A Challenge-Nonce Freshness Gap in Project Veraison's TPM Reference Schemes, Found by Appraising Application-Layer Action Evidence End-to-End
Anton Sokolov
Abstract
When an automated agent (an AI agent, say) takes a consequential action, the record it leaves behind is produced by the very software stack whose integrity is in question. A signed log proves which key wrote the record, not what the runtime was. Prior work proposed treating that record (an Action Evidence Package, AEP: a signed append-only record of an action, its authorising principal, and its outcome) as application-layer Evidence under the IETF Remote ATtestation procedureS (RATS) architecture (RFC 9334), binding the outcome into a hardware-rooted TPM quote so that swapping it invalidates the quote. But that prior work appraised the result only against a minimal Verifier stand-in. This article closes that gap. We drive an AEP quote, produced on an emulated software TPM, end-to-end through a conformant Project Veraison RATS Verifier. We generate an EC P-256 attestation key, measure the AEP outcome digest into a PCR, pack a genuine quote into Veraison's tpm-enacttrust format, provision a Concise Reference Integrity Manifest (trust anchor plus golden reference value), and obtain a signed EAT Attestation Result (EAR). Good evidence yields affirming; an outcome-swap or a one-byte signature tamper yields contraindicated. Along the way we uncover, responsibly disclose, and fix a security-relevant finding: the reference scheme does not enforce challenge-nonce freshness, so a replayed quote still appraises as affirming. We give an exact, upstreamable two-part fix and validate it end-to-end. With the fix active, the same valid quote that is affirming in its own session flips to contraindicated when replayed to a fresh one. The pipeline is fully reproducible; the Attester remains an emulated swtpm, not a hardware guarantee.
Create a lesson
Related papers
Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs
Ramana Ranganatham, Chirag Adiga, Michael Zuzak et al.
Characterizing Network Centralization and Observability in the Remote MCP Ecosystem
Muhammad Abdullah Sohail
When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic
Muhammad Abdullah Sohail
Hamming Ideals and Grobner Bases for ISD-like Syndrome Decoding
Roberto La Scala, Marco Marchesin, Sharwan K. Tiwari
ASLEval: Measuring Privacy Exposure Displacement in LLM Agent Sessions
Guosen Wu, Huizhen Huang, Guoxiong Long et al.
CASHEWS: Source Preprocessor for LLM-based Malicious Package Detection
Jean-Charles Noirot Ferrand, David Adei, Anders Møller et al.