[Notes] Attested Builds and Layered Attestations

Last updated Attestable Computing Software supply chain security Papers

Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution Environments by Hugenroth et al. and Full Trust Alchemist: Reforging Attestation for Cloud-based Confidential Workloads by Galanou et al. explore complementary approaches to hardware-rooted software build provenance. They explain how attesting the initial execution environment does not establish which inputs were consumed, what code executed, or how the resulting artifacts were produced. Both approaches can support verifiable provenance without reproducible builds.

Hugenroth et al. isolate a trusted observer inside a TEE (AWS Nitro Enclaves) from sandboxed, untrusted build execution, binding declared inputs and output digests to attestation evidence. Galanou et al. extend runtime attestation using eBPF/LSM enforcement, IMA measurements, and protected evidence recording inside an AMD SEV-SNP confidential VM. Their policy-driven architecture captures build inputs, execution events, and configuration changes, linking artifacts and SBOMs to hardware-backed evidence without requiring changes to existing build toolchains. They exemplify two approaches to extend the HW RoT to runtime: Hugenroth minimizes the trusted observer while isolating build execution; Galanou protects the mechanisms that enforce policies and record runtime state.

This connects the build provenance problem in Kettle with the architectural concern in Designing Trustworthy Layered Attestations: the mechanisms that observe execution and produce evidence must themselves be protected. For attested builds, the layers need to connect the measured environment to a trustworthy observer, the build’s inputs and execution, and ultimately its output artifacts.