{"id":32718117,"url":"https://github.com/automata-network/aws-nitro-enclave-attestation","last_synced_at":"2026-04-01T17:35:29.099Z","repository":{"id":320172053,"uuid":"1012977801","full_name":"automata-network/aws-nitro-enclave-attestation","owner":"automata-network","description":"AWS Nitro Enclave Attestation CLI","archived":false,"fork":false,"pushed_at":"2026-03-20T09:54:16.000Z","size":4602,"stargazers_count":7,"open_issues_count":2,"forks_count":2,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-03-21T02:27:13.534Z","etag":null,"topics":["nitro-enclave","solidity","tee"],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/automata-network.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-07-03T07:12:54.000Z","updated_at":"2026-03-20T23:04:24.000Z","dependencies_parsed_at":"2025-10-22T11:32:53.364Z","dependency_job_id":"4fec05cc-90a6-448f-a8d8-af075673daf6","html_url":"https://github.com/automata-network/aws-nitro-enclave-attestation","commit_stats":null,"previous_names":["automata-network/aws-nitro-enclave-attestation"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/automata-network/aws-nitro-enclave-attestation","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/automata-network%2Faws-nitro-enclave-attestation","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/automata-network%2Faws-nitro-enclave-attestation/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/automata-network%2Faws-nitro-enclave-attestation/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/automata-network%2Faws-nitro-enclave-attestation/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/automata-network","download_url":"https://codeload.github.com/automata-network/aws-nitro-enclave-attestation/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/automata-network%2Faws-nitro-enclave-attestation/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31290537,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-01T13:12:26.723Z","status":"ssl_error","status_checked_at":"2026-04-01T13:12:25.102Z","response_time":53,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["nitro-enclave","solidity","tee"],"created_at":"2025-11-02T17:00:49.942Z","updated_at":"2026-04-01T17:35:29.088Z","avatar_url":"https://github.com/automata-network.png","language":"Rust","funding_links":[],"categories":["Repositories","🌟 Active Builder Projects"],"sub_categories":["SDKs","🚀 Infrastructure \u0026 SDKs"],"readme":"\u003cdiv align=\"center\"\u003e\n  \u003cpicture\u003e\n    \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://raw.githubusercontent.com/automata-network/automata-brand-kit/main/PNG/ATA_White%20Text%20with%20Color%20Logo.png\"\u003e\n    \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://raw.githubusercontent.com/automata-network/automata-brand-kit/main/PNG/ATA_Black%20Text%20with%20Color%20Logo.png\"\u003e\n    \u003cimg src=\"https://raw.githubusercontent.com/automata-network/automata-brand-kit/main/PNG/ATA_White%20Text%20with%20Color%20Logo.png\" width=\"50%\"\u003e\n  \u003c/picture\u003e\n\u003c/div\u003e\n\n# AWS Nitro Enclave Attestation SDK\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](LICENSE)\n\nA comprehensive SDK for AWS Nitro Enclave attestation verification that generates zero-knowledge proofs for on-chain verification with batch processing capabilities.\n\n## Features\n\n* **Zero-Knowledge Proof Generation**\n  * Creates on-chain verifiable zero-knowledge proofs (ZKPs) for attestation reports\n  * Supports both single and batch attestation verification\n* **Multi-Backend Support**\n  * Compatible with both Risc0 and Succinct proving systems, providing a unified user experience\n  * Optimized performance profiles for different use cases\n* **Batch Verification**\n  * Supports attestation report batch verification to significantly reduce on-chain verification costs\n* **Smart Contract Integration**\n  * Includes on-chain verification contracts for seamless blockchain integration\n  * Gas-optimized verification with certificate revocation support\n* **Comprehensive