AWS re:Inforce 2025-Demystifying attestation: Measure and verify your execution environment (DAP442)
Highly sensitive workloads often rely on cryptographic proof about the code, config, and other aspects of the execution environment before unsealing code for data to be processed. In this code talk we will see examples of cryptographic attestation using AWS Nitro Enclaves, Nitro Trusted Platform Module (NitroTPM), and Amazon EC2 instance identity documents. We will also visit common scenarios where this is useful in multi-party computation setups for data analytics and generative AI.