Keylime: Trust on the Edge with TPM Attestation cover

Technology · Ebook

Keylime: Trust on the Edge with TPM Attestation

by Shriira Press

4.6(396)162 pagesPublished 2026

Keylime is a CNCF project, born at MIT's Lincoln Laboratory, that brings hardware-rooted trust to machines we cannot physically reach: edge nodes, cloud VMs, and IoT devices. It uses the Trusted Platform Module to prove a machine's identity, verify that it booted the firmware and kernel we expected, and watch continuously for files that stray from policy. This book builds the whole picture from the ground up: the problem of trusting a remote computer, the TPM and its root of trust, Keylime's agent, registrar, verifier, and tenant, the enrollment handshake, measured boot and IMA runtime checks, the elegant U/V key split that gates secure payloads, the revocation framework, and the move to an agent-driven push model.

Contents

  1. 1Preface
  2. 2Chapter 1 — The Problem of Trusting a Machine
  3. 3Chapter 2 — The TPM and the Root of Trust
  4. 4Chapter 3 — The Four Services
  5. 5Chapter 4 — Enrolling an Agent
  6. 6Chapter 5 — Measured Boot Attestation
  7. 7Chapter 6 — Runtime Integrity with IMA
  8. 8Chapter 7 — Secure Payloads and the Key Split
  9. 9Chapter 8 — Revocation and the Push Model
  10. 10Chapter 9 — Keylime in Practice