CLI Tool**\n  * Comprehensive CLI tool for proof generation, verification, and debugging\n\n## Predeploy Contracts\n\n## Mainnet Deployments\n\n| Network | Chain ID | NitroEnclaveVerifier | SP1 Verifier | RISC0 Verifier |\n|---------|----------|---------------------|--------------|----------------|\n| Ethereum Mainnet | 1 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://etherscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://etherscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x8EaB2D97Dfce405A1692a21b3ff3A172d593D319`](https://etherscan.io/address/0x8EaB2D97Dfce405A1692a21b3ff3A172d593D319) |\n| Optimism | 10 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://optimistic.etherscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://optimistic.etherscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://optimistic.etherscan.io/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n| Polygon | 137 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://polygonscan.com/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://polygonscan.com/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0xdBAD523786971B75A7b1c1CFdCfECDeb59A764B9`](https://polygonscan.com/address/0xdBAD523786971B75A7b1c1CFdCfECDeb59A764B9) |\n| Arbitrum One | 42161 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://arbiscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://arbiscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://arbiscan.io/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n| Avalanche C-Chain | 43114 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://snowtrace.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://snowtrace.io/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://snowtrace.io/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n| World Chain | 480 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://worldscan.org/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://worldscan.org/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187`](https://worldscan.org/address/0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187) |\n| BNB Smart Chain | 56 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://bscscan.com/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x940467b232cAD6A44FF36F2FBBe98CBd6509EFf2`](https://bscscan.com/address/0x940467b232cAD6A44FF36F2FBBe98CBd6509EFf2) | [`0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187`](https://bscscan.com/address/0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187) |\n| Automata | 65536 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://explorer.ata.network/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x5d1B5BEd5365942421afD473c121abEAc138A3E1`](https://explorer.ata.network/address/0x5d1B5BEd5365942421afD473c121abEAc138A3E1) | [`0x18Fe24Cf185DD45533b24384666aF3be1b74cC64`](https://explorer.ata.network/address/0x18Fe24Cf185DD45533b24384666aF3be1b74cC64) |\n| Base | 8453 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://basescan.org/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://basescan.org/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://basescan.org/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n\n## Testnet Deployments\n\n| Network | Chain ID | NitroEnclaveVerifier | SP1 Verifier | RISC0 Verifier |\n|---------|----------|---------------------|--------------|----------------|\n| Sepolia | 11155111 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://sepolia.etherscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://sepolia.etherscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187`](https://sepolia.etherscan.io/address/0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187) |\n| Optimism Sepolia | 11155420 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://sepolia-optimistic.etherscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://sepolia-optimistic.etherscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0xB369b4dd27FBfb59921d3A4a3D23AC2fc32FB908`](https://sepolia-optimistic.etherscan.io/address/0xB369b4dd27FBfb59921d3A4a3D23AC2fc32FB908) |\n| Unichain