# Run an end-to-end Attestation Flow with Arm CCA

## In this learning path

- [Introduction](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-essentials/)
- [Overview of the Software Architecture](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-essentials/cca-essentials/)
- [Run an end-to-end Attestation with Arm CCA](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-essentials/example/)
- [Next Steps](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-essentials/_next-steps/)

## About this Learning Path

| Skill level: | Advanced |
|--------------|----------|
| Reading time: | 2 hrs    |
| Last updated: | 03 Jul 2026 |

| Authors:                   | Arm IP:                                                  | Tags:                                      |
|----------------------------|---------------------------------------------------------|-------------------------------------------|
| Arnaud de Grandmaison, Arm | [Neoverse](https://support.arm.com/?tab=compute-ip&Product%20Type=Infrastructure%20Processors) | [Performance and Architecture](https://learn.arm.com/tag/performance-and-architecture), [Linux](https://learn.arm.com/tag/linux), [GCC](https://learn.arm.com/tag/gcc), [FVP](https://learn.arm.com/tag/fvp), [RME](https://learn.arm.com/tag/rme), [CCA](https://learn.arm.com/tag/cca), [Docker](https://learn.arm.com/tag/docker), [Veraison](https://learn.arm.com/tag/veraison), [Runbook](https://learn.arm.com/tag/runbook) |
| Paul Howard                |                                                         |                                           |
| Pareena Verma, Arm        |                                                         |                                           |

### Who is this for?
This is an advanced topic for software developers who want to learn how to run an end-to-end attestation flow with Arm's Confidential Computing Architecture (CCA).

### What will you learn?
Upon completion of this Learning Path, you will be able to:
- Describe how you can use attestation with Arm's Confidential Computing Architecture (CCA).
- Deploy a simple workload in a CCA realm on an Armv9-A AEM Base Fixed Virtual Platform (FVP) that has support for RME extensions.
- Connect the workload with additional software services to create an end-to-end example that uses attestation to unlock the confidential processing of data.

### Prerequisites
Before starting, you will need the following:
- An AArch64 or x86_64 computer running Linux. You can use cloud instances, see this list of [Arm cloud service providers](https://learn.arm.com/learning-paths/servers-and-cloud-computing/csp/).
- Completion of [Get Started with CCA Attestation and Veraison](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-veraison/) Learning Path.
- Completion of the [Run an application in a Realm using the Arm Confidential Computing Architecture (CCA)](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-container/) Learning Path.

### Summary
You’ll deploy a sample workload in a Linux realm on an Armv9-A AEM Base Fixed Virtual Platform (FVP) with Realm Management Extension (RME) support and connect it to attestation services to control access to secrets. First, you’ll start a minimal Key Broker Server (KBS) from the Veraison project in a container, then integrate it with the realm so that confidential data is released only after successful attestation. You’ll focus on the flow of evidence, verification, and key release to recognize a complete end-to-end run when service logs report a successful attestation result and the workload in the realm receives its key.

### Frequently asked questions

<details>
<summary>Which components need to be running to exercise the end-to-end flow?</summary>
You need the RME-enabled Armv9-A AEM Base FVP hosting a Linux realm, the attestation services, and the Veraison Key Broker Server (KBS) container. Run these in the order described so that attestation can evaluate the realm before secrets are requested.
</details>

<details>
<summary>How do I know the Key Broker Server is ready?</summary>
After starting the provided container image, confirm the container is running and check its logs for a startup or listening message. Proceed only when the KBS indicates it is ready to handle requests.
</details>

<details>
<summary>What result should I expect when attestation succeeds?</summary>
The attestation services accept the realm’s evidence, and the KBS authorizes release of a key or secret. You should see logs showing a positive attestation outcome and the workload receiving the expected data.
</details>

<details>
<summary>When should the confidential data be released to the realm?</summary>
Only after the attestation step verifies that the Linux realm provides the required level of confidential isolation. The example gates key release on that successful verification.
</details>

<details>
<summary>What should I check if attestation fails or no key is returned?</summary>
Verify the Linux realm is running on the RME-enabled FVP and that the attestation services and KBS are up and reachable. Inspect their logs for configuration or connectivity errors, then restart the flow after addressing the issue.
</details>
