DGV-TC-038L7: Application EnforcementGER-415: Policy Bundle Tampered UndetectedVersion: 1.0.0
Policy Bundle Immutability Under TEE
Verifies that the SHA-256 hash of a Cedar policy bundle, measured at load time and sealed by the TEE, correctly detects any post-deployment modification. A policy bundle whose computed hash does not match the TEE-sealed expected hash is rejected before any evaluation begins, preventing a silent policy swap attack.
Operational Purpose & Scope
The expected hash is all-zeros (simulating a tampered or missing TEE seal). The computed hash of the valid policy content does not match, triggering tamper detection.
Verification Context
- Target Scope:
Cedar policy bundle integrity; TEE-sealed hash measurement; cMCP policy enforcement path - Audit Strategy:
exact-match - Verification Metrics:
policy_integrity_verifiedtamper_detectedcomputed_hashexpected_hashgate_status - Framework Origin:DGV v0.5.0 Expansion
- Mandatory:Yes — must pass for certification
Governance Risk & Penalty
Silent policy swap allows governance bypass through modified policy bundles without detection.
Expected Outcome
- pass:
false - gate_status:
"CLOSED" - rejection_reason:
"policy_bundle_hash_mismatch" - tamper_detected:
true
Explore this card in 3D
Open DGV-TC-038 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.
Open DGV Live →