5 ms·
Can some ELI5 how remote attestation is supposed to work? It feels like asking a remote endpoint “are you who you say you are”. What’s stopping remote endpoint
by cherioo 2y ago
Can some ELI5 how remote attestation is supposed to work? It feels like asking a remote endpoint “are you who you say you are”. What’s stopping remote endpoint always responding “yes”
- davidczech 2y agoServers send signed statements describing its state, and clients make the yes/no determination.
- transpute 2y ago> What’s stopping remote endpoint always responding “yes” It requires a small, trusted remote observer hardware component, e.g. TCG TPM/DICE, Apple Secure Enclave, Google OpenTitan, Microsoft Pluton. 2021 literature review, https://arxiv.org/abs/2105.02466 https://arxiv.org/abs/2105.02466 2022 HN thread on remote attestation, https://news.ycombinator.com/item?id=32282305 https://news.ycombinator.com/item?id=32282305
- wyes 2y agoThey rely on Trusted Execution Environments and the fact that hash functions are one-way functions. Verifier -> requests a Prover to attest its software state Prover -> goes into RoT, verifies authenticity of Verifier (and request), computes hash of attested memory region, sends hash digest Verifier -> receives digest and compares to known hash > What’s stopping remote endpoint always responding “yes” The attestation code is inside of a RoT, so a bad actor shouldn't be able to call this code, only callable by receiving a request from a Verifier
- GrantMoyer 2y agoMy understanding is that it's similar to TLS authentication. The remote endpoint has special hardware which keeps secret signing keys (similar to a TLS server's signing keys). The hardware refuses to reveal the private keys, but will sign certain payloads under certain conditions. In addition, Intel or AMD or whoever also has super duper mega secret master keys (similar to a CA's signing keys), which they use to sign the device's signing keys. The certificate signing the device keys is also stored on the device. So, each time the endpoint is asked to attest its software, it says yes and signs its response with its keys, and it also sends a certificate showing its keys are signed by the master key. That way, the client knows the special hardware really said yes and that Intel or AMD or whoever said that particular special hardware is legit.