Expand description
Specified producer and verifier processing for Physical-Site Engagement Receipts
under wilder.pser/0.5 and wilder.pser/0.6.
Package names (pask-*), profile versions (wilder.pser/<version>) and
Internet-Draft revision numbers identify different things and are versioned
independently of one another.
Passing the implemented checks does not establish complete profile conformance, authenticated ownership of a supplied key, or that a physical event occurred. The crate README describes the supported processing and remaining limits.
Modules§
- testvectors
- Compile-time test vectors required by the profile package.
Structs§
- Affiliation
Change - One point inside a presentation at which
issuerAffiliationchanged. - Chain
Report - What a Chain-Verifier observed about a presentation it accepted.
- Envelope
Report - Exact original input is borrowed even on oversized/malformed inputs (no copy). Protected/payload/signature contents are exact, never re-encoded for signing. Effective headers are decoded conveniences, NOT replacement signed bytes. No field asserts registration, application acceptance, crypto or TS identity.
- Expected
Digest - Expected value is never inferred from a producer file or from the statement.
- Inclusion
Proof - A decoded
RFC9162_SHA256inclusion proof. - Inspection
Finding - One independently scoped finding. Codes are machine-readable, not acceptance badges.
- Inspection
Limits - Finite local resource ceilings, not universal RFC limits. Only Phase 1 budgets live here: attachment/statement/key-attempt limits belong to later APIs.
- Inspection
Policy - Selected local policy. Support, protected kid and empty external AAD are fixed to the accepted initial profile; callers cannot declare new supported semantics. Limits may be tightened, never raised above the default hard ceilings.
- Issuer
KeyInput - A single explicit issuer verification key, not a receipt-controlled kid lookup. Time, permitted algorithm, exact issuer binding and origin are caller inputs.
- Outer
Statement Report - Exact signed byte contents plus unauthenticated decoded conveniences.
- Payload
- Strongly typed
wilder.pser/0.5payload. - Proof
Verification - Root reconstruction alone is explicitly not inclusion authentication.
- Receipt
- A decoded attached Receipt, before its signature has been checked.
- Receipt
Verification Policy - Cross-map strictness remains OFF by default in Phase 1. No #70 helper is called. Empty external AAD, strict Ed25519 verification and all-supplied-proofs success are fixed local policy. A valid proof never hides another proof’s failure.
- Receipt
Verification Report - Independent dimensions, with original inputs borrowed and signed bytes preserved.
- Statement
Receipt Outcome - Owned per-Receipt findings, preserving every encoded input and proof outcome. No borrowed self-reference and no collapsing a bad attachment into absence.
- Statement
Verification Inputs - Subject
Mapping - Exact mapping row, including the TS identity. No normalization or wildcard.
- Transparent
Statement Policy - Tightenable local ceilings. Aggregate receipt work is at most eight times the unchanged Phase 2 hard ceiling (256 signature attempts per Receipt).
- Transparent
Statement Report - TsKey
Association - An independently provisioned association, not an identity extracted from a Receipt.
- TsTrust
Context - Borrowed offline input: no network, live clock, global key store, or hidden defaults.
- Unauthenticated
Receipt Claims - Receipt-controlled text, explicitly unauthenticated. Subject TYPE is checked; subject semantic correspondence is not. No URI normalization is performed.
- Verification
Limits - Tightenable hard ceilings. Raw statement/trust limits precede allocating decoders and key/proof Cartesian work is checked before the first signature attempt.
- Verified
Inclusion - What an attached Receipt was found to prove.
- Verifying
KeyEvidence - The actual crypto key, not kid. Indices reference the exact supplied context.
Enums§
- AckProvenance
- How the acknowledgement recorded in
adapter.ackDigestwas obtained. - Attached
Receipts - The
receipts(394) header of a Signed Statement, as read. - Binding
Mode - The attestation-binding mode a receipt was produced under.
- Binding
Provenance - Evidence must bind this row’s exact service identity, algorithm and public key. These fields are caller assertions, not receipt fields and not fetched URLs.
- Digest
Target - Error
- Errors returned while parsing, producing, or verifying a statement.
- Inspection
Status - Finding vocabulary shared with the proposed recipient report.
- Issuer
Affiliation - Whether the Site Owner and the Issuer are affiliated parties.
- Receipt
Container State - Absence, malformed enclosing container and malformed encoded Receipt differ.
- Rotation
Policy - The only implemented rotation convention. No historical signing time is inferred from untrusted claims; overlapping current windows permit key rollover.
- Statement
Application Policy - Named software-only JSON-site policy. It never establishes PSER conformance.
- Subject
Policy - Trust
Input Origin - This API does not authenticate an external configuration transport.
- TsPublic
Key - Algorithm and key type are independent inputs and must agree.
Constants§
- CONTENT_
TYPE - Required protected content type for the profile.
- CONTENT_
TYPE_ 06 - Content type for the 0.6 profile version.
- INCLUSION_
PROOF_ LABEL - Key within the
vdpmap holding inclusion proofs. - RECEIPTS_
LABEL - COSE header parameter carrying attached Receipts (RFC 9942 Section 5.1).
- RFC9162_
SHA256 - The
RFC9162_SHA256Verifiable Data Structure identifier. - SOFTWARE_
SITE_ CONTENT_ TYPE - Private software-fixture application convention, not a core PSER version.
- SPEC_
VERSION - Supported PSER profile version.
- SPEC_
VERSION_ 06 - Profile version carrying the timestamp containment requirement.
- VDP_
LABEL - COSE unprotected header parameter carrying Verifiable Data Structure Proofs.
- VDS_
LABEL - COSE protected header parameter carrying the VDS identifier.
Functions§
- attached_
receipts - Reads the
receipts(394) header from aCOSE_Sign1Signed Statement. - candidate_
leaf_ hash - Computes the leaf hash for a candidate entry using RFC 9162 Section 2.1.1.
- canonical_
example - Emits the canonical example instance, pretty-printed for the document.
- canonical_
example_ 06 - Emits the canonical example instance for the 0.6 profile, pretty-printed.
- canonicalize_
json - Canonicalizes one JSON value according to RFC 8785.
- derive_
candidate_ entry - Derives the candidate entry from a presented Transparent Statement.
- inspect_
scitt_ receipt - Inspect a single encoded tagged Receipt under explicit local policy, with no keys, I/O, network, crypto, subject binding or attachment acceptance decision. A passed structure/claims finding does NOT establish a valid signature.
- inspect_
transparent_ statement - Inspect the transmitted object before deriving a candidate or doing crypto. Accepts one tag-18 wrapper or legacy untagged local producer form. Payload must be attached. Receipts must be byte strings, never repaired legacy arrays.
- is_
supported_ spec - Returns true when the given spec string is a supported profile version.
- leaf_
hash MTH({d})for a single entry:HASH(0x00 || d).- produce_
ed25519 - Produces an attached-payload
COSE_Sign1statement using Ed25519. - produce_
es256 - Produces an attached-payload
COSE_Sign1statement using ES256. - sha256_
prefixed - Computes a lowercase
sha256:<hex>digest. - validate_
sha256 - Validates the exact lowercase
sha256:<64 hex digits>representation. - verify_
chain - Verifies a slice of receipts as one contiguous chain.
- verify_
ed25519 - Parses and verifies an Ed25519
COSE_Sign1statement and its PSER payload. - verify_
es256 - Parses and verifies an ES256
COSE_Sign1statement and its PSER payload. - verify_
inclusion - Verifies an attached Receipt’s inclusion proof and Ed25519 signature, offline.
- verify_
scitt_ receipt - Verify one supported Receipt against a candidate derived from those exact
statement bytes. This does NOT validate the outer statement’s header semantics,
issuer signature, attachment container, application policy or physical-event truth.
LocalSimulationcan demonstrate conditional trust but never passes registration.CallerAuthenticatedExternalstill relies on the caller to authenticate provisioning. - verify_
transparent_ statement - Coordinate exact transmitted bytes. A good Receipt never erases the findings for others. Only malformed outer structure/policy stops all dependent work. Passed origin/trust means conditional on explicit caller assertions, not an authenticated transport observed by this library. LocalSimulation cannot pass registration or application acceptance. No application policy means unestablished.
Type Aliases§
- Result
- Result type used by this crate.