Skip to content

Add optional mutual post-handshake attestation - #6

Draft
atulpatildbz wants to merge 1 commit into
google:mainfrom
atulpatildbz:mutualattestedtls
Draft

atulpatildbz wants to merge 1 commit into
google:mainfrom
atulpatildbz:mutualattestedtls

Conversation

@atulpatildbz

Copy link
Copy Markdown
Collaborator

Summary

  • add optional mutual post-handshake attestation while preserving the existing server-only flow by default
  • bind role-specific client and server proofs to the TLS exporter and the complete negotiation transcript
  • require server verification before the client sends its proof, and require client verification before the server authorizes application traffic
  • add protocol version, mode, phase, role, challenges, timeouts, and fail-closed state handling to prevent downgrade, reflection, and replay attacks
  • document the architecture and extend the codelab with an opt-in confidential-space client example

Why

The SDK currently authenticates only a confidential server. Workloads in which the client also runs in a trusted execution environment need both peers to prove their environment and bind those proofs to the same TLS session before protected application requests are accepted.

Compatibility and impact

Mutual attestation is disabled unless explicitly configured. Existing clients and servers therefore retain their current server-attestation behavior. When enabled, both sides must negotiate the mutual protocol and satisfy their configured attestation policies; incomplete or mismatched negotiations fail closed.

The codelab's existing flow is unchanged. An additional script, client container, and configuration flags demonstrate the mutual flow.

Validation

  • 161 tests and 32 subtests passed
  • mutual protocol and integration coverage uses mocked attestation providers because a confidential-space environment was unavailable
  • shell syntax checks passed for the codelab scripts
  • formatting, bytecode compilation, and staged-diff checks passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant