K-0004

Remote attestation

A process in which a device sends signed evidence about its state, such as software measurements, so a remote party can judge its trustworthiness.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

Remote attestation is a process in which a device produces evidence about its own state, signed with keys it protects, so that a remote party can decide whether to consider it trustworthy S-1603 S-1600.

The IETF RATS architecture names three roles:

  • Attester. It produces evidence: claims that may include configuration data, measurements and telemetry, typically signed with its key material S-1603.
  • Verifier. It appraises the evidence against reference values and an appraisal policy, and produces attestation results S-1603.
  • Relying party. It uses the results to decide whether to treat the attester as trustworthy S-1603.

In the Trusted Computing Group's model, a root of trust for reporting gives attested platform characteristics their authenticity and non-repudiation S-1602. A nonce sent by the appraising party and signed into the evidence shows that the evidence is fresh rather than replayed S-1603. Attestation is distinct from isolation. A trusted execution environment protects a workload, while attestation lets a remote party check what a genuine TEE loaded, and confidential computing requires both S-1604. In AI verification, attestation underlies TEE remote attestation for AI workloads and chip location verification. For location, Scher and Thiergart note that if the chip's private key were extracted, its location could be spoofed S-0005.

Connections in the research map

Related research

Sources and provenance

  1. S-1603 / Tier B

    Remote ATtestation procedureS (RATS) Architecture (RFC 9334) ↗

    H. Birkholz, D. Thaler, M. Richardson, N. Smith, W. Pan · 2023 · Internet Engineering Task Force (RATS Working Group)

    Supports: purpose of attestation; Attester, Evidence, Verifier, Relying Party, Attestation Result; evidence generated with key material; nonces for freshness

    Locator: §1; §3.1; §4; §10.2

    Version and catalogue details
  2. S-1600 / Tier A

    NIST Computer Security Resource Center (CSRC) Glossary ↗

    National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center

    Supports: NIST definition of attestation as signing measurements securely stored in hardware, which the requester validates

    Locator: term: attestation (NIST SP 1800-19B)

    Version and catalogue details
  3. S-1602 / Tier B

    TCG Glossary ↗

    Trusted Computing Group · 2017 · Trusted Computing Group

    Supports: Root of Trust for Reporting provides authenticity and non-repudiation when attesting to platform characteristics

    Locator: p. 9

    Version and catalogue details
  4. S-1604 / Tier B

    Common Terminology for Confidential Computing ↗

    Confidential Computing Consortium · 2022 · Confidential Computing Consortium

    Supports: attestability as an optional TEE attribute that confidential computing requires; attestation as validation of a hardware-signed report of TCB measurements

    Locator: TEE attributes; attestation

    Version and catalogue details
  5. S-0005 / Tier B

    Mechanisms to Verify International Agreements About AI Development ↗

    A. Scher, L. Thiergart · 2025 · arXiv

    Supports: an extracted private key would let a chip's location be spoofed

    Locator: On-chip mechanisms for location verification

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review