Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement (reproducible artefact)
Published software archive; associated manuscript publication status is stated below. Zenodo
Yulliwas Ameur; Soumya Banerjee; Samia Bouzefrane. "Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement (reproducible artefact)." Version v1.1, Zenodo, 28 August 2026. DOI: 10.5281/zenodo.22146879.
Software archive
Version: v1.1. Published: 28 August 2026. Software license: MIT, as stated in the Zenodo record.
The archive compares four enforcement configurations: bearer JWTs, certificate-bound tokens using RFC 8705, an attestation-gated bound-token control, and SPIFFE X.509 SVIDs. The described architecture combines an NGINX-style policy enforcement point with Open Policy Agent.
Materials and reproduction instructions
The package includes a measurement harness, bootstrap and TOST analysis, ablations and second-host experiments, a ProVerif 2.05 model suite with replay, forwarding and self-assertion controls, and SPIRE 1.9.6 validation material. Download LNET_V3_artifact.zip from the official archive for the reproduction instructions and recorded results.
Associated manuscript
Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement
The archive describes the associated manuscript as a submission to IEEE Networking Letters. Acceptance and publication of the manuscript are not established by this software release. The DOI on this page identifies the software archive, not a journal or proceedings paper.
Cite the version used
Yulliwas Ameur; Soumya Banerjee; Samia Bouzefrane. Bearer, Bound, Attested: Factoring Key Binding, Provenance, and Attestation for Zero-Trust Enforcement (reproducible artefact). Version v1.1. Zenodo, 2026. Version DOI.
The concept DOI groups versions of the archive. Cite the version DOI above when using this specific release. Download the site bibliography in BibTeX.
