Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Concise Evidence support #83

Open
henkbirkholz opened this issue May 10, 2023 · 5 comments
Open

Add Concise Evidence support #83

henkbirkholz opened this issue May 10, 2023 · 5 comments
Labels
enhancement New feature or request good first issue Good for newcomers

Comments

@henkbirkholz
Copy link
Member

https://github.com/TrustedComputingGroup/concise-evidence is based on CoRIM.

The structure of Concise Evidence is directly symmetric to the CoRIM structure (as it reuses the CoRIM CDDL definitions).
Corresponding Appraisal Procedures for Evidence can be boiled down to a minimum set of code that has to be implemented and would match the appraisal guidance that will come with CoRIM's default profile (DICE), PSA Endorsements, and future profiles.

Adding Concise Evidence support seems to be a quite low hanging fruit and provides an convenient alternative option to EAT in cases where Attester composition becomes a bit more complex.

@thomas-fossati thomas-fossati added enhancement New feature or request good first issue Good for newcomers labels May 10, 2023
@Priyanshuthapliyal2005
Copy link
Contributor

Priyanshuthapliyal2005 commented Dec 14, 2024

Hi @henkbirkholz and @thomas-fossati

I noticed this issue has been open for long time and wanted to check if it is still active and requires contribution. Could you please confirm if this is still a priority?

Additionally, to implement Concise Evidence support effectively, should we focus on updating the relevant data structures, constraints, and extensions within the current CoRIM framework? Any specific areas or examples you could provide would be helpful in understanding the scope and expectations for this enhancement.

Looking forward to your guidance!

@deeglaze
Copy link
Collaborator

Do we have any systems producing concise evidence that could be used as a test platform? I’m still in the middle of convincing different projects (confidential containers, confidential space) to produce concise evidence or even just an EAT wrapping a cmw with custom evidence formats.

@Priyanshuthapliyal2005
Copy link
Contributor

Thanks for the update @deeglaze. Are there specific technical or organizational blockers you're running into with the confidential containers and confidential space teams? Understanding these challenges could help focus our efforts.

@deeglaze
Copy link
Collaborator

The challenge is primarily priority. They’re aware of the standardization efforts but have goals concerning feature enablement. Also the specifications aren’t finalized. We may have something to go off when the open compute project decides on an EAT profile for a standard attester.

@Priyanshuthapliyal2005
Copy link
Contributor

Thank you for the clarification, @deeglaze!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

4 participants