01 / The mechanism and its boundary
What is being described
Remote attestation is a process in which a device produces evidence about its own state, signed with keys it protects, so that a remote party can decide whether to consider it trustworthy S-1603 S-1600.
The IETF RATS architecture names three roles:
- Attester. It produces evidence: claims that may include configuration data, measurements and telemetry, typically signed with its key material S-1603.
- Verifier. It appraises the evidence against reference values and an appraisal policy, and produces attestation results S-1603.
- Relying party. It uses the results to decide whether to treat the attester as trustworthy S-1603.
In the Trusted Computing Group's model, a root of trust for reporting gives attested platform characteristics their authenticity and non-repudiation S-1602. A nonce sent by the appraising party and signed into the evidence shows that the evidence is fresh rather than replayed S-1603. Attestation is distinct from isolation. A trusted execution environment protects a workload, while attestation lets a remote party check what a genuine TEE loaded, and confidential computing requires both S-1604. In AI verification, attestation underlies TEE remote attestation for AI workloads and chip location verification. For location, Scher and Thiergart note that if the chip's private key were extracted, its location could be spoofed S-0005.
Connections in the research map
Related research
Sources and provenance
- S-1603 / Tier B
Remote ATtestation procedureS (RATS) Architecture (RFC 9334) ↗
H. Birkholz, D. Thaler, M. Richardson, N. Smith, W. Pan · 2023 · Internet Engineering Task Force (RATS Working Group)
Supports: purpose of attestation; Attester, Evidence, Verifier, Relying Party, Attestation Result; evidence generated with key material; nonces for freshness
Locator: §1; §3.1; §4; §10.2
Version and catalogue details - S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: NIST definition of attestation as signing measurements securely stored in hardware, which the requester validates
Locator: term: attestation (NIST SP 1800-19B)
Version and catalogue details - S-1602 / Tier B
TCG Glossary ↗
Trusted Computing Group · 2017 · Trusted Computing Group
Supports: Root of Trust for Reporting provides authenticity and non-repudiation when attesting to platform characteristics
Locator: p. 9
Version and catalogue details - S-1604 / Tier B
Common Terminology for Confidential Computing ↗
Confidential Computing Consortium · 2022 · Confidential Computing Consortium
Supports: attestability as an optional TEE attribute that confidential computing requires; attestation as validation of a hardware-signed report of TCB measurements
Locator: TEE attributes; attestation
Version and catalogue details - S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: an extracted private key would let a chip's location be spoofed
Locator: On-chip mechanisms for location verification
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review