Skip to main content

Crate pask_wire

Crate pask_wire 

Source
Expand description

Specified producer and verifier processing for Physical-Site Engagement Receipts under wilder.pser/0.5 and wilder.pser/0.6.

Package names (pask-*), profile versions (wilder.pser/<version>) and Internet-Draft revision numbers identify different things and are versioned independently of one another.

Passing the implemented checks does not establish complete profile conformance, authenticated ownership of a supplied key, or that a physical event occurred. The crate README describes the supported processing and remaining limits.

Modules§

testvectors
Compile-time test vectors required by the profile package.

Structs§

AffiliationChange
One point inside a presentation at which issuerAffiliation changed.
ChainReport
What a Chain-Verifier observed about a presentation it accepted.
EnvelopeReport
Exact original input is borrowed even on oversized/malformed inputs (no copy). Protected/payload/signature contents are exact, never re-encoded for signing. Effective headers are decoded conveniences, NOT replacement signed bytes. No field asserts registration, application acceptance, crypto or TS identity.
ExpectedDigest
Expected value is never inferred from a producer file or from the statement.
InclusionProof
A decoded RFC9162_SHA256 inclusion proof.
InspectionFinding
One independently scoped finding. Codes are machine-readable, not acceptance badges.
InspectionLimits
Finite local resource ceilings, not universal RFC limits. Only Phase 1 budgets live here: attachment/statement/key-attempt limits belong to later APIs.
InspectionPolicy
Selected local policy. Support, protected kid and empty external AAD are fixed to the accepted initial profile; callers cannot declare new supported semantics. Limits may be tightened, never raised above the default hard ceilings.
IssuerKeyInput
A single explicit issuer verification key, not a receipt-controlled kid lookup. Time, permitted algorithm, exact issuer binding and origin are caller inputs.
OuterStatementReport
Exact signed byte contents plus unauthenticated decoded conveniences.
Payload
Strongly typed wilder.pser/0.5 payload.
ProofVerification
Root reconstruction alone is explicitly not inclusion authentication.
Receipt
A decoded attached Receipt, before its signature has been checked.
ReceiptVerificationPolicy
Cross-map strictness remains OFF by default in Phase 1. No #70 helper is called. Empty external AAD, strict Ed25519 verification and all-supplied-proofs success are fixed local policy. A valid proof never hides another proof’s failure.
ReceiptVerificationReport
Independent dimensions, with original inputs borrowed and signed bytes preserved.
StatementReceiptOutcome
Owned per-Receipt findings, preserving every encoded input and proof outcome. No borrowed self-reference and no collapsing a bad attachment into absence.
StatementVerificationInputs
SubjectMapping
Exact mapping row, including the TS identity. No normalization or wildcard.
TransparentStatementPolicy
Tightenable local ceilings. Aggregate receipt work is at most eight times the unchanged Phase 2 hard ceiling (256 signature attempts per Receipt).
TransparentStatementReport
TsKeyAssociation
An independently provisioned association, not an identity extracted from a Receipt.
TsTrustContext
Borrowed offline input: no network, live clock, global key store, or hidden defaults.
UnauthenticatedReceiptClaims
Receipt-controlled text, explicitly unauthenticated. Subject TYPE is checked; subject semantic correspondence is not. No URI normalization is performed.
VerificationLimits
Tightenable hard ceilings. Raw statement/trust limits precede allocating decoders and key/proof Cartesian work is checked before the first signature attempt.
VerifiedInclusion
What an attached Receipt was found to prove.
VerifyingKeyEvidence
The actual crypto key, not kid. Indices reference the exact supplied context.

