New Verified Access API provides cryptographic guarantees about the identify and security state of Chrome OS devices Companies will now be able to cryptographically validate the identity of Chrome OS devices connecting to their networks and verify that those devices conform to their security policies.On Thursday, Google announced a new feature and administration API called Verified Access. The API relies on digital certificates stored in the hardware-based Trusted Platform Modules (TPMs) present in every Chrome OS device to certify that the security state of those devices has not been altered.Many organizations have access controls in place to ensure that only authorized users are allowed to access sensitive resources and they do so from enterprise-managed devices conforming to their security policies.Most of these checks are currently performed on devices using heuristic methods, but the results can be faked if the devices’ OSes are compromised. With Verified Access, Google plans to make it impossible to fake those results in Chromebooks. Organizations will be able to integrate their WPA2 EAP-TLS networks, VPN servers, and intranet pages that use mutual TLS-based authentication with the Verified Access API through the cloud-based Google Admin console.The cryptographic verification mechanism can be used to guarantee the identity of a Chrome OS device and user, but more importantly to ensure that they have the proper verified boot mode device policy or user policy as specified by the domain admin. “When integrating with an enterprise CA, for instance, hardware-protected device certificates can be distributed only to managed, verified devices,” Saswat Panigrahi, senior product manager for Chrome for Work, said in a blog post.However, before organizations can use the new feature, they need to install a special extension on their Chrome OS devices and to have network services that understand the Verified Access protocol. That’s why Google is inviting identity, network, and security providers to integrate their products with its new API. Related content news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Electronic Health Records Electronic Health Records news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software news SpecterOps to use in-house approximation to test for global attack variations The new offering uses atomic tests and in-house approximation in purple team assessment to test all known techniques of an attack. By Shweta Sharma Sep 28, 2023 3 mins Penetration Testing news New Trojan ZenRAT masquerades as Bitwarden password manager A report by Proofpoint identifies the new Trojan as undocumented and possessing information-stealing capabilities. By Lucian Constantin Sep 28, 2023 4 mins Cyberattacks Hacking Data and Information Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe