# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T04:02:28Z", "synthesisSha256": "1fe93b552eb052fc6ce46d99968375531dfca644fb17603dce1c66e10e0fd3bc", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-006", "registryId": "vr.wm-xct-006", "name": "Verification / ZK Attestation", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.PRF" ], "tags": [ "verification", "zk", "attestation", "xct.prf" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-006-verification-zk-attestation/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-006", "model": { "registry_id": "vr.wm-xct-006", "model_id": "WM-XCT-006", "name": "Verification / ZK Attestation", "entry_kind": "mixin", "purpose": "Attach a governed predicate, proof or attestation and source-qualified verification result to another model while minimizing disclosure and remaining independent of storage and interface format.", "scope_statement": "Owns the host proof-binding identity, statement and predicate, verifier request, public inputs and commitments, proof-system and cryptosuite profile, challenge and audience binding, proof or presentation reference, disclosure manifest, verification activity and result, privacy-property assessment, status observations and lifecycle. Credentials, actors, subjects, keys, trust registries, policies, decisions, source datasets and audit logs remain external.", "in_scope": [ "Host binding, statement, predicate schema and canonical form, request, purpose, audience, public inputs, commitments and witness non-retention boundary", "Actor roles and authority references, proof system, cryptosuite, circuit, verification key, setup, challenge, holder binding, proof, presentation and verification result", "Disclosure minimization, zero-knowledge and unlinkability claims, status and freshness, time, interoperability, access, retention and safe operations" ], "out_of_scope": [ "Credential, person, organization, subject, key, trust registry, authorization policy, relying-party decision, source dataset or audit-log master lifecycle", "Persisting witnesses, private inputs, holder secrets or undisclosed claims and implementing cryptographic prover or verifier algorithms", "Universal identity truth, authorization or legal-effect decisions, guaranteed zero knowledge, unsupported algorithm fallback or certified cross-format equivalence" ], "boundary_notes": [ { "neighbor": "Credential / Claim", "distinction": "A credential or claim owns asserted content and issuer authority; this mixin binds a selected statement and proof or verification evidence to a host.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Digital Signature / Proof", "distinction": "WM-XCT-034 can provide a generic signature or proof artifact mixin; this model adds verifier request, formal predicate, privacy properties, challenge, status and verification-result semantics for attestation use.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "neighbor": "Key / Verification Method / Trust Registry", "distinction": "Keys, controllers, trust anchors and status sources remain external masters; the attestation pins their identifiers, versions and observations.", "source_refs": [ "SRC-002", "SRC-003" ] }, { "neighbor": "Authorization / Eligibility / Decision", "distinction": "Cryptographic verification is evidence for an external policy decision and never establishes authorization, eligibility or business acceptance by itself.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "Audit Log / Evidence Record", "distinction": "This mixin owns proof-specific provenance and result evidence but delegates generic append-only audit persistence and organization-wide retention.", "source_refs": [ "SRC-009" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines issuer, holder, verifier, claims, credentials, presentations, validity, status and privacy and security considerations." }, { "id": "SRC-002", "title": "Verifiable Credential Data Integrity 1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-data-integrity/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines proof purpose, verification method, cryptosuite, proof value, domain, challenge, created time and verification processing for data integrity proofs." }, { "id": "SRC-003", "title": "Bitstring Status List v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-bitstring-status-list/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines privacy-aware credential status, revocation, suspension, refresh, status messages, validity, retrieval and validation errors." }, { "id": "SRC-004", "title": "Data Integrity BBS Cryptosuites v1.0", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/vc-di-bbs/", "version_or_date": "W3C Candidate Recommendation Draft, 7 April 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines BBS signatures, selective disclosure and unlinkable derived proofs and documents the draft conformance boundary." }, { "id": "SRC-005", "title": "Selective Disclosure for JSON Web Tokens", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9901", "version_or_date": "RFC 9901, November 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines SD-JWT disclosures, digests, decoys, holder binding, issuance and presentation formats and verification requirements." }, { "id": "SRC-006", "title": "OpenID for Verifiable Presentations 1.0", "organization": "OpenID Foundation", "url": "https://openid.net/specs/openid-4-verifiable-presentations-1_0-final.html", "version_or_date": "Final Specification, 9 July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines verifier requests, credential presentation transport, nonce, client binding, response modes, presentation formats and validation responsibilities." }, { "id": "SRC-007", "title": "Privacy-Enhancing Cryptography: Zero-Knowledge Proofs", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/projects/pec/zkproof", "version_or_date": "Project reference accessed 2026-09-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines the public statement, instance, witness and proof-of-knowledge framing and explains that a witness remains undisclosed." }, { "id": "SRC-008", "title": "ZKProof Community Reference", "organization": "ZKProof", "url": "https://docs.zkproof.org/reference", "version_or_date": "Version 0.3, 17 July 2022", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Provides draft community terminology and deployment considerations for proof systems, statements, witnesses, soundness, zero knowledge, setup and implementation." }, { "id": "SRC-009", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Provides provenance for requests, proof generation, presentations, verification activities, results and responsible agents." }, { "id": "SRC-010", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:58:00Z", "relevance": "Defines offset-bearing timestamps for creation, challenge, presentation, receipt, verification, status observation and knowledge events." } ], "structure": { "bundles": [ { "id": "attestation-identity-statement-and-request", "name": "Attestation identity, statement and request", "description": "Identifies the proof binding and defines exactly what statement a verifier requests.", "rationale": "A verification binding is a mixin on a host claim or interaction and does not become the credential, subject, policy or decision it supports.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "binding-identity-host-and-statement", "name": "Binding identity, host and statement", "description": "Stable identity and unambiguous subject matter for the attestation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ], "findings": [ { "id": "attestation-binding-identifier-host-record-purpose-and-version", "name": "Attestation binding identifier, host record, purpose and version", "description": "Mixin identifier, host record and path, binding purpose, profile, version, predecessor, lifecycle state and authoritative registry.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "attestation-binding-identifier-host-record-purpose-and-version-q01", "text": "What identities, roles, versions, scope and values define attestation binding identifier, host record, purpose and version?", "kind": "identity", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "attestation-binding-identifier-host-record-purpose-and-version-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support attestation binding identifier, host record, purpose and version?", "kind": "evidence", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "attestation-binding-identifier-host-record-purpose-and-version-q03", "text": "How may attestation binding identifier, host record, purpose and version be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "validation", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "attestation-binding-identifier-host-record-purpose-and-version-data", "name": "Attestation binding identifier, host record, purpose and version data", "description": "Structured proof-binding data for attestation binding identifier, host record, purpose and version.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "artifacts": [ { "id": "attestation-binding-identifier-host-record-purpose-and-version-record", "name": "Attestation binding identifier, host record, purpose and version record", "description": "Versioned evidence-bearing attestation record for attestation binding identifier, host record, purpose and version with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus attestation-binding-identifier-host-record-purpose-and-version assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "statement-predicate-relation-public-instance-schema-and-canonical-form", "name": "Statement, predicate, relation, public instance, schema and canonical form", "description": "Predicate identifier and version, formal relation, public instance, parameterization, schema, canonical bytes or digest and semantic description.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ], "questions": [ { "id": "statement-predicate-relation-public-instance-schema-and-canonical-form-q01", "text": "What identities, roles, versions, scope and values define statement, predicate, relation, public instance, schema and canonical form?", "kind": "definition", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "statement-predicate-relation-public-instance-schema-and-canonical-form-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support statement, predicate, relation, public instance, schema and canonical form?", "kind": "authority", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "statement-predicate-relation-public-instance-schema-and-canonical-form-q03", "text": "How may statement, predicate, relation, public instance, schema and canonical form be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "interoperability", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "statement-predicate-relation-public-instance-schema-and-canonical-form-data", "name": "Statement, predicate, relation, public instance, schema and canonical form data", "description": "Structured proof-binding data for statement, predicate, relation, public instance, schema and canonical form.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "statement-predicate-relation-public-instance-schema-and-canonical-form-record", "name": "Statement, predicate, relation, public instance, schema and canonical form record", "description": "Versioned evidence-bearing attestation record for statement, predicate, relation, public instance, schema and canonical form with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus statement-predicate-relation-public-instance-schema-and-canonical-form assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "verifier-request-purpose-and-acceptance-boundary", "name": "Verifier request, purpose and acceptance boundary", "description": "Captures requested evidence without treating verification as authorization.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ], "findings": [ { "id": "verification-request-identifier-verifier-audience-purpose-and-requested-claims", "name": "Verification request identifier, verifier, audience, purpose and requested claims", "description": "Request identity, external verifier, audience, purpose, requested predicates or disclosures, format choices, expiry and request-object digest.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ], "questions": [ { "id": "verification-request-identifier-verifier-audience-purpose-and-requested-claims-q01", "text": "What identities, roles, versions, scope and values define verification request identifier, verifier, audience, purpose and requested claims?", "kind": "relationship", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "verification-request-identifier-verifier-audience-purpose-and-requested-claims-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support verification request identifier, verifier, audience, purpose and requested claims?", "kind": "temporal", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "verification-request-identifier-verifier-audience-purpose-and-requested-claims-q03", "text": "How may verification request identifier, verifier, audience, purpose and requested claims be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "access", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "verification-request-identifier-verifier-audience-purpose-and-requested-claims-data", "name": "Verification request identifier, verifier, audience, purpose and requested claims data", "description": "Structured proof-binding data for verification request identifier, verifier, audience, purpose and requested claims.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "verification-request-identifier-verifier-audience-purpose-and-requested-claims-record", "name": "Verification request identifier, verifier, audience, purpose and requested claims record", "description": "Versioned evidence-bearing attestation record for verification request identifier, verifier, audience, purpose and requested claims with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus verification-request-identifier-verifier-audience-purpose-and-requested-claims assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "acceptance-policy-reference-required-assurance-and-decision-separation", "name": "Acceptance policy reference, required assurance and decision separation", "description": "External policy identifier and version, required proof and freshness properties, exception path and explicit separation of cryptographic result from relying-party decision.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "acceptance-policy-reference-required-assurance-and-decision-separation-q01", "text": "What identities, roles, versions, scope and values define acceptance policy reference, required assurance and decision separation?", "kind": "requirement", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "acceptance-policy-reference-required-assurance-and-decision-separation-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support acceptance policy reference, required assurance and decision separation?", "kind": "decision", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "acceptance-policy-reference-required-assurance-and-decision-separation-q03", "text": "How may acceptance policy reference, required assurance and decision separation be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "exception", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "acceptance-policy-reference-required-assurance-and-decision-separation-data", "name": "Acceptance policy reference, required assurance and decision separation data", "description": "Structured proof-binding data for acceptance policy reference, required assurance and decision separation.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "acceptance-policy-reference-required-assurance-and-decision-separation-record", "name": "Acceptance policy reference, required assurance and decision separation record", "description": "Versioned evidence-bearing attestation record for acceptance policy reference, required assurance and decision separation with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus acceptance-policy-reference-required-assurance-and-decision-separation assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "actors-authority-keys-and-trust-material", "name": "Actors, authority, keys and trust material", "description": "References issuers, holders, provers, verifiers and versioned verification material.", "rationale": "Cryptographic control, claim authority, subject identity, holder possession and verifier trust are related but distinct assertions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "actor-roles-authority-and-binding", "name": "Actor roles, authority and binding", "description": "Keeps external identity and role-specific authority explicit.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ], "findings": [ { "id": "issuer-attester-holder-prover-subject-verifier-and-relying-party-reference", "name": "Issuer, attester, holder, prover, subject, verifier and relying-party reference", "description": "External actor identifiers, protocol roles, subject relation, holder binding, delegation and role validity intervals.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ], "questions": [ { "id": "issuer-attester-holder-prover-subject-verifier-and-relying-party-reference-q01", "text": "What identities, roles, versions, scope and values define issuer, attester, holder, prover, subject, verifier and relying-party reference?", "kind": "ownership", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "issuer-attester-holder-prover-subject-verifier-and-relying-party-reference-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support issuer, attester, holder, prover, subject, verifier and relying-party reference?", "kind": "provenance", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "issuer-attester-holder-prover-subject-verifier-and-relying-party-reference-q03", "text": "How may issuer, attester, holder, prover, subject, verifier and relying-party reference be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "privacy", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "issuer-attester-holder-prover-subject-verifier-and-relying-party-reference-data", "name": "Issuer, attester, holder, prover, subject, verifier and relying-party reference data", "description": "Structured proof-binding data for issuer, attester, holder, prover, subject, verifier and relying-party reference.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "issuer-attester-holder-prover-subject-verifier-and-relying-party-reference-record", "name": "Issuer, attester, holder, prover, subject, verifier and relying-party reference record", "description": "Versioned evidence-bearing attestation record for issuer, attester, holder, prover, subject, verifier and relying-party reference with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus issuer-attester-holder-prover-subject-verifier-and-relying-party-reference assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "claim-authority-delegation-proof-purpose-and-verification-method-control", "name": "Claim authority, delegation, proof purpose and verification-method control", "description": "Authority source, delegation scope, proof purpose, controller relation, verification method and authority validity evidence.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "claim-authority-delegation-proof-purpose-and-verification-method-control-q01", "text": "What identities, roles, versions, scope and values define claim authority, delegation, proof purpose and verification-method control?", "kind": "classification", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "claim-authority-delegation-proof-purpose-and-verification-method-control-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support claim authority, delegation, proof purpose and verification-method control?", "kind": "quality", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "claim-authority-delegation-proof-purpose-and-verification-method-control-q03", "text": "How may claim authority, delegation, proof purpose and verification-method control be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "security", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "claim-authority-delegation-proof-purpose-and-verification-method-control-data", "name": "Claim authority, delegation, proof purpose and verification-method control data", "description": "Structured proof-binding data for claim authority, delegation, proof purpose and verification-method control.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "claim-authority-delegation-proof-purpose-and-verification-method-control-record", "name": "Claim authority, delegation, proof purpose and verification-method control record", "description": "Versioned evidence-bearing attestation record for claim authority, delegation, proof purpose and verification-method control with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus claim-authority-delegation-proof-purpose-and-verification-method-control assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "verification-material-status-and-trust", "name": "Verification material, status and trust", "description": "Pins keys, parameters and status observations without importing key or trust registries.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "verification-key-method-identifier-parameters-validity-and-resolution", "name": "Verification key, method identifier, parameters, validity and resolution", "description": "External key or method identifier, type, controller, public material digest, algorithm parameters, resolver, valid interval and resolution evidence.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ], "questions": [ { "id": "verification-key-method-identifier-parameters-validity-and-resolution-q01", "text": "What identities, roles, versions, scope and values define verification key, method identifier, parameters, validity and resolution?", "kind": "composition", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "verification-key-method-identifier-parameters-validity-and-resolution-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support verification key, method identifier, parameters, validity and resolution?", "kind": "measurement", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "verification-key-method-identifier-parameters-validity-and-resolution-q03", "text": "How may verification key, method identifier, parameters, validity and resolution be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "validation", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "verification-key-method-identifier-parameters-validity-and-resolution-data", "name": "Verification key, method identifier, parameters, validity and resolution data", "description": "Structured proof-binding data for verification key, method identifier, parameters, validity and resolution.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "verification-key-method-identifier-parameters-validity-and-resolution-record", "name": "Verification key, method identifier, parameters, validity and resolution record", "description": "Versioned evidence-bearing attestation record for verification key, method identifier, parameters, validity and resolution with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus verification-key-method-identifier-parameters-validity-and-resolution assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "credential-proof-key-and-status-source-revocation-suspension-and-freshness", "name": "Credential, proof, key and status source, revocation, suspension and freshness", "description": "External credential and status references, status purpose, observed status, source authority, retrieval time, validity, cache age and error state.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "questions": [ { "id": "credential-proof-key-and-status-source-revocation-suspension-and-freshness-q01", "text": "What identities, roles, versions, scope and values define credential, proof, key and status source, revocation, suspension and freshness?", "kind": "state", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "credential-proof-key-and-status-source-revocation-suspension-and-freshness-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support credential, proof, key and status source, revocation, suspension and freshness?", "kind": "lifecycle", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "credential-proof-key-and-status-source-revocation-suspension-and-freshness-q03", "text": "How may credential, proof, key and status source, revocation, suspension and freshness be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "retention", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "credential-proof-key-and-status-source-revocation-suspension-and-freshness-data", "name": "Credential, proof, key and status source, revocation, suspension and freshness data", "description": "Structured proof-binding data for credential, proof, key and status source, revocation, suspension and freshness.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "credential-proof-key-and-status-source-revocation-suspension-and-freshness-record", "name": "Credential, proof, key and status source, revocation, suspension and freshness record", "description": "Versioned evidence-bearing attestation record for credential, proof, key and status source, revocation, suspension and freshness with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus credential-proof-key-and-status-source-revocation-suspension-and-freshness assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "proof-system-circuit-commitments-and-privacy-properties", "name": "Proof system, circuit, commitments and privacy properties", "description": "Pins the cryptographic system, formal relation and privacy claims required to interpret a proof.", "rationale": "No proof may be called zero knowledge, sound, unlinkable or setup-free without a named system, version, assumptions and profile evidence.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007", "SRC-008" ], "layers": [ { "id": "public-inputs-commitments-and-witness-boundary", "name": "Public inputs, commitments and witness boundary", "description": "Records what is revealed and binds undisclosed inputs without storing them.", "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-008" ], "findings": [ { "id": "public-input-challenge-commitment-disclosure-digest-and-context", "name": "Public input, challenge, commitment, disclosure digest and context", "description": "Typed public inputs, commitments, disclosed values or digests, challenge, domain, audience, context and canonical ordering.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007" ], "questions": [ { "id": "public-input-challenge-commitment-disclosure-digest-and-context-q01", "text": "What identities, roles, versions, scope and values define public input, challenge, commitment, disclosure digest and context?", "kind": "identity", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "public-input-challenge-commitment-disclosure-digest-and-context-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support public input, challenge, commitment, disclosure digest and context?", "kind": "evidence", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "public-input-challenge-commitment-disclosure-digest-and-context-q03", "text": "How may public input, challenge, commitment, disclosure digest and context be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "validation", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "public-input-challenge-commitment-disclosure-digest-and-context-data", "name": "Public input, challenge, commitment, disclosure digest and context data", "description": "Structured proof-binding data for public input, challenge, commitment, disclosure digest and context.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "public-input-challenge-commitment-disclosure-digest-and-context-record", "name": "Public input, challenge, commitment, disclosure digest and context record", "description": "Versioned evidence-bearing attestation record for public input, challenge, commitment, disclosure digest and context with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus public-input-challenge-commitment-disclosure-digest-and-context assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "private-input-witness-secret-and-non-retention-boundary", "name": "Private input, witness, secret and non-retention boundary", "description": "Witness class and relation only, prohibition on stored value, prover-side master reference if allowed, zeroization or non-retention claim and audit evidence.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008" ], "questions": [ { "id": "private-input-witness-secret-and-non-retention-boundary-q01", "text": "What identities, roles, versions, scope and values define private input, witness, secret and non-retention boundary?", "kind": "definition", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "private-input-witness-secret-and-non-retention-boundary-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support private input, witness, secret and non-retention boundary?", "kind": "authority", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "private-input-witness-secret-and-non-retention-boundary-q03", "text": "How may private input, witness, secret and non-retention boundary be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "interoperability", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "private-input-witness-secret-and-non-retention-boundary-data", "name": "Private input, witness, secret and non-retention boundary data", "description": "Structured proof-binding data for private input, witness, secret and non-retention boundary.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "private-input-witness-secret-and-non-retention-boundary-record", "name": "Private input, witness, secret and non-retention boundary record", "description": "Versioned evidence-bearing attestation record for private input, witness, secret and non-retention boundary with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus private-input-witness-secret-and-non-retention-boundary assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "proof-system-suite-circuit-and-setup", "name": "Proof system, suite, circuit and setup", "description": "Pins all inputs needed to interpret security claims and verification.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-007", "SRC-008" ], "findings": [ { "id": "proof-system-cryptosuite-algorithm-group-curve-and-security-parameter", "name": "Proof system, cryptosuite, algorithm, group, curve and security parameter", "description": "Named system and version, cryptosuite, algorithm identifiers, group or curve, security parameter, implementation profile and deprecation status.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008" ], "questions": [ { "id": "proof-system-cryptosuite-algorithm-group-curve-and-security-parameter-q01", "text": "What identities, roles, versions, scope and values define proof system, cryptosuite, algorithm, group, curve and security parameter?", "kind": "relationship", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "proof-system-cryptosuite-algorithm-group-curve-and-security-parameter-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support proof system, cryptosuite, algorithm, group, curve and security parameter?", "kind": "temporal", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "proof-system-cryptosuite-algorithm-group-curve-and-security-parameter-q03", "text": "How may proof system, cryptosuite, algorithm, group, curve and security parameter be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "access", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "proof-system-cryptosuite-algorithm-group-curve-and-security-parameter-data", "name": "Proof system, cryptosuite, algorithm, group, curve and security parameter data", "description": "Structured proof-binding data for proof system, cryptosuite, algorithm, group, curve and security parameter.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "proof-system-cryptosuite-algorithm-group-curve-and-security-parameter-record", "name": "Proof system, cryptosuite, algorithm, group, curve and security parameter record", "description": "Versioned evidence-bearing attestation record for proof system, cryptosuite, algorithm, group, curve and security parameter with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus proof-system-cryptosuite-algorithm-group-curve-and-security-parameter assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "circuit-relation-verification-key-srs-setup-ceremony-and-assumptions", "name": "Circuit, relation, verification key, SRS, setup ceremony and assumptions", "description": "Circuit or relation digest and version, verification key, structured reference string, setup kind and ceremony evidence, assumptions and compatibility constraints.", "source_refs": [ "SRC-007", "SRC-008" ], "questions": [ { "id": "circuit-relation-verification-key-srs-setup-ceremony-and-assumptions-q01", "text": "What identities, roles, versions, scope and values define circuit, relation, verification key, srs, setup ceremony and assumptions?", "kind": "requirement", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "circuit-relation-verification-key-srs-setup-ceremony-and-assumptions-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support circuit, relation, verification key, srs, setup ceremony and assumptions?", "kind": "decision", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "circuit-relation-verification-key-srs-setup-ceremony-and-assumptions-q03", "text": "How may circuit, relation, verification key, srs, setup ceremony and assumptions be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "exception", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "circuit-relation-verification-key-srs-setup-ceremony-and-assumptions-data", "name": "Circuit, relation, verification key, SRS, setup ceremony and assumptions data", "description": "Structured proof-binding data for circuit, relation, verification key, srs, setup ceremony and assumptions.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "circuit-relation-verification-key-srs-setup-ceremony-and-assumptions-record", "name": "Circuit, relation, verification key, SRS, setup ceremony and assumptions record", "description": "Versioned evidence-bearing attestation record for circuit, relation, verification key, srs, setup ceremony and assumptions with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus circuit-relation-verification-key-srs-setup-ceremony-and-assumptions assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "proof-presentation-transcript-and-verification", "name": "Proof, presentation, transcript and verification", "description": "Binds anti-replay context, proof material and attributable verification outcomes.", "rationale": "A proof artifact, its successful mathematical verification, credential validation and business acceptance are separate records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009", "SRC-010" ], "layers": [ { "id": "challenge-domain-session-and-holder-binding", "name": "Challenge, domain, session and holder binding", "description": "Prevents replay and cross-context proof substitution.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010" ], "findings": [ { "id": "nonce-challenge-domain-audience-client-session-and-expiry-binding", "name": "Nonce, challenge, domain, audience, client, session and expiry binding", "description": "Fresh nonce or challenge, verifier domain, audience, client identifier, session, issue and expiry time, one-time-use state and entropy evidence.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010" ], "questions": [ { "id": "nonce-challenge-domain-audience-client-session-and-expiry-binding-q01", "text": "What identities, roles, versions, scope and values define nonce, challenge, domain, audience, client, session and expiry binding?", "kind": "ownership", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "nonce-challenge-domain-audience-client-session-and-expiry-binding-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support nonce, challenge, domain, audience, client, session and expiry binding?", "kind": "provenance", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "nonce-challenge-domain-audience-client-session-and-expiry-binding-q03", "text": "How may nonce, challenge, domain, audience, client, session and expiry binding be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "privacy", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "nonce-challenge-domain-audience-client-session-and-expiry-binding-data", "name": "Nonce, challenge, domain, audience, client, session and expiry binding data", "description": "Structured proof-binding data for nonce, challenge, domain, audience, client, session and expiry binding.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010" ] } ], "artifacts": [ { "id": "nonce-challenge-domain-audience-client-session-and-expiry-binding-record", "name": "Nonce, challenge, domain, audience, client, session and expiry binding record", "description": "Versioned evidence-bearing attestation record for nonce, challenge, domain, audience, client, session and expiry binding with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus nonce-challenge-domain-audience-client-session-and-expiry-binding assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-005", "SRC-006", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "holder-binding-key-binding-possession-and-replay-correlation-control", "name": "Holder binding, key binding, possession and replay-correlation control", "description": "Binding method, key or nonce reference, possession proof, replay cache reference, verifier-specific context, correlation risk and mitigation.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "holder-binding-key-binding-possession-and-replay-correlation-control-q01", "text": "What identities, roles, versions, scope and values define holder binding, key binding, possession and replay-correlation control?", "kind": "classification", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "holder-binding-key-binding-possession-and-replay-correlation-control-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support holder binding, key binding, possession and replay-correlation control?", "kind": "quality", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "holder-binding-key-binding-possession-and-replay-correlation-control-q03", "text": "How may holder binding, key binding, possession and replay-correlation control be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "security", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "holder-binding-key-binding-possession-and-replay-correlation-control-data", "name": "Holder binding, key binding, possession and replay-correlation control data", "description": "Structured proof-binding data for holder binding, key binding, possession and replay-correlation control.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "holder-binding-key-binding-possession-and-replay-correlation-control-record", "name": "Holder binding, key binding, possession and replay-correlation control record", "description": "Versioned evidence-bearing attestation record for holder binding, key binding, possession and replay-correlation control with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus holder-binding-key-binding-possession-and-replay-correlation-control assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "proof-artifact-processing-and-result", "name": "Proof artifact, processing and result", "description": "Preserves inputs, outputs and errors for independent review.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-009" ], "findings": [ { "id": "proof-presentation-derived-proof-disclosure-set-format-and-integrity", "name": "Proof, presentation, derived proof, disclosure set, format and integrity", "description": "Proof value or external artifact, format and media type, derived-proof profile, disclosure manifest, host and request binding, digest and size.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "proof-presentation-derived-proof-disclosure-set-format-and-integrity-q01", "text": "What identities, roles, versions, scope and values define proof, presentation, derived proof, disclosure set, format and integrity?", "kind": "composition", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "proof-presentation-derived-proof-disclosure-set-format-and-integrity-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support proof, presentation, derived proof, disclosure set, format and integrity?", "kind": "measurement", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "proof-presentation-derived-proof-disclosure-set-format-and-integrity-q03", "text": "How may proof, presentation, derived proof, disclosure set, format and integrity be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "validation", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "proof-presentation-derived-proof-disclosure-set-format-and-integrity-data", "name": "Proof, presentation, derived proof, disclosure set, format and integrity data", "description": "Structured proof-binding data for proof, presentation, derived proof, disclosure set, format and integrity.", "value_kind": "binary", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "proof-presentation-derived-proof-disclosure-set-format-and-integrity-record", "name": "Proof, presentation, derived proof, disclosure set, format and integrity record", "description": "Versioned evidence-bearing attestation record for proof, presentation, derived proof, disclosure set, format and integrity with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus proof-presentation-derived-proof-disclosure-set-format-and-integrity assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "verification-activity-inputs-checks-result-errors-time-and-evidence", "name": "Verification activity, inputs, checks, result, errors, time and evidence", "description": "Verifier implementation and version, resolved inputs, algorithm checks, status and freshness checks, valid or invalid result, structured errors and provenance.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-009" ], "questions": [ { "id": "verification-activity-inputs-checks-result-errors-time-and-evidence-q01", "text": "What identities, roles, versions, scope and values define verification activity, inputs, checks, result, errors, time and evidence?", "kind": "state", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "verification-activity-inputs-checks-result-errors-time-and-evidence-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support verification activity, inputs, checks, result, errors, time and evidence?", "kind": "lifecycle", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "verification-activity-inputs-checks-result-errors-time-and-evidence-q03", "text": "How may verification activity, inputs, checks, result, errors, time and evidence be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "retention", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "verification-activity-inputs-checks-result-errors-time-and-evidence-data", "name": "Verification activity, inputs, checks, result, errors, time and evidence data", "description": "Structured proof-binding data for verification activity, inputs, checks, result, errors, time and evidence.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "verification-activity-inputs-checks-result-errors-time-and-evidence-record", "name": "Verification activity, inputs, checks, result, errors, time and evidence record", "description": "Versioned evidence-bearing attestation record for verification activity, inputs, checks, result, errors, time and evidence with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus verification-activity-inputs-checks-result-errors-time-and-evidence assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "disclosure-privacy-status-and-lifecycle", "name": "Disclosure, privacy, status and lifecycle", "description": "Makes disclosure and correlation effects visible and preserves time-qualified validity.", "rationale": "Selective disclosure does not automatically imply zero knowledge or unlinkability, and a proof can remain mathematically valid after its credential or policy becomes unacceptable.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-008", "SRC-009", "SRC-010" ], "layers": [ { "id": "disclosure-minimization-linkability-and-leakage", "name": "Disclosure minimization, linkability and leakage", "description": "Records intended and observed privacy properties.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008" ], "findings": [ { "id": "requested-disclosed-derived-undisclosed-and-inferred-claim-manifest", "name": "Requested, disclosed, derived, undisclosed and inferred claim manifest", "description": "Claim paths or predicate IDs by category, necessity, derivation, value or commitment visibility, verifier purpose and minimization justification.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "requested-disclosed-derived-undisclosed-and-inferred-claim-manifest-q01", "text": "What identities, roles, versions, scope and values define requested, disclosed, derived, undisclosed and inferred claim manifest?", "kind": "identity", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "requested-disclosed-derived-undisclosed-and-inferred-claim-manifest-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support requested, disclosed, derived, undisclosed and inferred claim manifest?", "kind": "evidence", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "requested-disclosed-derived-undisclosed-and-inferred-claim-manifest-q03", "text": "How may requested, disclosed, derived, undisclosed and inferred claim manifest be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "validation", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "requested-disclosed-derived-undisclosed-and-inferred-claim-manifest-data", "name": "Requested, disclosed, derived, undisclosed and inferred claim manifest data", "description": "Structured proof-binding data for requested, disclosed, derived, undisclosed and inferred claim manifest.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "requested-disclosed-derived-undisclosed-and-inferred-claim-manifest-record", "name": "Requested, disclosed, derived, undisclosed and inferred claim manifest record", "description": "Versioned evidence-bearing attestation record for requested, disclosed, derived, undisclosed and inferred claim manifest with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus requested-disclosed-derived-undisclosed-and-inferred-claim-manifest assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment", "name": "Zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment", "description": "Property claimed, proof-system basis, threat model, verifier collusion assumptions, linkable fields, status-channel leakage, residual inference and confidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008" ], "questions": [ { "id": "zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment-q01", "text": "What identities, roles, versions, scope and values define zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment?", "kind": "definition", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment?", "kind": "authority", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment-q03", "text": "How may zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "interoperability", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment-data", "name": "Zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment data", "description": "Structured proof-binding data for zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008" ] } ], "artifacts": [ { "id": "zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment-record", "name": "Zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment record", "description": "Versioned evidence-bearing attestation record for zero knowledge, selective disclosure, unlinkability, anonymity and leakage assessment with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus zero-knowledge-selective-disclosure-unlinkability-anonymity-and-leakage-assessment assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "validity-status-change-and-event-history", "name": "Validity, status change and event history", "description": "Separates cryptographic, credential and policy time.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009", "SRC-010" ], "findings": [ { "id": "proof-created-presented-received-verified-observed-and-knowledge-time", "name": "Proof created, presented, received, verified, observed and knowledge time", "description": "Distinct RFC 3339 event times, source clock, accuracy, ordering, observation and ingestion time, and later knowledge correction.", "source_refs": [ "SRC-002", "SRC-006", "SRC-009", "SRC-010" ], "questions": [ { "id": "proof-created-presented-received-verified-observed-and-knowledge-time-q01", "text": "What identities, roles, versions, scope and values define proof created, presented, received, verified, observed and knowledge time?", "kind": "relationship", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "proof-created-presented-received-verified-observed-and-knowledge-time-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support proof created, presented, received, verified, observed and knowledge time?", "kind": "temporal", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "proof-created-presented-received-verified-observed-and-knowledge-time-q03", "text": "How may proof created, presented, received, verified, observed and knowledge time be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "access", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "proof-created-presented-received-verified-observed-and-knowledge-time-data", "name": "Proof created, presented, received, verified, observed and knowledge time data", "description": "Structured proof-binding data for proof created, presented, received, verified, observed and knowledge time.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-006", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "proof-created-presented-received-verified-observed-and-knowledge-time-record", "name": "Proof created, presented, received, verified, observed and knowledge time record", "description": "Versioned evidence-bearing attestation record for proof created, presented, received, verified, observed and knowledge time with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus proof-created-presented-received-verified-observed-and-knowledge-time assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-006", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "credential-proof-key-policy-and-trust-status-change-effect", "name": "Credential, proof, key, policy and trust status change effect", "description": "External status event, purpose, source, prior and next state, effective time, reversibility, affected verification and re-evaluation requirement.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "credential-proof-key-policy-and-trust-status-change-effect-q01", "text": "What identities, roles, versions, scope and values define credential, proof, key, policy and trust status change effect?", "kind": "requirement", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "credential-proof-key-policy-and-trust-status-change-effect-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support credential, proof, key, policy and trust status change effect?", "kind": "decision", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "credential-proof-key-policy-and-trust-status-change-effect-q03", "text": "How may credential, proof, key, policy and trust status change effect be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "exception", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "credential-proof-key-policy-and-trust-status-change-effect-data", "name": "Credential, proof, key, policy and trust status change effect data", "description": "Structured proof-binding data for credential, proof, key, policy and trust status change effect.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "artifacts": [ { "id": "credential-proof-key-policy-and-trust-status-change-effect-record", "name": "Credential, proof, key, policy and trust status change effect record", "description": "Versioned evidence-bearing attestation record for credential, proof, key, policy and trust status change effect with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus credential-proof-key-policy-and-trust-status-change-effect assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "interoperability-provenance-access-and-agent-governance", "name": "Interoperability, provenance, access and agent governance", "description": "Provides versioned projections, reproducibility and safe autonomous handling.", "rationale": "Proof formats and protocols expose different semantics, and verification logs can undermine privacy if they retain stable identifiers or undisclosed material.