跳转到内容

ak.profile.traffic_metadata_hardened.v1

← Profiles

ak.profile.traffic_metadata_hardened.v1

role

"admin"

description

"Service/deployment hardening profile for high-privacy traffic metadata. A declaring service exposes support through ServiceDescribe.supported_profiles and applies the profile to deployment-configured routes; federation fanout timing, batch size, Welcome size, push wakeups, and retry cadence MUST satisfy the declared observable bounds. Arkret v1 defines no Realm activation carrier for this profile."

enforcement_phases

[
  "build",
  "conformance"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.self.events.command.submit.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.committed_event.stream.subscribe.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.edge.push.command.notify.v1",
    "binding_kind": "http_json"
  }
]

required_event_kinds

[
  "ak.message.create",
  "ak.mls.commit"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.event.v1",
  "ak.schema.encrypted_envelope.v1",
  "ak.schema.notification.v1"
]

required_fixtures

[
  "privacy-security-fixture.json"
]

optional_extensions

[
  "ohttp_relay",
  "relay_indirection",
  "decoy_wakeup"
]

feature_discovery

{
  "required": [
    "federation_batch_padding",
    "welcome_padding_bucket",
    "bounded_send_jitter",
    "blind_or_batch_wakeup",
    "retry_cadence_padding",
    "traffic_metadata_observability_bounds"
  ],
  "unsupported_optional": "fail closed before claiming traffic metadata hardening"
}

profile_parameters

{
  "federation_batch_min_item_count": {
    "minimum": 2,
    "default": 8,
    "description": "Minimum outbound federation batch size before padding. Empty/padded batches count toward the observable batch size.",
    "value_shape": "integer"
  },
  "welcome_padding_buckets_bytes": {
    "items": {
      "minimum": 4096,
      "value_shape": "integer"
    },
    "default": [
      4096,
      16384,
      65536
    ],
    "description": "Allowed padded Welcome / GroupInfo blob sizes. Sender MUST round up to the smallest bucket that fits and MUST NOT leak exact leaf count by raw ciphertext length.",
    "value_shape": "array"
  },
  "send_jitter_ms": {
    "required": [
      "min",
      "max"
    ],
    "properties": {
      "min": {
        "minimum": 0,
        "default": 250,
        "value_shape": "integer"
      },
      "max": {
        "minimum": 1,
        "default": 3000,
        "value_shape": "integer"
      }
    },
    "description": "Bounded randomized delay added before federation fanout and retry scheduling. Implementations MUST NOT encode activity by selecting deterministic edge values.",
    "value_shape": "object"
  },
  "push_wakeup_mode": {
    "enum": [
      "blind_wakeup",
      "batch_wakeup",
      "no_notification"
    ],
    "default": "batch_wakeup",
    "description": "High-privacy push default. visible_notification is incompatible unless Realm policy explicitly opts out of this hardening profile for that recipient route.",
    "value_shape": "string"
  },
  "relay_requirement": {
    "enum": [
      "ohttp",
      "trusted_relay",
      "decoy_traffic"
    ],
    "description": "At least one relay/indirection/decoy mechanism MUST be enabled for cross-domain high-privacy routes.",
    "value_shape": "string"
  }
}

Source