During boot, a PCR from the vTPM is prolonged with the root of the Merkle tree, and later on verified because of the KMS just before releasing the HPKE personal essential. All subsequent reads in the root partition are https://johsocial.com/story8669843/5-easy-facts-about-safe-ai-described