Techniques relating to cryptographic
key exchange operations are disclosed. In some embodiments, a computing device includes a cryptographic circuit coupled to a secure memory to which the computing device's processor has no access. Program instructions executed on the computing device can request a
key exchange to establish a
shared secret with another device. The cryptographic circuit is configured to perform the
key exchange, including deriving the
shared secret using private key material held in the secure memory.In some embodiments, the key exchange includes verifying a key
authorization data structure issued by a key
authorization instance, comprising a first public key of a first participant
authorization instance and a second public key of a second participant authorization instance. Upon successful
verification, the exchange uses a public key pair attested by the first participant authorization instance as belonging to a member of the first device group.