Insights Topic

Attestation

Browse Attomus insight related to attestation, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.

Topic summary

2 related insights

Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.

What Android's Keystore Actually Does with AES Keys (and What It Doesn't)

There is a question that comes up constantly in Android security engineering, usually phrased something along the lines of: “how do I prove to my server that this AES key is hardware-backed?” The common answers to this question are often wrong in that they make you think you have a guarantee that you do not have. The short answer is: you cannot prove an AES key’s hardware provenance to a server directly. The certificate chain mechanism that makes remote attestation possible for asymmetric keys does not exist for symmetric keys. If you are building a system that depends upon being able to remotely attest an AES key’s provenance, you need to redesign the system, not find a better API call.

Read article

Hardware Roots of Trust: What 'Hardware-Backed' Actually Means

“Hardware-backed” is among the most widely used and least interrogated phrases in security. At its best it names a specific and valuable protection: a small, deliberately limited piece of hardware that holds cryptographic keys and will not surrender them, even to software that has otherwise taken over the machine. At its worst it is an adjective applied to make a product sound safer than it is. The distance between those two is the subject of this piece.

Read article