- 可配置的信任模型,支持多 attestor 部署以及 m-of-n 法定签名阈值验证。
- 企业级密钥安全,支持本地密钥库,或通过 HSM、KMS、专用签名基础设施进行远程签名。
- 灵活部署,支持云环境、Kubernetes 或自托管环境。
- 多网络互操作能力,通过链适配器和部署模式覆盖 Cosmos、EVM、Solana、Besu 以及基于 L2 的环境。
- 生产级可观测性,包括 gRPC、健康检查、Prometheus 指标、结构化日志与追踪。
Attestor 可保护任意两条网络之间的消息
企业版 attestor 方案重点强调跨链操作中的三项优势:- 自定义你的信任模型,可选择由哪些参与方对证明进行签名,以及验证消息所需的签名阈值。团队可以围绕自己的验证者、受信第三方、Cosmos Labs 或其他受信参与方来构建法定签名策略。
- 确保密钥安全,内置支持远程签名、HSM 和 KMS 风格集成,以及在 attestor 进程之外受控地管理密钥。
- 按你的方式部署,可在 AWS、Azure、GCP 或自托管环境中运行,灵活选择自建基础设施、全托管运维,或完全自主控制的自托管方案。
团队为何使用 attestor
- 支持证明型轻客户端,attestor 提供由证明型轻客户端消费的链下签名证明。
- 可验证的法定签名模型,可组合多个 attestor,使轻客户端仅在达到配置的 m-of-n 签名阈值后才接受消息。
- 已最终确定状态验证,attestor 会拒绝高于已配置最终确定高度的请求,并且仅在验证所请求状态后才进行签名。
- 数据包与状态证明,attestor 既可以对区块状态签名,也可以对数据包承诺声明签名,以支持跨链数据包传递。
- 多链适配器,服务通过可插拔适配器支持 EVM、Cosmos 和 Solana,并面向 Besu 与连接 L2 的环境提供企业级定位。
- 无状态请求处理,attestor 通过 gRPC API 按需发布证明。
安全模型
在证明模型中,信任是被显式定义的。每个 attestor 都使用 secp256k1 密钥对已最终确定的链状态签名,而链上的轻客户端会验证是否有足够数量的已注册 attestor 对同一声明完成签名。 这使团队能够自行决定哪些参与方纳入信任模型,包括自有基础设施、验证者、受信第三方、Cosmos Labs 或其他受信参与方,并设置符合内部安全与合规要求的阈值。架构
attestor 作为独立服务运行,包含四个主要层次:gRPC API 服务器、证明逻辑、签名后端和链适配器。gRPC 服务响应证明请求,适配器负责获取并验证链状态,签名器则返回可恢复的 ECDSA 签名,供证明型轻客户端在链上验证。 如需查看完整系统视图,请参阅 部署概览、证明型轻客户端 以及 Cosmos ↔ EVM 互操作教程。源代码
源代码可在 cosmos/ibc-attestor 仓库中获取。可用文档
可用性
IBC Attestor 仓库以 Source Available Evaluation License 发布。用于生产环境或商业用途时,需要从 Cosmos Labs 获取企业许可证。 详情请参阅 许可证文件。如需企业授权,请联系 Cosmos Labs。The IBC Attestor is an enterprise-ready attestation service for the attestation light client. It is designed to secure cross-chain messages across Cosmos, EVM, Solana, Hyperledger Besu, and L2 rollup environments through quorum-signed attestations of finalized chain state. Attestors are used with the attestation light client because verifying consensus from chains such as EVM networks directly on chain can be prohibitively expensive. The attestation model trades some trust assumptions for a more operationally practical and gas-efficient way to verify cross-chain packets. The attestor is designed for organizations that require:
- Configurable trust models, with multi-attestor deployments and m-of-n quorum verification.
- Enterprise-grade key security, with support for local keystores or remote signing through HSM, KMS, or dedicated signer infrastructure.
- Flexible deployment, with support for cloud, Kubernetes, or self-hosted environments.
- Multi-network interoperability, through chain adapters and deployment patterns spanning Cosmos, EVM, Solana, Besu, and L2-based environments.
- Production observability, including gRPC, health checks, Prometheus metrics, structured logging, and tracing.
Attestors secure messages between any two networks
The Enterprise attestor offering emphasizes three advantages for cross-chain operations:- Define your trust model, by choosing which actors sign attestations and what signature threshold is required to validate messages. Teams can build quorum policies around their own validators, trusted third parties, Cosmos Labs, or additional trusted actors.
- Ensure key security, with built-in support for remote signing, HSM and KMS-style integrations, and controlled key management outside the attestor process.
- Deploy your way, in AWS, Azure, GCP, or self-hosted environments, with the flexibility to run your own infrastructure, choose fully managed operations, or self-host with complete control.
Why teams use attestors
- Attestation light client support, attestors provide the off-chain signed attestations consumed by the attestation light client.
- Verified quorum model, multiple attestors can be combined so the light client accepts messages only after the configured m-of-n signature threshold is met.
- Finalized state verification, attestors reject requests above the configured finalized height and sign only after validating the requested state.
- Packet and state attestations, attestors can sign both block state and packet commitment statements for cross-chain packet delivery.
- Multi-chain adapters, the service supports EVM, Cosmos, and Solana through pluggable adapters, with enterprise positioning across Besu and L2-connected environments.
- Stateless request handling, attestors publish attestations on demand through a gRPC API.
Security model
Within the attestation model, trust is defined explicitly. Each attestor signs finalized chain state with a secp256k1 key, and the on-chain light client verifies that a sufficient number of registered attestors signed the same statement. This lets teams choose who participates in the trust model, including their own infrastructure, validators, trusted third parties, Cosmos Labs, or additional trusted actors, and set thresholds that align with internal security and compliance requirements.Architecture
The attestor runs as a standalone service with four main layers: a gRPC API server, attestation logic, a signing backend, and a chain adapter. The gRPC service answers attestation requests, the adapter retrieves and validates chain state, and the signer returns a recoverable ECDSA signature that the attestation light client can verify on chain. For a full system view, see the Deployment Overview, the Attestation Light Client, and the Cosmos ↔ EVM Interoperability Tutorial.Source Code
The source code is available in the cosmos/ibc-attestor repository.Available Documentation
- IBC Attestor Overview
- IBC Attestor Guide
- Attestation Light Client
- Cosmos ↔ EVM Interoperability Tutorial
- Configure Attestors in the Tutorial
- Deployment Overview