Self-Certifying Devices: Proof of Safety You Can Verify in a Millisecond

The thesis
Trust in medical devices today rests on paper: a certificate in a binder, a sticker, a serial number, and faith that the firmware in the field matches the one that was approved. In a world of connected, updatable devices, faith is not a security model.
Make the device prove itself
Every device carries a cryptographic passport: signed attestations of its firmware hash, calibration state, approval scope and maintenance history. Before it is used, a clinician's system verifies the proof in milliseconds — is this firmware the approved one? Is calibration current? Is it operating inside its cleared indication? A tampered or drifted device simply fails verification.
What this kills
- Silent firmware tampering and counterfeit components.
- "Off-label by accident" — the device refuses to operate outside its cleared scope.
- Recall chaos — you can cryptographically identify every affected unit instantly.
The standard needed
A shared attestation format (a "device SBOM + calibration receipt") that manufacturers sign and hospitals verify — think TLS certificates, but for physical safety.
Provocation
We would never trust a website whose identity couldn't be verified. Why do we trust a machine wired to a human heart on the strength of a laminated card? Verifiable devices are how the field grows up.
A first-principles provocation from the Anxya Health Futures desk. Directional and informational — not medical, legal, financial or regulatory advice. The point is to move the debate, then do the hard validation work.