Cloud Secure Area - Server Reference Implementation

Note: This reference implementation is not production quality. Use at your own risk.

Attestation Root

Certificate

SEQUENCE (8 elem)
  [0] (1 elem)
    INTEGER 2
  INTEGER 1
  SEQUENCE (1 elem)
    OBJECT IDENTIFIER 1.2.840.10045.4.3.3 ECDSA coupled with SHA-384
  SEQUENCE (1 elem)
    SET (1 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.4.3 commonName (X.520 DN component)
        UTF8String csa_dev_root
  SEQUENCE (2 elem)
    UTCTime 2025-12-20T07:54:46Z
    UTCTime 2035-12-20T07:54:46Z
  SEQUENCE (1 elem)
    SET (1 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.4.3 commonName (X.520 DN component)
        UTF8String Cloud Secure Area Attestation Root
  SEQUENCE (2 elem)
    SEQUENCE (2 elem)
      OBJECT IDENTIFIER 1.2.840.10045.2.1 Elliptic curve public key cryptography
      OBJECT IDENTIFIER 1.2.840.10045.3.1.7 NIST Curve P-256
    BIT STRING (520 bit) 0000010011100101010011111100000010001101100101000111100000010010100010000100111010010010010101010110001100011110011011001000000101100111100101101101000100011011110010100100010010001001111011000010010011101001010010000100110011010010001110000010111011010111011100000010111011101111101110110001000011110101100001010101101000110000010001111010110011001011101111001111001010111101000100000100010101001011000111011010101000100111011101001000110000111100101001111001010110101111011110100110011010111111010101011001011010000010
  [3] (1 elem)
    SEQUENCE (4 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.29.35 authorityKeyIdentifier (X.509 extension)
        OCTET STRING (24 byte) 30 16 80 14 e3 22 54 be 34 d3 0a 98 51 98 68 bc a4 d9 69 8b d6 68 b1 f2 ("0.�.�"T�4�.�Q�h���i��h��")
      SEQUENCE (3 elem)
        OBJECT IDENTIFIER 2.5.29.15 keyUsage (X.509 extension)
        BOOLEAN true
        OCTET STRING (4 byte) 03 02 02 04 ("....")
      SEQUENCE (3 elem)
        OBJECT IDENTIFIER 2.5.29.19 basicConstraints (X.509 extension)
        BOOLEAN true
        OCTET STRING (5 byte) 30 03 01 01 ff ("0...�")
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.29.14 subjectKeyIdentifier (X.509 extension)
        OCTET STRING (22 byte) 04 14 f6 2a ec 09 13 55 51 86 11 e9 03 b4 c4 6e 1b da de ab a8 ff ("..�*�..UQ�.�.��n.�ޫ��")

