However, mechanisms for efficiently managing multiple, independent Attesters are missing. Assessing the trustworthiness of large numbers of independent devices individually can result in high conveyance and processing overhead. This comes into effect particularly when these devices share identical hardware or firmware components, which can lead to redundancy between all individual remote attestation procedures. One example would be a smart factory scenario where numerous sensors of the same model monitor different parts of the manufacturing process. These sensors share identical hardware and firmware configurations. This document proposes a model by which these separate sensors devices can be grouped into a single Attester Group and a shared remote attestation procedure can appraise their authenticity collectively rather than individually. Direct Anonymous Attestation (DAA) [I-D.ietf-rats-daa] has a similar concept of using one unique ID for one group of attesters, but its goal is to mitigate the issue of uniquely (re-)identifiable Attesting Environments, while the scalability is the major concern in this document. 2. Terminology The following terms are imported from [RFC9334]: Attester, Composite Device, Evidence, Layered Attester, Verifier. Newly defined terms for this document: Attester Group: A role performed by a group of Attesters whose Evidence must be appraised in order to infer the extent to which the individual Attesters comprising the group are considered trustworthy. Labiod, et al. Expires 4 January 2025 [Page 2] Internet-Draft Attester Groups for Remote Attestation July 2024 group-id: A new Attester Identity type (see [I-D.ietf-rats-ar4si] section 2.2.1.). It is a unique identifier assigned to each Attester Group, allowing the group to dynamically adjust its membership without redefining its fundamental identity. 3. Attester Group and Comparison to Composite Devices An Attester Group is inherently a dynamic entity. Attesters can join or leave the group, in contrast to Composite Devices that have a static composition with a pre-defined set of Attesting Environments and fixed parameters. The dynamic nature of an Attester Group allows for the flexibility to tailor group parameters, such as the number of Lead Attesters in the group (if any), the range of devices included in the group, and which or how much Evidence is expected to be produced by each groups. This kind of flexibility facilitates the implementation of various group aggregation schemes that can optimize the resources required to conduct remote attestation procedures for large device groups. The table below summarizes the key differences between the Group Attester concept and the Composite Device concept. | Feature | Composite Device | Attester Group | |--------------|------------------|-------------------------| | Evidence | One evidence | More granular, e.g., | | Submission |per composite | one evidence | | |device | per two members | |-----------------------------------------------------------| | Lead Attester| One lead attester|Multiple or no | | | communicates |lead attesters (i.e. | | | with Verifier |distributed collection) | |-----------------------------------------------------------| | Identity | Identifiable by | Identified by unique | | |its lead attester | group-id, independent | | | | of lead attester | |-----------------------------------------------------------| | Flexibility | Static, with | Dynamic, members can | | & Dynamics | predefined | join or leave | | | members and roles| | 4. IANA Considerations This document has no IANA actions. 5. 