The Cr-48's Integrity measurement is done without involving the TPM by using a device-mapper target. Boot-time trust in the kernel allows for efficient block level integrity checking which has different applications than linux-ima and avoids some of the performance bottlenecks along the way: