{"_id":"@dashlane/nsm-attestation","_rev":"8-a2a0e7059c7c55afa375830ce475d8a0","name":"@dashlane/nsm-attestation","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.1":{"name":"@dashlane/nsm-attestation","version":"1.0.1","author":{"name":"Dashlane Inc."},"license":"PROPRIETARY","_id":"@dashlane/nsm-attestation@1.0.1","maintainers":[{"name":"swauquier","email":"sebastien.wauquier@dashlane.com"},{"name":"bastien.granger","email":"grangerbastien@gmail.com"},{"name":"guillaumemarondashlane","email":"guillaume.maron@dashlane.com"},{"name":"dashlaneqbarbe","email":"quentin@dashlane.com"}],"dist":{"shasum":"8006c190f38157a5d3c88792c295b57c947c4403","tarball":"https://registry.npmjs.org/@dashlane/nsm-attestation/-/nsm-attestation-1.0.1.tgz","fileCount":27,"integrity":"sha512-okfOXLusPqWbadGOTikCY76hXz7Fi6tW0ORCevXQZg3h+O+QEftE2QijUw7VJa4bPHtT8d2nWPnpGqfnLb59Kw==","signatures":[{"sig":"MEYCIQDzS228FmPhKEeAAX54+i8NJJXnXyfteIQ2yOB2r091zwIhAP1AFGidBm8YI1FNDYQFP1a1bM9T/FJml/5ngv23Fj3R","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":55185},"main":"dist/index.js","_from":"file:dashlane-nsm-attestation-1.0.1.tgz","types":"./dist/index.d.ts","scripts":{"lint":"pnpm eslint --ext ts \"src/**/*.ts\"","build":"tsc -b","start":"NODE_ENV=dev node dist/index.js","watch":"tsc -w","lint:fix":"pnpm --quiet run lint --fix","prettier":"prettier --check --cache *.json 'src/**/*.ts'","prettier:fix":"prettier -w --cache *.json 'src/**/*.ts'","prettier:clear-cache":"prettier --check *.json src/**/*.ts"},"_npmUser":{"name":"dashlaneqbarbe","email":"quentin@dashlane.com"},"_resolved":"/tmp/36a1472bada7a917a73e8fa8286ee456/dashlane-nsm-attestation-1.0.1.tgz","_integrity":"sha512-okfOXLusPqWbadGOTikCY76hXz7Fi6tW0ORCevXQZg3h+O+QEftE2QijUw7VJa4bPHtT8d2nWPnpGqfnLb59Kw==","repository":{"url":"git@gitlab.dashlane.com:dashlane/teams/code/server/nitro-encryption-service.git","type":"git"},"_npmVersion":"10.5.0","description":"NSM Attestation Module","directories":{"src":"src"},"_nodeVersion":"18.20.2","dependencies":{"pem":"1.14.8","cbor":"9.0.2","cose-js":"0.9.0"},"publishConfig":{"@dashlane:registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"@types/pem":"1.14.4","@types/cose-js":"0.8.3"},"_npmOperationalInternal":{"tmp":"tmp/nsm-attestation_1.0.1_1715781747637_0.53811644712055","host":"s3://npm-registry-packages"}},"1.0.2":{"name":"@dashlane/nsm-attestation","version":"1.0.2","author":{"name":"Dashlane Inc."},"license":"PROPRIETARY","_id":"@dashlane/nsm-attestation@1.0.2","maintainers":[{"name":"swauquier","email":"sebastien.wauquier@dashlane.com"},{"name":"bastien.granger","email":"grangerbastien@gmail.com"},{"name":"guillaumemarondashlane","email":"guillaume.maron@dashlane.com"},{"name":"dashlaneqbarbe","email":"quentin@dashlane.com"}],"dist":{"shasum":"f4bf881ae3e1ee9f575a476ed00382cc28532f1c","tarball":"https://registry.npmjs.org/@dashlane/nsm-attestation/-/nsm-attestation-1.0.2.tgz","fileCount":27,"integrity":"sha512-bJEVhy5HQAZTEvsFO0s/dqGDXN8j+onFElOB+BYK5CYf7ApsQ2MhyIG8u/NbLpD6gFH8Or4LdaJTEM+MthV4/Q==","signatures":[{"sig":"MEUCIQCyUw1K1jBuJ4sVqUsoRD4K85xM6G5hZRMTOwRM0xvA1gIgPet9eV22l3CI4M/jZNLeJBuYR0ULGLqJ7UzMFQitlZU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":55290},"main":"dist/index.js","_from":"file:dashlane-nsm-attestation-1.0.2.tgz","types":"./dist/index.d.ts","scripts":{"lint":"pnpm eslint --ext ts \"src/**/*.ts\"","build":"tsc -b","start":"NODE_ENV=dev node dist/index.js","watch":"tsc -w","lint:fix":"pnpm --quiet run lint --fix","prettier":"prettier --check --cache *.json 'src/**/*.ts'","prettier:fix":"prettier -w --cache *.json 'src/**/*.ts'","prettier:clear-cache":"prettier --check *.json src/**/*.ts"},"_npmUser":{"name":"dashlaneqbarbe","email":"quentin@dashlane.com"},"_resolved":"/tmp/61ca94ec852c66bdd8cce6ce2d3808af/dashlane-nsm-attestation-1.0.2.tgz","_integrity":"sha512-bJEVhy5HQAZTEvsFO0s/dqGDXN8j+onFElOB+BYK5CYf7ApsQ2MhyIG8u/NbLpD6gFH8Or4LdaJTEM+MthV4/Q==","repository":{"url":"git@gitlab.dashlane.com:dashlane/teams/code/server/nitro-encryption-service.git","type":"git"},"_npmVersion":"10.7.0","description":"NSM Attestation Module","directories":{"src":"src"},"_nodeVersion":"18.20.3","dependencies":{"pem":"1.14.8","cbor":"9.0.2","cose-js":"0.9.0"},"publishConfig":{"@dashlane:registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"@types/pem":"1.14.4","@types/cose-js":"0.8.3"},"_npmOperationalInternal":{"tmp":"tmp/nsm-attestation_1.0.2_1717403884724_0.1205247906831699","host":"s3://npm-registry-packages"}}},"time":{"created":"2024-05-15T14:02:27.553Z","modified":"2026-07-24T07:47:37.206Z","1.0.0":"2024-05-15T12:28:47.273Z","1.0.1":"2024-05-15T14:02:27.809Z","1.0.2":"2024-06-03T08:38:04.903Z"},"author":{"name":"Dashlane Inc."