through boot, a PCR of the vTPM is extended with the root of the Merkle tree, and afterwards verified by the KMS in advance of releasing the HPKE private critical. All subsequent reads from the basis partition are checked against the Merkle tree. This makes sure that all the contents of the root partition are attested and any attempt to tamper Usin