跳转到内容

ak.schema.key_backup_active_series.v1

← Schemas

Arkret Key Backup Active Series Record
ak.schema.key_backup_active_series.v1 · file: schemas/key-backup-active-series.schema.json

Signed principal-control record selecting the backup series for one actor and backup kind. Servers verify the accepted record; ordinary clients consume BackupActiveSeriesState from their Account Station instead of replaying PCR history.

* $ · object
Signed principal-control record selecting the backup series for one actor and backup kind. Servers verify the accepted record; ordinary clients consume BackupActiveSeriesState from their Account Station instead of replaying PCR history.
* schema · const "ak.schema.key_backup_active_series.v1"
enum: "ak.schema.key_backup_active_series.v1"
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* backup_kind · string (enum) · $ref #/$defs/backup_kind
enum: "secret_storage"
* active_series_id · string · $ref #/$defs/backup_series_id
pattern: ^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* series_pointer_version · integer
Strictly monotonic per (actor_id, backup_kind). The first record is 1 and every successor is previous+1; receivers reject rollback, gaps and same-version forks.
* previous_series_ids · array<$ref #/$defs/backup_series_id>
Retained old series used only for read-old-data or erasure transition. MUST NOT be treated as a primary recovery source.
items · string · $ref #/$defs/backup_series_id
pattern: ^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* source_commit_ref · object · $ref #/$defs/source_commit_ref
Principal Control Realm source RealmCommit and current identity-root device generation under which active_series_id was selected.
* realm_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* device_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic device generation. This is not a DID versionId and MUST equal the accepted current_device_generation_ref at the referenced checkpoint.
* issued_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* auth_data · object
* verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature_algorithm · string (enum)
enum: "Ed25519"
* signature · string
base64url signature over RFC 8785 JCS(record without auth_data.signature). The closed record shape fixes the authenticated projection.
pattern: ^[A-Za-z0-9_-]+$
* device_authorize_event_id · string
Accepted current-generation ak.device.authorize Event anchoring the device that signed this active-series selection.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
(^x_[a-z][a-z0-9_]{0,63}$) · any

Source