Sepolia | 1301 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://sepolia.uniscan.xyz/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://sepolia.uniscan.xyz/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187`](https://sepolia.uniscan.xyz/address/0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187) |\n| Automata Testnet | 1398243 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://explorer-testnet.ata.network/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x7291752B7c1e0E69adF9801865b25435b0bE4Fc6`](https://explorer-testnet.ata.network/address/0x7291752B7c1e0E69adF9801865b25435b0bE4Fc6) | [`0xaE7F7EC735b6A90366e55f87780b36e7e6Ec3c65`](https://explorer-testnet.ata.network/address/0xaE7F7EC735b6A90366e55f87780b36e7e6Ec3c65) |\n| Arbitrum Sepolia | 421614 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://sepolia.arbiscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://sepolia.arbiscan.io/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://sepolia.arbiscan.io/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n| Avalanche Fuji | 43113 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://testnet.snowtrace.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://testnet.snowtrace.io/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://testnet.snowtrace.io/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n| Hoodi | 560048 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://hoodi.etherscan.io/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x7DA83eC4af493081500Ecd36d1a72c23F8fc2abd`](https://hoodi.etherscan.io/address/0x7DA83eC4af493081500Ecd36d1a72c23F8fc2abd) | [`0x32Db7dc407AC886807277636a1633A1381748DD8`](https://hoodi.etherscan.io/address/0x32Db7dc407AC886807277636a1633A1381748DD8) |\n| Polygon Amoy | 80002 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://amoy.polygonscan.com/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://amoy.polygonscan.com/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187`](https://amoy.polygonscan.com/address/0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187) |\n| Base Sepolia | 84532 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://sepolia.basescan.org/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x397A5f7f3dBd538f23DE225B51f532c34448dA9B`](https://sepolia.basescan.org/address/0x397A5f7f3dBd538f23DE225B51f532c34448dA9B) | [`0x0b144E07A0826182B6b59788c34b32Bfa86Fb711`](https://sepolia.basescan.org/address/0x0b144E07A0826182B6b59788c34b32Bfa86Fb711) |\n| BNB Smart Chain Testnet | 97 | [`0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B`](https://testnet.bscscan.com/address/0x08e49F31Ab11b17f3a5BaA36e6744E9B532bC87B) | [`0x3B6041173B80E77f038f3F2C0f9744f04837185e`](https://testnet.bscscan.com/address/0x3B6041173B80E77f038f3F2C0f9744f04837185e) | [`0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187`](https://testnet.bscscan.com/address/0x925d8331ddc0a1F0d96E68CF073DFE1d92b69187) |\n\n\n| ZkType | Verifier ID | Verifier Proof ID | Aggregator ID |\n| ------ | ----------- | ----------------- | ------------- |\n| Risc0  | 0x3f836c01f54526864b30333d462b252ddfeb8458f13865da287daa9a62d1f963 | 0x3f836c01f54526864b30333d462b252ddfeb8458f13865da287daa9a62d1f963 | 0x7f15bdde5ebc6e3697df945e4a550e6e82df6dadc76a2862fa1825e6dbc2be1f |\n| SP1    | 0x00e874289e8c7f42381b6220f438801d2d1478dc8230f866a31e5ceec6e93322 | 0x4f143a748ed01f231e446c03d2018843e4c6a3689ae1c308ddb93c462233e946 | 0x002bb66c60302a81a621d7899e3f6ee1d0db9fb1eae5d1e80e94a33cb1e24922 |\n\u003c!-- | Pico    | 0x009fa7467192bf60230f423dcc0b880ebebbffe955d7f75a8ac9bcbf5a58ba98 | 0x38a3d34f08d8af64b947e861eb80b8404affdf756add5f577e79931598ba585a | 0x00093dbf39d4986be382e062dcbf34d2bc8105637de89bdaaa588014a9c53e9b | --\u003e\n\n\u003e [!NOTE]\n\u003e\n\u003e Pico zkVM does not currently provide remote provers. For that reason, Pico integration is only available on local for testing purposes.