Skip to content
iadgovuser26 edited this page Aug 27, 2024 · 5 revisions

Host Integrity at Runtime and Start-up (HIRS) Attestation Certificate Authority (ACA)

TPM Provisioning with Trusted Computing based Supply Chain Validation

The Host Integrity at Runtime and Start-up Attestation Certificate Authority is a Proof of Concept - Prototype intended to spur interest and adoption of the Trusted Platform Module (TPM). Its intended for testing and development purposes only and is not intended for operational use.

The ACA main function is to create an Attestation Identity Credential for a device holding a TPM. There are a few policy options that the ACA Portal will support:

  • Validation of the TPM's Endorsement or Platform Credentials
  • Validate the Endorsement Credential (typical PKI Cert validation: signatures, expiration dates, etc.)
  • Validate the Platform Credential (same basic certificate validation as the Endorsement Credential)
  • Check Platform Credential parameters against the device holding the TPM.
  • Check Firmware measurements provided by the OEM against the eventLog created by device startup.

Please use the menu on the rightmost column to navigate the HIRS wiki pages.