Commit Graph

4 Commits

Author SHA1 Message Date
Aere Network
8f5f0bd00d verify-layer: verify-consistency names the signer of each head (or unsigned); identity: Travel Rule requires a replay store
- verify-consistency without --signer now says whether each head is signed and by which key, and that no expected signer was
  checked (verify-inclusion already did; the README said the output does)
- openMessage opens nothing without a replay store (seen: an object with has/add that keeps the ids for at least maxAgeS);
  before, the same signed and sealed message could be opened any number of times when no store was given

Tests: verify-layer tree 20/20, negative control 14/14; sidecar 44/44, 9/9; travel rule 19/19, negative control 19/19.
2026-09-30 10:31:23 +03:00
Aere Network
082b862d78 verify-layer: the audit log as a Merkle tree (RFC 9162) - signed tree heads, and inclusion and consistency proofs anyone checks without the log 2026-09-30 10:13:10 +03:00
Aere Network
35d711fa55 verify-layer: signed heads. keygen makes the operator's ML-DSA-65 head key; attest-head --sign-key signs the head statement in the form the AIP-23 reference verifier checks at its signature level (outside the statement, so the statementHash and its notarization are unchanged); verify-log --attested --signer requires the expected key, and without it says who signed and that no expected signer was compared. A signature says who vouches for the head, not when and not that the history is true. Tests 44/44 with the reference verifier (39 run and 5 skipped without it); negative control 9/9 here. 2026-09-29 22:58:20 +03:00
Aere Network
3465550e91 Add verify-layer (an audit-log sidecar whose head can be notarized on Aere Network for post-quantum finality) and proof-kinds (the AIP-23 envelope builder it uses) 2026-09-29 18:09:34 +03:00