Expand description
Verification of TEE attestation evidence carried in an RFC 9711 EAT.
The server embeds exactly one TEE-specific evidence blob in the EAT submods map, under a
label from submod. verify_evidence dispatches on that label:
| Label | TEE | Evidence | Verified by |
|---|---|---|---|
aws_nitro | AWS Nitro | NSM attestation document (COSE_Sign1) | nitro |
sev_snp | AMD SEV-SNP | map {report, vcek}: report + VCEK (DER) | sev_snp |
tdx | Intel TDX | DCAP quote v4/v5 with PCK chain | dcap |
sgx | Intel SGX | DCAP quote v3/v4/v5 with PCK chain | dcap |
Every verifier checks the vendor signature chain up to a root in the TrustStore and
returns a VerifiedEvidence. verify_evidence then enforces the Policy and checks
that the evidence’s report data is bound to the expected hash (the SHA-256 of the RA-TLS
certificate’s public key).
Modules§
- dcap
- Intel TDX and SGX evidence: ECDSA-P256 DCAP quotes (SGX v3, SGX/TDX v4 and v5).
- nitro
- AWS Nitro Enclaves evidence: an NSM attestation document (COSE_Sign1, ES384) whose signing certificate chains to the AWS Nitro Enclaves root.
- sev_snp
- AMD SEV-SNP evidence: an attestation report signed by the chip’s VCEK, whose certificate chains through the ASK to the AMD Root Key (ARK) of the processor family.
- submod
- EAT
submodslabels identifying the TEE that produced the nested evidence.
Structs§
- Policy
- Relaxations of the default (strict) verification policy.
- Trust
Store - Trust anchors for each vendor’s attestation signing chain.
- Verified
Evidence - Evidence whose signature chain has been verified.
Enums§
- TeeKind
- The trusted execution environment that produced a piece of evidence.
Functions§
- is_
bound_ to - Returns
trueifreport_dataequalsbinding, or starts with it and is zero-padded. - verify_
evidence - Verifies the TEE evidence in
eat_bytesat timenowand checks that it is bound tobinding, the SHA-256 of the RA-TLS certificate’s public key.