Skip to content

Commit d41931a

Browse files
committed
Add terminology section to DTAM spec.
1 parent b0be522 commit d41931a

File tree

1 file changed

+6
-2
lines changed
  • specifications/device-trust-anchor-management

1 file changed

+6
-2
lines changed

specifications/device-trust-anchor-management/spec.ocp

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,12 @@ This specification does not impact sustainability.
8787

8888
-->
8989

90+
## Terminology
91+
92+
- **Device owner**: An entity that relies on the authenticity of a given device. The term bears no relation to the concept of device ownership transfer.
93+
- **PKI anchor point**: The point at which a certificate issued by an external PKI connects to a device's internal identity key hierarchy.
94+
- **Trust anchor**: A root public key implicitly trusted by an attestation verifier. May belong to a vendor, data center operator, or a sophisticated tenant.
95+
9096
## Introduction
9197

9298
In a data center environment, hardware roots of trust leverage device identity keys to attest to their current configuration. Verifiers ensure that the device emitting the attestation is authentic, before going on to evaluate the attested claims against a policy.
@@ -101,8 +107,6 @@ The security of this scheme relies on the ongoing security of the vendor's PKI.
101107

102108
To mitigate the risk of a vendor's PKI becoming compromised, a device owner can issue their own certificate for the device's identity upon receipt of the device. This owner certificate chains back to the owner's own PKI, rather than the vendor's. Verifiers can verify attestations against the owner's PKI, and thus be insulated from a compromise of the vendor's PKI.
103109

104-
Note that in this document, a "device owner" refers to an entity that relies on the device's authenticity. The term bears no relation to the concept of device ownership transfer.
105-
106110
@fig:operator-anchor-point illustrates the case of a data center operator acting as the device owner and issuing a certificate for the device's identity.
107111

108112
![Operator PKI anchor point](./diagrams/operator_anchor_point.drawio.svg){#fig:operator-anchor-point}

0 commit comments

Comments
 (0)