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-008", "SRC-009", "SRC-010" ], "layers": [ { "id": "format-protocol-crosswalk-and-reproducibility", "name": "Format, protocol, crosswalk and reproducibility", "description": "Maps proof families with explicit information loss and environment evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-008", "SRC-009" ], "findings": [ { "id": "vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk", "name": "VC Data Integrity, BBS, SD-JWT, OpenID4VP and ZKP crosswalk", "description": "Source and target versions, field and event mappings, canonicalization, holder binding, disclosure semantics, omissions and round-trip limits.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-008" ], "questions": [ { "id": "vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk-q01", "text": "What identities, roles, versions, scope and values define vc data integrity, bbs, sd-jwt, openid4vp and zkp crosswalk?", "kind": "ownership", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support vc data integrity, bbs, sd-jwt, openid4vp and zkp crosswalk?", "kind": "provenance", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk-q03", "text": "How may vc data integrity, bbs, sd-jwt, openid4vp and zkp crosswalk be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "privacy", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk-data", "name": "VC Data Integrity, BBS, SD-JWT, OpenID4VP and ZKP crosswalk data", "description": "Structured proof-binding data for vc data integrity, bbs, sd-jwt, openid4vp and zkp crosswalk.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-008" ] } ], "artifacts": [ { "id": "vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk-record", "name": "VC Data Integrity, BBS, SD-JWT, OpenID4VP and ZKP crosswalk record", "description": "Versioned evidence-bearing attestation record for vc data integrity, bbs, sd-jwt, openid4vp and zkp crosswalk with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus vc-data-integrity-bbs-sd-jwt-openid4vp-and-zkp-crosswalk assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "implementation-build-test-vector-verifier-environment-and-reproducibility", "name": "Implementation, build, test vector, verifier environment and reproducibility", "description": "Implementation and dependency versions, build digest, platform, test-vector set, conformance result, execution evidence and reproducibility status.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008", "SRC-009" ], "questions": [ { "id": "implementation-build-test-vector-verifier-environment-and-reproducibility-q01", "text": "What identities, roles, versions, scope and values define implementation, build, test vector, verifier environment and reproducibility?", "kind": "classification", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "implementation-build-test-vector-verifier-environment-and-reproducibility-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support implementation, build, test vector, verifier environment and reproducibility?", "kind": "quality", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "implementation-build-test-vector-verifier-environment-and-reproducibility-q03", "text": "How may implementation, build, test vector, verifier environment and reproducibility be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "security", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "implementation-build-test-vector-verifier-environment-and-reproducibility-data", "name": "Implementation, build, test vector, verifier environment and reproducibility data", "description": "Structured proof-binding data for implementation, build, test vector, verifier environment and reproducibility.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "implementation-build-test-vector-verifier-environment-and-reproducibility-record", "name": "Implementation, build, test vector, verifier environment and reproducibility record", "description": "Versioned evidence-bearing attestation record for implementation, build, test vector, verifier environment and reproducibility with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus implementation-build-test-vector-verifier-environment-and-reproducibility assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "purpose-bound-access-retention-and-safe-operations", "name": "Purpose-bound access, retention and safe operations", "description": "Controls sensitive proof metadata and agent changes.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009", "SRC-010" ], "findings": [ { "id": "prover-verifier-auditor-regulator-public-and-analytical-view", "name": "Prover, verifier, auditor, regulator, public and analytical view", "description": "Audience, purpose, authority, permitted fields, witness exclusion, pseudonymization, correlation budget, expiry, disclosure event and re-identification risk.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009" ], "questions": [ { "id": "prover-verifier-auditor-regulator-public-and-analytical-view-q01", "text": "What identities, roles, versions, scope and values define prover, verifier, auditor, regulator, public and analytical view?", "kind": "composition", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "prover-verifier-auditor-regulator-public-and-analytical-view-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support prover, verifier, auditor, regulator, public and analytical view?", "kind": "measurement", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "prover-verifier-auditor-regulator-public-and-analytical-view-q03", "text": "How may prover, verifier, auditor, regulator, public and analytical view be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "validation", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "prover-verifier-auditor-regulator-public-and-analytical-view-data", "name": "Prover, verifier, auditor, regulator, public and analytical view data", "description": "Structured proof-binding data for prover, verifier, auditor, regulator, public and analytical view.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009" ] } ], "artifacts": [ { "id": "prover-verifier-auditor-regulator-public-and-analytical-view-record", "name": "Prover, verifier, auditor, regulator, public and analytical view record", "description": "Versioned evidence-bearing attestation record for prover, verifier, auditor, regulator, public and analytical view with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus prover-verifier-auditor-regulator-public-and-analytical-view assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention", "name": "Agent authority, operation, pre-write, post-write, concurrency, recovery and retention", "description": "Actor and agent, delegated authority, operation, expected head, validation, idempotency, confirmation class, outcome, rollback, deletion and audit event.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ], "questions": [ { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-q01", "text": "What identities, roles, versions, scope and values define agent authority, operation, pre-write, post-write, concurrency, recovery and retention?", "kind": "state", "answer_data": [ "identifiers and roles", "versions and profiles", "scope and values", "explicit unknowns" ] }, { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-q02", "text": "Which statement, authority, cryptographic evidence, event time and knowledge time support agent authority, operation, pre-write, post-write, concurrency, recovery and retention?", "kind": "lifecycle", "answer_data": [ "statement and authority", "proof or status evidence", "event and knowledge time", "assumptions" ] }, { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-q03", "text": "How may agent authority, operation, pre-write, post-write, concurrency, recovery and retention be validated, contested, corrected, superseded, retained and disclosed without exposing a witness or equating verification with authorization?", "kind": "retention", "answer_data": [ "validation", "contest and correction", "successor history", "witness exclusion", "decision boundary" ] } ], "data_elements": [ { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-data", "name": "Agent authority, operation, pre-write, post-write, concurrency, recovery and retention data", "description": "Structured proof-binding data for agent authority, operation, pre-write, post-write, concurrency, recovery and retention.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-record", "name": "Agent authority, operation, pre-write, post-write, concurrency, recovery and retention record", "description": "Versioned evidence-bearing attestation record for agent authority, operation, pre-write, post-write, concurrency, recovery and retention with statement, suite, event and knowledge time, provenance and disclosure marking.", "media_or_form": [ "logical verification or attestation assertion", "cryptographic proof, status or verifier-evidence reference" ], "serial": true, "identity_strategy": "Attestation binding identifier plus agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention assertion or event identifier; subject name, predicate, proof value, date and digest never identify the binding alone.", "source_refs": [ "SRC-001", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-attestation-binding", "name": "Register attestation binding", "description": "Attach stable proof-binding identity and host path without importing the host record.", "inputs": [ "host record", "binding purpose", "authority" ], "outputs": [ "attestation-binding revision" ], "preconditions": [ "host, namespace, authority and mixin cardinality validate" ], "effects": [ "proof context becomes resolvable without asserting success" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "id": "define-statement-and-predicate", "name": "Define statement and predicate", "description": "Pin formal relation, public instance, predicate schema, parameters and canonical representation.", "inputs": [ "binding", "predicate", "schema", "public inputs" ], "outputs": [ "statement revision" ], "preconditions": [ "predicate version, schema, encoding and digest validate" ], "effects": [ "prover and verifier can refer to the same statement" ], "source_refs": [ "SRC-002", "SRC-007", "SRC-008" ] }, { "id": "create-verification-request", "name": "Create verification request", "description": "Record verifier, purpose, audience, requested predicates or disclosures, formats, nonce and expiry.", "inputs": [ "binding", "verifier", "purpose", "requirements" ], "outputs": [ "verification request" ], "preconditions": [ "authority, minimization, nonce entropy, domain and expiry validate" ], "effects": [ "request is bound to a purpose and anti-replay context" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-006" ] }, { "id": "bind-proof-system-and-verification-material", "name": "Bind proof system and verification material", "description": "Pin cryptosuite, circuit, algorithms, verification key, parameters, setup and assumptions.", "inputs": [ "statement", "proof-system profile", "public material" ], "outputs": [ "proof-system binding" ], "preconditions": [ "versions, key control, circuit digest, setup and deprecation validate" ], "effects": [ "proof security claims become interpretable and reviewable" ], "source_refs": [ "SRC-002", "SRC-004", "SRC-005", "SRC-008" ] }, { "id": "record-proof-generation", "name": "Record proof generation", "description": "Append a prover-side generation event and proof artifact reference without persisting witness or secret input.", "inputs": [ "request", "statement", "prover", "proof reference" ], "outputs": [ "proof-generation event" ], "preconditions": [ "request binding, suite, public inputs and witness non-retention validate" ], "effects": [ "proof is linked to its context while secrets remain outside the model" ], "source_refs": [ "SRC-004", "SRC-005", "SRC-007", "SRC-009" ] }, { "id": "receive-and-bind-presentation", "name": "Receive and bind presentation", "description": "Record receipt, disclosed and derived claims, holder binding, challenge, domain and presentation integrity.", "inputs": [ "request", "presentation", "receiver" ], "outputs": [ "presentation-receipt revision" ], "preconditions": [ "format, request, nonce, audience, holder binding and expiry validate" ], "effects": [ "received material is fixed before verification" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ] }, { "id": "verify-proof-and-record-result", "name": "Verify proof and record result", "description": "Record the exact verifier, inputs, checks, status lookups, result and structured errors.", "inputs": [ "presentation", "statement", "verification material", "status sources" ], "outputs": [ "verification result" ], "preconditions": [ "algorithm allowlist, canonicalization, challenge, key, status and freshness validate" ], "effects": [ "cryptographic outcome becomes attributable without making a business decision" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-006", "SRC-009" ] }, { "id": "assess-disclosure-and-privacy-properties", "name": "Assess disclosure and privacy properties", "description": "Compare requested, disclosed, derived and inferable data and record linkability and leakage claims.", "inputs": [ "request", "presentation", "proof-system profile", "threat model" ], "outputs": [ "privacy assessment" ], "preconditions": [ "purpose, property definitions, status channel and collusion assumptions validate" ], "effects": [ "zero knowledge, selective disclosure and unlinkability remain separately evidenced" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008" ] }, { "id": "issue-purpose-bound-verification-view", "name": "Issue purpose-bound verification view", "description": "Create prover, verifier, auditor or regulator projection with minimum data and declared loss.", "inputs": [ "binding revision", "audience", "purpose", "target profile" ], "outputs": [ "validated verification projection" ], "preconditions": [ "access, witness exclusion, correlation budget, freshness and target version validate" ], "effects": [ "consumer receives traceable evidence and limitations" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-009" ] }, { "id": "correct-supersede-reevaluate-or-retire", "name": "Correct, supersede, re-evaluate or retire", "description": "Append correction, status-triggered re-evaluation, supersession, expiry or tombstone while preserving evidence.", "inputs": [ "binding", "change authority", "reason", "new status or evidence" ], "outputs": [ "successor revision or retirement event" ], "preconditions": [ "expected head, authority, status, legal hold and retention validate" ], "effects": [ "current state changes without rewriting proof or result history" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-010" ] } ], "composition": [ { "target": "Host Model", "relation": "MIX-IN", "purpose": "Attach proof and verification semantics without replacing host identity or lifecycle.", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "WM-XCT-034 Digital Signature / Proof", "relation": "REFERENCE", "purpose": "Reuse generic signature or proof artifact semantics while adding predicate, privacy, request, status and verification context.", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-005" ] }, { "target": "Credential, Actor, Key, Trust, Policy and Decision models", "relation": "REFERENCE", "purpose": "Resolve source claims, roles, verification material, trust and external acceptance decisions.", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ] }, { "target": "VC Data Integrity, BBS, SD-JWT and OpenID4VP", "relation": "ALIGN", "purpose": "Project credential proof, selective disclosure and presentation protocol data with declared loss.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-006" ] }, { "target": "PROV-O and RFC 3339", "relation": "ALIGN", "purpose": "Represent accountable generation and verification activities and explicit event times.", "required": false, "source_refs": [ "SRC-009", "SRC-010" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, verification authority, namespace and accountable privacy steward", "Attestation, predicate, proof-system, request, verification-result, status and trust registries", "Master-system mappings for subjects, actors, credentials, keys, policies, decisions, source data and audit logs", "Cryptographic-suite, disclosure, challenge, trust, status, access, retention and agent-operation policies" ], "namespace_guidance": "Mint a Dimension identifier for the attestation binding and retain authoritative host, request and proof-system identifiers. Keep people, organizations, credentials, keys, policies, decisions, source datasets and audit logs as external references.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local predicate, proof-system, verification-method, status-source and attestation-binding registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by authoritative master-system attestation-binding identifier plus host path, statement digest and request identity, never by subject name, disclosed value, proof value, timestamp or verifier result alone.", "Canonicalization and encoding versions are part of the statement and proof-system binding and cannot be inferred from media type alone." ], "patch_rules": [ "Extensions declare proof family and application profile, target finding, predicate, cryptosuite, canonicalization, status and protocol versions and interoperability impact.", "Changes to statement, public inputs, circuit, verification key, setup, challenge binding, disclosure semantics or privacy properties require a successor revision, migration map and preserved evidence." ], "compatibility_rules": [ "Unknown additive fields may be ignored only when host binding, statement, request, proof suite, public inputs, challenge, result, status, access and provenance remain intact.", "Every VC Data Integrity, BBS, SD-JWT, OpenID4VP or ZKP projection pins versions and states transformed fields, privacy-property changes, omissions and round-trip limits." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system attestation-binding identifier qualified by host record and owning Dimension.", "Governed globally resolvable proof or verification IRI bound to the authoritative host and request.", "Dimension UUID or ULID when no external identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; separate request, challenge, proof creation, presentation, receipt, verification, status observation, decision, expiration and knowledge times.", "serial_naming_rule": "Use {attestation-id}--{artifact-kind}--{assertion-or-event-id}; never use subject name, predicate, disclosed value, proof value, date or digest alone.", "integrity_rule": "Store digest, media type, host and request binding, predicate, proof-system, cryptosuite and canonicalization versions, event and knowledge times, verification authority, status freshness, access and provenance." }, "policies": [ "Never persist a witness, private input, holder secret or undisclosed claim in this model; record only its class, relation and non-retention evidence.", "Cryptographic success, credential validity, issuer trust, current status, authorization, eligibility and business acceptance remain separate attributable outcomes.", "Zero knowledge, selective disclosure, unlinkability, anonymity and soundness may be asserted only for named systems and versions under an explicit threat model and assumptions.", "Agents may perform allowlisted reversible verification and record maintenance but may not extract hidden values, silently downgrade algorithms, reuse challenges or make external decisions without delegated authority." ], "crud": { "read": [ "Resolve Dimension policy, host record, statement, request, proof-system versions, verification method, challenge, status freshness, access purpose and head revision." ], "create": [ "Create binding identity, host path, statement, request, disclosure policy and explicit unknowns before attaching proof material or a verification result." ], "update": [ "Append request, proof, presentation, verification, privacy assessment, status or correction events with actor, version, event and knowledge time and provenance; never overwrite cited history." ], "delete": [ "Apply privacy-minimizing retention, legal hold and audit policy; remove expired proof bytes or correlation data only through authorized disposition while preserving a tombstone, result provenance and required evidence." ] }, "roles": [ { "name": "Attestation binding owner", "responsibilities": [ "Own host attachment, identity, lifecycle and purpose boundary." ] }, { "name": "Issuer or attester", "responsibilities": [ "Own claims or credentials and their source authority, validity and status semantics." ] }, { "name": "Holder or prover", "responsibilities": [ "Control presentations and witnesses and authorize purpose-bound disclosure." ] }, { "name": "Verifier", "responsibilities": [ "Issue bounded requests, verify according to pinned profiles and record attributable results." ] }, { "name": "Proof-system and key steward", "responsibilities": [ "Maintain allowed suites, parameters, circuits, verification keys, setup evidence and deprecation." ] }, { "name": "Relying-party decision owner", "responsibilities": [ "Apply external acceptance policy after verification and own the resulting decision." ] }, { "name": "Privacy and records steward", "responsibilities": [ "Control minimization, correlation, access, retention, disposition and auditability." ] } ], "access": { "default_rule": "Deny witnesses, private inputs, holder secrets, undisclosed claims, stable correlation handles and purpose-unrelated logs; grant only minimum proof and verification data required by an authorized purpose.