%% You should probably cite draft-tsyrulnikov-rats-attested-inference-receipt-02 instead of this revision. @techreport{tsyrulnikov-rats-attested-inference-receipt-01, number = {draft-tsyrulnikov-rats-attested-inference-receipt-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-tsyrulnikov-rats-attested-inference-receipt/01/}, author = {Borys Tsyrulnikov}, title = {{Attested Inference Receipt (AIR): A COSE/CWT Profile for Confidential AI Inference}}, pagetotal = 28, year = , month = , day = , abstract = {This document defines the Attested Inference Receipt (AIR), an application-layer COSE\_Sign1 envelope carrying CWT claims profiled per the Entity Attestation Token (EAT) framework. An AIR receipt binds model identity, input/output hashes, attestation-linked metadata, and operational telemetry into a single signed artifact suitable for independent third-party verification of a confidential AI inference event. AIR v1 targets single-inference receipts emitted by workloads running inside hardware-isolated Trusted Execution Environments (TEEs). AIR is attestation-linked: it carries measurements and a hash reference to the platform attestation evidence associated with the inference, but it does not replace platform-specific attestation verification. This version defines AWS Nitro Enclaves and Intel TDX measurement profiles only. Pipeline chaining, multi-inference receipts, and extensibility mechanisms for additional claim or platform profiles are out of scope.}, }