I-D Action: draft-wilder-scitt-physical-site-engage-receipt-00.txt
[email protected] Wed, 29 Jul 2026 16:53:10 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178536919057.1371316.4336619759677861758@dt-datatracker-d4d6ff9d9-ql5mb> |
Internet-Draft draft-wilder-scitt-physical-site-engage-receipt-00.txt is now available. Title: A SCITT Profile for Physical-Site Engagement Receipts Author: Rob Wilder Name: draft-wilder-scitt-physical-site-engage-receipt-00.txt Pages: 19 Dates: 2026-07-29 Abstract: This document defines a SCITT profile for _Physical-Site Engagement Receipts_ (PSER): tamper-evident, signed, offline-verifiable records that describe an autonomous or human-directed physical engagement at a specific real-world site governed by a defined operating envelope. Each receipt is a SCITT Signed Statement as defined by the SCITT architecture, encoded as a COSE Single Signer message, carrying a JCS-canonicalized JSON payload with a five-artifact vocabulary describing (1) the _Site_, (2) the _Operator_ and _Actor_, (3) the _Engagement Window_ and _Envelope_, (4) the _Attestation Evidence_ from a Trusted Execution Environment (TEE), and (5) the _Adapter Write-In_ recording that the receipt was posted into an out-of-band operations layer. A Physical-Site Engagement Receipt is registerable in any conforming SCITT Transparency Service to obtain non- equivocation and tail-truncation properties an issuer's own chain cannot provide alone. This profile deliberately makes a NARROW, checkable claim -- "this is a tamper-evident, signature-verifiable record that a specific engagement occurred at a specific site under a specific envelope, and its evidence was sealed by a specific TEE" -- and explicitly does NOT claim that the engagement was safe, correct, or wise, that the site conditions were as described, or that any downstream operational outcome followed. Compliance verdicts derived from the receipt (SLA credit, insurance underwriting, regulatory audit) are the responsibility of the relying party and its policies, not of this profile. The profile is designed around a three-party trust model in which no single party can unilaterally forge or repudiate a receipt: the _site owner_ physically hosts and controls the TEE hardware (they own the box); the _TEE silicon vendor_ attests the key material inside the TEE through its hardware root of trust (silicon vouches for the key); and the _Issuer_ writes the vocabulary, registers Signed Statements with a Transparency Service, and posts the resulting receipt into the site's operations layer via a WRITE_ONLY adapter. This separation is normative in this profile: implementations MUST NOT collapse these three roles into a single custodian, and relying parties MUST NOT trust a receipt that lacks any one of them. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-wilder-scitt-physical-site-engage-receipt/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-wilder-scitt-physical-site-engage-receipt-00 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]