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Auditor, regulator, incident-response or dispute access cites authority and remains purpose-bound, minimum-necessary, attributable, time-limited and separately logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, attestation, operation, policy, RFC 3339 time, host and request binding, proof profile, affected fields and outcome without logging a witness." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension host, predicate, proof-system, key, challenge, disclosure, trust, status, access, retention and agent-operation policies.", "Read this mixin and linked credential, key, trust, policy, decision, source-data and audit-log models before mutation." ] } }, "coverage": { "claim": "A source-grounded reviewable draft of a verification and zero-knowledge attestation mixin across W3C VC and Data Integrity, BBS, IETF SD-JWT, OpenID4VP, NIST, ZKProof, PROV-O and RFC 3339 materials, without universal identity, authorization, privacy, implementation-security or certified-crosswalk claims.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Attestation binding identity is qualified by host, statement and request and separated from credential, proof and actor identities." }, { "dimension": "classification and definition", "status": "covered", "notes": "Predicate, proof-system, cryptosuite, canonicalization, status and protocol profiles are versioned." }, { "dimension": "direct properties", "status": "covered", "notes": "Host binding, statement, public inputs, commitments, proof material, challenge, disclosures and result are first-class." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Proof receipt, status lookup, verification checks, errors, privacy assessment and confidence are covered." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Register, define, request, bind, record, receive, verify, assess, project and retire operations are governed." }, { "dimension": "composition", "status": "covered", "notes": "The mixin attaches to a host while credentials, actors, keys, policies, decisions, source data and logs retain external identity." }, { "dimension": "lifecycle", "status": "covered", "notes": "Request, challenge, generation, presentation, receipt, verification, re-evaluation, expiry, supersession and retirement preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Issuer, holder, prover, subject, verifier, key, status, predicate, policy and host relations are typed." }, { "dimension": "temporal", "status": "covered", "notes": "Request, challenge, creation, presentation, receipt, verification, status, decision, expiry and knowledge times remain distinct." }, { "dimension": "spatial", "status": "covered", "notes": "Jurisdiction and processing location are delegated to Dimension policy and external actors or systems when material." }, { "dimension": "provenance", "status": "covered", "notes": "Requests, proof generation, presentations, verification, status observations and projections retain responsible-agent provenance." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Host, credential, actor, key, trust, policy, decision, source-data and audit-log masters remain separate." }, { "dimension": "validation and quality", "status": "covered", "notes": "Statement, schema, canonicalization, suite, key, challenge, proof, status, result and stale-head checks are explicit." }, { "dimension": "access and privacy", "status": "covered", "notes": "Witness exclusion, disclosure minimization, correlation controls and purpose-bound views are explicit." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Proof bytes and correlation data can expire under policy while tombstones, results and required evidence remain." }, { "dimension": "interoperability", "status": "covered", "notes": "VC Data Integrity, BBS, SD-JWT, OpenID4VP and general ZKP projections are versioned and loss-aware." } ], "known_omissions": [ "No independent Claude or Grok result was available; later cryptography and credential review is required before canonical promotion.", "No approved relation rows were supplied; the asserted parent-child relationship with WM-XCT-034 Digital Signature / Proof remains a governance hold.", "Proof-system-specific algebra, circuit languages, hardware attestation, regulatory profiles and certified security levels require specialist review.", "BBS remains a Candidate Recommendation Draft and ZKProof Community Reference remains an incomplete 0.x reference; production profiles require explicit maturity gates." ], "conflicts": [ "Selective disclosure, zero knowledge, unlinkability, anonymity and holder binding can be present in different combinations.", "A proof may verify mathematically while the credential is expired or revoked, the issuer is untrusted, the request is stale, or relying-party policy rejects it.", "Data Integrity, BBS, SD-JWT and protocol presentations have different canonicalization, disclosure, binding and verification semantics." ], "regional_assumptions": [ "Credential trust, legal effect, age or residency predicates and acceptable assurance are jurisdiction and relying-party specific.", "W3C and OpenID specifications define technical models and protocols but do not establish universal identity or authorization truth.", "NIST and ZKProof materials provide conceptual and deployment guidance, not one mandatory universal ZKP suite." ], "adversarial_checks": [ "Reject an attestation whose statement, public inputs, canonicalization, proof system or verification key cannot be resolved exactly.", "Reject any persisted witness, secret, undisclosed claim or reusable unbound proof.", "Reject zero-knowledge or unlinkability claims inferred merely from selective disclosure or a successful signature check.", "Reject verification represented as identity truth, authorization, eligibility or business acceptance.", "Reject an agent operation that silently downgrades algorithms, reuses a challenge, expands disclosure or destroys cited verification evidence." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted as a proof and verification binding attached to a host claim or interaction", "rationale": "The mixin owns host binding, formal statement, request, public inputs, proof-system profile, challenge, proof reference, disclosure manifest and verification evidence. Credentials, actors, keys, trust, policies, decisions, source data and audit logs preserve external identity and lifecycle." }, "decisions": [ { "concept": "Host binding", "disposition": "accepted as a mixin boundary", "rationale": "Verification evidence attaches to another model and does not replace the host record, claim or interaction." }, { "concept": "Statement and predicate", "disposition": "accepted as explicit versioned semantics", "rationale": "The formal relation, public instance, schema and canonical representation must be known before a proof can be interpreted." }, { "concept": "Witness and private input", "disposition": "forbidden from storage", "rationale": "Only witness class and relation may be recorded; the secret value remains prover-side and outside this model." }, { "concept": "Zero knowledge and selective disclosure", "disposition": "accepted as distinct properties", "rationale": "Selective disclosure, zero knowledge, unlinkability and anonymity require separate proof-system and threat-model evidence." }, { "concept": "Proof and verification result", "disposition": "accepted as separate records", "rationale": "A proof artifact is input to a versioned verification activity whose result, checks, errors and provenance remain attributable." }, { "concept": "Challenge and context binding", "disposition": "accepted as mandatory anti-replay context", "rationale": "Nonce, domain, audience, client, session, request identity and expiry prevent reuse or substitution across contexts." }, { "concept": "Status and freshness", "disposition": "accepted as independent observations", "rationale": "Credential, key, policy and trust status can change after proof generation and can require re-evaluation." }, { "concept": "Verification and external decision", "disposition": "accepted as strictly separate", "rationale": "Mathematical verification does not establish identity truth, issuer trust, authorization, eligibility or business acceptance." }, { "concept": "Interoperability", "disposition": "accepted as loss-aware versioned projections", "rationale": "Data Integrity, BBS, SD-JWT, OpenID4VP and general ZKP systems differ in canonicalization, binding and privacy semantics." }, { "concept": "Parent relationship to WM-XCT-034", "disposition": "retained as unapproved reference only", "rationale": "The registry suggests a parent relation but no frozen relation contract exists, so cardinality and ownership remain a publication hold." } ], "publicationHolds": [ "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.", "No approved relation row establishes the parent-child contract with WM-XCT-034 Digital Signature / Proof.", "Proof-system-specific algebra, circuit languages, hardware attestation, regulatory profiles and certified security levels require specialist review.", "BBS remains a Candidate Recommendation Draft and ZKProof Community Reference remains an incomplete 0.x reference; production profiles require explicit maturity gates.", "Certified VC Data Integrity, BBS, SD-JWT, OpenID4VP and ZKP crosswalks and conformance fixtures remain unverified.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Approve the WM-XCT-006 and WM-XCT-034 division, relation direction, cardinality and inherited responsibilities.", "Develop proof-system profiles for predicates, circuits, public inputs, setup, verification keys, security assumptions and upgrade paths.", "Create fixtures for replay, wrong audience, stale status, revoked credential, invalid proof, key rotation, selective disclosure, verifier collusion and re-evaluation.", "Validate certified cross-format projections with statement, authority, privacy, time, access, information-loss and round-trip tests." ] }, "statistics": { "sources": 10, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }