Invariants / DC-CRYPTO-04
DC-CRYPTO-04
DC derived enforcedKES signing transcript equivalence and verification symmetry. For canonical inputs (kes_secret, period, msg) the RED signer produces a KesSignature byte-identical to Haskell cardano-base's Sum6KES reference and verifying under ade_crypto::kes::verify_kes. After PHASE4-N-P S5 the algorithm is BLUE-owned (ade_crypto::kes_sum::Sum6Kes); cross-impl agreement with the Haskell reference is mechanically validated against a cardano-cli ground-truth corpus (DC-CRYPTO-08). Private-key execution is RED-shell confined; BLUE consumes the KesSignature as a captured signed artifact.
- Source
docs/planning/phase4-n-c-invariants.md §1 (NC-KES-1); docs/planning/phase4-n-p-invariants.md; Cardano Sum6KES specification (depth-6 sum composition over ed25519)
- Introduced in
- PHASE4-N-C
Enforcement trace
Code
Tests 5
- kes_sign_matches_reference_vectors
- kes_sign_then_verify_round_trip
- kes_signature_from_bytes_round_trips
- verify_kes_signature_agrees_with_existing_verify_kes
- cardano_cli_corpus_sign_then_upstream_verifies