{
  "vercy": "1.0-draft",
  "publication": {
    "status": "research-draft",
    "adjudicationStatus": "unreviewed",
    "publishableCanonical": false,
    "generatedAt": "2026-09-13T03:12:16Z",
    "providers": [
      "Claude"
    ],
    "breadth": "written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify",
    "pass": 2,
    "wave": 3,
    "engine": "claude"
  },
  "metaModel": {
    "id": "THING-Q1254335",
    "registryId": "vr.tr.cryptographic-protocol",
    "name": "cryptographic protocol",
    "version": "0.2.0-wave.3",
    "entryKind": "thing",
    "family": "Thing Registry",
    "domain": [
      "INF.KNW"
    ],
    "status": "research-draft"
  },
  "canonicalUrl": "https://ver.cy/models/thing/q1254335/",
  "model": {
    "registry_id": "vr.tr.cryptographic-protocol",
    "name": "cryptographic protocol",
    "purpose": "Let an agent explain cryptographic protocols and their goals, relay major protocols and standards from IETF and academic sources, describe analysis and common weaknesses in general terms, and distinguish protocols from primitives and from applications.",
    "definition": "A protocol that uses cryptographic primitives to achieve security goals such as confidentiality, integrity, authentication and non-repudiation between parties over a network, including key exchange protocols such as Diffie-Hellman and its post-quantum extensions, password-authenticated key agreement, authentication and secure channel protocols such as TLS with its cipher suites, and protocols for special tasks such as mental poker, secure multiparty computation and trustless systems such as blockchains; protocols are analysed formally and standardised by bodies such as the IETF.",
    "what_it_is_for": "Securing communication and computation.",
    "affordances": [
      "explain goals and kinds",
      "relay major protocols",
      "describe analysis and weaknesses",
      "distinguish from primitives"
    ],
    "distinguishing_features": [
      "Security goals",
      "Composition of primitives",
      "Formal analysis",
      "Standardisation"
    ],
    "appearance": "Not a visible object; message exchanges defined in specifications.",
    "visual_identification": [
      "Protocol built on cryptographic primitives",
      "Key exchange, PAKE, TLS cipher suites, post-quantum extended Diffie-Hellman, mental poker, trustless systems",
      "Ciphers and hashes are primitives; applications such as messaging apps use protocols"
    ],
    "physical_properties": [
      {
        "quantity": "Diffie-Hellman published",
        "typical_range": "1976",
        "unit": "year",
        "note": ""
      },
      {
        "quantity": "TLS 1.3",
        "typical_range": "2018",
        "unit": "year",
        "note": "RFC 8446"
      }
    ],
    "families_and_kinds": [
      "key exchange and key agreement protocols including Diffie-Hellman and post-quantum extensions",
      "password-authenticated key agreement",
      "authentication protocols such as Kerberos",
      "secure channel protocols such as TLS, SSH and Signal, with cipher suites",
      "secure multiparty computation and mental poker",
      "zero-knowledge and commitment protocols",
      "trustless systems such as blockchains"
    ],
    "related_models": [
      {
        "relation": "is a kind of",
        "target": "computer network protocol",
        "why": "in registry terms"
      },
      {
        "relation": "is built from",
        "target": "cryptographic primitive",
        "why": "such as ciphers and hashes"
      },
      {
        "relation": "is exemplified by",
        "target": "Transport Layer Security",
        "why": "the TLS protocol"
      },
      {
        "relation": "is standardised by",
        "target": "Internet Engineering Task Force",
        "why": "among others"
      }
    ],
    "identifiers": [],
    "standards_and_regulation": [
      "IETF RFCs for TLS, SSH and related protocols",
      "NIST post-quantum cryptography standards",
      "ISO/IEC 11770 key management standards",
      "Export and use regulations on cryptography in some countries"
    ],
    "failure_modes_and_hazards": [
      "Protocol flaws despite secure primitives",
      "Downgrade and replay attacks",
      "Weak cipher suites",
      "Agents providing attack guidance against systems without authorisation"
    ],
    "in_scope": [],
    "out_of_scope": [],
    "characteristics": []
  },
  "sources": [],
  "structure": {
    "bundles": [
      {
        "id": "understand",
        "name": "Understand",
        "description": "What a cryptographic protocol is.",
        "rationale": "Definition.",
        "layers": [
          {
            "id": "definition",
            "name": "Definition",
            "description": "Definition and goals.",
            "findings": [
              {
                "id": "definition-finding",
                "name": "Definition",
                "description": "Definition.",
                "questions": [
                  {
                    "text": "What is a cryptographic protocol, and what security goals does it serve?",
                    "kind": "definition"
                  },
                  {
                    "text": "Is the question about a protocol, a primitive or an application?",
                    "kind": "boundary"
                  }
                ]
              }
            ]
          },
          {
            "id": "kinds",
            "name": "Kinds",
            "description": "Kinds.",
            "findings": [
              {
                "id": "kinds-finding",
                "name": "Kinds",
                "description": "Kinds.",
                "questions": [
                  {
