This is a pretty standard application of trusted computing and can be done entirely on the iPhone. A server would only possibly be needed for anonymization (while retaining key revocation capabilities if a key does end up leaking), but there are serverless ways to do even that (TPMs have supported these for a while now).
I think a big part of validation for things like these are just "could it have been modified since Z event happened", because Z was not something people paid attention to before.