NOTICE: Due to a lapse in annual appropriations, most of this website is not being updated. Learn more.
Form submissions will still be accepted but will not receive responses at this time. Sections of this site for programs using non-appropriated funds (such as NVLAP) or those that are excepted from the shutdown (such as CHIPS and NVD) will continue to be updated.
An official website of the United States government
Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Supply Chain Assurance: Validating the Integrity of Computing Devices
Published
Author(s)
Nakia R. Grayson, Murugiah Souppaya, Andrew Regenscheid, Tim Polk, Christopher Brown, Karen Scarfone, Chelsea Deane
Abstract
Product integrity and the ability to distinguish trustworthy products is a critical foundation of C-SCRM. Authoritative information regarding the provenance and integrity of components provides a strong basis for trust in a computing device whether it is a client device, server, or other technology. The goal of this project is to demonstrate how organizations can verify that the components of their acquired computing devices are genuine and have not been tampered with or otherwise modified throughout the devices' life cycles. This project addresses several processes: how to create verifiable descriptions of components and platforms, which may be done by original equipment manufacturers (OEMs), platform integrators, and even information technology (IT) departments how to verify devices and components within the single transaction between an OEM and a customer how to verify devices and components at subsequent stages in the system life cycle in the operational environment. This project will use a combination of commercial off-the-shelf and open-source tools to describe the components of a device in a verifiable manner using cryptography. Future builds of this project may cover other critical phases of C-SCRM.
Grayson, N.
, Souppaya, M.
, Regenscheid, A.
, Polk, T.
, Brown, C.
, Scarfone, K.
and Deane, C.
(2022),
Supply Chain Assurance: Validating the Integrity of Computing Devices, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.SP.1800-34, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=935521
(Accessed October 9, 2025)