-
Notifications
You must be signed in to change notification settings - Fork 0
Add a distributed enclave attestation protocol #61
Copy link
Copy link
Open
Labels
component:blockchainSubstrate runtime, node, pallets, and bridgeSubstrate runtime, node, pallets, and bridgecomponent:provider-agentRust Provider Agent and Docker executionRust Provider Agent and Docker executioncomponent:validatorIndependent proof verification and provider scoring networkIndependent proof verification and provider scoring networkpriority:mediumImportant follow-upImportant follow-uptype:securitySecurity hardeningSecurity hardening
Description
Metadata
Metadata
Assignees
Labels
component:blockchainSubstrate runtime, node, pallets, and bridgeSubstrate runtime, node, pallets, and bridgecomponent:provider-agentRust Provider Agent and Docker executionRust Provider Agent and Docker executioncomponent:validatorIndependent proof verification and provider scoring networkIndependent proof verification and provider scoring networkpriority:mediumImportant follow-upImportant follow-uptype:securitySecurity hardeningSecurity hardening
Prove, to anyone and not just to the tenant, that a workload is genuinely running inside a valid TEE on the provider it claims. Without distributed attestation, #60's confidentiality guarantee rests on the provider's own word, which is precisely the trust this roadmap removes.
Blocked by: ADR-019 (see ADR-012 §6) — no implementation before acceptance. Ships with #60.
Acceptance criteria:
Original request (FR, preserved verbatim):