Invariants / DC-CRYPTO-05
DC-CRYPTO-05
DC derived enforcedKES evolution discipline: evolve(k_i) -> k_{i+1} is one-way. The evolved key signs period i+1 and MUST NOT sign for period i. RED kes_sign is forbidden when the requested period > current_period + evolutions_remaining; kes_evolve is forbidden when to < from or to > from + evolutions_remaining. Forward secrecy is a RED-shell discipline; BLUE has no recovery path if RED violates it. After PHASE4-N-P S5 the underlying algorithm (ade_crypto::kes_sum::Sum6Kes::update_kes) is BLUE-owned; per-field zeroize on Drop of consumed sub-seeds is implemented via ZeroizingSeed (DC-CRYPTO-08).
- Source
docs/planning/phase4-n-c-invariants.md §1 (NC-KES-2); docs/planning/phase4-n-p-invariants.md §1 (I6); Cardano Sum6KES specification
- Introduced in
- PHASE4-N-C
Enforcement trace
Tests 4
- kes_update_chain_matches_reference
- kes_sign_rejects_period_past_evolutions_remaining
- kes_update_rejects_backwards_evolution
- zeroizing_seed_drop_overwrites_bytes