← Back to catalogue
Published

Content Provenance Credential

vr.wm-med-008 · wm-med-008-content-provenance-credential

Represent an issuer-attributable, integrity-protected and asset-bound set of provenance assertions with verifiable lineage, status, validation and disclosure context.

World Models Information and virtual systems INF.MED.PRV

Bundle → Layer → Finding → Questions Filled

6 bundles · 12 layers · 24 findings · 96 questions

Credential identity, scope and asset binding Groups the governed Resource Consumption concern for credential identity, scope and asset binding.

Credential, manifest, claim and assertion boundary

Groups Resource Consumption context for credential, manifest, claim and assertion boundary without importing neighboring master lifecycles.

Credential identifier, namespace, version, issuer, holder, owner and master system

Records credential identifier, namespace, version, issuer, holder, owner and master system as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish credential identifier, namespace, version, issuer, holder, owner and master system? identity
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews credential identifier, namespace, version, issuer, holder, owner and master system, and under which authority? provenance
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify credential identifier, namespace, version, issuer, holder, owner and master system? measurement
  4. Which security, privacy, retention, disclosure and interoperability checks apply to credential identifier, namespace, version, issuer, holder, owner and master system? access

Manifest store, active manifest, claim, assertion, signature and presentation boundary

Records manifest store, active manifest, claim, assertion, signature and presentation boundary as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish manifest store, active manifest, claim, assertion, signature and presentation boundary? composition
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews manifest store, active manifest, claim, assertion, signature and presentation boundary, and under which authority? ownership
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify manifest store, active manifest, claim, assertion, signature and presentation boundary? evidence
  4. Which security, privacy, retention, disclosure and interoperability checks apply to manifest store, active manifest, claim, assertion, signature and presentation boundary? exception

Asset subject, region and content binding

Groups Resource Consumption context for asset subject, region and content binding without importing neighboring master lifecycles.

Asset, rendition, segment, region, resource and credential-subject binding

Records asset, rendition, segment, region, resource and credential-subject binding as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish asset, rendition, segment, region, resource and credential-subject binding? relationship
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews asset, rendition, segment, region, resource and credential-subject binding, and under which authority? authority
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify asset, rendition, segment, region, resource and credential-subject binding? quality
  4. Which security, privacy, retention, disclosure and interoperability checks apply to asset, rendition, segment, region, resource and credential-subject binding? interoperability

Hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery

Records hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery? evidence
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery, and under which authority? requirement
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery? validation
  4. Which security, privacy, retention, disclosure and interoperability checks apply to hard hash, soft fingerprint, watermark binding, algorithm, scope and recovery? decision
Assertions, actions, ingredients and lineage Groups the governed Resource Consumption concern for assertions, actions, ingredients and lineage.

Assertion identity, payload and source

Groups Resource Consumption context for assertion identity, payload and source without importing neighboring master lifecycles.

Assertion label, version, instance, schema, format, source and claim reference

Records assertion label, version, instance, schema, format, source and claim reference as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish assertion label, version, instance, schema, format, source and claim reference? definition
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews assertion label, version, instance, schema, format, source and claim reference, and under which authority? constraint
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify assertion label, version, instance, schema, format, source and claim reference? security
  4. Which security, privacy, retention, disclosure and interoperability checks apply to assertion label, version, instance, schema, format, source and claim reference? identity

Asserted, gathered or attested metadata, digital source type, confidence and evidence

Records asserted, gathered or attested metadata, digital source type, confidence and evidence as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish asserted, gathered or attested metadata, digital source type, confidence and evidence? provenance
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews asserted, gathered or attested metadata, digital source type, confidence and evidence, and under which authority? process
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify asserted, gathered or attested metadata, digital source type, confidence and evidence? privacy
  4. Which security, privacy, retention, disclosure and interoperability checks apply to asserted, gathered or attested metadata, digital source type, confidence and evidence? classification

Actions, ingredients and derivation chain

Groups Resource Consumption context for actions, ingredients and derivation chain without importing neighboring master lifecycles.

