Semantic Remote Attestation is a promising approach for establishing trust in remote systems. In its simplest form an appraiser makes a request for an attestation to a target; the target returns evidence of its state; and the appraiser makes a determination about the attester and its target. In essence, remote attestation evaluates the expectedness of a remote system.
Over the past decade we have engaged with our colleagues in developing a semantic basis for remote attestation and realizing that semantics in operational tools. We now find ourselves in a position to make significant strides towards systematic design, analysis and implementation of layered attestation systems. Three major research topics are being investigated:
- Evidence and Time - A semantics of evidence over time that allows predictions about the effectiveness of attestation evidence in appraising systems.
- Flexible Mechanisms at Scale - A semantics for appraisal architectures and its realization as a collection of reusable attestation components and tools for static analysis.
- Empirical Case Studies - Large scale empirical studies of defining, implementing, and running attestation architectures with applications in supply chain and zero trust.
Our research program will put layered attestation on a firm semantic basis while providing semantically sound techniques, languages and tools that allow others to successfully field complex attestation systems.