IEC 62443 firmware integrity enforcement suite
DFIM remote attestation uses an ECC NIST P-256 Attestation Key created as a restricted, fixed-TPM object under the endorsement hierarchy. The verifier trusts the AK public key only after controlled device enrollment.
clockInfo.safe must be set.The TPM extraData is:
This binds freshness, authorized release, enforcement policy, and DFIM image identity into the signed quote. A response for another nonce, release, policy, or image cannot be replayed.
The remote verifier performs these fail-closed gates in order:
TPMS_ATTEST; require TPM magic, quote type, safe clock, SHA-256 bank, and the
exact PCR bitmap.extraData with the expected challenge binding.PCR values are read before and after TPM2_Quote; any update-counter or value change rejects evidence,
preventing an asynchronous PCR-read race.
--features tpm.attestation-enroll once in a controlled enrollment channel. Protect the TPM private-object
blob with mode 0600; enroll the emitted AK public key at the verifier.attestation-policy.attestation-challenge; its nonce must come from a CSPRNG
and must never be reused.attestation-quote; the verifier runs attestation-verify.Set DFIM_TPM_TCTI=swtpm:host=127.0.0.1,port=2321 when using the CI swtpm gate instead of
/dev/tpmrm0.
Production enrollment must additionally validate device identity through an approved EK certificate chain or an equivalent asset-registration channel. Exact PCR baselines provide the release gate; event-log collection should be retained for diagnostics and independent measurement replay.