Valutazione della tecnologia di Confidential Computing per Servizi Blockchain Attestati
View/ Open
Author
Korejo, Muhammad Tahir <2000>
Date
2026-09-03Data available
2026-09-10Abstract
I dati logistici sono prodotti da un'organizzazione, elaborati da un'altra e registrati su un registro condiviso. La cifratura li protegge a riposo e in transito, ma non durante l'elaborazione: risiedono in chiaro in memoria, esposti al software privilegiato della macchina. Per un sistema connesso a una blockchain ciò conta: il valore di una registrazione inalterabile dipende dall'integrità del servizio off-chain che l'ha prodotta.
Un registro permissioned è adatto perché nella logistica nessuna parte è proprietaria del dato. Hyperledger Fabric offre uno storico condiviso e in sola aggiunta, in cui ogni transazione è legata a un'identità responsabile. Le sue garanzie, però, valgono solo dopo la sottomissione di una transazione. Ciò che il registro non può stabilire è lo stato di esecuzione del servizio che detiene la credenziale: la stessa identità valida può appartenere al servizio atteso o a uno manomesso su host compromesso. Questa lacuna di fiducia precedente al registro è il problema affrontato.
La tesi valuta come Intel TDX, la Remote Attestation e RA-TLS possano rendere tale stato verificabile dall'esterno. Sono realizzati due prototipi. Il primo stabilisce un canale mutuamente attestato tra un servizio su Confidential VM Intel TDX in cloud e uno su host TDX on-premise, ciascuno legando la propria chiave TLS dentro la propria evidenza hardware, così che non possano essere separate. Il secondo mappa eventi DCSA Track & Trace nel modello BiTAS di una piattaforma Hyperledger Fabric esistente senza modificarne il chaincode.
L'accettazione del canale può dipendere da evidenze sullo stato di esecuzione anziché dalle sole credenziali. Un risultato trasferibile: le evidenze generate nel Trust Domain in cloud non sono verificabili tramite un percorso DCAP/PCCS on-premise, rendendo necessario un verificatore gestito. Sono risultati di fattibilità: nessuno dei due meccanismi stabilisce la verità fisica dell'evento riportato. Logistics records are produced by one organisation, processed by another, and committed to a shared ledger that several parties later rely on. Encryption protects such records in storage and in transit, but not while they are processed, when data sits in cleartext, exposed to whatever privileged software controls the machine. For a blockchain-facing system this matters: the worth of a tamper-evident ledger entry depends on the integrity of the off-chain service that produced it.
A permissioned ledger suits this setting, since logistics has no single owner of the record. Hyperledger Fabric gives independent parties a shared append-only history in which every transaction is bound to an accountable identity. Its guarantees, however, take effect only once a transaction has been submitted. What the ledger cannot establish is the runtime state of the service that held the credential: the same valid identity could belong to the expected service or to a tampered one on a compromised host. This pre-ledger runtime-trust gap is the problem addressed here.
The thesis evaluates how Intel TDX, Remote Attestation and Remote Attestation over TLS can make that runtime externally verifiable. Two prototypes are built. The first establishes a mutually attested channel between a service on a cloud Intel TDX Confidential VM and one on an on-premises TDX host, each binding its TLS key into its hardware-rooted evidence so the two cannot be separated. The second maps DCSA Track & Trace events into the BiTAS model of an existing Hyperledger Fabric platform without altering its chaincode.
Channel acceptance can be made to depend on runtime evidence rather than credentials alone. One transferable finding emerged: evidence generated in the cloud Trust Domain could not be verified through an on-premises DCAP/PCCS path, so a managed verifier was required. These are feasibility results, and neither mechanism establishes the physical truth of a reported event.
Type
info:eu-repo/semantics/masterThesisCollections
- Laurea Magistrale [8051]

