Runtime protection and platform attestation provide different trust sources. Shared business policy is possible while evidence formats and support conditions remain platform-specific.
Evaluation approach
Platform services verify defined claims for the server. RASP supplies environment or tampering signals within its scope. Bind both to the intended operation and assess freshness and unavailable results.
Application example
The server validates platform evidence for sensitive actions, considers RASP context and applies its own authorization. Positive evidence does not establish unlimited user authority or freedom from fraud.
Limits and considerations
Platform services have different fields and usage models. One clean-device flag loses useful distinctions.
Checks and decisions
- State each evidence claim
- Verify transaction binding
- Model unsupported results
Explain which threat-model gap each layer addresses instead of assuming automatic substitution.
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.