Arm's Platform Security Architecture Attestation Token
RFC 9783, “Arm's Platform Security Architecture Attestation Token”, is an Informational document published in June 2025 by H. Tschofenig, S. Frost, M. Brossard, A. Shaw, T. Fossati. The canonical text is published by the RFC Editor.
Abstract
Arm's Platform Security Architecture (PSA) is a family of hardware and firmware security specifications, along with open-source reference implementations, aimed at helping device makers and chip manufacturers integrate best-practice security into their products. Devices that comply with PSA can generate attestation tokens as described in this document, which serve as the foundation for various protocols, including secure provisioning and network access control. This document specifies the structure and semantics of the PSA attestation token.
The PSA attestation token is a profile of the Entity Attestation Token (EAT). This specification describes the claims used in an attestation token generated by PSA-compliant systems, how these claims are serialized for transmission, and how they are cryptographically protected.
This Informational document is published as an Independent Submission to improve interoperability with Arm's architecture. It is not a standard nor a product of the IETF.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9783 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9782 Entity Attestation Token Media Types
- RFC 9784 Virtual Ethernet Segments for EVPN and Provider Backbone Bridge EVPN
- RFC 9781 A Concise Binary Object Representation Tag for Unprotected CBOR Web Token Claims Sets
- RFC 9785 Preference-Based EVPN Designated Forwarder Election
- RFC 9780 Bidirectional Forwarding Detection for Multipoint Networks over Point-to-Multipoint MPLS Label Switched Paths
- RFC 9786 EVPN Port-Active Redundancy Mode
- RFC 9779 Performance Measurement for Segment Routing Networks with the MPLS Data Plane
- RFC 9787 Guidance on End-to-End Email Security