Next Article in Journal
Combinatorial Analysis of k-Oresme and k-Oresme–Lucas Sequences
Previous Article in Journal
FlexRay Static Segment Message Scheduling Based on Heterogeneous Scheduling Algorithm
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Article

Secure and Scalable Device Attestation Protocol with Aggregate Signature

by
Hyunsoo Kwon
Department of Computer Engineering, Inha University, Incheon 22212, Republic of Korea
Symmetry 2025, 17(5), 698; https://doi.org/10.3390/sym17050698 (registering DOI)
Submission received: 6 April 2025 / Revised: 28 April 2025 / Accepted: 30 April 2025 / Published: 2 May 2025
(This article belongs to the Section Computer)

Abstract

In cloud computing environments, security challenges emerge due to compromised firmware and supply chain attacks that target devices deployed within data centers. The Secure Protocol and Data Model (SPDM) has been widely adopted for device attestation, which verifies device identity and firmware integrity. However, the scalability of the SPDM is challenged by the resource constraints of peripheral devices and the inherent asymmetry of the protocol, where a heavy verification burden on the central requester leads to a potential bottleneck. In order to solve these problems, we propose a secure and scalable device attestation protocol, SPDM-AggSig, that integrates a chainless-certificate-based aggregate signature scheme within the SPDM framework supporting group messaging. Our protocol reduces the communication overhead by replacing the conventional X.509 certificates with lightweight chainless certificates. It also improves the scalability through group-based attestation with constant-size aggregated signatures. The proposed delegation mitigates the asymmetry in the attestation, introducing a tendency toward functional symmetry by distributing the verification burdens from the central requester to group leaders. We also provide a formal security proof demonstrating existential unforgeability under an adaptive chosen message attack (EUF-ACMA). SPDM-AggSig achieves an approximately 84.18% improvement in the computation overhead and a 96.22% decrease in the communication overhead compared to the baseline.
Keywords: aggregate signature; device attestation protocol; group-based attestation; peripheral device security; secure protocol and data model (SPDM) aggregate signature; device attestation protocol; group-based attestation; peripheral device security; secure protocol and data model (SPDM)

Share and Cite

MDPI and ACS Style

Kwon, H. Secure and Scalable Device Attestation Protocol with Aggregate Signature. Symmetry 2025, 17, 698. https://doi.org/10.3390/sym17050698

AMA Style

Kwon H. Secure and Scalable Device Attestation Protocol with Aggregate Signature. Symmetry. 2025; 17(5):698. https://doi.org/10.3390/sym17050698

Chicago/Turabian Style

Kwon, Hyunsoo. 2025. "Secure and Scalable Device Attestation Protocol with Aggregate Signature" Symmetry 17, no. 5: 698. https://doi.org/10.3390/sym17050698

APA Style

Kwon, H. (2025). Secure and Scalable Device Attestation Protocol with Aggregate Signature. Symmetry, 17(5), 698. https://doi.org/10.3390/sym17050698

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop