beginner 2 min answer Multiple choice

A gateway requires each device to prove it is running approved firmware. The device sends a signed measurement of its boot image, and the gateway verifies the signature against the device's registered key. Why is a valid signature not yet evidence that this device is trustworthy right now?

attestationtpmreplaynoncesecure-boot
Pick one
Show the full answer Hide the answer

The mechanism

A measurement is a hash of what was loaded at boot, held in hardware registers; on a TPM 2.0 part (standardised as ISO/IEC 11889:2015), the platform configuration registers, with firmware and bootloader landing in the first eight. A quote is those register values signed by a key the hardware will not release.

A quote with no challenge in it is a bearer token. Capture one from a healthy device and it verifies forever, on any number of other devices, because nothing in the bytes says when it was produced or who asked. This is how one compromised unit becomes an attestation for a thousand modified ones.

The fix is a nonce. The verifier sends 20 to 32 bytes of randomness, the hardware signs the register values together with that value, and a quote is now only acceptable in the conversation that requested it. Bind the quote to the session key as well, so the attested identity and the channel carrying the data are the same identity.

The second limit, which the nonce does not fix

Boot measurements describe what booted, not what is running. A process exploited at runtime changes no register, so the device attests perfectly while it is under someone else's control. Attestation is therefore a gate at the moment of key release, not a standing guarantee: prefer issuing a credential that expires in 15 minutes against a fresh quote, re-attest per session, and add runtime measurement of files if the threat model needs it. The cost is one extra round trip and a hardware signature per cycle, which on a constrained part is measurable energy.

Why the other options fail

  • "A hash can be reversed." Preimage resistance is not the weak point here, and the sentence confuses secrecy with freshness. The measurement is not secret; its value as evidence depends entirely on when it was produced.
  • "The vendor signed the image." Code signing proves provenance for an artefact. It says nothing about which artefact this device actually loaded, which is the question attestation exists to answer.
  • "TLS already authenticates the device." TLS proves possession of a private key. Malware running on the device possesses that key too, which is precisely why possession and integrity are separate claims.

When this is more than you need

A fleet in a physically controlled space, where the realistic threat is a misconfigured update rather than an attacker with a soldering iron, gets more safety per unit of effort from short-lived credentials and a verified boot chain than from a full attestation service. Attestation needs three things to pay off: hardware with a measured boot chain, a verifier you control, and a client that refuses to proceed when verification fails. Without the third, you have built a dashboard.