Attest's PublicKey
Image Header
decrypts
Signature
tbsCertificate
Image Data
Issuer's Name
AttestationCA's PublicKey
Attest Private Key
RootCA's Name
AttestationCA'sSignature
1. get Digital Hash of image data 2. use Private Key generate Signature of the hash Value
AttestationCA' Name
image Signature
AttestationCA Private Key
Owner's Name
RootCA Private Key
RootCA's PublicKey
RootCA's Signature
Attest certificate's Name