Anyway, even provided someone could conceive a real implementation, there are still the same issues we've seen with signed OSes (Trusted Boot) and signed device drivers in Windows:
Who gets to be a root CA for peripheral software? How do small/homebrew manufacturers get approved? How does the CA verify the legitimacy of the people they're issuing certs to? How do compromised certs get revoked? What happens when the cert for a legitimate device gets stolen? What if nobody wants to pay for a cert for their crappy fly-by-night flash drives, and users learn to "just click Install?"
1) Getting a (legitimate) USB vendor ID is already a big barrier to entry for smaller players in the hardware business. The USB Forum is basically a cartel of people who aren't interested in selling you a product ID unless you want to buy 65,536 of them at once for thousands of dollars. Then there's the expensive kernel-mode code signing certificate that you'll have to buy in order to deploy your Windows driver. The world needs fewer crypto-cartels, not more.
2) It's always been accepted as a truism that once an attacker has physical access to your computer, the security game is over. Why is everyone rushing to discard this axiom all of a sudden? Don't people understand that this will lead to a world where your computer relies on third-party gatekeepers to treat you as a security threat?