About Us Our Work Employment News & Events
MITRE Remote Access for MITRE Employees Site Map
Our Work
Share this page

Follow Us On:

Visit MITRE on Facebook
Visit MITRE on Twitter
Visit MITRE on YouTube
View MITRE's RSS Feeds
Home > Our Work > Technical Papers >

Attestation: Evidence and Trust

March 2007

Justin Sheehy, The MITRE Corporation
George Coker, National Security Agency
Joshua Guttman, The MITRE Corporation
Peter Loscocco, National Security Agency
Amy Herzog, The MITRE Corporation
Jon Millen, The MITRE Corporation
Leonard Monk, The MITRE Corporation
John Ramsdell, The MITRE Corporation
Brian Sniffen, The MITRE Corporation

ABSTRACT

Attestation is the activity of making a claim about properties of a target by supplying evidence to an appraiser. An open-ended framework for attestation is desirable for safe support to sensitive or highvalue activities on heterogeneous networks.

We identify five central principles to guide development of attestation systems. We argue that (i) attestation must be able to deliver temporally fresh evidence; (ii) comprehensive information about the target should be accessible; (iii) the target, or its owner, should be able to constrain disclosure of information about the target; (iv) attestation claims should have explicit semantics to allow decisions to depend on several claims; and (v) the underlying attestation mechanism must be trustworthy.

We propose an architecture for attestation that is guided by these principles, as well as an implementation that adheres to this architecture. Virtualized platforms, which are increasingly well supported on stock hardware, provide a natural basis for our attestation architecture.

» Download Paper [PDF, 440KB]

Additional Search Keywords

N/A

 

Page last updated: September 17, 2008   |   Top of page

Homeland Security Center Center for Enterprise Modernization Command, Control, Communications and Intelligence Center Center for Advanced Aviation System Development

 
 
 

Serving as Architects of Information Advantage.™
Copyright © 1997-2009, The MITRE Corporation. All rights reserved.
MITRE is a registered trademark of The MITRE Corporation.
Material on this site may be copied and distributed with permission only.

MITRE Named to FORTUNE's "100 Best Companies to Work For" List for Eighth Straight Year MITRE Named to "Best Places to Work in IT" List for Fifth Consecutive Year
 

Privacy Policy | Contact Us