
Claim 4 | TRACE Claim key binding and disclosure resistance
========================================================================

P1  JWK thumbprint determinism
  thumbprint run 1: c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa2
  thumbprint run 2: c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa2
  PASS: thumbprint is deterministic and re-derivable from cnf.jwk.x

P2  report_data[:32] equals the thumbprint (key binding)
  nonce: c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa21111111111111111111111111111111111111111111111111111111111111111
  report_data[:32]: c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa2
  PASS: report is bound to this gateway key

P3  Instance binding -- different TEE key -> different thumbprint
  key 1 thumbprint: c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa2
  key 2 thumbprint: 040f973708d86a64653cbc507ec4eef93ead9e68e63ffb3a37acba5708bfabb0
  PASS: nonce[:32] changes with the TEE key

P4  Freshness -- different salt -> different nonce
  nonce (salt A): c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa21111111111111111111111111111111111111111111111111111111111111111
  nonce (salt B): c9ba2e39cc8488b8f0bc655b654a617a6fb09670d24bd6b6e0ca832de55eefa22222222222222222222222222222222222222222222222222222222222222222
  PASS: per-startup salt makes each instance nonce distinct

P5  Session binding -- session_id tamper breaks the Ed25519 signature
  signature on original claim (session-A): VALID
  signature after replacing session_id: INVALID
  PASS: a claim cannot be presented under a different session

P6  Selective disclosure resistance -- removing one audit entry breaks export hash
  Full audit (5 entries) bundle_hash: sha256:b67d8d965002c500fe3c4d1d376167c61ae98a1f3393887c286aa96863f1a688
  After removing call-2 (4 entries): sha256:bd898904adde29ec45de00db78b3f198cce39f9dfa0d40dd1ebdb4ed04626d84
  Hashes match?: False
  Export signature valid on modified bundle?: False
  PASS: removing one audit entry changes bundle_hash, signature fails

Summary:
  P1: Thumbprint deterministic / re-derivable     PASS
  P2: report_data[:32] binds the TEE key          PASS
  P3: Thumbprint changes with TEE key             PASS
  P4: Salt makes each instance nonce fresh        PASS
  P5: session_id tamper breaks Ed25519 sig        PASS
  P6: Entry removal breaks export signature       PASS

In hardware TEE mode, the nonce is committed into the hardware-signed
report_data field. The operator cannot forge a thumbprint for a different
key without compromising the TEE.

