Secure Boot and Model Attestation
Objective
Verify the model/firmware executing at the edge is the authorized version.
Control / requirement
Secure boot with hardware root of trust; runtime attestation at configurable interval; defined safety response (not merely a log entry) on attestation failure.
Applicability
Physical AI systems where model or firmware compromise could lead to unsafe behavior.
Expected evidence
Secure boot architecture documentation; attestation success/failure logs; attestation-failure response test records. [T2]
Assurance expectation
Architecture evidence plus test evidence of the failure response, not merely presence of the attestation mechanism.
Dependencies
PAI-SF-ATT-003 (key custody) — attestation is only as trustworthy as its key protection.
Exclusions
May be proportionally implemented for systems with negligible physical risk from model compromise.
Maturity / conformance relevance
Expected at Operational and High-Assurance levels; Foundational expects at minimum boot-time integrity verification.
Ecosystem relationship
Extends GAISSF™ model integrity/supply chain controls; provides attestation-failure incident categories for UAIF™; defines attestation failure as an AI-IRF™ trigger event.