AIP-23: the proof kinds AERE produces, with their conformance envelopes (aips/aip23-kinds/: fifteen kinds, authorization, settlement and provenance added 2026-09-28; KINDS.json lists each kind's required fields); correction: the notary on chain 2800 has held digests since 2026-09-17 (the measured status of 2026-09-27 said nothing was notarized there), Errata 1
This commit is contained in:
parent
f86746a376
commit
a464214626
@ -56,7 +56,8 @@ A proof is a JSON object:
|
|||||||
|
|
||||||
- `statement` is the payload: what happened. Its `kind` names the proof type (`aere-proof-of-software`, `aere-proof-of-data`,
|
- `statement` is the payload: what happened. Its `kind` names the proof type (`aere-proof-of-software`, `aere-proof-of-data`,
|
||||||
`aere-proof-of-ai`, `aere-proof-of-execution`, `aere-proof-of-identity`, `aere-proof-of-compliance`, ...). The type-specific
|
`aere-proof-of-ai`, `aere-proof-of-execution`, `aere-proof-of-identity`, `aere-proof-of-compliance`, ...). The type-specific
|
||||||
fields are that type's business; the protocol constrains only the envelope.
|
fields are that type's business; the protocol constrains only the envelope. The kinds AERE produces, with their fields and one
|
||||||
|
conformance envelope each, are listed in `aere-research/aips/aip23-kinds/` (added 2026-09-29).
|
||||||
- `statementHash` binds the statement.
|
- `statementHash` binds the statement.
|
||||||
- `signature` (optional) is the producer's signature over the canonical statement text.
|
- `signature` (optional) is the producer's signature over the canonical statement text.
|
||||||
- `notarization` (optional) records that `statementHash` was written to the on-chain notary. It is a claim of the producer; a
|
- `notarization` (optional) records that `statementHash` was written to the on-chain notary. It is a claim of the producer; a
|
||||||
@ -166,6 +167,10 @@ covering anchor post-quantum from the presence of a certificate; it is replaced
|
|||||||
certificate check exists in one place. `node verify-proof.mjs <envelope.json> [--rpc <url>] [--chain 2800|28001] [--json]`.
|
certificate check exists in one place. `node verify-proof.mjs <envelope.json> [--rpc <url>] [--chain 2800|28001] [--json]`.
|
||||||
- `aere-node/tools/proof-vectors/`: envelopes with their expected verdicts, a real Proof-of-Software attestation among them, and one
|
- `aere-node/tools/proof-vectors/`: envelopes with their expected verdicts, a real Proof-of-Software attestation among them, and one
|
||||||
notarized on the public testnet 28001.
|
notarized on the public testnet 28001.
|
||||||
|
- `aere-research/aips/aip23-kinds/` (added 2026-09-29): the proof kinds AERE produces, fifteen on that date (data, execution,
|
||||||
|
identity, compliance, runtime, location, device, payment, ownership, time, block, authorization, settlement, provenance, AI; the
|
||||||
|
last three before AI were added on 2026-09-28), each with its required fields in `KINDS.json` and one envelope. A `settlement`
|
||||||
|
carries its transaction and block as 32-byte hashes as they are, never re-hashed; a `provenance` names a non-empty list of parents.
|
||||||
|
|
||||||
### Measured status (2026-09-27)
|
### Measured status (2026-09-27)
|
||||||
|
|
||||||
@ -180,6 +185,15 @@ covering anchor post-quantum from the presence of a certificate; it is replaced
|
|||||||
is refused by its code hash. With a check removed in a copy of the verifier (the header binding, the code hash, the node hash, the
|
is refused by its code hash. With a check removed in a copy of the verifier (the header binding, the code hash, the node hash, the
|
||||||
anchor verdict), the corresponding case no longer gives the expected verdict, four of four.
|
anchor verdict), the corresponding case no longer gives the expected verdict, four of four.
|
||||||
- On chain 2800 nothing is notarized yet; there the verifier proves the absence of a hash from the certified state.
|
- On chain 2800 nothing is notarized yet; there the verifier proves the absence of a hash from the certified state.