Enums§

AckProvenance
How the acknowledgement recorded in adapter.ackDigest was obtained.
AttachedReceipts
The receipts (394) header of a Signed Statement, as read.
BindingMode
The attestation-binding mode a receipt was produced under.
BindingProvenance
Evidence must bind this row’s exact service identity, algorithm and public key. These fields are caller assertions, not receipt fields and not fetched URLs.
DigestTarget
Error
Errors returned while parsing, producing, or verifying a statement.
InspectionStatus
Finding vocabulary shared with the proposed recipient report.
IssuerAffiliation
Whether the Site Owner and the Issuer are affiliated parties.
ReceiptContainerState
Absence, malformed enclosing container and malformed encoded Receipt differ.
RotationPolicy
The only implemented rotation convention. No historical signing time is inferred from untrusted claims; overlapping current windows permit key rollover.
StatementApplicationPolicy
Named software-only JSON-site policy. It never establishes PSER conformance.
SubjectPolicy
TrustInputOrigin
This API does not authenticate an external configuration transport.
TsPublicKey
Algorithm and key type are independent inputs and must agree.

Constants§

CONTENT_TYPE
Required protected content type for the profile.
CONTENT_TYPE_06
Content type for the 0.6 profile version.
INCLUSION_PROOF_LABEL
Key within the vdp map holding inclusion proofs.
RECEIPTS_LABEL
COSE header parameter carrying attached Receipts (RFC 9942 Section 5.1).
RFC9162_SHA256
The RFC9162_SHA256 Verifiable Data Structure identifier.
SOFTWARE_SITE_CONTENT_TYPE
Private software-fixture application convention, not a core PSER version.
SPEC_VERSION
Supported PSER profile version.
SPEC_VERSION_06
Profile version carrying the timestamp containment requirement.
VDP_LABEL
COSE unprotected header parameter carrying Verifiable Data Structure Proofs.
VDS_LABEL
COSE protected header parameter carrying the VDS identifier.

Functions§

attached_receipts
Reads the receipts (394) header from a COSE_Sign1 Signed Statement.
candidate_leaf_hash
Computes the leaf hash for a candidate entry using RFC 9162 Section 2.1.1.
canonical_example
Emits the canonical example instance, pretty-printed for the document.
canonical_example_06
Emits the canonical example instance for the 0.6 profile, pretty-printed.
canonicalize_json
Canonicalizes one JSON value according to RFC 8785.
derive_candidate_entry
Derives the candidate entry from a presented Transparent Statement.
inspect_scitt_receipt
Inspect a single encoded tagged Receipt under explicit local policy, with no keys, I/O, network, crypto, subject binding or attachment acceptance decision. A passed structure/claims finding does NOT establish a valid signature.
inspect_transparent_statement
Inspect the transmitted object before deriving a candidate or doing crypto. Accepts one tag-18 wrapper or legacy untagged local producer form. Payload must be attached. Receipts must be byte strings, never repaired legacy arrays.
is_supported_spec
Returns true when the given spec string is a supported profile version.
leaf_hash
MTH({d}) for a single entry: HASH(0x00 || d).
produce_ed25519
Produces an attached-payload COSE_Sign1 statement using Ed25519.
produce_es256
Produces an attached-payload COSE_Sign1 statement using ES256.
sha256_prefixed
Computes a lowercase sha256:<hex> digest.
validate_sha256
Validates the exact lowercase sha256:<64 hex digits> representation.
verify_chain
Verifies a slice of receipts as one contiguous chain.
verify_ed25519
Parses and verifies an Ed25519 COSE_Sign1 statement and its PSER payload.
verify_es256
Parses and verifies an ES256 COSE_Sign1 statement and its PSER payload.
verify_inclusion
Verifies an attached Receipt’s inclusion proof and Ed25519 signature, offline.
verify_scitt_receipt
Verify one supported Receipt against a candidate derived from those exact statement bytes. This does NOT validate the outer statement’s header semantics, issuer signature, attachment container, application policy or physical-event truth. LocalSimulation can demonstrate conditional trust but never passes registration. CallerAuthenticatedExternal still relies on the caller to authenticate provisioning.
verify_transparent_statement
Coordinate exact transmitted bytes. A good Receipt never erases the findings for others. Only malformed outer structure/policy stops all dependent work. Passed origin/trust means conditional on explicit caller assertions, not an authenticated transport observed by this library. LocalSimulation cannot pass registration or application acceptance. No application policy means unestablished.

Type Aliases§

Result
Result type used by this crate.