{
  "schema_version": "1.4.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "I-0023",
    "slug": "cove",
    "title": "Cove",
    "aliases": [
      "Compositional Multi-Party Confidential Workflows"
    ],
    "status": "draft",
    "last_reviewed": "2026-10-08",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [
      "provider-reported"
    ],
    "one_liner": "Composes attested confidential workflow stages, with owner-approved input release and certificates linking each stage to its inputs, outputs and dependencies.",
    "summary": "Cove is a framework and open-source reference implementation for confidential workflows shared by parties that do not trust each other. Its developers describe a workflow as a graph of enclave-run stages. Owners approve the exact hashed manifest of each stage before releasing keys to their private assets. Each stage produces an attested certificate linking its manifest, inputs, outputs and verified predecessors. A verifier checks that chain from the terminal certificate. The reference architecture runs Docker Compose inside Intel TDX through Phala's dstack. The developers document an end-to-end demo of the workflow primitives. The design trusts the hardware attestation path, Docker, pinned components and human code review. A compromised guest host kernel or container runtime defeats those guarantees, and published workflow bundles are hashed but lack publisher signatures [[S-1505]].",
    "category": "cryptographic-computational",
    "secondary_categories": [
      "on-chip"
    ],
    "verifies": [
      {
        "claim": "C-0011",
        "role": "primary",
        "note": "Reviewed workflow manifests and attested certificates bind evaluation stages to admitted inputs, results and predecessor evidence, under the documented host and review assumptions (S-1505)."
      }
    ],
    "threat_model": "semi-trusted",
    "adversarial_evaluation": "analysis",
    "hardware_requirement": "existing-features",
    "prover_cooperation": "required",
    "confidentiality": "preserving",
    "depends_on": [
      {
        "target": "M-0008",
        "note": "Attested key release and stage certificates rely on Intel TDX through dstack."
      }
    ],
    "readiness": {
      "assessment": true,
      "level": "R2",
      "scope": "composing owner-approved confidential workflow stages on Intel TDX",
      "rubric_version": "1.1",
      "rationale": "Public source and documentation describe an end-to-end implementation on commercial confidential hardware.\n- **R1** met: the reference documentation defines artifacts, workflow manifests, certificates and trust assumptions [[S-1505]].\n- **R2** met through a public reference implementation and documented end-to-end demo on Phala's Intel TDX stack. The demo exercises owner approval, attested release and dependency certificates [[S-1505]].\n- **R3** not met: reference code and a demo do not establish a production-grade evaluation workflow or another party's reliance on its result [[S-1505]].",
      "evidence": [
        "S-1505"
      ],
      "next_level_gaps": [
        "A production-grade, available confidential evaluation workflow, or another party's documented reliance on its results."
      ],
      "confidence": "medium",
      "assessed_by": [
        "ai-draft"
      ],
      "assessed_on": "2026-10-08",
      "status": "current",
      "dispute": null
    },
    "flaws": [
      {
        "assessment": true,
        "title": "Guest host and container compromise defeat the workflow guarantees",
        "kind": "theoretical-argument",
        "severity": "significant",
        "status": "open",
        "description": "The developers state that compromise of the Docker daemon, host kernel or trusted TEE stack defeats Cove's guarantees. Owners must also review generated manifests and the provisioning code (S-1505).",
        "sources": [
          "S-1505"
        ],
        "response": null
      },
      {
        "assessment": true,
        "title": "Workflow bundles lack publisher signatures",
        "kind": "open-question",
        "severity": "minor",
        "status": "open",
        "description": "The published bundle format is hashed and reviewable but lacks an application-level publisher signature. The developers list a signing layer as missing (S-1505).",
        "sources": [
          "S-1505"
        ],
        "response": null
      }
    ],
    "blockers": [
      {
        "text": "Docker policy cannot prove that arbitrary guest workloads cannot generate quotes when quote channels are globally exposed.",
        "theme": "evidence-binding",
        "blocked_by": null,
        "sources": [
          "S-1505"
        ]
      },
      {
        "text": "The production workflow depends on owners reviewing manifests, allow rules and provisioning code.",
        "theme": "access-governance",
        "blocked_by": null,
        "sources": [
          "S-1505"
        ]
      }
    ],
    "challenge_themes": [
      "evidence-binding",
      "hardware-trust",
      "access-governance"
    ],
    "organizations": [],
    "people": [],
    "sources": [
      {
        "source": "S-1505",
        "supports": "reference implementation; artifact and workflow model; verification; documented demos; host trust; residual risks",
        "locator": "README.md; docs/internal/architecture.md; docs/internal/security_model.md at a3e4904"