|
||||||
|
*Corrected 2026-09-29:* the sentence above was wrong when written. The notary on chain 2800 does hold digests (measured: one
|
||||||
|
first seen at 2026-09-17T21:08:06Z); what holds is that none of the published conformance vectors is notarized there, so for
|
||||||
|
them the verifier proves the absence of their hash from the certified state.
|
||||||
|
|
||||||
|
### Measured status (2026-09-29)
|
||||||
|
|
||||||
|
- Each of the fifteen envelopes in `aere-research/aips/aip23-kinds/` is `VALID` with the reference verifier offline (form and
|
||||||
|
integrity pass; signature and finality are `ABSENT`). The folder is written from one source, and a copy altered, a foreign file,
|
||||||
|
a kind without its description or a vector whose statement no longer hashes to its `statementHash` stops the publication.
|
||||||
|
|
||||||
### Adoption path
|
### Adoption path
|
||||||
|
|
||||||
@ -189,7 +203,8 @@ verification layer rather than one more product. Concretely: the verifier and ve
|
|||||||
|
|
||||||
## Errata
|
## Errata
|
||||||
|
|
||||||
None.
|
1. *2026-09-29, Measured status (2026-09-27), last item.* It said that nothing was notarized on chain 2800. The notary there held
|
||||||
|
digests from 2026-09-17; the statement was true only of the published conformance vectors. Corrected in place, with its date.
|
||||||
|
|
||||||
## Post-Acceptance Outcome Record
|
## Post-Acceptance Outcome Record
|
||||||
|
|
||||||
|
|||||||
520
aips/aip23-kinds/KINDS.json
Normal file
520
aips/aip23-kinds/KINDS.json
Normal file
@ -0,0 +1,520 @@
|
|||||||
|
{
|
||||||
|
"protocol": "AIP-23",
|
||||||
|
"kinds": [
|
||||||
|
{
|
||||||
|
"kind": "data",
|
||||||
|
"statementKind": "aere-proof-of-data",
|
||||||
|
"envelopeKind": "aere-proof-of-data-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "sha256",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "name",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"sha256",
|
||||||
|
"name",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a file or dataset had exactly this content (its SHA-256) under this name",
|
||||||
|
"vector": "data.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "execution",
|
||||||
|
"statementKind": "aere-proof-of-execution",
|
||||||
|
"envelopeKind": "aere-proof-of-execution-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "inputHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "outputHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "programSha256",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "program",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "exitCode",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"program",
|
||||||
|
"inputHash",
|
||||||
|
"outputHash",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a program ran on this input and produced this output (digests), with this exit code",
|
||||||
|
"vector": "execution.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "identity",
|
||||||
|
"statementKind": "aere-proof-of-identity",
|
||||||
|
"envelopeKind": "aere-proof-of-identity-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "publicKeyHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "subjectHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "method",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "subjectId",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"subjectId",
|
||||||
|
"publicKeyHash",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a subject identifier is bound to this public key (digest), by this method",
|
||||||
|
"vector": "identity.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "compliance",
|
||||||
|
"statementKind": "aere-proof-of-compliance",
|
||||||
|
"envelopeKind": "aere-proof-of-compliance-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "evidenceHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "subject",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "policy",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "result",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"subject",
|
||||||
|
"policy",
|
||||||
|
"result",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a subject was checked against a named policy with this result; the evidence is referenced by digest",
|
||||||
|
"vector": "compliance.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "runtime",
|
||||||
|
"statementKind": "aere-proof-of-runtime",
|
||||||
|
"envelopeKind": "aere-proof-of-runtime-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "artifactSha256",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "attestedSha256",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "host",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "unit",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "matches",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"host",
