Technical design documents and architecture details for the Dstack TEE platform.
epoch
during key derivation.
The rotation of the RootKey will immediately changes all the keys in the system, while the interval of updating epoch
can be configured independently for different storage services so they can be rotated in different frequencies based on the requirements.
The update of the applications, which will change the app_hash
above, can be regarded as a special key rotation for the application.