跳转到内容

ak.schema.high_risk_authority_proof.v1

← Schemas

Arkret High-Risk Authority Proof Family
ak.schema.high_risk_authority_proof.v1 · file: schemas/high-risk-authority-proof.schema.json

Shared authority proof family for service operations that key-management.md designates as high-risk material destruction or equivalent (first consumer: active-series key backup tail deletion, key-management.md section 7.8). Exactly one closed branch: recovery_unlock, device_quorum, or trusted_recovery_service, discriminated by `kind`. Every branch reuses the common detached-JWS leaf (event-envelope.schema.json#/$defs/proof) over the operation's single canonical delete-intent transcript; branches never restate the leaf fields. An ordinary current-device session proof is deliberately NOT a branch of this family — operations that accept it for low-risk paths must say so in their own normative text. This is one wire leaf with per-consumer domain separation: the transcript context is owned by the consuming operation, never by the leaf, so x-arkret-proof-contexts below enumerates every registered consumer context and proof-context-registry.json carries the matching consumer_operation on each row.

* $ · oneOf[3]
Shared authority proof family for service operations that key-management.md designates as high-risk material destruction or equivalent (first consumer: active-series key backup tail deletion, key-management.md section 7.8). Exactly one closed branch: recovery_unlock, device_quorum, or trusted_recovery_service, discriminated by `kind`. Every branch reuses the common detached-JWS leaf (event-envelope.schema.json#/$defs/proof) over the operation's single canonical delete-intent transcript; branches never restate the leaf fields. An ordinary current-device session proof is deliberately NOT a branch of this family — operations that accept it for low-risk paths must say so in their own normative text. This is one wire leaf with per-consumer domain separation: the transcript context is owned by the consuming operation, never by the leaf, so x-arkret-proof-contexts below enumerates every registered consumer context and proof-context-registry.json carries the matching consumer_operation on each row.
oneOf · oneOf[0] · object · $ref #/$defs/recovery_unlock_proof
Recovery-unlock proof. recovery_session_id MUST select a verified, unexpired recovery session for the transcript's exact account. The session's accepted proof summary MUST be recovery_unlock and bind proof.verification_method; the verifier resolves that key only from the recovery policy frozen into the session. Current device keys, DID-document fallback keys, service keys and revoked recovery keys MUST be rejected.
* kind · const "recovery_unlock"
enum: "recovery_unlock"
* recovery_session_id · string · $ref #/$defs/recovery_session_id
pattern: ^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* proof · object · $ref #/$defs/detached_proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
oneOf · oneOf[1] · object · $ref #/$defs/device_quorum_proof
Device-quorum proof. The schema enforces only the minimum wire shape (threshold>=2, signatures.minItems=1). Verification is normative in the consuming operation's text: (a) every signature MUST verify over the same canonical transcript; (b) signatures MUST be deduplicated by device_id; (c) the count of valid deduplicated signatures MUST be >= threshold; (d) threshold MUST equal the currently accepted recovery policy device-quorum k — a smaller issuer-supplied threshold MUST be rejected as failed_precondition. A deployment whose policy k is below 2 cannot use this branch and must use recovery_unlock or trusted_recovery_service instead; a single current device proof is not a high-risk quorum.
* kind · const "device_quorum"
enum: "device_quorum"
* threshold · integer
The quorum threshold the issuer claims to satisfy. MUST equal the principal's currently accepted recovery_policy device-quorum k; receivers MUST cross-check per description rule (d).
* signatures · array<$ref #/$defs/device_quorum_signature>
minItems=1 is the schema floor only; receiver-side verification requires deduplicated valid signature count >= threshold per description rule (c).
items · object · $ref #/$defs/device_quorum_signature
* device_id · string · $ref #/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* proof · object · $ref #/$defs/detached_proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
oneOf · oneOf[2] · object · $ref #/$defs/trusted_recovery_service_proof
Trusted recovery service proof. The verification_method of `proof` MUST be controlled by service_id, and service_id MUST be authorized as a trusted recovery service by the recovery policy / DID delegation snapshotted into the referenced recovery session. The session MUST be unexpired, unconsumed for this purpose, and MUST have been established by recovery_unlock or device_quorum — the service alone is never a sufficient factor. v1 registers no attestation carrier on this branch: the recovery policy has no attestation_required switch, so an attestation reference here would be an unverified configuration surface rather than an enforced factor.
* kind · const "trusted_recovery_service"
enum: "trusted_recovery_service"
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* recovery_session_id · string · $ref #/$defs/recovery_session_id
Verified, unexpired, unconsumed recovery session authenticated by recovery_unlock or device_quorum. A service-only session is not a second factor.
pattern: ^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* proof · object · $ref #/$defs/detached_proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$

Source