Capture, create, edit, generate, transform or publish action, actor, tool, time and parameters

Records capture, create, edit, generate, transform or publish action, actor, tool, time and parameters as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish capture, create, edit, generate, transform or publish action, actor, tool, time and parameters? event
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews capture, create, edit, generate, transform or publish action, actor, tool, time and parameters, and under which authority? event
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify capture, create, edit, generate, transform or publish action, actor, tool, time and parameters? retention
  4. Which security, privacy, retention, disclosure and interoperability checks apply to capture, create, edit, generate, transform or publish action, actor, tool, time and parameters? composition

Ingredient, parent, derived, composed, rendition relationship, redaction and chain

Records ingredient, parent, derived, composed, rendition relationship, redaction and chain as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish ingredient, parent, derived, composed, rendition relationship, redaction and chain? lifecycle
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews ingredient, parent, derived, composed, rendition relationship, redaction and chain, and under which authority? measurement
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify ingredient, parent, derived, composed, rendition relationship, redaction and chain? access
  4. Which security, privacy, retention, disclosure and interoperability checks apply to ingredient, parent, derived, composed, rendition relationship, redaction and chain? relationship
Signer, cryptography, time and credential status Groups the governed Resource Consumption concern for signer, cryptography, time and credential status.

Signer, controller, key and signature

Groups Resource Consumption context for signer, controller, key and signature without importing neighboring master lifecycles.

Signer, claim generator, identity provider, certificate chain, policy and extended key usage

Records signer, claim generator, identity provider, certificate chain, policy and extended key usage as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish signer, claim generator, identity provider, certificate chain, policy and extended key usage? authority
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews signer, claim generator, identity provider, certificate chain, policy and extended key usage, and under which authority? evidence
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify signer, claim generator, identity provider, certificate chain, policy and extended key usage? exception
  4. Which security, privacy, retention, disclosure and interoperability checks apply to signer, claim generator, identity provider, certificate chain, policy and extended key usage? state

Signature suite, algorithm, key ID, protected payload, canonicalization and digest

Records signature suite, algorithm, key id, protected payload, canonicalization and digest as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish signature suite, algorithm, key id, protected payload, canonicalization and digest? security
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews signature suite, algorithm, key id, protected payload, canonicalization and digest, and under which authority? quality
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify signature suite, algorithm, key id, protected payload, canonicalization and digest? interoperability
  4. Which security, privacy, retention, disclosure and interoperability checks apply to signature suite, algorithm, key id, protected payload, canonicalization and digest? lifecycle

Trusted time, status and algorithm lifecycle

Groups Resource Consumption context for trusted time, status and algorithm lifecycle without importing neighboring master lifecycles.

Claimed signing time, trusted timestamp, validation, ingestion and observation clocks

Records claimed signing time, trusted timestamp, validation, ingestion and observation clocks as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish claimed signing time, trusted timestamp, validation, ingestion and observation clocks? temporal
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews claimed signing time, trusted timestamp, validation, ingestion and observation clocks, and under which authority? validation
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify claimed signing time, trusted timestamp, validation, ingestion and observation clocks? decision
  4. Which security, privacy, retention, disclosure and interoperability checks apply to claimed signing time, trusted timestamp, validation, ingestion and observation clocks? temporal

Certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility

Records certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility? lifecycle
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility, and under which authority? security
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility? identity
  4. Which security, privacy, retention, disclosure and interoperability checks apply to certificate validity, revocation, suspension, refresh, trust at signing and algorithm agility? spatial
Storage, discovery, versioning and preservation Groups the governed Resource Consumption concern for storage, discovery, versioning and preservation.

Manifest store location and durable discovery

Groups Resource Consumption context for manifest store location and durable discovery without importing neighboring master lifecycles.

