The State of Boot Integrity on Linux - a Brief Review

Robert Haas, Martin Pirker · 2024

With the upcoming generational change from Windows 10 to Windows 11, the Trusted Platform Module as a security supporting component will be a requirement for every common PC. While the TPM has seen use with some applications already, its near future ubiquitous presence in all PCs motivates an updated review of TPM supporting software. This paper focuses on the software ecosystem that supports secure boot, a chain of measurements for integrity assessments, and challenges in remote attestation. A brief reflection on the state of the various projects gives a rough overview, but is not an exhaustive and in-depth survey. Still, this short paper contributes to the ongoing adoption and reflection of TPM v2’s features and opportunities.

Read the paper · More papers on PaperTik