During the ATM’s operation, we need proof that the security suite within the bank system is still running and that it is up-to-date. We propose that the security suite actively gives some kind of a “sign of life” from time to time. We may assume that this application is the only one that is given access to the vTPM within the bank system—i.e. the authorization code for the vTPM is only known by that application.The current timestamp is needed to prevent replay attacks and the information about the software version is needed as the security suite needs to be up-to-date at any time.