Repository navigation
feat(enclave): sign receipts with a Tinfoil attested key - #9553
Merged
Merged
Conversation
The receipt key is now an ed25519 key Tinfoil makes inside the enclave at boot (attested-keys in the config). The receipt carries a v3 report that lists the key, so verify_receipt checks it without the key bundle, and upload_to_rekor takes the key from the receipt.
|
Check out this pull request on See visual diffs & provide feedback on Jupyter Notebooks. Powered by ReviewNB |
Drop runPublicKey and the identity-key fallback: receipts are signed only with the Tinfoil attested key, and verify_receipt / upload_to_rekor read it from the report's crypto_material. The report nonce is now random. Predicate type bumped to receipt/v3.
evalPipeline lists models and config apart; each entry has an id and appliesTo names the models it works on. evalDataset replaces eval.evalSet.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Receipts are now signed with a Tinfoil attested key instead of the enclave's syft identity key.
enclave-signing-keyand grant it to thesyft-enclavecontainer. Tinfoil makes it inside the enclave at boot and mounts it at/run/tinfoil/keys/enclave-signing-key/. Both configs passtinfoil-configvalidation.cvm-version0.14.12 already supports it (attested keys landed in 0.14.10).receipt/signing_key.py): receipts are signed only with the attested key. Without it (off Tinfoil, or a config without the key) the job shipsreceipt_error.txt. The identity-key fallback is gone.receipt/key_binding.py): once per boot the enclave fetches a v3 report from/tinfoil/attestation.sock(random nonce) and puts it in each receipt asexecution.attestation.keyBinding. The report'scrypto_materialis the only place the receipt names its key:runPublicKeyis removed, and the predicate type is bumped toreceipt/v3.verify_receipt(envelope)andupload_to_rekor(envelope)take only the envelope. They check that the report data matches the report's key list, read the key listed underenclave-signing-key, and check that key signed the receipt.model→evalPipeline, withmodels(base, adapter) andconfig(sampling) as separate lists. Every entry has anid, andappliesTonames the model ids it works on.eval.evalSet→evalDataset. The modelwrap hash moves frommodel.weightsinto the base model'salsoKnownAs.attestation: truestays, because only the socket returns v3 reports (/tinfoil/attestation.jsonis v2).Caveat
verify_receiptdoesn't check the report's hardware signature: the tinfoil Python SDK can't read v3 reports yet (tinfoil-go can). Before this PR the notebook checked the receipt against the bundle from the live attestation it had just verified.Release
Nothing is released yet. To use it:
just tinfoil-build, thenjust tinfoil-release <tag> tinfoil/tinfoil-config-receipts.yml(opens a PR onOpenMined/syft-enclave-tinfoil). After that, update the release table inSETUP.md.Tests
packages/syft-enclave/tests: 282 passed;just test-unit-fast: 518 passedenclave-signing-key, tampered report data, a missing attested key, and fetching the report over the socket