> How do we ascertain that it is, in fact, running on tamper-proof > hardware? You engage in a challenge/response protocol with the tamperproof card. How the card verifies that a proper OS is running on proper hardware is something I cannot comment on at this time. Jonathan S. Shapiro, Ph. D. IBM T.J. Watson Research Center Email: shapj@us.ibm.com Phone: +1 914 784 7085 (Tieline: 863) Fax: +1 914 784 7595