|
||||||
|
"artifactSha256",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a host runs this artifact (digest), and whether it matches the attested one",
|
||||||
|
"vector": "runtime.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "location",
|
||||||
|
"statementKind": "aere-proof-of-location",
|
||||||
|
"envelopeKind": "aere-proof-of-location-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "evidenceHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "subject",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "region",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "method",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"subject",
|
||||||
|
"region",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a subject is in this region, by this method; the evidence is referenced by digest",
|
||||||
|
"vector": "location.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "device",
|
||||||
|
"statementKind": "aere-proof-of-device",
|
||||||
|
"envelopeKind": "aere-proof-of-device-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "attestationHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "publicKeyHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "deviceId",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "posture",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"deviceId",
|
||||||
|
"attestationHash",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a device identifier carries this attestation and key (digests) and this posture",
|
||||||
|
"vector": "device.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "payment",
|
||||||
|
"statementKind": "aere-proof-of-payment",
|
||||||
|
"envelopeKind": "aere-proof-of-payment-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "txHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "from",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "to",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "amount",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "asset",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"from",
|
||||||
|
"to",
|
||||||
|
"amount",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a payment of this amount and asset from one party to another, with its transaction (digest)",
|
||||||
|
"vector": "payment.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "ownership",
|
||||||
|
"statementKind": "aere-proof-of-ownership",
|
||||||
|
"envelopeKind": "aere-proof-of-ownership-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "assetHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "owner",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "assetId",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"owner",
|
||||||
|
"assetId",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "an owner holds this asset identifier; the asset is referenced by digest",
|
||||||
|
"vector": "ownership.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "time",
|
||||||
|
"statementKind": "aere-proof-of-time",
|
||||||
|
"envelopeKind": "aere-proof-of-time-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "subjectHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "source",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "at",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"subjectHash",
|
||||||
|
"at",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a subject (digest) existed at this time, from this time source",
|
||||||
|
"vector": "time.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "block",
|
||||||
|
"statementKind": "aere-proof-of-block",
|
||||||
|
"envelopeKind": "aere-proof-of-block-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "stateTransitionProof",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "blockHash",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "stateRoot",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "anchorHeight",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "certificateDigest",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"blockHash",
|
||||||
|
"stateRoot",
|
||||||
|
"certificateDigest",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a block hash and state root, with the post-quantum anchor certificate digest that covers them",
|
||||||
|
"vector": "block.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "authorization",
|
||||||
|
"statementKind": "aere-proof-of-authorization",
|
||||||
|