Embedded, external, cloud or repository location, active selection and receipt

Records embedded, external, cloud or repository location, active selection and receipt as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish embedded, external, cloud or repository location, active selection and receipt? access
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews embedded, external, cloud or repository location, active selection and receipt, and under which authority? privacy
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify embedded, external, cloud or repository location, active selection and receipt? classification
  4. Which security, privacy, retention, disclosure and interoperability checks apply to embedded, external, cloud or repository location, active selection and receipt? provenance

Soft-binding query, repository response, candidate confidence, collision and recovery

Records soft-binding query, repository response, candidate confidence, collision and recovery as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish soft-binding query, repository response, candidate confidence, collision and recovery? process
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews soft-binding query, repository response, candidate confidence, collision and recovery, and under which authority? retention
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify soft-binding query, repository response, candidate confidence, collision and recovery? composition
  4. Which security, privacy, retention, disclosure and interoperability checks apply to soft-binding query, repository response, candidate confidence, collision and recovery? ownership

Manifest lifecycle, preservation and failure

Groups Resource Consumption context for manifest lifecycle, preservation and failure without importing neighboring master lifecycles.

Standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate

Records standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate? lifecycle
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate, and under which authority? access
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate? relationship
  4. Which security, privacy, retention, disclosure and interoperability checks apply to standard, update or attestation manifest, predecessor, successor, active, orphan and duplicate? authority

Removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state

Records removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state? state
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state, and under which authority? exception
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state? state
  4. Which security, privacy, retention, disclosure and interoperability checks apply to removed, corrupt, unbound, redacted, revoked, expired, archived, tombstoned and revalidation state? requirement
Validation, trust decision and human interpretation Groups the governed Resource Consumption concern for validation, trust decision and human interpretation.

Validation result and trust policy

Groups Resource Consumption context for validation result and trust policy without importing neighboring master lifecycles.

Well-formed or valid component, status code, failure evidence, validator and profile

Records well-formed or valid component, status code, failure evidence, validator and profile as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish well-formed or valid component, status code, failure evidence, validator and profile? validation
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews well-formed or valid component, status code, failure evidence, validator and profile, and under which authority? interoperability
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify well-formed or valid component, status code, failure evidence, validator and profile? lifecycle
  4. Which security, privacy, retention, disclosure and interoperability checks apply to well-formed or valid component, status code, failure evidence, validator and profile? constraint

Trust list, anchor, private store, policy, purpose, context, decision and review

Records trust list, anchor, private store, policy, purpose, context, decision and review as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish trust list, anchor, private store, policy, purpose, context, decision and review? decision
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews trust list, anchor, private store, policy, purpose, context, decision and review, and under which authority? decision
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify trust list, anchor, private store, policy, purpose, context, decision and review? temporal
  4. Which security, privacy, retention, disclosure and interoperability checks apply to trust list, anchor, private store, policy, purpose, context, decision and review? process

Meaning, disclosure and accessible explanation

Groups Resource Consumption context for meaning, disclosure and accessible explanation without importing neighboring master lifecycles.

Integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction

Records integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction? classification
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction, and under which authority? identity
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction? spatial
  4. Which security, privacy, retention, disclosure and interoperability checks apply to integrity, provenance, authenticity, identity, authorship, copyright, truth and endorsement distinction? event

Indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal

Records indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal? quality
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal, and under which authority? classification
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal? provenance
  4. Which security, privacy, retention, disclosure and interoperability checks apply to indicator, disclosure level, summary, detail, accessibility, localization, warning and appeal? measurement
Privacy, governance and interoperability Groups the governed Resource Consumption concern for privacy, governance and interoperability.

Privacy, safety, harms and access control

Groups Resource Consumption context for privacy, safety, harms and access control without importing neighboring master lifecycles.

Consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data

Records consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data? privacy
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data, and under which authority? composition
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data? ownership
  4. Which security, privacy, retention, disclosure and interoperability checks apply to consent, data minimization, selective disclosure, redaction, sensitive identity, location and device data? evidence

Surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy

Records surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy? exception
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy, and under which authority? relationship
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy? authority
  4. Which security, privacy, retention, disclosure and interoperability checks apply to surveillance, coercion, exclusion, spoofing, removal, re-identification, harm review and remedy? quality

Profiles, crosswalk, conformance and semantic loss

Groups Resource Consumption context for profiles, crosswalk, conformance and semantic loss without importing neighboring master lifecycles.

