Skip to main content

Module verifier

Module verifier 

Source
Expand description

Verification of TEE attestation evidence carried in an RFC 9711 EAT.

The server embeds exactly one TEE-specific evidence blob in the EAT submods map, under a label from submod. verify_evidence dispatches on that label:

LabelTEEEvidenceVerified by
aws_nitroAWS NitroNSM attestation document (COSE_Sign1)nitro
sev_snpAMD SEV-SNPmap {report, vcek}: report + VCEK (DER)sev_snp
tdxIntel TDXDCAP quote v4/v5 with PCK chaindcap
sgxIntel SGXDCAP quote v3/v4/v5 with PCK chaindcap

Every verifier checks the vendor signature chain up to a root in the TrustStore and returns a VerifiedEvidence. verify_evidence then enforces the Policy and checks that the evidence’s report data is bound to the expected hash (the SHA-256 of the RA-TLS certificate’s public key).

Modules§

dcap
Intel TDX and SGX evidence: ECDSA-P256 DCAP quotes (SGX v3, SGX/TDX v4 and v5).
nitro
AWS Nitro Enclaves evidence: an NSM attestation document (COSE_Sign1, ES384) whose signing certificate chains to the AWS Nitro Enclaves root.
sev_snp
AMD SEV-SNP evidence: an attestation report signed by the chip’s VCEK, whose certificate chains through the ASK to the AMD Root Key (ARK) of the processor family.
submod
EAT submods labels identifying the TEE that produced the nested evidence.

Structs§

Policy
Relaxations of the default (strict) verification policy.
TrustStore
Trust anchors for each vendor’s attestation signing chain.
VerifiedEvidence
Evidence whose signature chain has been verified.

Enums§

TeeKind
The trusted execution environment that produced a piece of evidence.

Functions§

is_bound_to
Returns true if report_data equals binding, or starts with it and is zero-padded.
verify_evidence
Verifies the TEE evidence in eat_bytes at time now and checks that it is bound to binding, the SHA-256 of the RA-TLS certificate’s public key.