[Notes] Designing Trustworthy Layered Attestations
Designing Trustworthy Layered Attestations discusses how the attestation mechanism itself as part of the threat model in attested systems.
Protecting an attestation signing key against extraction is insufficient if a compromised component can still invoke it to endorse fabricated evidence. The authors propose TPM policy and locality-based authorization, and recommend Linux/SELinux changes to bind TPM commands to particular security contexts. Similarly, moving LKIM outside the kernel being measured can remove problematic cyclic trust relationships between measurer and measured system.
This generalizes nicely beyond runtime attestation. For example, for attested builds (see Kettle), a constrained builder with bounded inputs, short-lived workers, limited interactions, and policy-enforced execution is fundamentally easier to make meaningful claims about than a generic CI runner supporting arbitrary execution and persistent state.
Readers interested in this topic may also find the Framework for Continuous Remote Attestation draft a useful read.