A person logs in, a server approves the request, and the device simply executes the result. In that model, a device's identity was defined by externally assigned credentials — accounts, certificates, pre-injected keys — and the device itself was rarely asked to prove anything.

In a QAAS world — where quantum computing, AI-driven attacks, advanced persistent threats (APTs), and supply chain compromise increasingly converge — that assumption no longer holds. Devices are no longer passive endpoints; they've become the entry point and the propagation path for attacks. AI-powered attacks learn a device's normal behavior and imitate it. APTs live inside devices for months, quietly eroding trust. Supply chain attacks target the exact moment a device enters a system in a trusted state. In this environment, "who owns this device" is no longer the key question. The question that matters is: "Is this device still the same entity, and is it still in its intended state?"

The Limits of Legacy Device Identity: An ID Without an Existence

Legacy device identity has mostly relied on externally assigned identifiers. Serial numbers, MAC addresses, certificates, and keys stored in flash memory are perfectly adequate for telling devices apart. What they can't do is guarantee that a device is genuinely the device it claims to be — and that it hasn't been tampered with over time.

In a QAAS environment, that gap becomes fatal. A clonable ID can be replaced. A stolen key can be transplanted into another device. A device manipulated somewhere in the supply chain can enter a system carrying flawlessly legitimate credentials. At that point, identity stops being a foundation for trust and becomes camouflage for the attacker.

The PAZI Question: "Who Are You?" Isn't Enough

PAZI asks a different question about device identity. Not "who are you" — but "are you still the same entity," and "are you still in your intended state?"

The moment that question is asked, device identity stops being a name or a number and becomes a matter of capability. A device can no longer be something that merely claims an identity. It has to be something that can prove, on its own, that it is unmodified and unchanged.

PUF-Based Device Identity: Where Proof of Existence Begins

This is where the Physically Unclonable Function (PUF) becomes the starting point for device identity. A PUF doesn't rely on a secret stored inside the device — it establishes identity from physical characteristics that exist only in that specific piece of silicon. The device's identity isn't injected from outside; it's generated from the device's own physical existence.

In this structure, cloning an ID becomes equivalent to cloning the physical device itself — a practically impossible condition. And that impossibility is exactly what turns device identity from a declaration into a fact. The continuous attestation PAZI requires can only operate reliably on top of this physical anchor.

Identity Isn't Proven Once and Done

In a PAZI environment, device identity is not a static attribute. After boot, after updates, and throughout operation, a device must repeatedly demonstrate that it remains in the same verified state. Identity shifts from being a possession — something issued once — to being a state that is continuously confirmed.

This matters enormously in a QAAS environment. An attacker can no longer win by compromising a device once. The moment a device fails to maintain its verified state, its actions automatically lose trust. The device may still exist inside the system, but it can no longer act as a trusted party.

How Device Identity Neutralizes Attacks in a QAAS Environment

Attacks in a QAAS environment are built on propagation: compromise one device, then ride its trust into other systems and devices. But in a PAZI-based device identity structure, every device has to prove its own state independently.

In this structure, attacks don't spread. A breach on one device stays isolated as that one device's problem, with no effect on the trust state of any other device. This is precisely where the attacker's success condition structurally collapses.

Conclusion: In the QAAS Era, Devices Become Subjects of Trust

Devices in the QAAS era are no longer passive execution units. A device proves itself, accounts for its own state, and — if it fails to maintain that trust — is naturally excluded from the system. PAZI treats this shift not as a matter of individual technologies but as a matter of trust architecture. And at the core of that architecture sits a device identity capable of proving itself.

Frequently Asked Questions

How is PUF-based identity different from certificates or serial numbers?

Legacy IDs are assigned externally and stored on the device, which means they can be cloned, stolen, or transplanted. A PUF-based identity is generated from physical characteristics unique to that specific chip — cloning the ID would require cloning the physical device itself. It's the difference between an issued ID card and a fingerprint you're born with.

Once a device is authenticated, does its identity stay valid?

Not from a PAZI perspective. Through boot, updates, and ongoing operation, a device must repeatedly prove it remains in the same verified state. Identity is a continuously confirmed state, not a one-time possession.

If one device is hacked, are other devices on the network at risk?

In a PAZI-based structure, every device proves its own state independently, so a compromise on one device stays contained to that device. The path where an attacker "borrows" trust to move laterally is structurally closed off.

References

IEEE 802.1AR, "Secure Device Identity" — the international standard for device identity (DevID): standards.ieee.org

NIST SP 800-207, "Zero Trust Architecture" — the official document defining per-resource trust verification: csrc.nist.gov




a387ba571383e.png


CMO(Chief Marketing Officer), ICTK

CTO(Chief Technical Officer), ICTK

Director, Cisco Systems Korea 

Developer, SK Teletec


Read more






Copyright ⓒ 2025 ICTK.com. All Rights Reserved.

16, Gangnam-daero 84-gil, Gangnam-gu, Seoul, Republic of Korea (06241)

+82.2.569.0010