Edge Security & Attestation
Secure boot, hardware roots of trust, and proving what is running on a device.
4 to work through
-
beginner Multiple choice
A gateway requires each device to prove it is running approved firmware. The device sends a signed measurement of its boot image, and the gateway verifies the signature against the device's registered key. Why is a valid signature not yet evidence that this device is trustworthy right now?
2 min answer -
advanced
An attacker has physical possession of one of your devices. What should they be able to obtain, and what protects the rest of the fleet?
2 min answer -
advanced
How do you establish that code running on a remote device or accelerator is what you deployed?
2 min answer -
advanced
In June 2024 Apple described Private Cloud Compute, where a user's device will only send a request to a server node that cryptographically attests to running a specific software image, and the device checks that measurement against a public append-only transparency log before sending anything. What problem does this solve that signed code and audits do not, what does it cost, and where would copying it be a mistake?
3 min answer
4 terms in this topic
Attestation Freshness
The property that a hardware attestation can only be used in the exchange that requested it - without which a captured measurement is a reusable bear…
patternAttestation Transparency Log
A public append-only log of every software measurement a fleet is allowed to run, checked by the client before it sends data, which removes the possi…
conceptEdge Security and Attestation
Establishing that a device is running expected software and has not been tampered with — the trust foundation when you do not control the physical en…
protocolSecure Boot Chain
Each boot stage verifying the signature of the next before executing it, anchored in immutable hardware, so only authorised software runs.
Neighbouring topics
Edge, Mobile & IoT
General material on architecture beyond the data centre boundary.
Mobile App Architecture
Layering, navigation, background execution, and the platform rules you do not set.
Offline-First
Treating connectivity as an optimisation, with a local store as the source of truth.
Sync & Conflict Resolution
Two devices that both changed the same record while neither could see the other.
CRDTs
Data types that converge without coordination, and the semantics you must accept.
Mobile Release Strategy
Store review, staged rollout, and supporting versions you can never force off.
Push & Background Work
Delivery that is best-effort, and an operating system that will kill your process.
Device Identity
Identifying a thing rather than a person, and rotating a credential you cannot type.
Edge Compute Topologies
Regional, metro, on-premises and on-device, and what each tier is genuinely for.
Edge Functions
Short-lived compute at the CDN, its runtime limits, and what must stay at origin.
Edge Data Consistency
Replicated read state at hundreds of locations, and writes that still go to one.
IoT Ingest Architecture
Millions of small, unreliable, frequently duplicated messages arriving continuously.
Device Provisioning
Getting identity and configuration onto hardware at manufacture or first boot.
Fleet Management
Inventory, health, configuration and grouping across devices you will never see.
OTA Updates
Updating firmware over a flaky link, with rollback, and without bricking the device.
Constrained Protocols
MQTT, CoAP and their kin, chosen for power, packet size and intermittent links.
Device Telemetry at Scale
Deciding what a device sends, how often, and what is aggregated before it leaves.
Digital Twin
A server-side model of a physical thing's reported and desired state.
Physical-World Failure Modes
Power loss, tampering, clock drift, thermal limits, and a truck through the fibre.