跳转到内容

ak.schema.key_backup_unlock_proof.v1

← Schemas

Arkret Key Backup Unlock Proof
ak.schema.key_backup_unlock_proof.v1 · file: schemas/key-backup-unlock-proof.schema.json

Exact single-object backup unlock intent signed by the accepted current device or by the verified recovery session frozen replacement identity key. Current authority and immutable object identity are rechecked even on exact replay.

* $ · object
Exact single-object backup unlock intent signed by the accepted current device or by the verified recovery session frozen replacement identity key. Current authority and immutable object identity are rechecked even on exact replay.
oneOf · oneOf[0] · object
kind · const "current_device"
enum: "current_device"
oneOf · oneOf[1] · object
kind · const "recovery_session"
enum: "recovery_session"
* schema · const "ak.schema.key_backup_unlock_proof.v1"
enum: "ak.schema.key_backup_unlock_proof.v1"
recovery_session_id · string · $ref #/$defs/recovery_session_id
pattern: ^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* requesting_device_id · string · $ref #/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* backup_id · string · $ref #/$defs/backup_id
pattern: ^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* backup_kind · string (enum) · $ref #/$defs/backup_kind
enum: "secret_storage"
* series_id · string · $ref #/$defs/backup_series_id
pattern: ^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* ciphertext_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* challenge · string
Required exact server challenge: current-device challenge record, or recovery_session.challenge. Caller-minted values are forbidden.
pattern: ^[A-Za-z0-9_-]{43}$
* issued_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* auth_data · object
* verification_method · string · $ref #/$defs/did_url
current_device: exact current accepted device method; recovery_session: the exact frozen requesting_device_public_key_did from the session. A recovery factor signer or arbitrary DID resolver fallback MUST NOT authorize this intent.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature_algorithm · string (enum)
enum: "Ed25519"
* signature · string
base64url signature over RFC 8785 JCS(unlock proof without auth_data.signature), including every present closed-branch field.
pattern: ^[A-Za-z0-9_-]+$
* kind · string (enum)
enum: "current_device" "recovery_session"
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* audience · string · $ref ./keys-operations.schema.json#/$defs/non_empty_string
Exact authenticated service origin. Must equal the current-device server challenge origin or the recovery service origin bound by the authenticated recovery grant.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
challenge_id · string · $ref ./keys-operations.schema.json#/$defs/keys_backups_unlock_challenge/properties/challenge_id
pattern: ^[A-Za-z0-9_-]+$
nonce · string · $ref ./keys-operations.schema.json#/$defs/base64url
pattern: ^[A-Za-z0-9_-]+$

Source