Technology · Ebook
Keylime: Trust on the Edge with TPM Attestation
by Shriira Press
Keylime is a CNCF project, born at MIT's Lincoln Laboratory, that brings hardware-rooted trust to machines we cannot physically reach: edge nodes, cloud VMs, and IoT devices. It uses the Trusted Platform Module to prove a machine's identity, verify that it booted the firmware and kernel we expected, and watch continuously for files that stray from policy. This book builds the whole picture from the ground up: the problem of trusting a remote computer, the TPM and its root of trust, Keylime's agent, registrar, verifier, and tenant, the enrollment handshake, measured boot and IMA runtime checks, the elegant U/V key split that gates secure payloads, the revocation framework, and the move to an agent-driven push model.
Contents
- 1Preface
- 2Chapter 1 — The Problem of Trusting a Machine
- 3Chapter 2 — The TPM and the Root of Trust
- 4Chapter 3 — The Four Services
- 5Chapter 4 — Enrolling an Agent
- 6Chapter 5 — Measured Boot Attestation
- 7Chapter 6 — Runtime Integrity with IMA
- 8Chapter 7 — Secure Payloads and the Key Split
- 9Chapter 8 — Revocation and the Push Model
- 10Chapter 9 — Keylime in Practice
