Skip to content

feat(enclave): sign receipts with a Tinfoil attested key - #9553

Merged
koenvanderveen merged 5 commits into
devfrom
koen/tinfoil-attested-receipt-key
Oct 5, 2026
Merged

koenvanderveen merged 5 commits into
devfrom
koen/tinfoil-attested-receipt-key

Conversation

@koenvanderveen

@koenvanderveen koenvanderveen commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

What

Receipts are now signed with a Tinfoil attested key instead of the enclave's syft identity key.

  • Config: both Tinfoil configs declare an ed25519 attested key enclave-signing-key and grant it to the syft-enclave container. Tinfoil makes it inside the enclave at boot and mounts it at /run/tinfoil/keys/enclave-signing-key/. Both configs pass tinfoil-config validation. cvm-version 0.14.12 already supports it (attested keys landed in 0.14.10).
  • Signing (receipt/signing_key.py): receipts are signed only with the attested key. Without it (off Tinfoil, or a config without the key) the job ships receipt_error.txt. The identity-key fallback is gone.
  • One place for the key (receipt/key_binding.py): once per boot the enclave fetches a v3 report from /tinfoil/attestation.sock (random nonce) and puts it in each receipt as execution.attestation.keyBinding. The report's crypto_material is the only place the receipt names its key: runPublicKey is removed, and the predicate type is bumped to receipt/v3.
  • Verify / Rekor: verify_receipt(envelope) and upload_to_rekor(envelope) take only the envelope. They check that the report data matches the report's key list, read the key listed under enclave-signing-key, and check that key signed the receipt.
  • Claims schema: model → evalPipeline, with models (base, adapter) and config (sampling) as separate lists. Every entry has an id, and appliesTo names the model ids it works on. eval.evalSet → evalDataset. The modelwrap hash moves from model.weights into the base model's alsoKnownAs.
  • Notebook: the benchmark owner's double blind eval notebook uses the new calls and writes the new claims.

attestation: true stays, because only the socket returns v3 reports (/tinfoil/attestation.json is v2).

Caveat

verify_receipt doesn't check the report's hardware signature: the tinfoil Python SDK can't read v3 reports yet (tinfoil-go can). Before this PR the notebook checked the receipt against the bundle from the live attestation it had just verified.

Release

Nothing is released yet. To use it: just tinfoil-build, then just tinfoil-release <tag> tinfoil/tinfoil-config-receipts.yml (opens a PR on OpenMined/syft-enclave-tinfoil). After that, update the release table in SETUP.md.

Tests

  • packages/syft-enclave/tests: 282 passed; just test-unit-fast: 518 passed
  • The full-job receipt tests run against a mocked Tinfoil: a generated key at the attested-key path, a fake config and boot report, and a fake attestation socket that serves a report listing that key
  • Unit tests cover tampering, forged signatures, receipts without a report, reports without enclave-signing-key, tampered report data, a missing attested key, and fetching the report over the socket
  • The parser was checked against tinfoil-go's ed25519 attested-key test vector
  • Not tested on a real Tinfoil enclave

The receipt key is now an ed25519 key Tinfoil makes inside the enclave at
boot (attested-keys in the config). The receipt carries a v3 report that
lists the key, so verify_receipt checks it without the key bundle, and
upload_to_rekor takes the key from the receipt.
@review-notebook-app

Copy link
Copy Markdown

Check out this pull request on  ReviewNB

See visual diffs & provide feedback on Jupyter Notebooks.


Powered by ReviewNB

Drop runPublicKey and the identity-key fallback: receipts are signed only
with the Tinfoil attested key, and verify_receipt / upload_to_rekor read
it from the report's crypto_material. The report nonce is now random.
Predicate type bumped to receipt/v3.
evalPipeline lists models and config apart; each entry has an id and
appliesTo names the models it works on. evalDataset replaces eval.evalSet.
@koenvanderveen
koenvanderveen merged commit 4da7557 into dev Oct 5, 2026
23 checks passed
@koenvanderveen
koenvanderveen deleted the koen/tinfoil-attested-receipt-key branch October 5, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant