Component RIMs¶
Component Reference Integrity Manifests (RIMs) are cryptographically signed data structures that provide a secure baseline of expected firmware and software measurements for hardware components. In other words, a Component RIM is a generic term for an object that holds "golden" expected measurements for a component. During computer attestation, validation services use these trusted manufacturer assertions to verify that a device's actual boot state remains secure, unmodified, and free from compromise.
Note
Compenent RIM processing is currently in progress for HIRS attestation services, but is not fully developed yet.
Component RIMs are similar in purpose to the PC Client RIM, but specifically designed for computer components. Unlike a PC Client RIM which typically exists as a single standardized metadata format - the SWID (Software Identification) tag - Component RIMs come in many different formats and typically use Concise Binary Object Representation (CBOR) encoding and CBOR Object Signing and Encryption (COSE) signatures.
The following table shows the relationship between some of the common formats:
| Encoding | Format | Description |
|---|---|---|
| Traditional XML Encoding (ISO / TCG) | TCG Component RIM SWID |
|
| IETF CoSWID |
|
|
| Modern Concise CBOR Encoding (IETF / RATS) | TCG Component RIM CoSWID |
|
| IETF CoRIM |
|
IETF CoSWID¶
The IETF Concise Software Identification (CoSWID) defined by RFC 9393 is a CBOR-encoded, size-optimized reformulation of the ISO/IEC 19770-2 SWID tag. It is used for the same purpose - a globally unique tag identifying a software product, its version, the entities responsible for it (creator, distributor, etc.), and optionally payload/evidence data such as file manifests with hashes - but replaces SWID's verbose XML with CDDL-defined CBOR so tags are small enough for constrained devices and can be COSE-signed. In other words it describes "what software is this" in a concise format.
TCG Component RIM CoSWID¶
The TCG Reference Integrity Manifest family defines how a platform/component vendor publishes the golden measurements a Verifier should expect from a device. The TCG defines a RIM for PC Client as well as a SWID/CoSWID binding for device components. The TCG Component RIM is expressed as a signed CoSWID whose link/meta extensions carry TCG-specific fields (platform manufacturer/model, binding spec version, RIM linkage).
Two examples of TCG Component RIMs are shown below, along with some insight into the bytes in each. The first has a 96-byte COSE signature, and the second has a 384-byte COSE signature.
TCG Component RIM with 96-byte COSE signature example¶

TCG Component RIM with 384-byte COSE signature example¶

IETF CoRIM¶
The Concise Reference Integrity Manifest (CoRIM draft here ) , from the IETF RATS working group, generalizes the RIM idea beyond a single TPM-measured component. A CoRIM is a signed CBOR container holding one or more CoMID (Concise Module Identifier) and/or CoSWID tags, each expressing reference values, endorsed values, identity/attestation-key material, or conditional endorsements for a target environment. It gives Verifiers a uniform, composable way to ingest reference/endorsement data for heterogeneous attesters (TPM, DICE, PSA, Intel TDX/SGX, CCA, etc.) rather than a per-technology format.
Since the CoRIM structure is complex, below is a diagram to help visualize it: