Nowadays, various contexts and applications include IoT devices. Due to their limited resources and power constraints, these systems are a possible threat vector that adversaries may exploit for cyberattacks. Despite the protection of network communication with Secure Channels, such as TLS and IPsec, the endpoint with which we exchange information may still be compromised. Thus, an adversary may obtain access to sensitive information or send corrupted data without being detected by the other network nodes. Remote Attestation is a possible security control that can detect device misbehaviours, allowing an external entity to verify a platform’s trustworthiness. Attestation reports contain system measures and configuration information to prove the system state. So, the external entity can verify the platform’s authenticity and integrity by comparing the data included in the report with the corresponding expected values. Several solutions addressing this issue are presented in the literature, including Remote Attestation over secure channels. Trusted Channels is the name given to these protocols, as the trustworthiness of the endpoints is a security property guaranteed by the Channel, in addition to the properties of a secure channel. This paper proposes a new certification protocol for IoT devices that merges Remote Attestation with the issuance of a certificate for a key pair generated and stored securely on the platform. This new credential enables the establishment of TLS channels; therefore, the other endpoint obtains information about the node’s trustworthiness. We implemented the protocol within the Keystone framework, which enables a customisable Trusted Execution Environment that provides the Remote Attestation mechanism.

Implicit end-point attestation for trusted channel establishment in the keystone TEE / Bruno, G., Sisinni, S., Bravi, E., Ferro, L., Ciravegna, F., Lioy, A.. - In: COMPUTER NETWORKS. - ISSN 1389-1286. - 288:(2026). [10.1016/j.comnet.2026.112603]

Implicit end-point attestation for trusted channel establishment in the keystone TEE

Bruno, Giacomo;Sisinni, Silvia;Bravi, Enrico;Ferro, Lorenzo;Ciravegna, Flavio;Lioy, Antonio
2026

Abstract

Nowadays, various contexts and applications include IoT devices. Due to their limited resources and power constraints, these systems are a possible threat vector that adversaries may exploit for cyberattacks. Despite the protection of network communication with Secure Channels, such as TLS and IPsec, the endpoint with which we exchange information may still be compromised. Thus, an adversary may obtain access to sensitive information or send corrupted data without being detected by the other network nodes. Remote Attestation is a possible security control that can detect device misbehaviours, allowing an external entity to verify a platform’s trustworthiness. Attestation reports contain system measures and configuration information to prove the system state. So, the external entity can verify the platform’s authenticity and integrity by comparing the data included in the report with the corresponding expected values. Several solutions addressing this issue are presented in the literature, including Remote Attestation over secure channels. Trusted Channels is the name given to these protocols, as the trustworthiness of the endpoints is a security property guaranteed by the Channel, in addition to the properties of a secure channel. This paper proposes a new certification protocol for IoT devices that merges Remote Attestation with the issuance of a certificate for a key pair generated and stored securely on the platform. This new credential enables the establishment of TLS channels; therefore, the other endpoint obtains information about the node’s trustworthiness. We implemented the protocol within the Keystone framework, which enables a customisable Trusted Execution Environment that provides the Remote Attestation mechanism.
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S1389128626006158-main.pdf

accesso aperto

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Creative commons
Dimensione 1.51 MB
Formato Adobe PDF
1.51 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3013770