"envelopeKind": "aere-proof-of-authorization-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "policyHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "grantor",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "grantee",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "scope",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "expiresAt",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"grantor",
|
||||||
|
"grantee",
|
||||||
|
"scope",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a grantor gave a grantee the right to act within a scope, under a policy (digest), until an expiry",
|
||||||
|
"added": "2026-09-28",
|
||||||
|
"vector": "authorization.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "settlement",
|
||||||
|
"statementKind": "aere-proof-of-settlement",
|
||||||
|
"envelopeKind": "aere-proof-of-settlement-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "instructionHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "txHash",
|
||||||
|
"type": "hash",
|
||||||
|
"note": "already a 32-byte hash (0x + 64 hex); any other form is refused, not hashed"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "blockHash",
|
||||||
|
"type": "hash",
|
||||||
|
"note": "already a 32-byte hash (0x + 64 hex); any other form is refused, not hashed"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "chainId",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "from",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "to",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "amount",
|
||||||
|
"type": "plain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "asset",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"chainId",
|
||||||
|
"txHash",
|
||||||
|
"blockHash",
|
||||||
|
"amount",
|
||||||
|
"asset",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "a settlement on a chain: its transaction and block (32-byte hashes carried as they are, never re-hashed), amount and asset",
|
||||||
|
"added": "2026-09-28",
|
||||||
|
"vector": "settlement.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "provenance",
|
||||||
|
"statementKind": "aere-proof-of-provenance",
|
||||||
|
"envelopeKind": "aere-proof-of-provenance-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "subjectHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "processHash",
|
||||||
|
"type": "digest",
|
||||||
|
"note": "sha256 of the content, 0x + 64 hex"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "parents",
|
||||||
|
"type": "list",
|
||||||
|
"note": "non-empty list of digests"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "actor",
|
||||||
|
"type": "plain"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"subjectHash",
|
||||||
|
"parents",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "an artifact (digest) was produced from a non-empty list of parents (digests), by a process (digest), by an actor",
|
||||||
|
"added": "2026-09-28",
|
||||||
|
"vector": "provenance.json"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "ai",
|
||||||
|
"statementKind": "aere-proof-of-ai",
|
||||||
|
"envelopeKind": "aere-proof-of-ai-attestation",
|
||||||
|
"fields": [
|
||||||
|
{
|
||||||
|
"name": "model",
|
||||||
|
"type": "object {name, version|null, weightsSha256|null}"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "promptHash",
|
||||||
|
"type": "digest|null"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "inputHash",
|
||||||
|
"type": "digest|null"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "outputHash",
|
||||||
|
"type": "digest|null"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "tools",
|
||||||
|
"type": "list of tool names"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "agentId",
|
||||||
|
"type": "plain|null"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "requesterHash",
|
||||||
|
"type": "digest|null"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"required": [
|
||||||
|
"model.name",
|
||||||
|
"createdAt"
|
||||||
|
],
|
||||||
|
"attests": "an AI action: which model and version, which prompt, input and output (digests), which tools, which agent, who asked",
|
||||||
|
"vector": "ai.json"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
54
aips/aip23-kinds/README.md
Normal file
54
aips/aip23-kinds/README.md
Normal file
@ -0,0 +1,54 @@
|
|||||||
|
# AERE Proof Protocol: proof kinds and their conformance vectors (AIP-23)
|
||||||
|
|
||||||
|
AIP-23 constrains only the envelope: a `statement`, its `statementHash`, an optional signature and an optional notarization. Each
|
||||||
|
kind of proof keeps its own statement fields. This folder lists the kinds AERE produces today, with one envelope per kind, so that an
|
||||||
|
independent implementation can produce and check them without us. The machine-readable list is `KINDS.json`.
