I-D Action: draft-wilder-scitt-physical-site-engage-receipt-00.txt

[email protected] Wed, 29 Jul 2026 16:53:10 -0700
Newsgroups gmane.ietf.announce
Message-ID <178536919057.1371316.4336619759677861758@dt-datatracker-d4d6ff9d9-ql5mb>
Internet-Draft draft-wilder-scitt-physical-site-engage-receipt-00.txt is now
available.

   Title:   A SCITT Profile for Physical-Site Engagement Receipts
   Author:  Rob Wilder
   Name:    draft-wilder-scitt-physical-site-engage-receipt-00.txt
   Pages:   19
   Dates:   2026-07-29

Abstract:

   This document defines a SCITT profile for _Physical-Site Engagement
   Receipts_ (PSER): tamper-evident, signed, offline-verifiable records
   that describe an autonomous or human-directed physical engagement at
   a specific real-world site governed by a defined operating envelope.
   Each receipt is a SCITT Signed Statement as defined by the SCITT
   architecture, encoded as a COSE Single Signer message, carrying a
   JCS-canonicalized JSON payload with a five-artifact vocabulary
   describing (1) the _Site_, (2) the _Operator_ and _Actor_, (3) the
   _Engagement Window_ and _Envelope_, (4) the _Attestation Evidence_
   from a Trusted Execution Environment (TEE), and (5) the _Adapter
   Write-In_ recording that the receipt was posted into an out-of-band
   operations layer.  A Physical-Site Engagement Receipt is registerable
   in any conforming SCITT Transparency Service to obtain non-
   equivocation and tail-truncation properties an issuer's own chain
   cannot provide alone.

   This profile deliberately makes a NARROW, checkable claim -- "this is
   a tamper-evident, signature-verifiable record that a specific
   engagement occurred at a specific site under a specific envelope, and
   its evidence was sealed by a specific TEE" -- and explicitly does NOT
   claim that the engagement was safe, correct, or wise, that the site
   conditions were as described, or that any downstream operational
   outcome followed.  Compliance verdicts derived from the receipt (SLA
   credit, insurance underwriting, regulatory audit) are the
   responsibility of the relying party and its policies, not of this
   profile.

   The profile is designed around a three-party trust model in which no
   single party can unilaterally forge or repudiate a receipt: the _site
   owner_ physically hosts and controls the TEE hardware (they own the
   box); the _TEE silicon vendor_ attests the key material inside the
   TEE through its hardware root of trust (silicon vouches for the key);
   and the _Issuer_ writes the vocabulary, registers Signed Statements
   with a Transparency Service, and posts the resulting receipt into the
   site's operations layer via a WRITE_ONLY adapter.  This separation is
   normative in this profile: implementations MUST NOT collapse these
   three roles into a single custodian, and relying parties MUST NOT
   trust a receipt that lacks any one of them.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-wilder-scitt-physical-site-engage-receipt/

There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-wilder-scitt-physical-site-engage-receipt-00

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]