Attestable-build proof lifecycle management

Develop the attestable-build variant of mutual reference-value bootstrapping, including mechanisms for revocation and transparency of confidential-computing build proofs.

Background

For artifact-measured architectures such as AWS Nitro Enclaves, the self-contained construction requires each node to reproducibly rebuild a peer’s artifact at run time, which imposes toolchain, memory, and latency costs. The paper discusses an alternative in which a vendor or deployer supplies a measurement together with a hardware-rooted confidential-computing proof that the measurement was produced from the peer’s reconstructed source.

Although the proof provider need not be trusted for the reference value itself, verifiers must validate the build proof and may need to trust the build TEE’s hardware root and endorsement PKI. The paper leaves the practical design of this offloaded scheme unresolved, specifically identifying revocation and transparency for build proofs as outstanding issues.

References

Working out this design, including revocation and transparency for build proofs, is future work.

Bootstrapping Mutual Attestation with Kleene's Second Recursion Theorem  (2608.20671 - Imamura, 21 Aug 2026) in Section 6.1, “Offloading the run-time build”