Meaning
Networked verification protocols allow one entity to confirm the integrity and configuration of a separate, distant computing platform over a network. Systems administrators use remote attestation to ensure that client devices or cloud servers are running authorized software versions before allowing them to access sensitive data. The process involves the distant platform providing a signed evidence package that includes measurements of its internal state.
This evidence is then compared against a set of known good values by the verifying party.
Evidence Collection
Hardware roots of trust generate the data required for a successful audit. During remote attestation, the target device produces a report that includes hashes of its firmware, operating system and security policies. This report is cryptographically bound to the hardware to prevent tampering during transmission.
Verification Logic
Comparison algorithms analyze the received data to determine the trustworthiness of the remote system. The verifier checks the signature of the report and confirms that the measurements in the remote attestation package match the expected baseline. If any discrepancy is found, the device is considered untrusted and its access is restricted.
Trust Establishment
Secure communication channels rely on the results of the check to protect against man in the middle attacks. By requiring remote attestation, an organization can maintain a consistent security posture across a diverse fleet of devices. This capability is necessary for managing high volume production environments where many machines must work together securely.