Skip to content

Threat model

Assets: issuer/holder secret keys and passwords, status allocations and revocation state, replay history, scope-specific trust policies, hidden credential values, and the distinction between authentic claims and trusted/corroborated claims.

Trust boundaries: untrusted input JSON, HTTPS endpoints, downloaded DID documents, local explicitly pinned contexts/schemas, private owner-controlled storage, and external policy/LLM consumers. TLS/DNS and local administrator configuration are trust assumptions, not issuer authority by themselves.

Threat Control and validation Residual boundary
Key theft/substitution AEAD key envelope, KDF, permissions, suite/controller/fingerprint checks Same UID/OS compromise; no HSM
Forged or altered VC Real Ed25519/P-256 suite operations, official vectors, independent JS interoperability Cryptographic adapter needs independent review
Wrapping/algorithm confusion Single proof object, exact type/suite dispatch, authorized relationship Only documented narrow profiles accepted
JSON-LD data loss Pinned contexts, strict expansion, duplicate/null rejection RDF-equivalent JSON ordering is intentionally not byte-bound
Unsafe schema/context retrieval Local content pins, no remote context loading or external schema refs Administrator-selected custom schemas/contexts are trusted configuration
False claim authority Scoped pins and explicit policies; authenticity separate from truth Policies and organizational source independence can be wrong
Fake corroboration Signed active evidence, explicit equality rules, independent groups No general scientific or semantic truth engine
Status outage/revocation rollback Signed lists, permanent registry revocation, freshness/pins, no active-on-error Valid caches impose bounded revocation latency; protect registry backups
Replay/audience substitution Holder auth, exact nonce/domain, <=5-minute proof, SQLite uniqueness Verifier must issue random challenges and preserve durable store
SSRF/rebinding/decompression Address checks, DNS-pinned connections, no proxy/redirect/compression, size/time bounds Service deployments should also enforce network egress policy
File overwrite/symlink Descriptor-relative paths, NOFOLLOW, atomic rename, explicit force Same-UID races and multi-file crash consistency are limited
Hidden-value leakage Genuine statement derivation, negative canary tests, redacted errors IDs/status/timing correlate; original credentials remain sensitive
Metadata staleness/conflict Expected fingerprint, signed linkage, digests, schemas, cross-document checks Static deployment must publish consistent generations
Prompt injection No evaluation of credential text, optional explicit quarantine Heuristic is not complete; agents need their own data/instruction boundary

Canonicalization rejects resource-exhausting graphs instead of falling back to a different algorithm. Inputs/HTTP responses are limited to 4 MiB; decoded status lists to 16 MiB; expanded graphs to 50,000 quads. DNS/connect/HTTP timeouts are 5/5/15 seconds. No heuristic signature acceptance or simulated disclosure exists.

Adversarial tests include duplicate properties, invalid purposes/keys/schemas, modified claims, unknown contexts, unavailable status, all status transitions, replay and audience mismatch, missing/contradictory evidence, instruction quarantine, public key rotation, malformed metadata, redirects, private addresses, HTTP compression, oversized responses and private-material rejection. Exact results and uncompleted gates, if any, are recorded in STATUS.md.