Expand description
Transparency log + OpenTimestamps + Evidence Records for Confium.
Three layers of artifact provenance over time:
- Merkle tree transparency log: every artifact (cert, signature, revocation, re-share event) is appended. Tree roots periodically anchored to Bitcoin via OpenTimestamps. Verifiers can prove any artifact was in the publicly-visible tree as of a given Bitcoin block.
- OpenTimestamps (OTS): anchors hashes to Bitcoin blockchain via public calendar servers.
- Evidence Records (RFC 4998 ERS): long-term archival protection via periodic re-timestamping as hash algorithms age.
See TODO.roadmap/36-transparency-and-ots.md and
TODO.roadmap/37-long-term-archival.md for full specs.
§Example
use confium_transparency::{MerkleTree, entry::{ArtifactType, MerkleEntry}};
let mut tree = MerkleTree::new();
let hash = [0u8; 32]; // sha256 of your artifact
let entry = MerkleEntry::new(0, ArtifactType::CertificateIssuance, hash);
let seq = tree.append(entry);
let root = tree.root();
let proof = tree.inclusion_proof(seq)?;
let entry_ref = tree.entry(seq)?;
MerkleTree::verify_inclusion(entry_ref, &proof, root)?;Re-exports§
Modules§
- entry
- Transparency log entries.
- ers
- RFC 4998 Evidence Record Syntax (ERS) for long-term archival.
- merkle
- Merkle tree implementation for transparency log.
- ots
- OpenTimestamps client and verifier.
- proof
- Inclusion and consistency proofs.
- test_
vectors - Deterministic test vectors for the transparency log.
- witness
- Witness gossip protocol for transparency log monitoring.