      }
    ],
    "concepts": [
      "K-0004",
      "K-0006",
      "K-0024"
    ],
    "kind": "open-source-project",
    "developer": [],
    "realises": [
      "M-0025",
      "M-0008"
    ],
    "repo": "https://github.com/covehub/cove",
    "type": "implementation",
    "url": "https://trustbutveri.fyi/implementations/cove/",
    "source_file": "content/implementations/cove.md",
    "flags_all": [
      "provider-reported"
    ],
    "body_markdown": "## What it is\n\nCove is an open-source reference implementation of [[M-0025|confidential multi-party verification]].\nIts developers describe workflows over private artifacts inside trusted execution environments, with\npublic certificates that bind each stage's claims to the measured stage that produced them [[S-1505]].\n\n## How it works\n\nA workflow is a directed acyclic graph. Each stage has a deterministically compiled manifest, represented\nas a Docker Compose file in the reference architecture. Its hash identifies the stage, and each asset\nowner approves the manifests allowed to access that owner's encrypted artifact [[S-1505]].\n\nAt runtime, a stage verifies predecessor certificates and preconditions before requesting decryption\nkeys. The owner's service releases keys only when the attestation matches the approved stage and\nprovisioner identity. The stage runs its workloads, encrypts declared outputs and emits a certificate\nbinding the manifest, admitted inputs, verified predecessors, outputs and results [[S-1505]].\n\nAn external verifier starts with the terminal certificate, workflow bytes and vendor attestation roots.\nThe verifier rederives manifest hashes and recursively checks predecessor certificates. Long-running\nservices can bind their live TLS keys to their stage certificate through remote-attestation TLS\n[[S-1505]].\n\n## Evidence\n\n- The public repository includes the compiler, command-line interface, runtime components, storage server\n  and documentation. The reference architecture uses Intel TDX through Phala's dstack [[S-1505]].\n- The developers document a demo exercising static and dynamic assets, two owners, approval rules,\n  dependency certificates, preconditions and a long-running attested service [[S-1505]].\n- The storage server, routing layer and orchestration are outside the integrity trust root. Verification\n  rests on the manifests, pinned components and attestation evidence [[S-1505]].\n\n## Limitations\n\nCove trusts the hardware attestation path, Docker's enforcement, pinned first-party components and human\nreview of public code. Compromise of the Docker daemon, guest host kernel or trusted TEE stack defeats its\nguarantees [[S-1505]]. Published bundles lack publisher signatures, and some trusted components use host\nnetworking. The developers distinguish demo key release from production attested key release [[S-1505]].",
    "body_text": "What it is Cove is an open-source reference implementation of confidential multi-party verification. Its developers describe workflows over private artifacts inside trusted execution environments, with public certificates that bind each stage's claims to the measured stage that produced them [S-1505]. How it works A workflow is a directed acyclic graph. Each stage has a deterministically compiled manifest, represented as a Docker Compose file in the reference architecture. Its hash identifies the stage, and each asset owner approves the manifests allowed to access that owner's encrypted artifact [S-1505]. At runtime, a stage verifies predecessor certificates and preconditions before requesting decryption keys. The owner's service releases keys only when the attestation matches the approved stage and provisioner identity. The stage runs its workloads, encrypts declared outputs and emits a certificate binding the manifest, admitted inputs, verified predecessors, outputs and results [S-1505]. An external verifier starts with the terminal certificate, workflow bytes and vendor attestation roots. The verifier rederives manifest hashes and recursively checks predecessor certificates. Long-running services can bind their live TLS keys to their stage certificate through remote-attestation TLS [S-1505]. Evidence - The public repository includes the compiler, command-line interface, runtime components, storage server and documentation. The reference architecture uses Intel TDX through Phala's dstack [S-1505]. - The developers document a demo exercising static and dynamic assets, two owners, approval rules, dependency certificates, preconditions and a long-running attested service [S-1505]. - The storage server, routing layer and orchestration are outside the integrity trust root. Verification rests on the manifests, pinned components and attestation evidence [S-1505]. Limitations Cove trusts the hardware attestation path, Docker's enforcement, pinned first-party components and human review of public code. Compromise of the Docker daemon, guest host kernel or trusted TEE stack defeats its guarantees [S-1505]. Published bundles lack publisher signatures, and some trusted components use host networking. The developers distinguish demo key release from production attested key release [S-1505].",
    "referenced_by": [
      {
        "id": "C-0011",
        "title": "The declared evaluation was run",
        "url": "https://trustbutveri.fyi/claims/declared-evaluation-was-run/"
      }
    ]
  }
}