Skip to main content

Module dcap

Module dcap 

Source
Expand description

Intel TDX and SGX evidence: ECDSA-P256 DCAP quotes (SGX v3, SGX/TDX v4 and v5).

Checks performed:

  1. the PCK certificate chain embedded in the quote (certification data type 5, PEM or DER) chains to the pinned Intel SGX Root CA and is valid now;
  2. the Quoting Enclave (QE) report is signed by the PCK key, and is not a debug enclave;
  3. the QE report’s REPORT_DATA binds the attestation key: SHA-256(attestation_key || qe_auth_data) followed by 32 zero bytes;
  4. the quote header and body are signed by the attestation key.

Not evaluated: TCB status and QE identity against Intel PCS collateral (TCB Info, QE Identity, PCK CRLs). A genuine but out-of-date or revoked platform is therefore accepted.

Functions§

verify
Verifies the DCAP quote produced by tee (TDX or SGX) at time now.