\n\u003e\n\u003e We advise you use a machine that is equipped with at least 256GB of memory to run the prover.\n\u003e\n\u003e It took us hours to generate EVM proofs (over Koalabear Field) by running the zkVM on an [Azure NC40ads H100 v5](https://learn.microsoft.com/en-us/azure/virtual-machines/sizes/gpu-accelerated/ncadsh100v5-series?tabs=sizebasic) instance.\n\u003e\n\u003e Currently the Pico SDK does not support GPU proving, and we believe the proving speed will significantly improve after GPU support is enabled.\n\n## Generating Attestation Reports\n\nThis repository does not include the attestation report generation functionality. Please refer to the following resources:\n\n* [aws-nitro-enclaves-sdk-c](https://github.com/aws/aws-nitro-enclaves-sdk-c)\n* [Cryptographic attestation](https://docs.aws.amazon.com/enclaves/latest/user/set-up-attestation.html)\n\n## Using the Prover SDK\n\nThe AWS Nitro Enclave Attestation Prover provides a comprehensive SDK for generating zero-knowledge proofs of attestation report validity. This SDK supports both RISC0 and SP1 proving systems and can be integrated into your Rust applications.\n\n### Installation\n\nAdd the prover to your `Cargo.toml`:\n\n```toml\n[dependencies]\naws-nitro-enclave-attestation-prover = { git = \"https://github.com/automata-network/aws-nitro-enclave-attestation\" }\n```\n\n### Examples\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e1. Basic Single Attestation Proof\u003c/b\u003e\u003c/summary\u003e\n\n```rust\nuse aws_nitro_enclave_attestation_prover::{NitroEnclaveProver, ProverConfig};\n\nfn main() -\u003e anyhow::Result\u003c()\u003e {\n    // Configure the prover (RISC0 example)\n    let config = ProverConfig::risc0();\n    \n    // Create prover instance\n    let prover = NitroEnclaveProver::new(config, None);\n    \n    // Load attestation report\n    let report_bytes = std::fs::read(\"samples/attestation_1.report\")?;\n    \n    // Generate proof\n    let result = prover.prove_attestation_report(report_bytes)?;\n    \n    // Save proof result\n    std::fs::write(\"proof.json\", result.encode_json()?)?;\n    \n    println!(\"Proof generated successfully!\");\n    println!(\"{}\", String::from_utf8_lossy(\u0026result.encode_json()?));\n    \n    Ok(())\n}\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e2. Batch Proving with Aggregation\u003c/b\u003e\u003c/summary\u003e\n\n```rust\nuse aws_nitro_enclave_attestation_prover::{NitroEnclaveProver, ProverConfig};\n\nfn prove_multiple_reports() -\u003e anyhow::Result\u003c()\u003e {\n    let config = ProverConfig::sp1();\n    let prover = NitroEnclaveProver::new(config, None);\n    \n    // Load multiple attestation reports\n    let reports = vec![\n        std::fs::read(\"samples/attestation_1.report\")?,\n        std::fs::read(\"samples/attestation_2.report\")?,\n    ];\n    \n    // Generate aggregated proof for all reports\n    let reports_count = reports.len();\n    let result = prover.prove_multiple_reports(reports)?;\n    \n    println!(\"Aggregated proof generated for {} reports\", reports_count);\n    println!(\"{}\", String::from_utf8_lossy(\u0026result.encode_json()?));\n    \n    Ok(())\n}\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e3. Smart Contract Integration\u003c/b\u003e\u003c/summary\u003e\n\nFor optimal gas efficiency, integrate with the Nitro Enclave Verifier contract:\n\n```rust\nuse aws_nitro_enclave_attestation_prover::{\n    NitroEnclaveProver, ProverConfig,\n    NitroEnclaveVerifierContract\n};\nuse alloy_primitives::Address;\n\nasync fn prove_with_contract() -\u003e anyhow::Result\u003c()\u003e {\n    // Connect to deployed verifier contract\n    let contract_address: Address = \"0x1234567890123456789012345678901234567890\".parse()?;\n    let rpc_url = \"https://1rpc.io/holesky\";\n    let verifier = NitroEnclaveVerifierContract::dial(rpc_url, contract_address, None)?;\n    let config = ProverConfig::risc0();\n    let prover = NitroEnclaveProver::new(config, Some(verifier));\n    \n    let report_bytes = std::fs::read(\"samples/attestation_2.report\")?;\n    \n    // Prove with contract optimization\n    let result = prover.prove_attestation_report(report_bytes)?;\n    \n    // The result.onchain_proof is ready for contract submission\n    std::fs::write(\"proof.json\", result.encode_json()?)