SATA: Sensor Attestation and Trust Anchoring: A Formally Specified, Simulation-Evaluated Continuous-Trust Protocol for Autonomous-Systems Sensor Edges
摘要
Autonomous systems in adversarial environments derive operational authority from sensor inputs whose integrity is itself contested. Binary sensor attestation fails under partial degradation multipath interference, calibration drift, transient denial of service forcing all-or-nothing lockout responses that are operationally inadequate. This article specifies SATA (Sensor Attestation and Trust Anchoring), a TPM-anchored protocol specification that computes a continuous trust scalar τ ∈ [0, 1] from a sliding window of cryptographically committed attestation records. SATA combines six replay-resistance barriers ECDSA P-256 signature, 256-bit CSPRNG nonce, TPM monotonic counter, PCR quote (TPM2_Quote), per-sensor sequence, and hardware tick-clock age yielding a signature-barrier unforgeability bound P_forge < 2− 128 under a formally specified A1/A2 adversary model, stated and proved as Theorem 1, with explicit degradation analysis under a physical (A3) adversary. A weighted Dempster Shafer fusion layer provides Byzantine fault tolerance f ≤ ⌊(n-1)/3⌋ and preserves the ignorance distrust distinction, anchored in a TPM 2.0 hardware root of trust. The state machine is checked by TLA+ bounded model checking across 18,892 reachable states with zero violations of eight safety invariants, and a 10,000-run Monte Carlo campaign provides implementation-conformance and parameter-sensitivity evidence, explicitly distinguished from the analytical guarantee of Theorem 1. SATA is presented as a complement to RATS/SGX/PSA attestation, addressing the intersection of continuous trust quantification, hardware anchoring, formal specification, and multi-sensor operation under adversarial pressure.