TrustMee: Self-Verifying Remote Attestation Evidence

πŸ“… 2026-02-13
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF

Technology Category

Application Domains: SecurityData Mining & Knowledge Management: Representing, Reasoning, and Using Provenance, TrustMultiagent Systems: Mechanism Design

Application Category

Security and Privacy: Data transparency and provenanceResponsible Web: Data and user privacy-enhancing technologies for the WebSystems and Infrastructure for Web, Mobile and WoT: Virtualization and resource management in Web systems and infrastructures
πŸ“ Abstract
Hardware-secured remote attestation is essential to establishing trust in the integrity of confidential virtual machines (cVMs), but is difficult to use in practice because verifying attestation evidence requires the use of hardware-specific cryptographic logic. This increases both maintenance costs and the verifiers'trusted computing base. We introduce the concept of self-verifying remote attestation evidence. Each attestation bundle includes verification logic as a WebAssembly component signed by a trusted party. This approach transforms evidence verification into a standard code-signing problem: the verifier checks the signature on the embedded logic and then executes it to validate the evidence. As a result, verifiers can validate attestation evidence without any platform-specific knowledge. We implement this concept as TrustMee, a platform-agnostic verification driver for the Trustee framework. We demonstrate its functionality with self-verifying evidence for AMD SEV-SNP and Intel TDX attestations, producing attestation claims in the standard EAT Attestation Result (EAR) format.
Problem

Research questions and friction points this paper is trying to address.

remote attestation
hardware security
trusted computing
confidential virtual machines
attestation evidence
Innovation

Methods, ideas, or system contributions that make the work stand out.

self-verifying attestation
WebAssembly
remote attestation
trusted computing base
platform-agnostic verification
πŸ”Ž Similar Papers
No similar papers found.
P
Parsa Sadri Sinaki
Aalto University
Z
Zainab Ahmad
Ericsson Research, Aalto University
W
Wentao Xie
Ericsson Research, Aalto University
Merlijn Sebrechts
Merlijn Sebrechts
Senior researcher at imec and teaching fellow at Ghent University in the IDLab research group
Confidential ComputingDevOpsCloud ComputingEdge Computing
J
Jimmy KjΓ€llman
Ericsson Research
L
Lachlan J. Gunn
Aalto University