|
||||||
|
|
||||||
|
## Check conformance
|
||||||
|
|
||||||
|
For each `<kind>.json`:
|
||||||
|
|
||||||
|
1. take the `statement` object;
|
||||||
|
2. serialize it canonically: `JSON.stringify(statement)`, keys in the order they appear in the file, UTF-8;
|
||||||
|
3. SHA-256 over those bytes, prefixed with `0x`;
|
||||||
|
4. the result MUST equal `statementHash`.
|
||||||
|
|
||||||
|
The same with the reference verifier, which also checks form, signature and finality when present:
|
||||||
|
|
||||||
|
```
|
||||||
|
node verify-proof.mjs data.json --json # verify-proof.mjs is published in aere-node/tools/
|
||||||
|
```
|
||||||
|
|
||||||
|
Every envelope here is VALID offline (form and integrity pass; it carries no signature and no notarization, so those levels are
|
||||||
|
ABSENT). Change one field of a statement and it is INVALID at the integrity level.
|
||||||
|
|
||||||
|
## Kinds
|
||||||
|
|
||||||
|
| kind | statement kind | required fields | what it attests |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| data | `aere-proof-of-data` | `sha256`, `name`, `createdAt` | a file or dataset had exactly this content (its SHA-256) under this name |
|
||||||
|
| execution | `aere-proof-of-execution` | `program`, `inputHash`, `outputHash`, `createdAt` | a program ran on this input and produced this output (digests), with this exit code |
|
||||||
|
| identity | `aere-proof-of-identity` | `subjectId`, `publicKeyHash`, `createdAt` | a subject identifier is bound to this public key (digest), by this method |
|
||||||
|
| compliance | `aere-proof-of-compliance` | `subject`, `policy`, `result`, `createdAt` | a subject was checked against a named policy with this result; the evidence is referenced by digest |
|
||||||
|
| runtime | `aere-proof-of-runtime` | `host`, `artifactSha256`, `createdAt` | a host runs this artifact (digest), and whether it matches the attested one |
|
||||||
|
| location | `aere-proof-of-location` | `subject`, `region`, `createdAt` | a subject is in this region, by this method; the evidence is referenced by digest |
|
||||||
|
| device | `aere-proof-of-device` | `deviceId`, `attestationHash`, `createdAt` | a device identifier carries this attestation and key (digests) and this posture |
|
||||||
|
| payment | `aere-proof-of-payment` | `from`, `to`, `amount`, `createdAt` | a payment of this amount and asset from one party to another, with its transaction (digest) |
|
||||||
|
| ownership | `aere-proof-of-ownership` | `owner`, `assetId`, `createdAt` | an owner holds this asset identifier; the asset is referenced by digest |
|
||||||
|
| time | `aere-proof-of-time` | `subjectHash`, `at`, `createdAt` | a subject (digest) existed at this time, from this time source |
|
||||||
|
| block | `aere-proof-of-block` | `blockHash`, `stateRoot`, `certificateDigest`, `createdAt` | a block hash and state root, with the post-quantum anchor certificate digest that covers them |
|
||||||
|
| authorization (added 2026-09-28) | `aere-proof-of-authorization` | `grantor`, `grantee`, `scope`, `createdAt` | a grantor gave a grantee the right to act within a scope, under a policy (digest), until an expiry |
|
||||||
|
| settlement (added 2026-09-28) | `aere-proof-of-settlement` | `chainId`, `txHash`, `blockHash`, `amount`, `asset`, `createdAt` | a settlement on a chain: its transaction and block (32-byte hashes carried as they are, never re-hashed), amount and asset |
|
||||||
|
| provenance (added 2026-09-28) | `aere-proof-of-provenance` | `subjectHash`, `parents`, `createdAt` | an artifact (digest) was produced from a non-empty list of parents (digests), by a process (digest), by an actor |
|
||||||
|
| ai | `aere-proof-of-ai` | `model.name`, `createdAt` | an AI action: which model and version, which prompt, input and output (digests), which tools, which agent, who asked |
|
||||||
|
|
||||||
|
Field types in `KINDS.json`: `digest` is the SHA-256 of some content (0x + 64 hex), so nothing sensitive enters the statement in
|
||||||
|
the clear; `hash` is a value that is already a 32-byte hash (a transaction or block hash) and is refused if it has another form;
|
||||||
|
`list` is a non-empty list of digests; `plain` is carried as given. Proof of Software has its own statement, and its conformance
|
||||||
|
vector is `aere-node/tools/proof-vectors/01-proof-of-software.json`.
|
||||||
|
|
||||||
|
## What an envelope does not prove
|
||||||
|
|
||||||
|
An envelope binds a claim to its hash and, when signed, to its signer; with a notarization, to a time certified post-quantum on
|
||||||
|
chain. It does not make the claim true in the world: the truth of a "location" or a "device" depends on who attests it and how.
