<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.liu-wimse-wit-attestation" target="https://datatracker.ietf.org/doc/html/draft-liu-wimse-wit-attestation-00">
   <front>
      <title>Carrying Remote Attestation Evidence in Workload Identity Tokens (WIT)</title>
      <author initials="D." surname="Liu" fullname="Dapeng Liu">
         <organization>Alibaba Group</organization>
      </author>
      <author initials="J." surname="Zhu" fullname="Judy Zhu">
         <organization>Alibaba Group</organization>
      </author>
      <author initials="J." surname="Jin" fullname="Jian Jin">
         <organization>Alibaba Group</organization>
      </author>
      <date month="March" day="25" year="2026" />
      <abstract>
	 <t>   This document specifies how Remote Attestation evidence, as defined
   by the IETF RATS architecture, can be conveyed within a Workload
   Identity Token (WIT) as used in the WIMSE (Workload Identity for
   Micro-Services Environments) framework.  The WIT includes attestation
   measurements that enable fast-path policy evaluation without
   requiring immediate access to full evidence.  The WIT is bound to the
   HTTP request using OAuth 2.0 Demonstrating Proof-of-Possession
   (DPoP), ensuring that attestation claims are protected against replay
   and token theft.

   This specification defines a two-tier verification model: lightweight
   verification using embedded measurements for common scenarios, and
   deep verification using externalized evidence for high-assurance
   requirements.  This enables secure, cross-domain verification of
   workload integrity without requiring direct access to platform-
   specific reference values, while enabling efficient deployments.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-liu-wimse-wit-attestation-00" />
   
</reference>