?;\n    \n    println!(\"Aggregation Proof generated successfully!\");\n    println!(\"{}\", String::from_utf8_lossy(\u0026result.encode_json()?));\n    let result = prover.verify_on_chain(\u0026result)?;\n    println!(\"onchain verfication result: {:?}\", result);\n    \n    Ok(())\n}\n```\n\u003c/details\u003e\n\n## Getting Started with CLI Tools\n\n### Prerequisites\n\nEnsure you have the following installed:\n- [Rust](https://rustup.rs/) (latest stable version)\n- [Foundry](https://getfoundry.sh/) for smart contract development\n- [RiscZero](https://dev.risczero.com/api/zkvm/install)\n- [Succinct](https://docs.succinct.xyz/docs/sp1/getting-started/install)\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e1. Generate Zero-Knowledge Proofs\u003c/b\u003e\u003c/summary\u003e\n\nGenerate proofs for single or multiple attestation reports:\n\n```bash\n$ cargo install --path crates/nitro-attest-cli\n$ export VERIFIER=$(NitroEnclaveVerifier address) RPC_URL=http://localhost:8545\n$ export DEV_MODE=true # Enable the dev mode for faster execution and generating fake proof\n\n# Generate proof using SP1 backend\n$ nitro-attest-cli prove --sp1 --report samples/attestation_1.report --out proof.json\n\n# Generate proof using RISC0 backend  \n$ nitro-attest-cli prove --risc0 --report samples/attestation_1.report --out proof.json\n\n# Batch verification with multiple reports\n$ nitro-attest-cli prove --sp1 --report samples/attestation_1.report --report samples/attestation_2.report --out samples/proofs/aggregated_proof.json\n\n# Verify proof on-chain\n$ nitro-attest-cli proof verify-on-chain --proof samples/proofs/aggregated_proof.json\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e2. Inspect Attestation Reports\u003c/b\u003e\u003c/summary\u003e\n\nExamine the contents of attestation reports for debugging and verification:\n\n```bash\n$ nitro-attest-cli debug doc --report samples/attestation_1.report\n```\n\n**Example Output:**\n```\nDoc:\n    Module ID: i-07fd4cc4df935eab0-enc01915a74e6ed4aa6\n    Timestamp: Aug 16 09:11:49 2024 +00:00(1723799509)\n    Digest: SHA384\n    PublicKey: 0x5075626c69634b657928343032626137353561336335346339653737643937656233663035663562383232373732326666383631653465633537623137356634636263656135613463343534643437613863316637386466343931373533623931346231313738333335636334326435653332666337323864393932613064333337333662633137336529\n    UserData: 0x4175746f6d617461204d50432044656d6f\n    Nonce: 0x31323334\n    PCR[3]: 0xb0c424e9f3727f78f370d4332f3e6e2bb02a288d9bc3c4697102d70744de0b064366fbb3190402deeb4d144e4ab17d4f\n    PCR[4]: 0xdcd9866c46ee2878f5fd80f955c12a8c11de276346846579d0d077933757988144c96dc4c5fb708c20c04a4ee34639ab\nCert Chain:\n    [0] Digest: 0x641a0321a3e244efe456463195d606317ed7cdcc3c1756e09893f3c68f79bb5b\n        Valid: Oct 28 13:28:05 2019 +00:00(1572269285) - Oct 28 14:28:05 2049 +00:00(2519044085)\n    [1] Digest: 0x348cc5b001ba75f7d3733ef512463194fea6781954fd416455699d4deb361acf\n        Valid: Aug 15 03:20:59 2024 +00:00(1723692059) - Sep  4 04:20:59 2024 +00:00(1725423659)\n    [2] Digest: 0x3792fe9068de61899676dfb2f31bf64a72439cf4883d3216629d3404b727c58d\n        Valid: Aug 16 00:33:37 2024 +00:00(1723768417) - Aug 21 13:33:37 2024 +00:00(1724247217)\n    [3] Digest: 0xb3b18683c518f2c462cd0252034e6a4758c42907add1880bd29a5e0a79aed71b\n        Valid: Aug 16 09:11:11 2024 +00:00(1723799471) - Aug 17 09:11:11 2024 +00:00(1723885871)\n    [4] Digest: 0x30941d6b61e8cd57b80a6da3705ec072adaa8acb514fbfd9b54ce3393a257e4f\n        Valid: Aug 16 09:11:46 2024 +00:00(1723799506) - Aug 16 12:11:49 2024 +00:00(1723810309)\n```\n\n\u003c/details\u003e\n\n## Getting Started with On-Chain Verification\n\nThe NitroEnclaveVerifier smart contract provides efficient on-chain verification of zero-knowledge proofs generated by the SDK. It supports both single and batch verification modes with advanced certificate caching optimization.