conxius-enclave-sdk
Overview
Section titled “Overview”conxius-enclave-sdk provides memory-safe C and Rust abstractions for running cryptographic signing and attestation workloads inside hardware Trusted Execution Environments (TEEs).
- Target Subdomain:
sdk.conxian.org - Supported TEE Architectures: AWS Nitro Enclaves, Intel SGX2, AMD SEV-SNP.
- Cryptographic Primitives: MuSig2 key aggregation (
BIP-340), Schnorr signatures (BIP-341), and Discrete Log Contract (DLC) adaptor signatures.
Technical Specifications
Section titled “Technical Specifications”Memory Safety & Attestation Flow
Section titled “Memory Safety & Attestation Flow”- Isolation: Key material is decrypted exclusively inside enclave memory and never swapped to untrusted host disk storage.
- Attestation Generation: Hardware attestation documents (PCR0/PCR1/PCR2 measurements) are signed directly by the processor security chip (e.g., AWS Nitro Security Chip or AMD Platform Security Processor).
- mTLS Handshake: The enclave uses its attestation key pair to establish mTLS channels with
conxian-gatewayandconxian-nexus.
// Rust Enclave Signing Interface Exampleuse lib_conxian_core::musig2::{MuSig2KeyAgg, PartialSignature};
pub fn generate_musig2_partial_sig( enclave_secret_key: &[u8; 32], agged_pubkey: &MuSig2KeyAgg, msg_hash: &[u8; 32],) -> Result<PartialSignature, EnclaveError> { // Verified memory-safe execution inside hardware enclave boundary enclave_crypto::musig2_sign_isolated(enclave_secret_key, agged_pubkey, msg_hash)}