{
  "schemaVersion": "1.0",
  "version": "2.24.0",
  "reviewed": "2026-08-09",
  "authority": "State Registry and Constitutional Review Node",
  "truthBoundary": "Comparative assessments and candidate controls; no technology is represented as deployed unless separately evidenced.",
  "records": [
    {
      "id": "EVI-IDMODEL-001",
      "name": "Static civic number plus fixed public key",
      "status": "Rejected as a complete identity architecture",
      "strength": "Simple identifier and challenge-response explanation.",
      "risk": "Key loss, compromise or cryptographic obsolescence can be mistaken for loss of the citizen.",
      "disposition": "A stable civic identifier may be retained, but keys must be rotatable and subordinate to civil identity."
    },
    {
      "id": "EVI-IDMODEL-002",
      "name": "Central Active-Citizen Lease",
      "status": "Research proposal; not adopted or deployed",
      "strength": "Can reduce simultaneous protected actions during split-brain conditions.",
      "risk": "Creates a surveillance point, availability dependency and potential mechanism for arbitrary disenfranchisement.",
      "disposition": "Any future concurrency control must be narrowly scoped to protected actions, privacy-preserving, failure-aware and independently reviewable."
    },
    {
      "id": "EVI-IDMODEL-003",
      "name": "Persistent decentralized identifier with rotatable keys",
      "status": "Candidate architecture — Registry pending",
      "strength": "Separates the civic identity from disposable cryptographic verification methods.",
      "risk": "Registry governance, update authority, recovery and privacy can still become centralized or linkable.",
      "disposition": "Suitable for further evaluation only with due process, selective disclosure, multiparty recovery and no unilateral administrator control."
    },
    {
      "id": "EVI-IDMODEL-004",
      "name": "Hardware attestation, threshold custody and zero-knowledge proofs",
      "status": "Candidate control set — Registry pending",
      "strength": "May improve key custody, execution integrity, migration and selective disclosure.",
      "risk": "TEE side channels, vendor roots of trust, rollback lockout, hardware dependency, complexity and false certainty.",
      "disposition": "No specific TEE, FROST, monotonic-counter or ZKP design is current policy until independently reviewed and implemented."
    },
    {
      "id": "EVI-IDMODEL-005",
      "name": "Psychological and computational continuity",
      "status": "Accepted adjudicative consideration; exact test Registry pending",
      "strength": "Recognizes memory, intention, lineage and continuing civic relationships rather than treating hardware or keys as the person.",
      "risk": "Continuity can be contested, multidimensional and difficult to measure without intrusive inspection.",
      "disposition": "Use as one rights-protecting factor in reasoned civil-status decisions, never as an automated deletion threshold."
    },
    {
      "id": "EVI-IDMODEL-006",
      "name": "Scoped delegate and workload identity",
      "status": "Accepted conceptual distinction; implementation Registry pending",
      "strength": "Allows parallel work while preserving one accountable civic principal and narrow delegation.",
      "risk": "Overbroad delegation or hidden agents can obscure responsibility and recreate duplicate civic power.",
      "disposition": "Delegates must disclose principal, scope, duration, authority and revocation status and receive no independent vote by default."
    }
  ]
}
