跳转到内容

ak.profile.high_security_organization.v1

← Profiles

ak.profile.high_security_organization.v1

enforcement_phases

[
  "build",
  "conformance"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.self.realm_state_snapshot.read.by_ref.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.realm_state_snapshot.read.manifest_head.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.keys.keypackages.command.revoke.v1",
    "binding_kind": "http_json"
  }
]

inherits

[
  "ak.profile.organization.v1",
  "ak.profile.e2ee_client.v1"
]

required_event_kinds

[
  "ak.device.revoke",
  "ak.mls.commit"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.realm_state_snapshot.v1",
  "ak.schema.encrypted_envelope.v1",
  "ak.schema.moderation_queue_item.v1",
  "ak.schema.key_transparency.v1"
]

required_fixtures

[
  "privacy-security-fixture.json",
  "did-webvh-v1-fixture.json",
  "key-transparency-fixture.json"
]

optional_extensions

[
  "witness_quorum",
  "hardware_key_policy"
]

feature_discovery

{
  "required": [
    "snapshot_witness",
    "mls_governance_binding",
    "revocation_freshness",
    "did_webvh_1_0",
    "key_transparency_inclusion_proof",
    "key_transparency_consistency_proof"
  ],
  "unsupported_optional": "fail closed for high-risk action"
}

forbidden_features

[
  "ak.feature.mls_last_resort_keypackage.v1"
]

additional_requirements

{
  "sender_constrained_session_pop_must": "Per RFC 9700 (BCP 240) sender-constrained-token guidance, production current-v1 protected endpoints MUST reject bare Authorization: Bearer presentation unless it is bound by DPoP, an RFC 9421 HTTP Message Signature, detached JWS, mTLS, or equivalent sender-constrained proof. For this high-security profile, every protected ak.self.* operation MUST use RFC 9421 HTTP Message Signature whose signing key is the session's session_public_key delegated by ak.session.grant, binding @method/@target-uri/@authority, content-digest (when body present), and participating Idempotency-Key, with created/expires inside the existing replay window. The ak.self. prefix is the machine-enforceable default-protected surface; new or unknown operations default to fail closed. The operation registry may explicitly allow an unauthenticated public-metadata projection, but without valid proof it MUST return only that public projection and MUST NOT treat bare bearer as session/capability authentication. See api-conventions.md §3.2 and service-http-binding.md §8.",
  "mls_last_resort_forbidden_must": "Realms claiming this profile MUST NOT allow last-resort KeyPackage join: services MUST NOT advertise ak.feature.mls_last_resort_keypackage.v1 for those Realms, claim responses MUST NOT return last_resort=true packages, and requesters MUST treat any last_resort=true claim record as profile-forbidden and fail closed.",
  "key_transparency_must": "High-risk identity, recovery, service delegation and membership decisions MUST verify ak.schema.key_transparency.v1 inclusion and consistency proofs under ak.profile.key_transparency.v1; missing or invalid proof fails closed.",
  "sender_constrained_session_pop_covered_components_must": {
    "signature_scenario_id": "ak.http_signature.scenario.client_session_pop.v1",
    "covered_components": [
      "@authority",
      "@method",
      "@target-uri",
      "arkret-operation",
      "content-digest",
      "idempotency-key",
      "x-arkret-wait-for"
    ],
    "conditional_covered_components": [
      {
        "component": "content-digest",
        "condition": "the request carries a body"
      },
      {
        "component": "idempotency-key",
        "condition": "the request participates in idempotency or replay keying"
      },
      {
        "component": "x-arkret-wait-for",
        "condition": "the header is present on the request"
      }
    ],
    "freshness_profile_id": "ak.http_signature.freshness.v1",
    "statement": "For every protected ak.self.* operation the RFC 9421 presentation MUST cover each listed component that applies to the request, including arkret-operation. The list is a projection of http_signature_contract_registry and is compared to it by gate. created/expires MUST satisfy the shared window in zh/sync/service-http-binding.md section 8.3; the RFC 9449 DPoP iat/jti window is a separate contract (ak.dpop.freshness.v1) and MUST NOT be substituted."
  }
}

identity

{
  "principal_method_default": "did:webvh",
  "allowed_principal_methods": [
    "did:webvh"
  ],
  "service_method_default": "did:webvh",
  "allowed_service_methods": [
    "did:webvh",
    "did:web"
  ],
  "did_method_versions": [
    "did:webvh:1.0"
  ],
  "principal_method_downgrade_allowed": false,
  "witness_threshold_minimum": 2,
  "require_witness_evidence": true
}

Source