Vendor and Product Reality
Claroty is a cybersecurity vendor whose product line spans xDome (industrial OT), xDome for Healthcare (clinical and biomedical devices), Continuous Threat Detection for legacy ICS environments, and Secure Remote Access (SRA) for vendor and contractor connectivity into operational-technology networks. xDome ingests passive network traffic from SPAN ports, packet brokers, and industrial-protocol parsers spanning a broad range of OT and IoMT protocols, builds an asset inventory keyed on attributes such as MAC, IP, vendor, model, and firmware version, and overlays a vulnerability and risk-scoring layer informed by Claroty's Team82 research group. Claroty publicly acquired Medigate, folding its clinical-device asset intelligence into the healthcare product line.
These are genuine strengths. For an operator that previously could not enumerate what was on a plant floor or hospital network, xDome produces a defensible inventory and extends it into vulnerability management, segmentation-policy generation, and threat detection. SRA replaces jump-host and VPN-based vendor access with a brokered, session-recorded, just-in-time pathway, a pattern well suited to the access-control expectations of frameworks such as NIS2, TSA pipeline directives, and FDA premarket cybersecurity guidance. The comparison below is scoped narrowly to one architectural axis and is not a claim that xDome does its stated job poorly.
Architectural Gap
xDome, like the passive OT and IoMT monitoring category generally, is a network-observer architecture: its primary evidence base is passively captured network traffic. Device identity is derived from network-visible signals such as DHCP fingerprints, MAC OUIs, protocol behavior, and vendor-specific handshakes; device health is derived from network anomalies, baseline deviation, and CVE-to-firmware-version matching. This is a capable inference layer, and for a large fraction of OT and clinical-device risk it is the right tool. It is, however, inference from the wire. A passive network observer does not, by construction, obtain a cryptographic attestation from the device itself that its boot chain matches the manufacturer's reference, that its running firmware hash is unmodified, or that the endpoint answering on a given address is the same physical unit observed previously.
That boundary is inherent to any passive network-monitoring design, not specific to Claroty. Publicly documented threat activity against critical infrastructure, and rising regulatory attention to medical-device firmware integrity, both point toward adversaries who aim to operate below the network-anomaly threshold: a controller executing attacker-supplied logic that mimics legitimate operation, or a re-flashed device that passes its self-test, need not present as anomalous on the wire. Closing that specific gap requires evidence sourced from or bound to the device, which is a different architectural axis from network telemetry.
What the AQ Primitive Provides
The Health Monitoring inventive step, as disclosed in the provisional, treats device and fleet health as credentialed, lineage-recorded observations rather than as inferences drawn from traffic. Four disclosed capabilities are relevant to the axis above. Device-integrity attestation: the disclosure describes continuity-based device identity in which the mechanism does not require storage of long-lived secrets on the device, together with an attestation-observation type carrying a device-identity attestation over the device's state. Tamper-evident reporting: the disclosure describes a tamper-evident seal monitor producing governance-credentialed tamper observations upon physical compromise, and dynamic-device-hash continuity that produces a detectable discontinuity upon firmware modification or hardware substitution.
PUF challenge-response: the disclosure describes a physical-unclonable-function challenge-response monitor producing observations of PUF-response consistency, binding identity to silicon characteristics that an exact firmware clone on identical hardware does not reproduce. Zero-trust and firmware-integrity-gated operation: the disclosure describes zero-trust infrastructure deployment in which every device continuously attests authenticity rather than relying on network-perimeter security, and firmware-integrity-gated operation in which devices refuse operation upon detected firmware tampering. Together these turn "what does this device look like on the wire" into "what is this device, as a credentialed observation, right now," with each health observation carrying an authority credential, a dynamic device hash, and recorded lineage.
Composition Pathway
The two architectures are complementary, and composition is the natural framing rather than replacement. A plausible integration surface is the asset record itself. Where each asset today carries network-derived attributes, an attestation-observation field can carry a freshness-stamped, credentialed claim sourced from the device or from a co-located attestation element, so that an alerting pipeline can fire on attestation drift alongside traffic anomaly. For devices that cannot themselves be modified, such as legacy controllers or regulator-locked clinical hardware, the disclosure's continuity-based identity and PUF challenge-response can be applied through a co-located element rather than requiring firmware changes on the monitored device.
