跳转到内容

ak.profile.signal_peer_relay.v1

← Profiles

ak.profile.signal_peer_relay.v1

role

"server"

description

"Optional symmetric Station profile for the encrypted Signal Extension single-hop peer relay. It does not imply durable Event federation and does not advertise any product signal kind."

enforcement_phases

[
  "conformance",
  "startup_claim_guard"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.server.read.describe.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.signal.command.send.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.signal.stream.subscribe.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.peer.signal.command.relay.v1",
    "binding_kind": "http_json"
  }
]

required_event_kinds

[]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.signal_envelope.v1",
  "ak.schema.signal_relay.v1"
]

required_fixtures

[
  "signal-federation-fixture.json"
]

optional_extensions

[]

prose_requirement_coverage

[
  {
    "requirement": "source current exact-account device authentication, destination peer/outer admission without remote device verification, recipient independent producer authentication, single-hop current joined-member ActorId routing and unchanged envelope",
    "coverage": [
      "ak.peer.signal.command.relay.v1",
      "signal-federation-fixture.json"
    ]
  },
  {
    "requirement": "opaque request-level outcome and anti-enumeration",
    "coverage": [
      "ak.schema.signal_relay.v1",
      "signal-federation-fixture.json"
    ]
  },
  {
    "requirement": "bounded batch/body/signature window and drop-unconfirmed retry behavior",
    "coverage": [
      "ak.peer.signal.command.relay.v1",
      "signal-federation-fixture.json"
    ]
  }
]

feature_discovery

{
  "required": [
    "service_id",
    "transport_bindings",
    "supported_operation_bundles",
    "supported_profiles"
  ],
  "unsupported_optional": "omit ak.profile.signal_peer_relay.v1 and ak.peer.signal.command.relay.v1; local Signal and durable federation remain independently usable"
}

additional_requirements

{
  "encrypted_only_must": "Every relayed item MUST be ak.schema.signal_envelope.v1; plaintext or unencrypted ephemeral inputs fail closed with signal_plaintext_forbidden.",
  "source_authority_must": "Source MUST authenticate exact-account current device authority and producer signature at local ingress and freshly before queued outbound dispatch, together with current scope/membership/action/TTL and MLS basis.",
  "destination_admission_must": "Destination MUST authenticate peer source/body, sender routing projection, closed proof transcript/digest and outer scope/RealmCommit/current membership/action/TTL/MLS basis; it MUST NOT require a remote device directory, producer signature verification, remote PCR replay or an MLS public-tree tracker to relay.",
  "recipient_authentication_must": "Relay acceptance is not device authentication. Recipient MUST independently verify current exact-account device trust, producer signature, winning MLS state and active-leaf actor/device/key/authorization binding, AAD/AEAD, plaintext schema and replay before display or effects; known revoked authority fails even before leaf Remove.",
  "single_hop_must": "A destination MUST NOT relay a peer-received SignalEnvelope to a third service. The original sender-side service performs one direct request per eligible destination service.",
  "no_kind_advertisement_must": "Describe MUST advertise only this profile and operation support; exact product signal kind and target remain encrypted and MUST NOT appear in supported-kinds or routing metadata.",
  "opaque_outcome_must": "A valid authenticated request returns only {accepted:true}; no recipient, binding, capability, count or per-item outcome is exposed.",
  "retry_must": "The operation forbids Idempotency-Key, is retry_safe=false and uses uncertain_outcome.strategy=drop_unconfirmed. A lost response MUST NOT cause automatic request replay.",
  "scope_authority_cut_must": "Circle Signal MUST bind independent exact accepted scope and parent Realm cuts in proof/AAD, validate historical and current parent membership/capability and scope membership/MLS in one authority read, and fail closed on current revoke/reset/ownership/join changes or missing current lineage/coverage. Realm Signal MUST omit the parent field. No cross-stream position or wall-clock causal inference is allowed."
}

Source