The checks:
- The signature chains to AMD. The attestation report is signed by a key that chains to AMD's root certificate.
- The platform is patched. Its security versions meet our published minimum.
- Debugging is off in the machine's policy.
- The code is ours. The launch measurement matches a release we published in a public transparency log.
- The report is bound to this run. The report data matches a hash of the receipt's key and the run's nonce.
- The receipt is intact. Its signature verifies, and the file hashes match.
Know what's attested and what isn't. The measurement, policy, security versions and report data are attested by AMD hardware.
"Documents read" and "copy erased" are statements made by the measured code.
- Can I perform attestation for my AMD-based confidential VMs?
- How do I verify an AMD SEV-SNP attestation report?
Written by the NexQloud Drawback team from the primary sources linked on this page.
Not legal advice. NexQloud Drawback is not a government agency.
NexQloud Drawback is software used by licensed customs brokers.
