Presence Attestation: The Missing Link in Dynamic Trust Bootstrapping
Zhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui, Zhoujun Li
Abstract
Many popular modern processors include an important hardware security feature in the form of a DRTM (Dynamic Root of Trust for Measurement) that helps bootstrap trust and resists software attacks. However, despite substantial body of prior research on trust establishment, security of DRTM was treated without involvement of the human user, who represents a vital missing link. The basic challenge is: how can a human user determine whether an expected DRTM is currently active on her device? In this paper, we define the notion of "presence attestation", which is based on mandatory, though minimal, user participation. We present three concrete presence attestation schemes: sightbased, location-based and scene-based. They vary in terms of security and usability features, and are suitable for different application contexts. After analyzing their security, we assess their usability and performance based on prototype implementations. KEYWORDS trusted computing, attestation, dynamic root of trust, human-inthe-loop, device I/O * The work was mainly done when the author visited SMU as a student intern. 1 We slightly expand the notion of DRTM as TrustZone functions differently from the TXT and SVM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b7efb73d-b9d2-4e1d-93b9-43f372db7aadCited by top-tier papers3
- CACTI: Captcha Avoidance via Client-side TEE IntegrationYoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene TsudikUSENIX Security 2021 · 11 citations
- Oblivious Digital TokensMihael Liskij, Xuhua Ding, Gene Tsudik, David A. BasinUSENIX Security 2025
- VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer RequestsScott Jordan, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd et al.NDSS 2023
Builds on2
Related papers
- Caveat (IoT) Emptor: Towards Transparency of IoT Device PresenceSashidhar Jakkamsetti, Youngil Kim, Gene TsudikCCS 2023 · 5 citations
- TrustWeave: Integrity Measurement and Attestation For Multi-Cloud LLMsJianchang Su, Wenhui Zhang, Yifan Zhang, Kexin Chu et al.EuroSys 2026
- PISTIS: Trusted Computing Architecture for Low-end Embedded SystemsMichele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno CrispoUSENIX Security 2022
- A Bad Dream: Subverting Trusted Platform Module While You Are SleepingSeunghun Han, Wook Shin, Jun-Hyeok Park, Hyoung-Chun KimUSENIX Security 2018 · 34 citations
- OPERA: Open Remote Attestation for Intel's Secure EnclavesGuoxing Chen, Yinqian Zhang, Ten-Hwang LaiCCS 2019 · 67 citations
