A YANG Data Model for Challenge-Response-Based Remote Attestation Procedures Using Trusted Platform Modules
RFC 9684, “A YANG Data Model for Challenge-Response-Based Remote Attestation Procedures Using Trusted Platform Modules”, is a Proposed Standard document published in December 2024 by H. Birkholz, M. Eckel, S. Bhandari, E. Voit, B. Sulzen, L. Xia, T. Laffey, G. C. Fedorkow. The canonical text is published by the RFC Editor.
Abstract
This document defines the YANG Remote Procedure Calls (RPCs) and configuration nodes that are required to retrieve attestation evidence about integrity measurements from a device, following the operational context defined in RFC 9683 "TPM-based Network Device Remote Integrity Verification". Complementary measurement logs originating from one or more Roots of Trust for Measurement (RTMs) are also provided by the YANG RPCs. The defined module requires the inclusion of the following in the device components of the composite device on which the YANG server is running: at least one Trusted Platform Module (TPM) of either version 1.2 or 2.0 as well as a corresponding TPM Software Stack (TSS), or an equivalent hardware implementation that includes the protected capabilities as provided by TPMs as well as a corresponding software stack.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9684 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9683 Remote Integrity Verification of Network Devices Containing Trusted Platform Modules
- RFC 9685 Listener Subscription for IPv6 Neighbor Discovery Multicast and Anycast Addresses
- RFC 9682 Updates to the Concise Data Definition Language Grammar
- RFC 9686 Registering Self-Generated IPv6 Addresses Using DHCPv6
- RFC 9681 IS-IS Fast Flooding
- RFC 9687 Border Gateway Protocol 4 Send Hold Timer
- RFC 9680 Antitrust Guidelines for IETF Participants
- RFC 9688 Use of the SHA3 One-Way Hash Functions in the Cryptographic Message Syntax