--- type: concept tags: [parking, security, crypto, access-control] sources: [parking-system-architecture] updated: 2026-06-14 --- # Challenge–Response Auth (asymmetric signatures) The authentication scheme for the [[esp32-custom-controller]]. Closes the actual hole in the [[uhppote-udp-protocol]]: **forged or replayed commands**. The requirement is **authenticity + freshness (anti-replay)**; encryption is optional. (See [[parking-system-architecture]] §7.) ``` Host (private key) ESP32 (host's PUBLIC key only) │── "open lane 2" ──────────────────▶│ generates fresh random nonce │◀──────────── nonce ─────────────────│ │ sign(nonce ‖ command ‖ ts) ────────▶│ verify vs stored public key │ │ check nonce fresh + unused → pulse relay ``` ## The elegant property The controller stores **only a public key**. Physically compromising the ESP32 (popping the cabinet, dumping flash via the [[atecc608]]) yields **nothing usable for forging commands**. The fresh per-command **nonce** defeats replay without counter-persistence headaches. A shared-secret / encrypted channel would **not** have this property — the secret would sit on both ends. That's why authentication (not encryption) is the right build here.