TPM Attestation in Home Environments based on Online and Offline Technologies

Authors

DOI:

https://doi.org/10.5753/jisa.2026.7658

Keywords:

TPM, Attestation at Home, QR-Code, Bluetooth

Abstract

Nowadays, society is applying a home office, since the isolation demanded by the pandemic. However, this remote access may lead to boot attack scenarios that are difficult or impossible to detect remotely. This reality led to the necessity of attestation, i.e., a way to prove the state of computers to a corporate server. One promising approach to address this situation is the usage of TPM (Trusted Platform Module) attestation, which is typically used to quarantine tampered computers in the corporate network. However, the usage of TPM attestation at home is still an open challenge, due to the lack of corporate control over network access outside the corporate firewall. Within this context, this paper presents a mechanism to support the TPM Attestation in a home environment, applying online and offline technologies, such as QR-Code and Bluetooth. In this way, the users at home may attest to the security of their workstations before using their login credentials. Results from real experiments using a real TPM chip suggest that the proposed solution is suitable to attest device security in both online and offline scenarios.

Downloads

Download data is not yet available.

Author Biography

Rafael L. Gomes, State University of Ceará

Rafael Lopes Gomes is an Associate Professor of State University of Ceará (UECE) and has a Productivity Technological Development and Innovative Extension Scholarship of CNPq (DT - Level 2). Currently, he is the coordinator of the Laboratory of Computer Networks and Security (LARCES). He received a Ph.D degree in Computer Science from the University of Campinas (UNICAMP) in Brazil. He was a research visitor at Network Research Lab from the University of California Los Angeles (UCLA) in 2014. He has experience and R&D projects on the following topics: Network Management, Cybersecurity, Software Defined Networks, Resilience Planning, Wireless Networks and Internet of Things.

References

Achemlal, M., Gharout, S., and Gaber, C. (2011). Trusted platform module as an enabler for security in cloud computing. In 2011 Conference on Network and Information Systems Security, pages 1-6. DOI: 10.1109/SAR-SSI.2011.5931361.

Arfaoui, G., Jacques, T., Lacoste, M., Onete, C., and Robert, L. (2023). Towards a privacy-preserving attestation for virtualized networks. IACR Cryptol. ePrint Arch., 2023:735. DOI: 10.1007/978-3-031-51482-1_18.

Brito, M. L. L., Ferreira, M. C. M., Portela, A. L. C., and Gomes, R. L. (2026). Ai-based estimation of bandwidth availability for data offloading in edge-cloud computing. IEEE Networking Letters, 8:69-73. DOI: 10.1109/LNET.2025.3614770.

Brooks, C. (2022). Global Thought Leader in Cybersecurity and Emerging Tech. Web site Forbes. Book.

Challener, D., Yoder, K., Catherman, R., Safford, D., and Doorn, L. V. (2008). A Practical Guide to Trusted Computing. Book.

Cheng, J., Zhang, K., and Tu, B. (2021). Remote attestation of large-scale virtual machines in the cloud data center. In 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pages 180-187. DOI: 10.1109/TrustCom53373.2021.00041.

Coker, G., Guttman, J., Loscocco, P., Herzog, A., Millen, J., O’Hanlon, B., Ramsdell, J., Segall, A., Sheehy, J., and Sniffen, B. (2011). Principles of remote attestation. Int. J. Inf. Secur., 10(2):63–81. DOI: 10.1007/s10207-011-0124-7.

Costa, M. A., Costa, Y. M., Almeida, Y. O., Cardoso, F. J., and Gomes, R. L. (2024). Connection management using automated firewall based on threat intelligence. In Proceedings of the 2024 Latin America Networking Conference, LANC '24, page 32–37, New York, NY, USA. Association for Computing Machinery. DOI: 10.1145/3685323.3685331.

Davi, L., Sadeghi, A.-R., and Winandy, M. (2009). Dynamic integrity measurement and attestation: towards defense against return-oriented programming attacks. page 49–54. DOI: 10.1145/1655108.1655117.

Death, D. (2017). Information Security Handbook. Packt. Book.

Du, R., Pan, W., and Tian, J. (2018). Dynamic integrity measurement model based on vtpm. China Communications, 15(2):88-99. DOI: 10.1109/CC.2018.8300275.

Gomes, R. L., Bittencourt, L. F., Madeira, E. R. M., Cerqueira, E. C., and Gerla, M. (2016). Software-defined management of edge as a service networks. IEEE Transactions on Network and Service Management, 13(2):226-239. DOI: 10.1109/TNSM.2016.2538821.

Hosseinzadeh, S., Sequeiros, B., Inácio, P. R., and Leppänen, V. (2020). Recent trends in applying tpm to cloud computing. Security and privacy, 3(1):e93. DOI: 10.1002/spy2.93.

Kinney, S. L. (2006). Trusted Platform Module Basics: Using TPM in Embedded Systems. Newnes, USA. Book.

Kirmani, M. S. and Banday, M. T. (2024). Exploring firmware-based anti-forensics in iot devices: Techniques and implications. SN Computer Science, 5(8):1-23. DOI: 10.1007/s42979-024-03476-y.