C2PA, VC, Data Integrity, JOSE, COSE, X.509, PROV, Annotation and IPTC crosswalk

Records c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk? interoperability
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk, and under which authority? state
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk? requirement
  4. Which security, privacy, retention, disclosure and interoperability checks apply to c2pa, vc, data integrity, jose, cose, x.509, prov, annotation and iptc crosswalk? validation

Profile, version, license, conformance, transformation, round trip and semantic loss

Records profile, version, license, conformance, transformation, round trip and semantic loss as a source-qualified Content Provenance Credential assertion while media assets, creative works, parties, keys, tools, events, repositories, rights and trust decisions retain external mastership.

  1. Which credential, manifest, claim, assertion, asset or region identity, version, values and bindings establish profile, version, license, conformance, transformation, round trip and semantic loss? requirement
  2. Who creates, asserts, gathers, signs, timestamps, stores, validates, trusts, discloses or reviews profile, version, license, conformance, transformation, round trip and semantic loss, and under which authority? lifecycle
  3. Which actions, ingredients, clocks, lineage, status, evidence, failures and competing assertions qualify profile, version, license, conformance, transformation, round trip and semantic loss? constraint
  4. Which security, privacy, retention, disclosure and interoperability checks apply to profile, version, license, conformance, transformation, round trip and semantic loss? security

Classifiers Filled

Family
World Models
Category
Information and virtual systems
Entry kind
aggregate
Navigation path
NAV.INF.MED.PRV
Domain
INF.MED.PRV
Industry
Cross-industry
Tags
contentprovenancecredentialinf.med.prv

What it is Filled

Owns content-provenance credential identity and revision; subject asset, rendition, segment and region scope; manifest, claim, assertion and attestation composition; hard and soft content bindings; action, ingredient and derivation references; signer, claim-generator, identity-provider, key, certificate, proof, timestamp and status evidence; embedded, external, repository and durable discovery bindings; validation component results and codes; trust-policy inputs and scoped decision references; human-facing disclosure; privacy, harms, lifecycle, preservation, access, retention, audit and loss-aware interoperability. Media assets, creative works, people, organizations, devices, software, keys, certificates, actions, repositories, rights instruments, evidence and trust decisions remain external masters.

In scope

  • Credential identity, subject and region scope, assertions, manifests, claims, bindings, signatures, times and status
  • Actions, ingredients, derivation, storage, discovery, recovery, validation, trust inputs and disclosure
  • Privacy, harms, lifecycle, preservation, access, retention, audit and version-pinned interoperability

Out of scope

  • Owning media-asset, creative-work, party, device, software, key, certificate, action, repository, rights, evidence or accountable trust-decision lifecycles
  • Treating a hash, filename, URL, watermark, manifest, signature, certificate, trust-list entry, validation result or label as universal asset or credential identity
  • Inferring factual truth, authorship, copyright, ownership, editorial endorsement, legality, safety or universal trust from provenance or cryptographic validity
  • Signing, attesting identity, changing trust lists, disclosing protected provenance, revoking credentials or irreversibly deleting records without accountable authority

Why it exists Filled

Represent an issuer-attributable, integrity-protected and asset-bound set of provenance assertions with verifiable lineage, status, validation and disclosure context.

Distinguishing features Filled

  • Describes signed claims about how an asset was made and changed, not the media asset or creative work itself.
  • Binds assertions to exact content through hard or soft bindings, unlike a filename, URL or embedded label.
  • Differs from a W3C Verifiable Credential about a person: its subject is content and its lineage of ingredients and actions.
  • A valid signature proves who signed and that content is unchanged, not that the content is true, original or lawful.

What robots and AI may and may not do Filled

Must not

  • Present a valid signature or trusted signer as proof of factual truth, authorship or copyright.
  • Sign or attest a credential with a key the agent does not hold under declared authority.
  • Strip, alter or re-sign a manifest to hide earlier actions or ingredients.
  • Treat a missing credential as evidence that content is fake.
  • Disclose redacted provenance details, such as creator location or identity, to unauthorized recipients.
  • Change trust lists or revoke credentials on its own judgement.

Only with a human decision

  • Issuing a credential under an organization's signing identity.
  • Revoking a credential or redacting assertions.
  • Changing the trust policy or trust list used for validation.

May

  • Read and validate a provenance credential and report each validation result with its code.
  • Trace actions and ingredients of an asset back through referenced manifests.
  • Recover a credential from a repository or durable binding when the embedded copy was stripped.
  • Show a viewer a minimal provenance summary that respects disclosure rules.

Moral aspects Filled

  • Provenance can expose the identity, location or devices of journalists, activists and sources; redaction must remain possible.
  • Labels on credentialed content can unfairly discredit authentic content that lacks a credential.
  • Disclosure of AI generation or editing helps audiences judge content and should not be removed silently.
  • Trust lists concentrate power over whose content counts as credible.

Who is affected

  • Creators and editors named in assertions
  • Audiences who rely on provenance labels
  • People depicted in the content
  • Sources and witnesses whose safety depends on redaction

Owners Filled

Steward

Declare the Dimension owner, credential master, issuer authority, signer and key custodian, identity provider, TSA, repository operator, validator, trust-policy owner, privacy steward and independent reviewer.

Roles

Dimension owner
Own namespace, mastership, delegation, access, retention and federation rules.
Credential steward
Own credential identity, scope, schema, lifecycle, revision and interoperability policy.
Issuer or assertion authority
Own the meaning, source and authority of credential claims and assertions.
Signer and key custodian
Control approved signing credentials, proof profiles, rotation and compromise response.
Identity or attestation provider
Own separately scoped signer, human or organizational identity evidence.
Timestamp or status authority
Own trusted-time, revocation, suspension and refresh evidence.
Repository and preservation custodian
Own durable storage, recovery, receipts, retention and revalidation triggers.
Validator or verifier
Run pinned validation and trust policy, preserving component evidence and limitations.
Privacy and harm reviewer
Own minimization, consent, redaction, disclosure, misuse and remedy controls.
Independent auditor
Review identity, binding, proof, trust, validation, lifecycle and access without rewriting originals.

Links to other meta-models Filled

composes

  • WM-MED-002 Media Asset / Rendition - Bind credentials to exact media assets, renditions, segments or regions while the media model retains identity and technical mastership.

references

  • WM-MED-001 Creative Work / Content - Resolve intellectual work context without using provenance as proof of authorship, ownership or truth.
  • Party, identity, device, software, key, certificate, action, repository, rights, evidence and decision masters - Resolve actors, mechanisms, events, custody, legal context and accountable decisions without importing their lifecycles.

aligned

  • C2PA 2.4 Content Credentials, crJSON, Attestations and Soft Binding API - Project the principal content-provenance ecosystem while preserving format independence and exposing version-specific semantics.
  • C2PA implementation, UX, security, harms, AI/ML, identity and conformance guidance - Project implementation and governance controls separately from normative credential structure.
  • W3C Verifiable Credentials 2.0, Data Integrity, VC JOSE/COSE, Controlled Identifiers and Bitstring Status - Project generic credential, proof, controller and status semantics with explicit non-equivalence to C2PA roles.
  • PROV-O and Web Annotation - Project derivation, activity, agent and region-scoped assertion graphs.
  • COSE, X.509 PKIX and Time-Stamp Protocol - Project protected envelopes, certificate paths, revocation and trusted-time evidence without making one proof suite canonical.
  • HTTP Digest Fields, JSON Canonicalization and RFC 3339 - Project digest, deterministic representation and unambiguous clock rules where adopted profiles require them.
  • IPTC Photo Metadata and NIST Generative AI Profile - Project digital-source vocabulary and complementary AI transparency and risk-control context.

neighbor

  • WM-MED-002 Media Asset / Rendition - The media model owns byte-bearing assets, renditions, technical formats and fixity. This model owns credentials and qualified bindings to those assets without importing media identity.
  • WM-MED-001 Creative Work / Content - The work model owns intellectual content and authorship context. Provenance assertions may reference it but do not prove authorship, ownership or truth.
  • C2PA manifest, claim, assertion and manifest store - These are profile-specific composition parts or containers. The logical credential record retains their identities and roles without requiring one serialization.
  • Signer, issuer, human identity and organization - A signer controls a key, an issuer makes claims, and an optional identity provider attests a person or organization. None is inferred from an asset creator field alone.
  • Validation result and trust decision - Validation establishes component outcomes under pinned rules. A verifier separately decides trust for a purpose and context; neither result proves assertion truth.
  • Copyright, rights and editorial policy - Credentials can carry or reference rights and editorial assertions, but legal ownership, permission and accountable publication decisions remain external.
  • W3C Verifiable Credential - VC 2.0 supplies a broader issuer-holder-verifier claim model. C2PA and VC representations may be mapped only with explicit subject, proof, status and lifecycle semantics.

parent

  • WM-XCT-012

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative credential or manifest identifier issued by the declared credential master.
  • Issuer-qualified globally resolvable IRI whose subject and revision semantics match the credential.
  • Adopting-Dimension UUID or ULID when no authoritative external identifier exists.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A provenance credential carries a signed claim, assertions and a content binding, usually in a manifest store.
  • Confused with plain metadata such as EXIF or XMP, with watermarks and with person-level verifiable credentials.

Capabilities and actions required Filled

  • Register provenance credential: Create one stable credential identity, subject scope and master authority without claiming media identity or truth.
  • Compose credential assertions: Add typed assertions and claim references with explicit source, schema, instance, scope and evidence.
  • Bind credential to content: Create hard or soft bindings to an exact asset, rendition, segment or region.
  • Record action and ingredient lineage: Append capture, edit, generation, transformation and ingredient relationships without importing their external lifecycles.
  • Issue and sign credential: Protect a canonical claim with an authorized signing key and an explicitly pinned proof profile.
  • Timestamp and publish status: Attach trusted-time evidence and publish applicable revocation, suspension or refresh information.
  • Store, embed or externalize credential: Place a manifest store in or outside an asset while preserving resolvability, receipts and integrity.
  • Recover durable credential: Use fingerprint or watermark evidence to query repositories and return ranked credential candidates.
  • Validate credential: Validate structure, claim, signature, time, status, assertions, ingredients and asset binding as separate components.
  • Evaluate trust and disclose: Apply verifier purpose and trust policy, then present accessible provenance without implying factual truth.
  • Revise, redact, revoke or tombstone: Append an authorized lifecycle change while preserving prior credential and validation history.
  • Validate and project crosswalk: Produce version-pinned C2PA, VC, PROV, IPTC or generic projections with explicit semantic loss.

Hazards and failure modes required Filled

  • Forged or replayed manifests attached to unrelated content.
  • Soft-binding matches that link a credential to the wrong asset.
  • Expired or revoked signing certificates accepted without a time-stamp check.
  • Privacy harm from provenance fields published without redaction.
  • Overtrust in content because it shows a provenance badge.

Standards and interfaces required Filled

  • C2PA Technical Specification for manifests, claims and assertions.
  • JUMBF, ISO/IEC 19566-5, for embedding manifests.
  • X.509 certificates and IETF RFC 5280 profile.
  • COSE signatures, IETF RFC 9052.
  • Time-Stamp Protocol, IETF RFC 3161.
  • XMP, ISO 16684-1, for metadata references.
  • W3C Verifiable Credentials Data Model 2.0 for identity assertions.

Context of use required Filled

  • Identity, electronic-signature, evidentiary, copyright, privacy, biometric, consumer-protection, records and disclosure duties depend on jurisdiction and purpose.
  • C2PA trust lists and conformance results are ecosystem-specific signals and do not create universal legal or factual trust.
  • IPTC digital-source terms are media-industry vocabulary and must not be treated as complete technical descriptions of AI generation or editing.