                    "text": "What are key exchange, PAKE, authentication, secure channel, multiparty and trustless protocols?",
                    "kind": "definition"
                  },
                  {
                    "text": "Which entry fits the specific protocol?",
                    "kind": "action"
                  }
                ]
              }
            ]
          }
        ]
      },
      {
        "id": "protocols",
        "name": "Protocols",
        "description": "Major protocols.",
        "rationale": "Standards.",
        "layers": [
          {
            "id": "exchange",
            "name": "Exchange",
            "description": "Key exchange.",
            "findings": [
              {
                "id": "exchange-finding",
                "name": "Exchange",
                "description": "Exchange.",
                "questions": [
                  {
                    "text": "How do Diffie-Hellman, its elliptic curve forms and post-quantum extended Diffie-Hellman work in general terms?",
                    "kind": "provenance"
                  },
                  {
                    "text": "Which references are standard?",
                    "kind": "provenance"
                  }
                ]
              }
            ]
          },
          {
            "id": "channels",
            "name": "Channels",
            "description": "Secure channels.",
            "findings": [
              {
                "id": "channels-finding",
                "name": "Channels",
                "description": "Channels.",
                "questions": [
                  {
                    "text": "How do TLS and its cipher suites, SSH and Signal establish secure channels?",
                    "kind": "provenance"
                  },
                  {
                    "text": "Which entry fits Transport Layer Security?",
                    "kind": "action"
                  }
                ]
              }
            ]
          }
        ]
      },
      {
        "id": "analyse",
        "name": "Analyse",
        "description": "Analysis and security.",
        "rationale": "Science.",
        "layers": [
          {
            "id": "analysis",
            "name": "Analysis",
            "description": "Formal analysis.",
            "findings": [
              {
                "id": "analysis-finding",
                "name": "Analysis",
                "description": "Analysis.",
                "questions": [
                  {
                    "text": "How are protocols analysed with formal models and proofs, and what classic flaws have been found?",
                    "kind": "provenance"
                  },
                  {
                    "text": "Which sources are cited?",
                    "kind": "provenance"
                  }
                ]
              }
            ]
          },
          {
            "id": "practice",
            "name": "Practice",
            "description": "Deployment practice.",
            "findings": [
              {
                "id": "practice-finding",
                "name": "Practice",
                "description": "Practice.",
                "questions": [
                  {
                    "text": "What deployment practices such as cipher suite selection and forward secrecy do standards recommend?",
                    "kind": "action"
                  },
                  {
                    "text": "Is the question seeking attack guidance against systems the user does not own, which the model does not provide?",
                    "kind": "boundary"
                  }
                ]
              }
            ]
          }
        ]
      },
      {
        "id": "context",
        "name": "Context",
        "description": "History and future.",
        "rationale": "Context.",
        "layers": [
          {
            "id": "history",
            "name": "History",
            "description": "History.",
            "findings": [
              {
                "id": "history-finding",
                "name": "History",
                "description": "History.",
                "questions": [
                  {
                    "text": "How did protocols develop from Diffie-Hellman and Needham-Schroeder to TLS 1.3 and Signal?",
                    "kind": "provenance"
                  },
                  {
                    "text": "Which entry fits the history of cryptography?",
                    "kind": "action"
                  }
                ]
              }
            ]
          },
          {
            "id": "future",
            "name": "Future",
            "description": "Post-quantum and trustless systems.",
            "findings": [
              {
                "id": "future-finding",
                "name": "Future",
                "description": "Future.",
                "questions": [
                  {
                    "text": "How are post-quantum migration and trustless systems such as blockchains changing protocol design, with positions attributed?",
                    "kind": "provenance"
                  },
                  {
                    "text": "Which entry fits post-quantum cryptography?",
                    "kind": "action"
                  }
                ]
              }
            ]
          }
        ]
      }
    ]
  },
  "openQuestions": [
    "Should key exchange protocol and TLS be separate primary entries?",
    "How should RFCs and academic references be linked?",
    "The registry entry has merged aliases naming specific protocols and concepts; should they be split off?"
  ],
  "statistics": {
    "bundles": 4,
    "layers": 8,
    "findings": 8,
    "questions": 16
  }
}