Certificate

SEQUENCE (8 elem)
  [0] (1 elem)
    INTEGER 2
  INTEGER ea a4 23 fd eb ed 82 7d f7 81 89 0d 33 6c 72 cd
  SEQUENCE (1 elem)
    OBJECT IDENTIFIER 1.2.840.10045.4.3.3 ECDSA coupled with SHA-384
  SEQUENCE (1 elem)
    SET (1 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.4.3 commonName (X.520 DN component)
        UTF8String csa_dev_root
  SEQUENCE (2 elem)
    UTCTime 2025-12-20T07:54:46Z
    UTCTime 2035-12-20T07:54:46Z
  SEQUENCE (1 elem)
    SET (1 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.4.3 commonName (X.520 DN component)
        UTF8String csa_dev_root
  SEQUENCE (2 elem)
    SEQUENCE (2 elem)
      OBJECT IDENTIFIER 1.2.840.10045.2.1 Elliptic curve public key cryptography
      OBJECT IDENTIFIER 1.3.132.0.34 EC Curve P-384
    BIT STRING (776 bit) 00000100100110000110101101010111111111110101000101010010100010111000101101101000000000110000101101101010000001100111101110101010111010010010100100001010011011100001111100010011111001001010011100111000101000100110101010100101001011001100100100010001101111011001000000111000101111000011000110100000101100110110000001000100100000111011101110011110111110110011101010000010101000010110111001111100110110101101111000101000010111010011010101001101100001111110100011111010010000111100110110100000110010000110101101001111111110111111100010010110001010010000101011000010011000011001000000000111111011110100101000010011100011111100000111001001001001110111011001101000110110111011110110110100110010000101010010111100110001010000111101100000101100111001111010011011110111000101000110101000
  [3] (1 elem)
    SEQUENCE (3 elem)
      SEQUENCE (3 elem)
        OBJECT IDENTIFIER 2.5.29.15 keyUsage (X.509 extension)
        BOOLEAN true
        OCTET STRING (4 byte) 03 02 02 04 ("....")
      SEQUENCE (3 elem)
        OBJECT IDENTIFIER 2.5.29.19 basicConstraints (X.509 extension)
        BOOLEAN true
        OCTET STRING (5 byte) 30 03 01 01 ff ("0...�")
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.29.14 subjectKeyIdentifier (X.509 extension)
        OCTET STRING (22 byte) 04 14 e3 22 54 be 34 d3 0a 98 51 98 68 bc a4 d9 69 8b d6 68 b1 f2 ("..�"T�4�.�Q�h���i��h��")

Cloud Binding Key Attestation Root

Certificate

SEQUENCE (8 elem)
  [0] (1 elem)
    INTEGER 2
  INTEGER 1
  SEQUENCE (1 elem)
    OBJECT IDENTIFIER 1.2.840.10045.4.3.2 ECDSA coupled with SHA-256
  SEQUENCE (1 elem)
    SET (1 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.4.3 commonName (X.520 DN component)
        UTF8String Cloud Secure Area Cloud Binding Key Attestation Root
  SEQUENCE (2 elem)
    UTCTime 2025-12-20T07:54:46Z
    UTCTime 2035-12-20T07:54:46Z
  SEQUENCE (1 elem)
    SET (1 elem)
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.4.3 commonName (X.520 DN component)
        UTF8String Cloud Secure Area Cloud Binding Key Attestation Root
  SEQUENCE (2 elem)
    SEQUENCE (2 elem)
      OBJECT IDENTIFIER 1.2.840.10045.2.1 Elliptic curve public key cryptography
      OBJECT IDENTIFIER 1.2.840.10045.3.1.7 NIST Curve P-256
    BIT STRING (520 bit) 0000010010000111000110010101010000001001111010000110001001001111100001010011110111110110001001101011111010011101101010010010010110111110010011011100111100001110010001111100110010011100010101111101011100001010100111100110000001101101010110101010000100011001100111100110100110100100000100100101110110011010111000101100101111000110100000011011011111101100100000110100101011100000011011000110111101100101000001100111011100001000010111000101011011011110000100000011001000110110001011010110110000011101000010001100110100001110
  [3] (1 elem)
    SEQUENCE (3 elem)
      SEQUENCE (3 elem)
        OBJECT IDENTIFIER 2.5.29.15 keyUsage (X.509 extension)
        BOOLEAN true
        OCTET STRING (4 byte) 03 02 02 04 ("....")
      SEQUENCE (3 elem)
        OBJECT IDENTIFIER 2.5.29.19 basicConstraints (X.509 extension)
        BOOLEAN true
        OCTET STRING (5 byte) 30 03 01 01 ff ("0...�")
      SEQUENCE (2 elem)
        OBJECT IDENTIFIER 2.5.29.14 subjectKeyIdentifier (X.509 extension)
        OCTET STRING (22 byte) 04 14 b9 7b b2 ea e8 6c 34 8a df b7 a9 5d ce 13 d0 b1 e2 5e 23 77 ("..�{���l4�߷�]�.б�^#w")