Internet-Draft draft-wilder-scitt-physical-site-engage-receipt-01.txt is now
available.
Title: A SCITT Profile for Physical-Site Engagement Receipts
Author: Rob Wilder
Name: draft-wilder-scitt-physical-site-engage-receipt-01.txt
Pages: 26
Dates: 2026-08-15
Abstract:
This document defines a SCITT profile for _Physical-Site Engagement
Receipts_ (PSER): tamper-evident, signed, offline-verifiable records
that describe an autonomous or human-directed physical engagement at
a specific real-world site governed by a defined operating envelope.
Each receipt is a SCITT Signed Statement as defined by the SCITT
architecture, encoded as a COSE Single Signer message, carrying a
JCS-canonicalized JSON payload with a five-artifact vocabulary
describing (1) the _Site_, (2) the _Operator_ and _Actor_, (3) the
_Engagement Window_ and _Envelope_, (4) the _Attestation Evidence_
from a Trusted Execution Environment (TEE), and (5) the _Adapter
Write-In_ recording that the receipt was posted into an out-of-band
operations layer. A Physical-Site Engagement Receipt is registerable
in any conforming SCITT Transparency Service, obtaining a Receipt
that proves the Statement's inclusion in that Service's verifiable
data structure. Registration does not establish that the Issuer
registered every receipt it issued.
This profile deliberately makes a NARROW, checkable claim -- "this is
a tamper-evident, signature-verifiable record that a specific
engagement occurred at a specific site under a specific envelope, and
its evidence was sealed by a specific TEE" -- and explicitly does NOT
claim that the engagement was safe, correct, or wise, that the site
conditions were as described, or that any downstream operational
outcome followed. Compliance verdicts derived from the receipt (SLA
credit, insurance underwriting, regulatory audit) are the
responsibility of the relying party and its policies, not of this
profile.
The profile is designed around a three-party trust model in which no
single party can unilaterally forge or repudiate a receipt: the _site
owner_ physically hosts and controls the TEE hardware (they own the
box); the _TEE silicon vendor_ attests the key material inside the
TEE through its hardware root of trust (silicon vouches for the key);
and the _Issuer_ writes the vocabulary, registers Signed Statements
with a Transparency Service, and posts the resulting receipt into the
site's operations layer via a WRITE_ONLY adapter. This separation is
normative in this profile: implementations MUST NOT collapse these
three roles into a single custodian, and relying parties MUST NOT
trust a receipt that lacks any one of them.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-wilder-scitt-physical-site-engage-receipt/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-wilder-scitt-physical-site-engage-receipt-01
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-wilder-scitt-physical-site-engage-receipt-01
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.