Secure Push Attestation with Extensible REST APIs
K.4.401 | Day 2 | 10:50 - 11:20 | Speakers: Jean Snyman
Abstract
Until now, the Keylime attestation software has operated on a pull basis: requiring open ports on each attesting node so the verifier can request evidence at a set interval. A new push mode developed by the community brings a number of advantages and presents new opportunities for the project in areas such as extensibility, containerisation and even confidential computing.
In this talk, we will take a whirlwind tour of the new REST-based APIs and how these are composed to achieve a robust security result. We will discuss the challenges of managing state in a multi-phase HTTP protocol and building resilience in the presence of misbehaving clients. Attendees will hear how these changes open the door for increased integration in the wider ecosystem and our vision for the future of attestation.
Attachments
Speakers
External Links
Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.
