%% You should probably cite draft-ietf-rats-pkix-key-attestation-07 instead of this revision. @techreport{ietf-rats-pkix-key-attestation-06, number = {draft-ietf-rats-pkix-key-attestation-06}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-rats-pkix-key-attestation/06/}, author = {Jean-Pierre Fiset and Mike Ounsworth and Hannes Tschofenig and Henk Birkholz and Monty Wiseman and Ned Smith}, title = {{Evidence Encoding for Hardware Security Modules}}, pagetotal = 56, year = , month = , day = , abstract = {This document specifies a vendor-agnostic format for Evidence produced and verified within a PKIX context. The Evidence produced this way includes claims collected about a cryptographic module, such as a Hardware Security Module (HSM), and elements found within it such as cryptographic keys. One scenario envisaged is that the state information about the cryptographic module can be securely presented to a remote operator or auditor in a vendor-agnostic verifiable format. A more complex scenario would be to submit this Evidence to a Certification Authority to aid in determining whether the storage properties of this key meet the requirements of a given certificate profile. This specification also offers a format for requesting a cryptographic module to produce Evidence tailored for expected use.}, }