DFIM — Deterministic Firmware Integrity Matrix

IEC 62443 firmware integrity enforcement suite

View the Project on GitHub Ahmadsi70/DFIM

DFIM TPM 2.0 Remote Attestation

DFIM remote attestation uses an ECC NIST P-256 Attestation Key created as a restricted, fixed-TPM object under the endorsement hierarchy. The verifier trusts the AK public key only after controlled device enrollment.

Enterprise profile

The TPM extraData is:

\[\operatorname{SHA256}(\texttt{DFIM-ATTEST-V1}\parallel nonce\parallel release\parallel policyGeneration\parallel merkleRoot)\]

This binds freshness, authorized release, enforcement policy, and DFIM image identity into the signed quote. A response for another nonce, release, policy, or image cannot be replayed.

Evidence verification

The remote verifier performs these fail-closed gates in order:

  1. Enforce release floor, policy generation, and enrolled Merkle root.
  2. Verify the quote signature with the enrolled AK public key.
  3. Parse canonical TPMS_ATTEST; require TPM magic, quote type, safe clock, SHA-256 bank, and the exact PCR bitmap.
  4. Compare extraData with the expected challenge binding.
  5. Compare each supplied PCR value with the enrolled baseline.
  6. Recompute the TPM quote digest over PCR 0, 2, 4, 7, and 14 and compare it with the signed digest.

PCR values are read before and after TPM2_Quote; any update-counter or value change rejects evidence, preventing an asynchronous PCR-read race.

Operational flow

  1. On Linux with TSS2 libraries, compile with --features tpm.
  2. Run attestation-enroll once in a controlled enrollment channel. Protect the TPM private-object blob with mode 0600; enroll the emitted AK public key at the verifier.
  3. Capture approved PCR values and build the verifier policy with attestation-policy.
  4. The verifier creates a challenge with attestation-challenge; its nonce must come from a CSPRNG and must never be reused.
  5. The device runs attestation-quote; the verifier runs attestation-verify.

Set DFIM_TPM_TCTI=swtpm:host=127.0.0.1,port=2321 when using the CI swtpm gate instead of /dev/tpmrm0.

Production enrollment must additionally validate device identity through an approved EK certificate chain or an equivalent asset-registration channel. Exact PCR baselines provide the release gate; event-log collection should be retained for diagnostics and independent measurement replay.