Sources Filled

  1. Content Credentials: C2PA Technical Specification - Coalition for Content Provenance and Authenticity
  2. Content Credentials JSON File Format - Coalition for Content Provenance and Authenticity
  3. Attestation in the C2PA Framework - Coalition for Content Provenance and Authenticity
  4. C2PA Soft Binding API - Coalition for Content Provenance and Authenticity
  5. C2PA Implementation Guidance - Coalition for Content Provenance and Authenticity
  6. C2PA User Experience Guidance - Coalition for Content Provenance and Authenticity
  7. C2PA Security Considerations - Coalition for Content Provenance and Authenticity
  8. C2PA Harms Modelling - Coalition for Content Provenance and Authenticity
  9. Guidance for Artificial Intelligence and Machine Learning - Coalition for Content Provenance and Authenticity
  10. Human and Organizational Identity Recommendation - Coalition for Content Provenance and Authenticity
  11. C2PA Conformance Explorer - Coalition for Content Provenance and Authenticity
  12. Verifiable Credentials Data Model v2.0 - World Wide Web Consortium
  13. Verifiable Credential Data Integrity 1.0 - World Wide Web Consortium
  14. Securing Verifiable Credentials using JOSE and COSE - World Wide Web Consortium
  15. Controlled Identifiers v1.0 - World Wide Web Consortium
  16. Bitstring Status List v1.0 - World Wide Web Consortium
  17. PROV-O: The PROV Ontology - World Wide Web Consortium
  18. Web Annotation Data Model - World Wide Web Consortium
  19. CBOR Object Signing and Encryption Structures - Internet Engineering Task Force
  20. Internet X.509 Public Key Infrastructure Certificate and CRL Profile - Internet Engineering Task Force
  21. Internet X.509 Public Key Infrastructure Time-Stamp Protocol - Internet Engineering Task Force
  22. Digest Fields - Internet Engineering Task Force
  23. JSON Canonicalization Scheme - Internet Engineering Task Force
  24. Date and Time on the Internet - Internet Engineering Task Force
  25. IPTC Photo Metadata User Guide - International Press Telecommunications Council
  26. Artificial Intelligence Risk Management Framework: Generative AI Profile - National Institute of Standards and Technology

Open questions

  • Image, video, audio, document, live-stream, model, sensor, news, legal and health-domain specialist profiles for Content Provenance Credential assertions, bindings, validation and trust policies.
  • Decentralized transparency logs, anonymous credentials, zero-knowledge proofs, post-quantum migration and biometric identity integration as future extensions.
  • Versioned algorithm migration policies for deprecated or compromised cryptographic algorithms with specific timelines, validator update requirements and legacy credential revalidation paths.
  • Jurisdiction-specific compliance profiles for EU (eIDAS, GDPR), UK (PSTI), US (state evidence rules, FTC Act), China (state control) and other major regulatory regions addressing electronic-signature validity, evidentiary admissibility, privacy and consent duties.
  • Soft-binding recovery confidence thresholds, false-positive bounds, collision resolution policies and audit trails for ambiguous fingerprint matches with multiple candidate credentials.
  • Operational credential revocation, suspension and refresh policies with specific time windows, repository consistency guarantees, offline verifier update mechanisms and legacy trust-anchor lifecycle.
  • Harm review and remedy frameworks for surveillance, coercion, exclusion, spoofing, re-identification and removal scenarios with specific disclosure, escalation, audit and user-appeal procedures.
  • Image, video, audio, document, live-stream, model, sensor, news, legal, health and jurisdiction-specific profiles require specialist review.
  • Media assets, creative works, parties, identities, devices, software, keys, certificates, actions, repositories, rights, evidence and trust decisions remain neighboring masters.
  • Decentralized transparency logs, anonymous credentials, zero-knowledge proofs, post-quantum migration, biometric identity and forensic truth assessment remain future profiles.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-med-008-content-provenance-credential/spec.yaml, ver-cy/world-models/card-supplements/wm-med-008-content-provenance-credential.json