\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e1. Contract Deployment\u003c/b\u003e\u003c/summary\u003e\n\nDeploy the verifier contract to your target network:\n\n```bash\n$ cd contracts\n\n# Deploy the NitroEnclaveVerifier\n$ forge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'deployVerifier()'\n\n# Deploy the SP1Verifier\n# If you want to use the official pre-deployed contract, please refer to https://github.com/succinctlabs/sp1-contracts/blob/main/contracts/deployments/\n# and export SP1_VERIFIER=$sp1VerifierAddr\n$ forge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'deploySP1Verifier()'\n\n# Deploy the Risc0Verifier\n# If you want to use the official pre-deployed contract, please refer to https://github.com/risc0/risc0-ethereum/blob/main/contracts/deployment.toml\n# and export RISC0_VERIFIER=$risc0VerifierAddr\n$ forge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'deployRisc0Verifier()'\n```\n\nThe contract deployment information will be saved in the deployments folder.\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e2. Contract Configuration\u003c/b\u003e\u003c/summary\u003e\n\nConfigure the verifier contract with appropriate settings:\n\n```bash\n# set the root cert (required)\n$ forge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'setRootCert(string)' ../samples/aws_root.der\n\n# Set the zk verifier\n# Note: sp1_program_id.json and risc0_program_id.json can be generated by `nitro-attest-cli upload --out ${path} [--sp1 | --risc0]`\n$ forge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'setZkVerifier(string)' ../samples/sp1_program_id.json # sp1\n$ forge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'setZkVerifier(string)' ../samples/risc0_program_id.json # risc0\n```\n\n\u003c/details\u003e\n\n## Development\n\n### Building Smart Contracts\n\nWe use [Foundry](https://getfoundry.sh/) for smart contract development. If you don't have it installed, please follow the [installation guide](https://getfoundry.sh/introduction/installation).\n\n```bash\n# Initialize and update submodules\n$ git submodule update --init --recursive\n\n# Navigate to contracts directory and build\n$ cd contracts\n$ forge build\n```\n\n### Project Structure\n\n```\n├── samples/               # Sample attestation reports and proofs\n├── contracts/              # Smart contracts for on-chain verification\n│   ├── src/\n│   │   ├── NitroEnclaveVerifier.sol     # Main verifier contract\n│   │   └── interfaces/\n│   │       └── INitroEnclaveVerifier.sol # Contract interface\n│   ├── script/             # Deployment scripts\n│   ├── test/               # Contract tests\n│   └── lib/                # Contract dependencies\n└── crates/                 # Rust workspace crates\n     ├── nitro-attest-cli/  # CLI application\n     ├── prover/            # Proof generation logic\n     ├── verifier/          # Verification utilities\n     ├── risc0-methods/     # RISC0-specific zkVM methods\n     ├── sp1-methods/       # SP1-specific zkVM methods\n     ├── pico-methods/      # Pico-specific zkVM methods\n     └── x509-verifier-rust-crypto/ # X509 certificate verification\n```\n\n## Performance Benchmarks\n\nThis section provides comprehensive performance metrics for both RISC0 and SP1 proving systems, demonstrating the efficiency gains from certificate caching and batch verification.\n\n\u003e [!NOTE]\n\u003e Proving a single Nitro Enclave attestation report requires approximately 300M cycles, primarily due to the need to verify certificate chains and document correctness through 6 P384 signature verifications, which constitute the majority of the computational overhead. To reduce ZKP proving costs, we have implemented caching at the contract level, which can reduce P384 signature verifications for a single report to as few as 1 verification. This caching system ensures security while supporting revocation operations - when a certificate is revoked, all related leaf certificate caches are invalidated. The caching system only optimizes certificate chain relationship verification; individual certificate validation (such as time validity) is still performed. The specific optimization results are shown below.