Skip to content

interop: independently verify SCITT Measurement Capsule ids and Merkle roots - #195

Closed
hippoley wants to merge 4 commits into
mainfrom
interop/measurement-capsule-independent-verifier
Closed

hippoley wants to merge 4 commits into
mainfrom
interop/measurement-capsule-independent-verifier

Conversation

@hippoley

@hippoley hippoley commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Why

The current SCITT Measurement Capsule draft defines one explicit experimental success criterion:

an implementation written by another party from the text recomputes the identifiers and roots of a published batch.

This PR builds the verifier side of that experiment without importing the CSOAI prototype builder/verifier.

Change

  • add independent RFC 8785 canonicalization through Trail of Bits rfc8785;
  • recompute capsule_id = SHA-256(JCS(capsule without capsule_id));
  • require stored JSONL capsule lines to be the exact JCS bytes;
  • enforce the generic no-decision/no-authority member/value boundary from draft Section 7.1;
  • enforce digest-only sources;
  • preserve UNCHECKABLE as a first-class measurement state;
  • implement RFC 9162 Merkle Tree Hash over capsule-id bytes:
    • leaf = SHA-256(0x00 || capsule_id_bytes)
    • node = SHA-256(0x01 || left || right)
    • ids sorted ascending by bytes
    • duplicate ids rejected;
  • verify expected published batch root and count.

Independence boundary

This implementation is written from the public draft/RFC algorithms and does not call CSOAI's prototype code.

It does use the independent Trail of Bits RFC 8785 library for JCS rather than reimplementing canonicalization.

Current limitation

This PR does not yet claim the draft's Section 13 experiment outcome.

The draft and public index are retrievable in the current environment, but the raw published capsules.jsonl.gz / leaves.json batch bytes have not yet been retrieved here.

Until a real published batch is fed through this verifier and the advertised root matches, this remains an implementation prepared for the experiment, not evidence that the experiment has succeeded.

Non-claims

A matching batch root would establish byte-level binding only. It would not prove that the measurements are true, independent, unbiased, authorised, or endorsed by SCITT/IETF.

hippoley commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #197, a clean replay onto current main after this branch became non-mergeable as the repository moved. No semantic expansion is intended in the replay.

@hippoley hippoley closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant