Anonymous attestations made practical
Amira Barki, Nicolas Desmoulins, Saïd Gharout, Jacques Traoré · 2017
Direct Anonymous Attestation (DAA) is a privacy preserving authentication protocol initially designed for Trusted Platform Modules (TPMs). This cryptographic protocol, and some of its extensions such as Intel's Enhanced Privacy ID (EPID), have been widely deployed in millions of chips. Usually part of the attestation computation is delegated to the host (in most cases, either a PC or a smartphone) embedding the TPM, which is generally much more powerful. However, in Machine-to-Machine (M2M) and Internet of Things (IoT) use cases, the host may be as resource constrained as the TPM. Furthermore, any malware residing in the host may enable the tracking of the TPM owner.