\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e1. Proving Cycles by Cached Certificate Count\u003c/b\u003e\u003c/summary\u003e\n\nThe following table shows how certificate caching reduces computational overhead. When more certificates are cached (trusted certs prefix length), fewer certificates need to be verified in the ZK circuit, resulting in lower cycle counts:\n\n#### RISC0\n\n| Cached Certificates | Proving Cycles | Cycles Improvement |\n| ------------------- | -------------- | ------------------ |\n| 0 (cache disabled)  | 390,594,560    | Baseline           |\n| 1                   | 326,107,136    | 16.5% reduction    |\n| 2                   | 261,095,424    | 33.2% reduction    |\n| 3                   | 196,083,712    | 49.8% reduction    |\n| 4                   | 131,072,000    | 66.4% reduction    |\n| 5                   | 66,060,288     | 83.1% reduction    |\n\n#### SP1 (Succinct)\n| Cached Certificates | Proving Cycles | Cycles Improvement |\n| ------------------- | -------------- | ------------------ |\n| 0 (cache disabled)  | 285,573,454    | Baseline           |\n| 1                   | 238,129,471    | 16.6% reduction    |\n| 2                   | 190,785,832    | 33.2% reduction    |\n| 3                   | 143,767,478    | 49.7% reduction    |\n| 4                   | 96,838,778     | 66.1% reduction    |\n| 5                   | 49,534,287     | 82.6% reduction    |\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e2. Proving Cycles for Proof Aggregation\u003c/b\u003e\u003c/summary\u003e\n\nThe following table shows the additional cycles used for aggregation.\n\n#### Succinct (SP1)\n| Aggregated Reports | Proving Cycles | Proving Cycles per Report | Cycles Improvement |\n| ------------------ | -------------- | ------------------------- | ------------------ |\n| 1                  | 1,368,769      | 1,368,769                 | Baseline           |\n| 2                  | 1,738,923      | 869,461                   | 36.5% reduction    |\n| 5                  | 2,884,700      | 576,940                   | 57.8% reduction    |\n| 10                 | 4,830,986      | 483,098                   | 64.7% reduction    |\n| 100                | 34,680,156     | 346,801                   | 74.7% reduction    |\n\n\u003e [!NOTE]\n\u003e **RISC0 (Boundless) Aggregation Costs**\n\u003e\n\u003e Unlike SP1 which uses efficient recursion circuits to verify child proofs as \"assumptions\", Boundless executes full Groth16 proof verification internally within the zkVM. This approach incurs approximately **200+ million cycles per additional proof** verified, meaning aggregation costs scale linearly rather than amortizing.\n\u003e\n\u003e Before using proof aggregation with Boundless, users should compare the additional proving cycle costs against the gas savings from batching on-chain verifications. In many cases, submitting individual Groth16 proofs for on-chain verification may be more cost-effective than paying for the expensive in-zkVM proof verification.\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e3. On-Chain Verification Gas Costs\u003c/b\u003e\u003c/summary\u003e\n\nGas costs for verifying attestation proofs on Ethereum mainnet (as of block 21,000,000):\n\n#### Single Attestation Verification\n\n| Backend | Verification Gas |\n| ------- | ---------------- |\n| RISC0   | 257,741          |\n| SP1     | 220,333          |\n\n#### Batch Verification Gas Costs\n\nBatch verification provides significant gas savings compared to individual verifications:\n\n| Attestations | RISC0 Total Gas | SP1 Total Gas |\n| ------------ | --------------- | ------------- |\n| 1            | 259,482         | 234,098       |\n| 2            | 260,376         | 235,218       |\n| 5            | 306,731         | 282,276       |\n| 10           | 384,552         | 361,372       |\n\n\u003c/details\u003e\n\n## Troubleshooting\n\n\u003cdetails\u003e\n\u003csummary\u003eRemote Proving API Key Issues\u003c/summary\u003e\n\n**SP1 Network Key Missing:**\n```\nNETWORK_PRIVATE_KEY environment variable is not set. Please set it to your private key or use the .private_key() method.