Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

221 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Auths

Auths is an open protocol and SDK for proof-carrying, bounded machine authority. The auths-proof component is its strictly offline reference kernel for Auths Proof Protocol V1.

Auths owns authority. Adapters establish bounded facts.

The workspace contains only the target V1 model, deterministic codec, effect-free ports and registries, mandatory Ed25519 and P-256/SHA-256 suites, authority attenuation, authorization-plan composition, assurance, status, staged verification, keyless authoring, raw-key, did:key, did:keri, bundled did:web, SPIFFE/X.509, WebAuthn, and HSM-attested methods, and the canonical language-neutral corpus.

The sealed verification pipeline is:

untrusted bytes
  -> DecodedProof
  -> ResolvedProof
  -> ControlVerifiedProof
  -> VerifiedAuthority
  -> VerifiedAction

The language-neutral boundary is verify_v1(proof_cbor, canonical_action_cbor, trusted_context_cbor) -> verification_result_cbor. The result includes stable stage/code values, self-binding digests, authorized branches, assurance satisfactions, and resource/work totals. The trusted context also binds the verifier-required composition obligation and the exact executable adapter/registry configuration commitment.

VerifiedAction has no public constructor. The kernel reads no clock, environment variable, network connection, filesystem, database, replay store, budget store, profile implementation, receipt sink, or private key. Every trust anchor, accepted executable registry and manifest, evaluation time, expected audience/challenge, status snapshot and issuer/floor trust, assurance policy, resource matcher, profile/channel policy, detached attachment input, and resource limit is an explicit immutable verifier input.

Target packages:

  • auths: supported consumer-facing Rust core facade;
  • auths-sdk: idiomatic embedded authorization SDK;
  • auths-proof: bounded proof-protocol component and actionable results;
  • auths-proof-wasm: prebuildable three-input WebAssembly boundary;
  • auths-model: validated V1 protocol and context types;
  • auths-codec: constrained deterministic CBOR and domain-separated IDs;
  • auths-ports: effect-free principal-method and signature-suite ports;
  • auths-registries: exact immutable implementations, status handlers, and verifier-configuration commitments;
  • auths-signature: mandatory Ed25519 and low-S P-256 suites;
  • auths-authority: scoped trust roots and grant attenuation;
  • auths-composition: proof, all-of, any-of, and K-of-N plans;
  • auths-assurance: role-indexed evidence assurance;
  • auths-verifier: the sealed pure pipeline;
  • auths-author: external-signing requests with no custody;
  • auths-multikey: the closed canonical Ed25519/P-256 Multikey subset;
  • auths-raw-key: self-certifying raw-key evidence;
  • auths-did-key: self-certifying did:key evidence;
  • auths-did-keri: bounded offline KEL replay with threshold and rotation commitment verification;
  • auths-did-web: locally pinned, bundled did:web evidence with distinct current, historical, and statement-existence claims;
  • auths-webauthn: challenge-bound WebAuthn assertions with RP, origin, presence, verification, counter, and attestation-policy checks;
  • auths-hsm-attested: verifier-pinned attestation profiles with protection, exportability, device-chain, key-handle, and transaction binding;
  • auths-spiffe-x509: bounded X.509-SVID path, URI SAN, client-EKU, trust-domain, key-suite, validity, and local status verification;
  • auths-testkit: canonical positive and negative corpus construction.

Focused validation:

cargo xtask arch
cargo xtask wire
cargo xtask conformance
cargo xtask fuzz-smoke
cargo run -p auths-proof-offline-example

Canonical .cbor files are generated only through:

cargo xtask wire --update

Networking and transports belong to the auths-proof-exchange components. Profiles, live resolvers, runtime state, receipts, execution, custody, independent implementations, and Auths Lab remain outside the offline proof kernel in the workspace's product and demo layers.

This repository is prelaunch and pre-audit. Passing corpus, fuzz-smoke, and WASM equivalence gates is not an independent security review.

About

Proof-carrying authorization for cryptographic principals

Resources

Contributing

Security policy

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages