suit-wg / information-model

1 stars 1 forks source link

Requirements on Time #11

Closed hannestschofenig closed 3 years ago

hannestschofenig commented 3 years ago

Ben Kaduk wrote:

Section 2

Secure time and secure clock refer to a set of requirements on time sources. For local time sources, this primarily means that the clock must be monotonically increasing, including across power cycles, firmware updates, etc. [...]

But it doesn't have to be anywhere close to an actual reference time source, just monotonic?

hannestschofenig commented 3 years ago

We might also discuss the risks when a device believes that it possesses a source of secure time but the timesource is actually flawed.