Offline receipt integrity vs. signer authority - where does the binding live? #978
Unanswered
source-origin
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Read the security model — the part that keeps receipt integrity (
integrity_valid) and signer trust (signer_trusted) as two separate verdicts, with the trusted key pinned out of band.The seam I'd like your read on: when the receipt is verified by someone who was not the operator — a third party, later, on a different machine — what tells them which key should have signed a given decision? Integrity is checkable offline; trust needs a binding between the decision and the expected signer that does not itself come from the machine under audit.
Do you treat that binding as out-of-band only (a pinned public-key file), or does anything in the receipt / EvidencePack carry a verifiable statement of who was authorized to act — so a third party can check authority, not just signature integrity? The gap I keep hitting is the case where the recorder's own key is the only thing that says the recorder was allowed to decide.
(Adjacent context: we separate a receipt of an action from a verdict about it, and the binding between authority and receipt is the part we have not closed.)
All reactions