| Abstract | Verification of integrity states via attestation enhances the overall security for different types of devices. Networks with heterogeneous devices that are capable of executing attestation with different technologies like Trusted Platform Module (TPM), Trusted Execution Environment (TEE), ARM TrustZone and attestation protocols, require continuous integrity verification to determine trust in an entire network. This results in additional costs for the development and operation of individual services for each technology. Existing solutions either support only single technologies, such as Keylime with a TPM-only solution, or are proprietary, such as Microsoft Azure Attestation (MAA). In this work, we introduce an abstract attestation model that covers the main principles for verification of devices with different attestation technologies. Because integrity must be validated continuously and for a long period of time, a high number and frequency of attestations is required to ensure the integrity of a device and to determine an entire network as trustworthy. To accomplish this objective, we define an abstract model for attestation protocols and technologies, to introduce concepts for the continuous attestation of devices. We present a modular attestation service with a technology-independent abstraction layer supporting various attestation protocols, with a queue-based architecture enabling continuous, scalable re-attestation. We will compare our concept to different existing solutions and demonstrate advantages of our approach. |
|---|