Invariants / DC-CRYPTO-08

DC-CRYPTO-08

DC derived enforced

Ade-owned Sum6KES algorithm is Haskell-equivalent. ade_crypto::kes_sum::Sum6Kes is byte-identical to Haskell cardano-base's Sum6KES Ed25519DSIGN: derive_verification_key, gen_key_kes_from_seed_bytes, update_kes (chain across all 64 periods), and sign_kes produce the same bytes as the Haskell reference for every (seed, period, msg) triple. Cross-impl validation against the cardano-cli ground-truth corpus is mechanically enforced under #[cfg(test)] only (3 throwaway 608-byte SKEY + VKEY pairs captured from cardano-cli 11.0.0.0; deserializing the SKEY through our impl produces the captured VK byte-for-byte). Note: cardano-crypto Rust 1.0.8 uses different expand_seed prefix bytes (0x00/0x01 vs Haskell's 0x01/0x02) — Ade matches Haskell, NOT cardano-crypto Rust; this divergence is asserted explicitly in sum6_kes_seed_expansion_diverges_from_cardano_crypto_rust_1_0_8. After PHASE4-N-P S5, KesSecret.inner is the Ade-owned signing key; cardano-crypto is a #[cfg(test)] oracle only. No compatibility shim may construct an upstream SumSigningKey through unsafe layout assumptions, transmute, vendored pub(crate) access, or fork-only constructors (N9), enforced by ci/ci_check_kes_sum_compatibility.sh Guard 3.

Source

docs/clusters/PHASE4-N-P/cluster.md; docs/planning/phase4-n-p-invariants.md §1 (I1, I2, I4, I6); §2 (N1, N9); docs/clusters/PHASE4-N-P/S4.md (cardano-cli ground-truth + prefix-divergence discovery)

Introduced in
PHASE4-N-P

Enforcement trace

Tests 18

  • sum0_kes_signs_and_verifies_at_period_0
  • sum0_kes_rejects_period_1
  • sum0_kes_update_expires_after_period_0
  • sum0_kes_verify_rejects_wrong_message
  • sum1_kes_signs_at_period_0_and_period_1
  • sum6_kes_total_periods_is_64
  • sum6_kes_sizes_match_recurrence
  • sum6_kes_chain_advances_through_all_64_periods
  • sum6_kes_update_after_period_63_expires
  • sum6_kes_sign_rejects_period_64
  • sum6_kes_verify_rejects_wrong_period_signature
  • sum6_kes_seed_expansion_diverges_from_cardano_crypto_rust_1_0_8
  • sum6_kes_vk_diverges_from_cardano_crypto_rust_for_same_seed
  • cardano_cli_corpus_skey_deserializes_and_vk_matches_ground_truth
  • cardano_cli_corpus_sign_then_upstream_verifies
  • sum0_signing_key_debug_is_redacted
  • sum_signing_key_debug_is_redacted
  • zeroizing_seed_drop_overwrites_bytes

Cross-references