Li, Y. and Liu, Q. (2021). A comprehensive review study of cyber-attacks and cyber security; emerging trends and recent developments. Energy Reports, 7:8176-8186. DOI: 10.1016/j.egyr.2021.08.126.

Menezes, R. A., Araujo, R. S., Rodrigues, L. S., Nascimento, E. S., and Gomes, R. L. (2026). Data protection through the integration of tpm and cryptography. International Journal of Wireless and Microwave Technologies(IJWMT), 16(1):37-49. DOI: 10.5815/ijwmt.2026.01.03.

Mohamed, N. and Ahmed, A. A. (2024). Ai in combatting man-in-the-middle attacks: A comprehensive review. In 2024 15th International Conference on Computing Communication and Networking Technologies (ICCCNT), pages 1-6. IEEE. DOI: 10.1109/icccnt61001.2024.10725789.

Nobre, F. V. J., Alves, D. O., Araujo, R. S., Campos, G. A., and Gomes, R. L. (2026). Risk classification of ip addresses using machine learning with weighted voting approach. In Rodrigues, L. A. and Oliveira, R., editors, Dependable and Secure Computing, pages 320-328, Cham. Springer Nature Switzerland. DOI: 10.1007/978-3-032-11539-3_19.

Nobre, F. V. J., Silva, D. d. S., Ferreira, M. C. M. M., Brito, M. L. M. L., de Araújo, T. P., and Gomes, R. L. (2025). Time-weighted correlation approach to identify high delay links in internet service providers. Journal of Internet Services and Applications, 16(1):419–430. DOI: 10.5753/jisa.2025.5218.

Oliver, I. (2021). Trust, security and privacy through remote attestation in 5g and 6g systems. In 2021 IEEE 4th 5G World Forum (5GWF), pages 368-373. DOI: 10.1109/5GWF52925.2021.00071.

Pimenta, I. A., Lee, M. H., Bittencourt, L. F., and Gomes, R. L. (2026). Adaptive privacy based on mutual information for machine learning in edge–cloud environments. IEEE Networking Letters, 8:49-53. DOI: 10.1109/LNET.2025.3607555.

Portela, A., Linhares, M. M., Nobre, F. V. J., Menezes, R., Mesquita, M., and Gomes, R. L. (2024). The role of tcp congestion control in the throughput forecasting. In Proceedings of the 13th Latin-American Symposium on Dependable and Secure Computing, LADC '24, page 196–199, New York, NY, USA. Association for Computing Machinery. DOI: 10.1145/3697090.3699869.

Proudler, G., Chen, L., and Dalton, C. (2014). Trusted Computing Platforms - TPM2.0 in Context. DOI: 10.1007/978-3-319-08744-3.

Ryu, C., Lee, J.-H., Kim, D.-H., Lee, H.-S., Kim, Y.-S., Han, J.-H., and nyeo Kim and, J. (2024). A comprehensive survey of tpm for defense systems. KSII Transactions on Internet and Information Systems, 18(7):1953-1967. DOI: 10.3837/tiis.2024.07.012.

TCG (2019). Trusted computing group: Trusted platform module library specification, family 2.0. Available at:[link].

TCG (2020). Trusted platform module library - part 1: Architecture. Available at:[link].

TCG (2025). TCG Guidance on Integrity Measurements and Event Log Processing. Available at:[link].

(TCG), T. C. G. (2025a). TPM 2.0 Keys for Device Identity and Attestation. Available at:[link].

(TCG), T. C. G. (2025b). Trusted Platform Module Library Specification. Available at:[link].

Vardakis, G., Hatzivasilis, G., Koutsaki, E., and Papadakis, N. (2024). Review of smart-home security using the internet of things. Electronics, 13(16):3343. DOI: 10.3390/electronics13163343.

Wang, J., Shi, Y., Peng, G., Zhang, H., Zhao, B., Yan, F., Yu, F., and Zhang, L. (2016). Survey on key technology development and application in trusted computing. China Communications, 13(11):70-90. DOI: 10.1109/CC.2016.7781720.

Won, Y.-S. and Bhasin, S. (2021). Are cold boot attacks still feasible: A case study on raspberry pi with stacked memory. In 2021 Workshop on Fault Detection and Tolerance in Cryptography (FDTC), pages 56-60. IEEE. DOI: 10.1109/fdtc53659.2021.00017.

Zeitouni, M., Santos, M., and Gomes, R. (2024). Melhorias no processo de armazenamento de dados em tpm para gerenciamento de integridade. In Anais Estendidos do XXIV Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 270-278. SBC. DOI: 10.5753/sbseg_estendido.2024.243344.

Downloads

Published

2026-09-22

How to Cite

Filho, M. D. P. de M., Monteiro, G. C. V., Monteiro, L. G. G., Pimentel, E. B., Menezes, R. A., Gomes, R. L., & Maia, P. H. M. (2026). TPM Attestation in Home Environments based on Online and Offline Technologies. Journal of Internet Services and Applications, 17(1), 443–456. https://doi.org/10.5753/jisa.2026.7658

Issue

Section

Research article