Spec v0.11 draft, work in progress (not approved)

Delivery 2 of capsule format 3, with the decisions the author took on
1 October 2026 after the review of Fable and Astra:

- A fixed area of 32 KiB for every capsule of a v0.11 writer, signed or
  not, and 64 KiB only when the person enlarges it expressly (29.2).
- What is signed (29.8): AUTHOR_MESSAGE of 66 bytes over control_commit
  of CONTROL_SIG, without I_PAYLOAD and with payload_length at zero,
  head_digest and signers_digest. The size of the area never changes
  what is signed, so the area can grow after signing.
- alg 1, strict Ed25519 with dkauthor1 keys (29.9, 29.12), and alg 2, a
  detached CMS signature with one or more X.509 signers, the list of
  required signers in key 1 and a CAdES-T timestamp per signer (29.10).
- seal_type 2, an RFC 3161 seal over SEAL_SUBJECT for capsules without a
  certificate signature (29.11), and the verdicts F2 to F6 and S3 to S5.
- The key of words (38.1), the public note datekeys.note (24.1) and the
  capsule extension datekeys.capsule of the .dkk, with the note, the date
  and a locator encrypted for the date (44.1).
- Writer rules 19 to 24, privacy, threat model 7.9, mutation tests,
  compatibility with v0.10 readers, the extension registry, provisional
  items (the 32 KiB to be measured) and the change log in 76.

The CDDL adds the schemas of alg 1, alg 2, seal_type 2 and the two
extensions. The reference still implements v0.10.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
v0.11
dev 6 days ago
parent 5b3d2d4f34
commit e224119f8f

File diff suppressed because it is too large Load Diff

@ -29,6 +29,12 @@
hashes and dates, encrypted, and reserves the `security` area for an author
signature and a timestamp seal that later versions will define without
changing the format. Its §76 records each change with its reproducible case.
- `DateKeys_Protocol_Specification_v0.11.md`: the draft v0.11, work in
progress and not approved. It defines the author signature of format 3,
with an Ed25519 key of one's own or with X.509 certificates (CMS, one or
several signers, a CAdES-T timestamp each), the RFC 3161 seal, a fixed
area of 32 KiB, the key of words, the public note and the capsule
extension of the .dkk. Its §76 records each change with its case.
- `datekeys.cddl`: the CBOR schemas of the v0.10 draft, the three control
versions and the security and head objects of format 3 included, with the
encoding rules CDDL cannot express. Those of v0.9 and v0.8.2 are at the tags

@ -1,7 +1,7 @@
; DateKeys Protocol Specification v0.10 (working draft) - CBOR schemas (RFC
; DateKeys Protocol Specification v0.11 (working draft) - CBOR schemas (RFC
; 8610 CDDL).
;
; Normative companion of spec/DateKeys_Protocol_Specification_v0.10.md. The
; Normative companion of spec/DateKeys_Protocol_Specification_v0.11.md. The
; reference implementation g.activething.com/go/DateKeys still implements
; v0.9, whose schemas are in tag spec-v0.9. These schemas include the three
; control versions: 1, of capsule format 1 (v0.8.2), 2, of format 2 (v0.9),
@ -154,9 +154,11 @@ max-payload-length = 8936830510563328
; Version 1 in every later version of the spec that keeps format 3. Keys 2
; and 3 hold separately encoded CBOR, author-signature and seal, with the
; CBOR profile; a failure of their content only changes its own verdict.
; This version defines no alg and no seal_type: alg 1 (Ed25519) and
; seal_type 1 (DateKeys), 2 (RFC 3161) and 3 (OpenTimestamps) are reserved,
; and a writer of this version writes security empty (22 bytes).
; v0.11 defines alg 1 (Ed25519, spec section 29.9), alg 2 (CMS with X.509
; certificates, 29.10) and seal_type 2 (RFC 3161, 29.11); seal_type 1
; (DateKeys) and 3 (OpenTimestamps) stay reserved. A writer writes security
; empty (22 bytes) in a capsule without signature or seal, and never key 3
; with alg 2.
security = {
0 => "datekeys-security",
1 => 1,
@ -173,6 +175,45 @@ seal = {
1 => bstr, ; token
}
; The author-signature of each alg this version defines (spec sections 29.9
; and 29.10). A reader that does not implement an alg checks only the
; generic author-signature above.
author-signature-ed25519 = {
0 => 1,
1 => bstr .size 32, ; public key A
2 => bstr .size 64, ; signature R || S
}
author-signature-cms = {
0 => 2,
1 => bstr .cbor signers, ; required signers, encoded on its own
2 => bstr, ; ContentInfo of type SignedData, DER, detached
}
; SHA-256 of the DER certificate of each required signer, in strictly
; ascending byte order, without repetitions.
signers = [1*16 bstr .size 32]
seal-rfc3161 = {
0 => 2,
1 => bstr, ; TimeStampToken, DER
}
; Spec section 24.1. data of extension datekeys.note, version 1, in the
; noncritical array of PUBLIC_HEADER: UTF-8 text with the rules of section
; 29.6, not CBOR.
note-data = bstr .size (1..1024)
; Spec section 44.1. data of extension datekeys.capsule, version 1, in the
; noncritical array of a .dkk.
capsule-data = {
? 0 => tstr .size (1..1024), ; note, a copy of the public note
1 => tstr, ; compact_datekey, canonical dk1_
? 2 => bstr, ; locator: an age file with one tlock stanza
}
; Plaintext of the locator, readable at the unlock date.
capsule-locator = {
0 => [1*16 tstr .size (1..2048)], ; addresses (URI)
1 => bstr .size 32, ; capsule_digest
}
; Spec section 29.4. HEAD_CBOR of format 3, at most 16 MiB. Always version 1
; in format 3: a new version needs a new format (spec section 22). These
; limits are normative and fixed with the format.

Loading…
Cancel
Save

Powered by TurnKey Linux.