Skip to content

Component RIMs

Component Reference Integrity Manifests (RIMs) are cryptographically signed data structures that provide a secure baseline of expected firmware and software measurements for hardware components. In other words, a Component RIM is a generic term for an object that holds "golden" expected measurements for a component. During computer attestation, validation services use these trusted manufacturer assertions to verify that a device's actual boot state remains secure, unmodified, and free from compromise.

Note

Compenent RIM processing is currently in progress for HIRS attestation services, but is not fully developed yet.

Component RIMs are similar in purpose to the PC Client RIM, but specifically designed for computer components. Unlike a PC Client RIM which typically exists as a single standardized metadata format - the SWID (Software Identification) tag - Component RIMs come in many different formats and typically use Concise Binary Object Representation (CBOR) encoding and CBOR Object Signing and Encryption (COSE) signatures.

The following table shows the relationship between some of the common formats:

Encoding Format Description
Traditional XML Encoding (ISO / TCG) TCG Component RIM SWID
  • Top-level signed XML envelope
  • Contains software/firmware data blocks formatted as SWID tags
IETF CoSWID
  • Top-level signed CBOR envelope
Modern Concise CBOR Encoding (IETF / RATS) TCG Component RIM CoSWID
  • Top-level signed CBOR envelope
IETF CoRIM
  • Top-level signed CBOR envelope
  • Payload = unsigned-corim-map structure
  • Subcomponent options inside the unsigned-corim-map
    • IETF CoSWID
    • TCG Component RIM CoSWID
    • IETF CoMID

IETF CoSWID

The IETF Concise Software Identification (CoSWID) defined by RFC 9393 is a CBOR-encoded, size-optimized reformulation of the ISO/IEC 19770-2 SWID tag. It is used for the same purpose - a globally unique tag identifying a software product, its version, the entities responsible for it (creator, distributor, etc.), and optionally payload/evidence data such as file manifests with hashes - but replaces SWID's verbose XML with CDDL-defined CBOR so tags are small enough for constrained devices and can be COSE-signed. In other words it describes "what software is this" in a concise format.

TCG Component RIM CoSWID

The TCG Reference Integrity Manifest family defines how a platform/component vendor publishes the golden measurements a Verifier should expect from a device. The TCG defines a RIM for PC Client as well as a SWID/CoSWID binding for device components. The TCG Component RIM is expressed as a signed CoSWID whose link/meta extensions carry TCG-specific fields (platform manufacturer/model, binding spec version, RIM linkage).

Two examples of TCG Component RIMs are shown below, along with some insight into the bytes in each. The first has a 96-byte COSE signature, and the second has a 384-byte COSE signature.

TCG Component RIM with 96-byte COSE signature example

Component RIM 96-byte sig

TCG Component RIM with 384-byte COSE signature example

Component RIM 96-byte sig

IETF CoRIM

The Concise Reference Integrity Manifest (CoRIM draft here ) , from the IETF RATS working group, generalizes the RIM idea beyond a single TPM-measured component. A CoRIM is a signed CBOR container holding one or more CoMID (Concise Module Identifier) and/or CoSWID tags, each expressing reference values, endorsed values, identity/attestation-key material, or conditional endorsements for a target environment. It gives Verifiers a uniform, composable way to ingest reference/endorsement data for heterogeneous attesters (TPM, DICE, PSA, Intel TDX/SGX, CCA, etc.) rather than a per-technology format.

Since the CoRIM structure is complex, below is a diagram to help visualize it:

📦 Signed IETF CoRIM (COSE Envelope) └── 📑 PAYLOAD: unsigned-corim-map ├── 🆔 corim.id (Manifest UUID) └── 🗂️ corim.tags [ Array of Child Tags ] ├── 🧩 Tag 1: IETF CoMID (hardware and reference values) ├── 📜 Tag 2: IETF CoSWID (software manifests and cryptographic hashes) └── 🏷️ Tag 3: TCG Component RIM CoSWID (TCG-specific CBOR mapping)