Matter has standardized how an appliance joins a home: commissioning attests the device against a manufacturer certificate chain and issues a Node Operational Certificate (NOC) that lets it speak Matter. Smart homes, however, are becoming agentic: appliances run local models and delegate subtasks to one another over agent protocols carried on ordinary IP channels that do not speak Matter and that must distinguish processes on a board rather than nodes in a fabric. A commissioned appliance therefore ends up holding a credential it cannot use where it actually needs one, and the gap is closed in practice with a shared pairing secret or a vendor cloud account. We characterize this as a two identity plane problem and close it by making the commissioning event the attestation input for workload identity issuance, through three bindings: the Matter Descriptor supplies the device type that grounds role and firmware binding; the board serial supplies the SPIFFE parent so identities are separated per board; and decommissioning revokes in both planes, with the hub persisting the intent until an unreachable device can be reached. We evaluate on a running deployment of one hub board and seven appliance boards with eight attested SPIRE agents, comparing against the pre-change revisions recovered from version control and driven by the same harness. Six adversarial experiments the baselines fail, including a compromised appliance obtaining an administrator token through the legitimate issuance path, are refused after the change, and the shared secret is removed rather than merely restricted.
10月11日
2026
10月14日
2026
报告提交截止日期
提前注册日期
初稿截稿日期
注册截止日期
发表评论