Attestation requiring a hardware TPM 2.0 (or higher), and not being able to extract the private key from the TPM on your system.
TPM is Mathematically Secure and you can't extract what's put in. See, Fritz-Chip.