Proof of Secure Element Attestation Without a Certificate Authority
Remote attestation of a secure element has always needed an issuer. A TPM's endorsement key is vendor-certified but cannot sign, so the key that signs must be certified by a privacy CA able to assert any chip's identity. We remove the issuer. TPM2_MakeCredential's credential blob is a deterministic function of its (seed, object name, secret) triple, so a possession challenge issued once can be recomputed offline by every verifier afterwards; the possession proof need only be ORDERED, not signed. Four published messages, with a commit-reveal across k challengers drawn by a public beacon, replace the certificate authority. No signing key and no long-lived secret exist anywhere in the construction; the verifier checks the endorsement chain against pinned vendor roots with no online service. We complete the enrolment on physical silicon. This gives permissionless systems a fourth admission resource beside work, stake and space: attested silicon, one identity per secure element. Any rule priced per identity costs an adversary holding n identities exactly what it costs an honest participant holding one, so raising the price never disadvantages the farm; in one deployment 1,000 of 1,191 mining identities belonged to two or three operators running browser farms and took 42% of emission. Attested silicon does not make identities scarce, only expensive - a device farm is this mechanism's ASIC - but it moves the marginal cost of an identity from nothing to the price of a chip. The privacy CA the standard route depends on was unavailable for 26.8% of 664 healthy TPM 2.0 machines and has never existed on Linux. The residual assumption is vendor CA integrity, not key extraction: extraction yields one identity per chip physically held. We show the collusion bound is weaker than it first appears - an adversary can resample the challenger draw - and quantify the resulting grinding cost.
Authors
- Jan Kučera
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-14
- DOI
- https://doi.org/10.5281/zenodo.22749219
- Primary Topic
- Physical Unclonable Functions (PUFs) and Hardware Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00