\n```\n\n**RISC0 Boundless Key Missing:**\n```\nmissing BOUNDLESS_PRIVATE_KEY\n```\n\n**Solution:**\n- For SP1 remote proving: Set `SP1_PRIVATE_KEY` environment variable with your SP1 network private key\n- For RISC0 remote proving via Boundless: Set the following environment variables:\n  - `BOUNDLESS_RPC_URL` - Boundless network RPC URL\n  - `BOUNDLESS_PRIVATE_KEY` - Your wallet private key (hex-encoded)\n  - [Storage Provider Configuration Environmental Variables](https://docs.boundless.network/developers/tutorials/request#storage-providers)\n- For local testing without remote proving: Set `DEV_MODE=true` to generate development proofs\n\n```bash\n# For SP1 production remote proving\nexport NETWORK_PRIVATE_KEY=your_sp1_network_private_key\n\n# For RISC0 production remote proving (via Boundless)\nexport BOUNDLESS_RPC_URL=https://rpc.boundless.xyz\nexport BOUNDLESS_PRIVATE_KEY=your_wallet_private_key\n# ... storage configuuration values\n\n# Optional Boundless configuration\nexport BOUNDLESS_VERIFIER_PROGRAM_URL=ipfs://...   # Pre-uploaded verifier ELF URL\nexport BOUNDLESS_AGGREGATOR_PROGRAM_URL=ipfs://... # Pre-uploaded aggregator ELF URL\nexport BOUNDLESS_MIN_PRICE=100000                  # Min price in wei per cycle\nexport BOUNDLESS_MAX_PRICE=1000000                 # Max price in wei per cycle\nexport BOUNDLESS_TIMEOUT=3600                      # Timeout in seconds\nexport BOUNDLESS_RAMP_UP_PERIOD=300                # Ramp-up period in seconds\n\n# For development/testing\nexport DEV_MODE=true\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eProgram ID Verification Failed\u003c/summary\u003e\n\n```\nError: Program ID verification failed: Failed to verify zkconfig for RiscZero\n\nCaused by:\n    Program ID mismatch with on-chain config: want: {verifierId=0x0000000000000000000000000000000000000000000000000000000000000000, verifierProofId=0x0000000000000000000000000000000000000000000000000000000000000000, aggregatorId=0x0000000000000000000000000000000000000000000000000000000000000000}, got: {verifierId=0xe012a57f515c0bd110db51b2887b36d874ad8d0f302d7f2c0562beb74d6b6729, verifierProofId=0xe012a57f515c0bd110db51b2887b36d874ad8d0f302d7f2c0562beb74d6b6729, aggregatorId=0x4d4bd302de3ae57d7de3a37fb6c27c6f6b217e6815af737dacb4ca6e45652494})\n```\n\n**Cause:** The NitroEnclaveVerifier contract hasn't been configured with the correct program IDs.\n\n**Solution:** Configure the verifier contract with the appropriate program IDs:\n\n```bash\n# Upload and set RISC0 program IDs\nnitro-attest-cli upload --risc0 --out samples/risc0_program_id.json\nforge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'setZkVerifier(string)' samples/risc0_program_id.json\n\n# Upload and set SP1 program IDs  \nnitro-attest-cli upload --sp1 --out samples/sp1_program_id.json\nforge script script/NitroEnclaveVerifier.s.sol --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast --sig 'setZkVerifier(string)' samples/sp1_program_id.json\n```\n\nRefer to [Contract Configuration](#contract-configuration) for complete setup instructions.\n\n\u003c/details\u003e\n\n## License\n\nThis project is licensed under the Apache License 2.0 - see the [LICENSE](LICENSE) file for details.\n\n## Contributing\n\nContributions are welcome! Please feel free to submit a Pull Request.\n\n## Support\n\nFor questions and support, please open an issue in the GitHub repository.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fautomata-network%2Faws-nitro-enclave-attestation","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fautomata-network%2Faws-nitro-enclave-attestation","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fautomata-network%2Faws-nitro-enclave-attestation/lists"}