The security wouldn't need to be perfect. Even something simple would be sufficient to deter an unscrupulous reseller.
The security wouldn't need to be perfect. Even something simple would be sufficient to deter an unscrupulous reseller.
If I were concerned about counterfeit things, in an application like this, you would pre program each one with a unique key and everything would be tied to it. Firmware upgrades need to be validated, to download, you would need the key, run the software, key needs to sign something back… etc.
But the original would have to see it coming and put this in the design, AND maintain a registry of all the valid chip serials. No hobbyist wants that headache.
Since the key is unique to the device, it can easily be disavowed in the central database if a device does become compromised. Anything less than this is probably a few hours from being completely broken. And this scheme can be broken by non-state actors, especially if the private key storage is naively or poorly implemented. Many MCUs have multiple levels of readout protection and it can be easy to misconfigure. A single mistake in memory mapping could expose information on external interfaces. And then you’re trying to do all of this in China, on the cheap. Pack a lunch.
Anyway, there's a litany of similar devices to fill whatever requirements you wish. SIM cards, for instance, are available in WSON8 MFF2 chips that you can directly solder to a board.
A SIM card is just one way to do exactly what I described. It’s expensive and probable not a good choice for small, cheap devices. Not to mention brings along a whole host of associated security complexity.
With the customer as a willing participant such things are hard to subvert.
If you had such a chip, who would check it for authenticity? That check would need to be well secured, so likely not the ARM firmware on the nanovna itself.
Possibly not nanoVNA-saver: the unscrupulous supplier might just include an unlabeled CDR with patched software.