On device clients should preferrably use a HSM device to store / generate keys. We need proof of concept code for this so others can implement it securely and easily.