01 / The mechanism and its boundary
What is being described
A root of trust is a hardware, firmware or software element that forms the basis of security functions such as measurement, storage, reporting, recovery, verification and update, and that must always behave as expected because its misbehaviour cannot be detected S-1601 S-1600.
It is typically the first element in a chain of trust and anchors more complex functions built on it S-1601. Because it is trusted by assumption, it must be secure by design S-1600. The Trusted Computing Group distinguishes a root of trust for measurement, which makes the first integrity measurement and adds it to a tamper-resistant log, from a root of trust for reporting, which vouches for platform characteristics during remote attestation S-1602. Shavit's framework needs hardware roots of trust on ML chips, and calls for open-source designs so that independent verifiers can check them for backdoors S-0029. A 2026 MIRI Technical Governance Team post on TEE-based attestation calls key provenance the most difficult part of TEE hardware to accept, because a few hardware vendors generated the keys and fused them onto the chips, and whoever holds a hardware key or can certify one can in principle produce valid attestation reports S-0014.
Connections in the research map
Related research
Sources and provenance
- S-1601 / Tier A
Platform Firmware Resiliency Guidelines (NIST SP 800-193) ↗
A. Regenscheid · 2018 · National Institute of Standards and Technology
Supports: definition of RoT and its security-specific functions; must always behave as expected because its misbehaviour cannot be detected; first element of a chain of trust anchoring more complex functionality
Locator: §3.3, pp. 11–12
Version and catalogue details - S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: roots of trust as highly reliable hardware, firmware and software components that must be secure by design
Locator: term: roots_of_trust (NIST SP 800-172r3; NISTIR 8320)
Version and catalogue details - S-1602 / Tier B
TCG Glossary ↗
Trusted Computing Group · 2017 · Trusted Computing Group
Supports: RTM and RTR definitions
Locator: p. 9
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: hardware roots of trust on ML chips; open-source RoT designs so verifiers can check for backdoors
Locator: §6.2
Version and catalogue details - S-0014 / Tier C
On TEEs for Privacy-Preserving Monitoring in AI Governance ↗
Gloria Z · 2026 · MIRI Technical Governance Team
Supports: key provenance as the most difficult part of TEE hardware to accept; vendors generate and fuse keys; holder or certifier of a hardware key can produce valid attestation reports
Locator: Limitations
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review