As part of #203 we have the following point of investigation: ASVS/MASVS: Consider using asymmetric cryptography for authentication and authorization purposes. Generate and use the private key directly within a platform supported secure hardware (e.g., Trusted Execution Environment (TEE), Secure Element (SE)).
Can we try to collaborate with the ASVS team and set something up for strong device authentication in terms of requirements based on asymmetric keys used for challenge-response mechanisms to authenticate devices?