|
||||||
|
Read the signer, not only the verdict.
|
||||||
23
aips/aip23-kinds/ai.json
Normal file
23
aips/aip23-kinds/ai.json
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-ai-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-ai",
|
||||||
|
"model": {
|
||||||
|
"name": "example-model",
|
||||||
|
"version": "1.0",
|
||||||
|
"weightsSha256": null
|
||||||
|
},
|
||||||
|
"promptHash": "0xbae9264d6d972b80f4fe23b4a22b599a1585c7faa7473232694978240159f3fe",
|
||||||
|
"inputHash": null,
|
||||||
|
"outputHash": "0x761b7ad8ad439b2855fcbb611331c646ef0870b0631247bba3f3025cb6df5a53",
|
||||||
|
"tools": [
|
||||||
|
"search"
|
||||||
|
],
|
||||||
|
"agentId": "agent-7",
|
||||||
|
"requesterHash": null,
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x496ba1813fe9923be9817a66dc413482103c0eee5166d55e3b8df3fc3a1c60cd"
|
||||||
|
}
|
||||||
15
aips/aip23-kinds/authorization.json
Normal file
15
aips/aip23-kinds/authorization.json
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-authorization-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-authorization",
|
||||||
|
"policyHash": "0xf062025b73d9324b189fcec2b5c88338aa6fa9fb7877700681b2049b57e6aedd",
|
||||||
|
"grantor": "org-x",
|
||||||
|
"grantee": "agent-7",
|
||||||
|
"scope": "payments:send<=100",
|
||||||
|
"expiresAt": "2026-12-31T00:00:00Z",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0xad70cb9db980eb04d739c7687fec8d3a3675c35105b3d3837c2012c81cd9d521"
|
||||||
|
}
|
||||||
15
aips/aip23-kinds/block.json
Normal file
15
aips/aip23-kinds/block.json
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-block-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-block",
|
||||||
|
"stateTransitionProof": null,
|
||||||
|
"blockHash": "0xabababababababababababababababababababababababababababababababab",
|
||||||
|
"stateRoot": "0xcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd",
|
||||||
|
"anchorHeight": 20255488,
|
||||||
|
"certificateDigest": "0xefefefefefefefefefefefefefefefefefefefefefefefefefefefefefefefef",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0xa18b21e49b38ab96633111d562f95738042a0ea63906164b022c075a3c5971ad"
|
||||||
|
}
|
||||||
14
aips/aip23-kinds/compliance.json
Normal file
14
aips/aip23-kinds/compliance.json
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-compliance-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-compliance",
|
||||||
|
"evidenceHash": "0x20e95ada67c778758b26bd6425863f9a53bb666a98e3fe060eec15866e87cc12",
|
||||||
|
"subject": "org-x",
|
||||||
|
"policy": "pq-ready",
|
||||||
|
"result": "pass",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0xbac39cebdd87825b034b4b25d5e44478b62d9623db62e5110e88e523187c6e32"
|
||||||
|
}
|
||||||
12
aips/aip23-kinds/data.json
Normal file
12
aips/aip23-kinds/data.json
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-data-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-data",
|
||||||
|
"sha256": "0x205830ca5b23bbe39ab510cfddc1dff2d9842e38b5fa7b7c48cd4ca7e44f92a1",
|
||||||
|
"name": "report.csv",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x2acbef682084c42c3f8a7bc9fa4370257ff83994ffa92c36e44c556b44d5c8b2"
|
||||||
|
}
|
||||||
14
aips/aip23-kinds/device.json
Normal file
14
aips/aip23-kinds/device.json
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-device-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-device",
|
||||||
|
"attestationHash": "0xaa70e763e0eceecb3f1033c9cc44e05681d741afc05d0479269fe859d523021d",
|
||||||
|
"publicKeyHash": "0xfcab7fcc2b4cffd9bb45003bfc2e468a04ef6f77ca8200a7341f027631584d25",
|
||||||
|
"deviceId": "dev-9",
|
||||||
|
"posture": "secure-boot",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x440956f2ba441931fd5dcfbf808c3a646187bd01c144052d52a3b127dc71659c"
|
||||||
|
}
|
||||||
15
aips/aip23-kinds/execution.json
Normal file
15
aips/aip23-kinds/execution.json
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-execution-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-execution",
|
||||||
|
"inputHash": "0x582967534d0f909d196b97f9e6921342777aea87b46fa52df165389db1fb8ccf",
|
||||||
|
"outputHash": "0x762069bc07a6e1b5df123a5ae7bd91c10daa04694fbaa17fba0cd6a8dcce8f22",
|
||||||
|
"programSha256": null,
|
||||||
|
"program": "aere-node",
|
||||||
|
"exitCode": 0,
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x06a106c24b5fd8cfc7ed0cee3dc6401c720c394566ad3d7ca899f9640414fc8e"
|
||||||
|
}
|
||||||
14
aips/aip23-kinds/identity.json
Normal file
14
aips/aip23-kinds/identity.json
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-identity-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-identity",
|
||||||
|
