Skip to main content

Secure Push Attestation with Extensible REST APIs

K.4.401 | Day 2 | 10:50 - 11:20 | Speakers: Jean Snyman

Secure Push Attestation with Extensible REST APIs
A picture of a devroom at FOSDEM 2024

Stream opens at 10:50 (Europe/Brussels)

Get involved in the conversation!Join the chat

Notes

Abstract

Until now, the Keylime attestation software has operated on a pull basis: requiring open ports on each attesting node so the verifier can request evidence at a set interval. A new push mode developed by the community brings a number of advantages and presents new opportunities for the project in areas such as extensibility, containerisation and even confidential computing.

In this talk, we will take a whirlwind tour of the new REST-based APIs and how these are composed to achieve a robust security result. We will discuss the challenges of managing state in a multi-phase HTTP protocol and building resilience in the presence of misbehaving clients. Attendees will hear how these changes open the door for increased integration in the wider ecosystem and our vision for the future of attestation.

Attachments

Speakers

Jean Snyman

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.