SEDAT:Security Enhanced Device Attestation with TPM2.0
Avani Dave, Monty Wiseman, David Safford

TL;DR
SEDAT introduces a secure, comprehensive remote attestation method utilizing TPM2.0, enhancing hardware, firmware, and software verification with protection against replay and DoS attacks through a novel communication protocol.
Contribution
It is the first to implement end-to-end hardware, firmware, and software remote attestation using TPM2.0 with enhanced security features and log representation in CEL format.
Findings
Secure communication via SPA protects against replay and DoS attacks.
Enables detection of counterfeit hardware and firmware modifications.
Supports retrieval and validation of TPM2.0 quotes for attestation.
Abstract
Remote attestation is one of the ways to verify the state of an untrusted device. Earlier research has attempted remote verification of a devices' state using hardware, software, or hybrid approaches. Majority of them have used Attestation Key as a hardware root of trust, which does not detect hardware modification or counterfeit issues. In addition, they do not have a secure communication channel between verifier and prover, which makes them susceptible to modern security attacks. This paper presents SEDAT, a novel methodology for remote attestation of the device via a security enhanced communication channel. SEDAT performs hardware, firmware, and software attestation. SEDAT enhances the communication protocol security between verifier and prover by using the Single Packet Authorization (SPA) technique, which provides replay and Denial of Service (DoS) protection. SEDAT provides a way…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSecurity and Verification in Computing · Physical Unclonable Functions (PUFs) and Hardware Security · Cloud Data Security Solutions
