Profile
- Container
- eviulon-detached-signature-set-1.0
- Mode
- DETACHED
- Canonicalization
- EVIULON-JCS-UTF8-SORTED-1.0
- Current profile algorithm
- Ed25519 local fixture profile
- Threshold policy
- {'state': 'PROPOSED_NOT_DEPLOYED', 'proposal': 'During an authorized rotation overlap, accept one valid signature from either the current or overlap anchor; future high-consequence profiles may require two-of-three after independent review.'}
Signed fields and algorithms
Signed field coverage
- The canonical bytes of the complete payload, including payloadSha256, origin, schema version, profile version, publication/expiry times, sequence, governance version, and connector state.
Algorithm identifiers
- Ed25519
- ML-DSA-65
- Ed25519+ML-DSA-65
Agility rules
- Algorithm identifiers are exact and case-sensitive.
- A verifier rejects an unlisted algorithm and never infers an algorithm from key length.
- Profile-version downgrade is rejected even when a cryptographic signature verifies.
- Algorithm migration requires an explicit overlap window, current trust-anchor record, and successor profile.
- Threshold or multi-signature policy remains a proposal until separately implemented and reviewed.
Verification states
- UNSIGNED
- SIGNATURE_UNVERIFIED
- SIGNATURE_INVALID
- ANCHOR_UNKNOWN
- ANCHOR_STALE
- VERIFIED
Defenses cover Exact origin and schema binding, Monotonic sequence and previous-digest chain outside signature verification, Payload self-digest verification, Exact algorithm allowlist, Exact anchor ID and fingerprint binding, Profile-version downgrade rejection, Retired and compromised anchor rejection, Canonicalization mismatch rejection, No cross-origin key substitution, Publication and expiry checks in the consuming validator.
Deterministic local vectors
| Fixture | Expected state | Reason |
|---|---|---|
| valid-current | VERIFIED | VALID_LOCAL_FIXTURE_SIGNATURE |
| valid-overlap-rotation | VERIFIED | VALID_LOCAL_FIXTURE_SIGNATURE |
| unknown-anchor | ANCHOR_UNKNOWN | ANCHOR_ID_NOT_REGISTERED |
| retired-anchor | ANCHOR_STALE | ANCHOR_RETIRED_OR_COMPROMISED |
| wrong-algorithm | SIGNATURE_INVALID | NO_VALID_ALLOWED_SIGNATURE |
| malformed-signature-container | SIGNATURE_INVALID | MALFORMED_SIGNATURE_CONTAINER |
| canonicalization-mismatch | SIGNATURE_INVALID | CANONICALIZATION_PROFILE_MISMATCH |
| wrong-origin | SIGNATURE_INVALID | WRONG_ORIGIN |
| replay | SIGNATURE_INVALID | REPLAY_OR_NON_MONOTONIC_SEQUENCE |
| downgrade-attempt | SIGNATURE_INVALID | PROFILE_DOWNGRADE_OR_UNSUPPORTED |
| unsigned | UNSIGNED | SIGNATURE_CONTAINER_ABSENT |
| payload-canonicalization-tamper | SIGNATURE_INVALID | PAYLOAD_DIGEST_MISMATCH |
Truth boundary
This profile and its public keys validate deterministic local fixtures only. A locally verified signature does not activate a connector, prove a remote deployment, create authority, establish legal effect, or evidence Patefacere adoption.
Connector effect: NONE — local fixture verification cannot activate the reciprocal connector.
Authority and record status
Responsible authority: National Engineering Directorate.
Local profile and fixture behavior only; no production cryptographic deployment.
Revision date: . Public corrections may be initiated through the diplomatic contact route.