Remote Attestation Procedures (RATS)

Created
2024-07-26
Last Updated
2026-07-20
Available Formats

XML

HTML

TXT

Registries Included Below

Entity Attestation Token (EAT) Intended Uses

Registration Procedure(s)
Expert Review
Expert(s)
Giridhar Mandyam, Jeremy O'Donoghue
Reference
[RFC 9711]
Available Formats

CSV
Value Description Reference
0 Reserved [RFC 9711]
1 Generic attestation describes an application where the EAT consumer requires the most up-to-date security assessment of the attesting entity. It is expected that this is the most commonly-used application of EAT. [RFC 9711]
2 Entities that are registering for a new service may be expected to provide an attestation as part of the registration process. This "intuse" setting indicates that the attestation is not intended for any use but registration. [RFC 9711]
3 Entities may be provisioned with different values or settings by an EAT consumer. Examples include key material or device management trees. The consumer may require an EAT to assess entity security state of the entity prior to provisioning. [RFC 9711]
4 Certification Authorities (CAs) may require attestation results (which in a background check model might require receiving evidence to be passed to a verifier) to make decisions about the issuance of certificates. An EAT may be used as part of the certificate signing request (CSR). [RFC 9711]
5 An EAT consumer may require an attestation as part of an accompanying proof-of-possession (PoP) application. More precisely, a PoP transaction is intended to provide to the recipient cryptographically-verifiable proof that the sender has possession of a key. This kind of attestation may be necessary to verify the security state of the entity storing the private key used in a PoP application. [RFC 9711]
6-255 Unassigned

RATS Conceptual Message Wrapper (CMW) Indicators

Registration Procedure(s)
IETF Review
Reference
[RFC 9999]
Available Formats

CSV
Indicator Value Conceptual Message Name Reference
0 Reference Values [RFC 9999, Section 3.1.1]
1 Endorsements [RFC 9999, Section 3.1.1]
2 Evidence [RFC 9999, Section 3.1.1]
3 Attestation Results [RFC 9999, Section 3.1.1]
4 Appraisal Policy [RFC 9999, Section 3.1.1]
5-31 Unassigned