A second surface is remote access. Where a brokered access product authenticates the human operator and records the session, a device-attestation observation can additionally gate each privileged session on the fresh attested state of the target asset, so access to a substation controller is admitted only while that controller attests as untampered. A third surface is the vulnerability feed: where CVE-to-firmware-version mapping reasons about the firmware a device reports, credentialed attestation of the running firmware hash narrows the gap between firmware reportedly applied and firmware actually executing.
Commercial Implication
The passive-monitoring category, which includes vendors such as Dragos, Nozomi Networks, and Armis alongside Claroty, competes largely on asset visibility and network-derived threat detection. That shared foundation is a strength for the visibility problem and equally a shared boundary at the device-attestation axis. Adding credentialed device-integrity attestation alongside network analytics shifts part of the conversation from passive-sensor coverage toward evidence sourced from or bound to the device. For operators working under regulatory regimes such as NIS2, the FDA premarket cybersecurity requirements associated with section 524B, and SEC cybersecurity disclosure rules, verifiable evidence is a natural fit for audit expectations.
The hospital and pharmaceutical segments, which Claroty serves through the Medigate acquisition and xDome for Healthcare, are a natural fit: clinical-engineering teams already manage device recalls and firmware updates on a per-unit basis, and a per-device attestation observation aligns with existing biomedical-asset workflows. For OT, credentialed continuous attestation supports the direction of zero-trust guidance reflected in the CISA Cross-Sector Cybersecurity Performance Goals.
Enabling Detail and Embodiment Breadth
A skilled implementer could build the disclosed approach from primitives the provisional describes. The attestation observation is a governed observation carrying an authority credential, a dynamic device hash, spatial and temporal references, a time-to-live, a payload, and a lineage field. The dynamic device hash is computed at the transmitting device and evolves gradually across successive transmissions, so a receiving verifier maintains a per-device history and evaluates a newly received hash against that sequence to compute a trust-slope metric, yielding continuity-based identity without long-lived device secrets. Supply-chain provenance health composes a device-authenticity attestation evaluator, a firmware-integrity-chain monitor tracking updates through an authorized-update-authority chain, a tamper-evident seal monitor, a PUF challenge-response monitor, an SBOM attestation verifier, and a supply-chain-health lineage recorder. Fleet health aggregates these per-device observations into fleet-level indicators such as availability rate, mean-time-between-failures, degradation trends, and cascade-risk.
The approach is intended broadly. Embodiments include, without limitation: device-resident attestation and co-located-element attestation for devices that cannot be modified; digital-signature, threshold-signature, zero-knowledge, and post-quantum attestation mechanisms as interchangeable options for the governance-chain attestation; deployment across controllers, pumps, human-machine interfaces, remote-access endpoints, and infrastructure agents; and cross-domain composite health patterns combining device, mesh, governance, and supply-chain categories. The cryptographic primitives are described as substitutable, including substitution with post-quantum equivalents, so the design is not bound to any single signature scheme.
Disclosure Scope
The device-health and device-identity mechanisms described here, including continuity-based device identity, the dynamic device hash, credentialed attestation observations, tamper-evident and PUF monitoring, firmware-integrity-gated operation, and fleet-health aggregation, are disclosed in U.S. Provisional Application No. 64/049,409. This article is a dated public description of that disclosure and its embodiments. References to Claroty, xDome, xDome for Healthcare, Continuous Threat Detection, Secure Remote Access, Team82, Medigate, other named vendors, and to regulatory regimes such as NIS2, FDA section 524B guidance, SEC disclosure rules, and CISA Cross-Sector Cybersecurity Performance Goals are external market and technical context, offered for accurate comparison only. Product names and trademarks belong to their respective owners; nothing here is a claim about, or on behalf of, any of those products, and the comparison asserts no defect in them beyond the architectural boundary inherent to passive network monitoring. No licensing terms, pricing, or commercial arrangement is asserted by this article.