},"license":"PROPRIETARY","repository":{"url":"git@gitlab.dashlane.com:dashlane/teams/code/server/nitro-encryption-service.git","type":"git"},"description":"NSM Attestation Module","maintainers":[{"email":"guillaume.maron@dashlane.com","name":"guillaumemarondashlane"},{"email":"quentin@dashlane.com","name":"dashlaneqbarbe"},{"email":"grangerbastien@gmail.com","name":"bastien.granger"}],"readme":"# NSM Attestation module\n\nThis module provides Nitro Enclaves with attestation capability.\n\n## Verify a Nitro Security Module (NSM) attestation\n\nFollowing the steps here: https://docs.aws.amazon.com/enclaves/latest/user/verify-root.html\n\n### Prerequisites\n\nYou must have embedded in your apps:\n\n-   the AWS Nitro Root certificate\n-   the expected PCRs of the enclave (unique measurements that allows to identify a Dashlane enclave)\n\nAWS Nitro uses the elliptic curve P384 to generate keys (secp384r1 on openssl) and SHA384 hash signatures.\n\n### Step 1. Decode the CBOR object and map it to a COSE_Sign1 structure\n\nMake sure that the CBOR object you received is signed with COSE.\nWhile decoding you must find an array containing 4 parts (see [IETF draft](https://tools.ietf.org/id/draft-ietf-cose-rfc8152bis-struct-00.html)):\n\n1. protected: the set of protected header parameters wrapped in a bstr\n1. unprotected: the set of unprotected header parameters as a map\n1. payload: the serialized content that was signed\n1. signature: array of signatures (contains the expected COSE_Sign1 signature)\n\nNote: CBOR object of NSM attestation is not tagged (18 for cosesign1).\n\n### Step 2. Extract the attestation document from the COSE_Sign1 structure\n\nYou must parse the payload of the attestation document and ensure it follows the structure defined by AWS.\n\nYou can find the structure [here](https://docs.aws.amazon.com/enclaves/latest/user/verify-root.html#validation-process).\n\n### Step 3. Verify the certificate's chain\n\nThe attestation document contains two important elements:\n\n-   a certificate: it's the public key certificate containing the public key that will be used to validate the COSE signature of the attestation\n-   a cabundle: it contains the certificate chains from the root CA to the intermediate CA that issued the above certificate\n\nThe goal of this step is to validate the certificate chain (+ the final certificate) with the root certificate (on production it's the AWS Nitro Root certificate).\n\n### Step 4. Ensure the attestation document is properly signed\n\nNow that we know the certificate chain is valid we can extract the public key from the attestation document certificate and use it to verify the COSE signature of the attestation.\n\n### Step 5. Ensure the PCRs are matching\n\nWe should compare the embedded PCRs in our apps to the ones signed in the attestation document. If they match we know we're talking to the right enclave.\n\n## Mock a Nitro Security Module (NSM) attestation\n\n### Step 1. Create a certificate chain\n\nInside the `certs` folder you can find:\n\n-   `createRootCA.sh` to generate a root certificate and an intermediate certificate (using secp384r1 algorithm and SHA384)\n-   `createEnclaveCert.sh` to generate the enclave certificate signed by the intermediate certificate\n\n### Step 2. Create an attestation document\n\nPut some sample data in an object following the structure provided by AWS: https://docs.aws.amazon.com/enclaves/latest/user/verify-root.html\n\n### Step 3. Encode the attestation\n\nEncode the previous object with CBOR.\n\n### Step 4. Sign the attestation\n\nTake the private key of your enclave certificate and sign the attestation using COSE with the algorithm ES384 (and remove the COSE tags).\n","readmeFilename":"README.md"}