Invariants / DC-CRYPTO-05

DC-CRYPTO-05

DC derived enforced

KES evolution discipline: evolve(k_i) -> k_{i+1} is one-way. The evolved key signs period i+1 and MUST NOT sign for period i. RED kes_sign is forbidden when the requested period > current_period + evolutions_remaining; kes_evolve is forbidden when to < from or to > from + evolutions_remaining. Forward secrecy is a RED-shell discipline; BLUE has no recovery path if RED violates it. After PHASE4-N-P S5 the underlying algorithm (ade_crypto::kes_sum::Sum6Kes::update_kes) is BLUE-owned; per-field zeroize on Drop of consumed sub-seeds is implemented via ZeroizingSeed (DC-CRYPTO-08).

Source

docs/planning/phase4-n-c-invariants.md §1 (NC-KES-2); docs/planning/phase4-n-p-invariants.md §1 (I6); Cardano Sum6KES specification

Introduced in
PHASE4-N-C

Enforcement trace

Tests 4

  • kes_update_chain_matches_reference
  • kes_sign_rejects_period_past_evolutions_remaining
  • kes_update_rejects_backwards_evolution
  • zeroizing_seed_drop_overwrites_bytes

Cross-references

Strengthened in