"publicKeyHash": "0xfcab7fcc2b4cffd9bb45003bfc2e468a04ef6f77ca8200a7341f027631584d25",
|
||||||
|
"subjectHash": null,
|
||||||
|
"method": "ml-dsa-65",
|
||||||
|
"subjectId": "agent-1",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x9c609bdaa3f6e7c0b926c2071a18026a6073e92c4344ea537f3ffabcd3a921b9"
|
||||||
|
}
|
||||||
13
aips/aip23-kinds/location.json
Normal file
13
aips/aip23-kinds/location.json
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-location-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-location",
|
||||||
|
"evidenceHash": "0x20e95ada67c778758b26bd6425863f9a53bb666a98e3fe060eec15866e87cc12",
|
||||||
|
"subject": "srv-eu",
|
||||||
|
"region": "eu-central",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x88d2213cf649be8237cc64cff901e2ad8051473d4aab76ca02a7206dee83ad6c"
|
||||||
|
}
|
||||||
13
aips/aip23-kinds/ownership.json
Normal file
13
aips/aip23-kinds/ownership.json
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-ownership-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-ownership",
|
||||||
|
"assetHash": "0x68eef920516b0af8f874dccb72bcffc6f25cdfad43fcb78417fc1feb6efcd698",
|
||||||
|
"owner": "0xowner",
|
||||||
|
"assetId": "nft-7",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0xd41b5b8eb450e3af02fd575a695258f66469c6e36e628cad9aebd724a38248bd"
|
||||||
|
}
|
||||||
15
aips/aip23-kinds/payment.json
Normal file
15
aips/aip23-kinds/payment.json
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-payment-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-payment",
|
||||||
|
"txHash": "0x536939ed0e78c5b5d2ee7e26767bbad66290547f9fa1fc6602a1aa95cc61b959",
|
||||||
|
"from": "0xa",
|
||||||
|
"to": "0xb",
|
||||||
|
"amount": "100",
|
||||||
|
"asset": "AERE",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x0e937d67740e2314dfa003848dc46600bf6086d3449097f5eb222665c75a4e32"
|
||||||
|
}
|
||||||
17
aips/aip23-kinds/provenance.json
Normal file
17
aips/aip23-kinds/provenance.json
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-provenance-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-provenance",
|
||||||
|
"subjectHash": "0x7fbd7ef36fdd97293aa5b3bcd597146101d3ea9a12b271ed0c88bdca25b63d12",
|
||||||
|
"processHash": "0x3053677e4333a96b20ed76c662bca07fb2e1ce059479170139209356787da09c",
|
||||||
|
"parents": [
|
||||||
|
"0x7624c3381360e030f4172f54c925584354cf3595e793f59311c7ac33a582984f",
|
||||||
|
"0xce1d96bce7b6086cd30375a4523daab06e55630c8405d304eaa5a96d0c6d0545"
|
||||||
|
],
|
||||||
|
"actor": "build-bot",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x87b2a679d9e8af836c911f87ca8050c9c826c30b011da63ed87cf82146c048c3"
|
||||||
|
}
|
||||||
14
aips/aip23-kinds/runtime.json
Normal file
14
aips/aip23-kinds/runtime.json
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-runtime-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-runtime",
|
||||||
|
"artifactSha256": "0xc73f954a0dcd410afe8d2117ec8a4bef49cf677c60045a5f21acfa2a756ff7d5",
|
||||||
|
"attestedSha256": "0xc73f954a0dcd410afe8d2117ec8a4bef49cf677c60045a5f21acfa2a756ff7d5",
|
||||||
|
"host": "h1",
|
||||||
|
"matches": true,
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0xdcbb527e5475efc0d5ecf518cd19d4ceb3546324d3f59310ffa9f787bbf96c63"
|
||||||
|
}
|
||||||
18
aips/aip23-kinds/settlement.json
Normal file
18
aips/aip23-kinds/settlement.json
Normal file
@ -0,0 +1,18 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-settlement-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-settlement",
|
||||||
|
"instructionHash": "0xd5ee7e3afb8ac427fe87d3f7acd285363550bff09ff9f617ecc303488b21be61",
|
||||||
|
"txHash": "0x1212121212121212121212121212121212121212121212121212121212121212",
|
||||||
|
"blockHash": "0x3434343434343434343434343434343434343434343434343434343434343434",
|
||||||
|
"chainId": 2800,
|
||||||
|
"from": "0xa",
|
||||||
|
"to": "0xb",
|
||||||
|
"amount": "100",
|
||||||
|
"asset": "AERE",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0x19d9b1141c923ed4faf8304daffd5639e813c3b70248ffefc5b8a5e6373d26cf"
|
||||||
|
}
|
||||||
13
aips/aip23-kinds/time.json
Normal file
13
aips/aip23-kinds/time.json
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-time-attestation",
|
||||||
|
"statement": {
|
||||||
|
"v": 1,
|
||||||
|
"kind": "aere-proof-of-time",
|
||||||
|
"subjectHash": "0xe12e3d24bc08d052711daa489e746297af597599f2726d945c1d6309427b9394",
|
||||||
|
"source": "aere-anchor",
|
||||||
|
"at": "2026-09-26T00:00:00Z",
|
||||||
|
"createdAt": "2026-09-26T00:00:00Z"
|
||||||
|
},
|
||||||
|
"statementHash": "0xbd803c1eae1875ac755df34e94e9cb20e30c12fe3c02b0c7c4cfe677040ecd31"
|
||||||
|
}
|
||||||
Loading…
Reference in New Issue
Block a user