The key to decrypt the basic system is not released by the TPM if the chain of trust cannot beestablished, i.e. if there is an integrity violation. Thus, the first requirement is met. In addition, we required that an ATM can be checked periodically by the manufacturer and the bank—whether the running system is still uncompromised.