Brick · 06

Own

Device identity you hold: adoption and signed updates

Why this band exists

Owning a device means it answers to you after the company that sold it moves on. Own is mID on the chip: each ESP32 mints a P-256 did:mata into its own identity partition on first boot, publishes a signed capability manifest, and becomes yours through adoption. Updates arrive only when they are signed by the maker and addressed to that exact model.

Why now

Adoption and a signed update have run on a XIAO ESP32-S3, the device DID stayed stable across six reflashes, and a signature takes 95 ms on the chip. Development firmware still keeps the key in plain NVS; eFuse-wrapped keys and a secure element are waiting on hardware, and the plan treats that as the gate for selling devices.

How it fits

Connect binds the iroh endpoint to the DID. Flash lays out the identity partition last so a reflash never touches it. See, Hear, and Sense only answer callers the owner adopted.

Bricks in Own

Each brick is a package in the Janus family under Remade-With-Rust. Read the field note, then snap it onto the rest of the house.

  • rusty_esp_mid · replaces vendor device identity clouds

    Device did:mata, signed manifest, adoption, signed OTA

  • mID · replaces central IdP cookies

    The identity the chip speaks, verified on the host

What to build first

  1. A household roster that adopts each new device with one signature
  2. Signed OTA updates checked before a single byte is written
  3. Devices that keep their identity through every reflash