# SSL private key security

**URL:** <https://forum.sierrawireless.com/t/ssl-private-key-security/26071>\
**Category:** HL78\
**Created:** [January 26, 2022, 11:43am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071 "2022-01-26T11:43:27Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jakub.polonsky](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@jakub.polonsky](https://forum.sierrawireless.com/u/jakub.polonsky)\
**Post date:** [January 26, 2022, 11:43am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/1 "2022-01-26T11:43:27Z")

</div>

I have a security concern about private key storage for SSL. According to documentation, AT+KPRIVKSTORE? can be used to read back the private key for the client certificate. Isn’t this a security problem? Like anyone who gets his hands on the module (or its UART lines, to be more specific) could read back the private key. Shouldn’t the private key be write-only? Or am I missing something?

---

<div class="post-metadata">

**Author:** ![Donald](https://avatars.discourse-cdn.com/v4/letter/d/ac8455/32.png) [@Donald](https://forum.sierrawireless.com/u/Donald)\
**Post date:** [January 26, 2022, 1:13pm UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/2 "2022-01-26T13:13:59Z")

</div>

Hi jakub.polonsky,

That’s the behavior on the HL78xx. AT+KPRIVKSTORE? can be used to read back the private key for the client certificate. I don’t find any command or option to private key be write-only.

---

<div class="post-metadata">

**Author:** ![jakub.polonsky](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@jakub.polonsky](https://forum.sierrawireless.com/u/jakub.polonsky)\
**Post date:** [January 26, 2022, 1:18pm UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/3 "2022-01-26T13:18:47Z")

</div>

OK, thank you for confirmation. It does not feel very secure. If we ship the product, then with some not-so-hard reverse engineering, the private key can be obtained. I know we should generate unique key for every device so only one can become compromised at a time but still…  
Can I propose a feature that would prevent readout of the private key? For example a separate AT command that will block the readout until the key is overwritten or erased. Similar to a readout protection of a typical MCU.

---

<div class="post-metadata">

**Author:** ![Donald](https://avatars.discourse-cdn.com/v4/letter/d/ac8455/32.png) [@Donald](https://forum.sierrawireless.com/u/Donald)\
**Post date:** [January 28, 2022, 10:20am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/4 "2022-01-28T10:20:57Z")

</div>

Hi jakub.polonsky ,

Please contact your distributor directly to propose a feature.

---

<div class="post-metadata">

**Author:** ![EllyMusiay](https://avatars.discourse-cdn.com/v4/letter/e/8e8cbc/32.png) [@EllyMusiay](https://forum.sierrawireless.com/u/EllyMusiay)\
**Post date:** [June 10, 2025, 7:57am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/5 "2025-06-10T07:57:01Z")

</div>

Yes, that’s a valid concern. Ideally, the private key should be write-only to prevent exposure. If AT+KPRIVKSTORE? allows reading it back, then anyone with UART access could extract it, which is a security risk. Best practice is to disable read-back or use a secure element that enforces key confidentiality.

---

<div class="post-metadata">

**Author:** ![imran.sarwar](https://avatars.discourse-cdn.com/v4/letter/i/ce7236/32.png) [@imran.sarwar](https://forum.sierrawireless.com/u/imran.sarwar)\
**Post date:** [August 25, 2026, 1:12pm UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/6 "2026-08-25T13:12:35Z")

</div>

Hi,

I wanted to ask about secure element, it is mentioned for the modules HL7900 and HL7900E (in their product overview pages) that they have secure element, but I have not found it in the documentation available for these modules.

Can you specify which document has information and details about it or provide me with such a document ?

I have looked into:

- HL7900 AT Command Guide
- Product Technical Specification HL7900/HL7900E
- Cybersecurity Design Guidelines for Module Integration 2174395-Rev 2

But I could not find “secure element” specifically mentioned in any of these documents.

Kindly feedback.

Thanks,  
Imran

---

<div class="post-metadata">

**Author:** ![jyijyi](https://sea1.discourse-cdn.com/flex025/user_avatar/forum.sierrawireless.com/jyijyi/32/4766_2.png) [@jyijyi](https://forum.sierrawireless.com/u/jyijyi)\
**Post date:** [August 25, 2026, 1:26pm UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/7 "2026-08-25T13:26:50Z")

</div>

How about at+kcertstore command for ssl communication?

I remember the firmware has secure boot feature, so only signed firmware can be downloaded to the module

---

<div class="post-metadata">

**Author:** ![imran.sarwar](https://avatars.discourse-cdn.com/v4/letter/i/ce7236/32.png) [@imran.sarwar](https://forum.sierrawireless.com/u/imran.sarwar)\
**Post date:** [August 26, 2026, 9:40am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/8 "2026-08-26T09:40:26Z")

</div>

What I want to confirm is that does HL7900 module provide built in “secure element” or it is provided separately ?

---

<div class="post-metadata">

**Author:** ![jyijyi](https://sea1.discourse-cdn.com/flex025/user_avatar/forum.sierrawireless.com/jyijyi/32/4766_2.png) [@jyijyi](https://forum.sierrawireless.com/u/jyijyi)\
**Post date:** [August 26, 2026, 9:46am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/9 "2026-08-26T09:46:36Z")

</div>

can you be more specific that what feature are you asking actually?

---

<div class="post-metadata">

**Author:** ![imran.sarwar](https://avatars.discourse-cdn.com/v4/letter/i/ce7236/32.png) [@imran.sarwar](https://forum.sierrawireless.com/u/imran.sarwar)\
**Post date:** [August 26, 2026, 9:54am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/10 "2026-08-26T09:54:01Z")

</div>

Sir, I am talking about “secure element” for HL7900 module as its page says, “Security keys encrypted are stored in a secure element.” So I am interested in knowing where it is documented, similarly I also want the related document for “secure boot” ?

---

<div class="post-metadata">

**Author:** ![jyijyi](https://sea1.discourse-cdn.com/flex025/user_avatar/forum.sierrawireless.com/jyijyi/32/4766_2.png) [@jyijyi](https://forum.sierrawireless.com/u/jyijyi)\
**Post date:** [August 26, 2026, 9:58am UTC](https://forum.sierrawireless.com/t/ssl-private-key-security/26071/11 "2026-08-26T09:58:09Z")

</div>

i don’t see there is specific application note that is talking about this “secure element” or “secure boot”

But if you are talking about SSL communication, you can see AT command user guide for at+kcertstore command

For secure boot, it means the official firmware is signed by Sierra, you cannot download any other modem firmware to it for security concern.
