Skip to content
Signatif

Glossary

The vocabulary of the framework

Every defined term from clause 2 of the standard, in alphabetical order. Alternative names allowed by the standard appear in parentheses; related terms are cross-linked as the standard's own definitions reference them.

A

aggregate key
public key that represents a trust authority, produced either from a single signing key or composed from multiple keys under a threshold scheme
→trust authority
authorization scope (scope)
multi-dimensional authorization boundary that defines the extent of a trust authority's signing power, carried as a signed field in every certificate and cryptographically enforced at every delegation link
→trust authority
authorization scope condition (scope condition)
executable predicate included in an authorization scope, evaluated at verification time against the content and context of a trusted artifact
→authorization scope·trusted artifact
authorization scope dimension (scope dimension)
one axis of an authorization scope, along which the scope is constrained independently of other dimensions
→authorization scope
authorization scope narrowing (scope narrowing)
act of constraining one or more authorization scope dimension when delegating from a parent trust authority to a child, such that the child's authorization scope is a subset of the parent's scope on every dimension
→authorization scope dimension·trust authority·authorization scope

C

canonical payload
deterministic byte-string representation of the artifact data that all co-signature attest
→co-signature
ceremony (signing ceremony)
protocol by which a quorum of key holders cooperates to produce a threshold signing signature, including the procedural, logistical, and cryptographic steps
→quorum·threshold signing
classification label (grade label)
scheme-defined label assigned to a trusted artifact by applying the classification policy to the coverage report, reflecting the artifact's dimensional coverage, authorization scope validity, transparency inclusion, and revocation status
→trusted artifact·dimensional coverage·authorization scope
co-signature
signature on the same canonical payload of a trusted artifact, produced by a signer from an independent trust dimension or an independent trust chain
→canonical payload·trusted artifact·trust dimension·trust chain
composite signature
single signature produced by the AND-composition of two or more signature algorithms over the same canonical payload
→canonical payload

D

delegated trust authority (DTA)
trust authority that has received signing authority through delegation from a parent trust authority and whose authorization scope is a subset of the parent's scope on every authorization scope dimension
→trust authority·authorization scope·authorization scope dimension
dimension attestation
co-signature tagged with a trust dimension type, attesting the canonical payload from the perspective of that dimension
→co-signature·trust dimension·canonical payload
dimension convergence
property of a trusted artifact on which multiple trust dimension have attested, each independently verifiable
→trusted artifact·trust dimension
dimensional coverage
set of verified trust dimension attested on a trusted artifact, recorded in the coverage report as input to the classification policy
→trust dimension·trusted artifact

E

end certificate
credential that authorizes a specific signing key to produce trusted artifact and that carries the narrowest authorization scope in its trust chain
→trusted artifact·authorization scope·trust chain

F

federated trust authority (FTA)
delegated trust authority whose members are independent organizations that cooperate under a threshold scheme to produce a single aggregate key
→delegated trust authority·aggregate key

G

gossip
protocol by which independent mirror and verifiers cross-check their views of a transparency log by comparing fingerprints of log state
→mirror·transparency log

I

inclusion proof
cryptographic proof (typically a Merkle audit path) that a trusted artifact or its end certificate is included in a transparency log === Transparency
→trusted artifact·end certificate·transparency log

M

mirror (log mirror)
independent operator that replicates a transparency log and serves inclusion proofs and log entries to verifiers
→transparency log
monotonic narrowing invariant
property of a delegation chain whereby the child authorization scope is a subset of (or equal to) the parent scope on every authorization scope dimension at every delegation link
→authorization scope·authorization scope dimension
multi-log attestation
attestation model in which a trusted artifact or end certificate is included in at least M of K independent transparency log, where M and K are specified by the issuing authority's policy === Machine-readable projection
→trusted artifact·end certificate·transparency log

P

passport
machine-readable public projection of an end certificate or trusted artifact, optimized for compact storage and rapid presentation (for example, via a two-dimensional barcode)
→end certificate·trusted artifact

Q

quorum
pair of parameters (T, N) specifying the number of members of a threshold group that are needed to produce a valid threshold signing signature === Trust chains and graphs
→threshold signing

R

root trust authority (RTA)
trust authority that serves as the root of a delegation hierarchy and defines the initial authorization scope under which all subordinate authorities operate
→trust authority·authorization scope

S

scheme
organization that instantiates this framework for a domain by maintaining its registries, defining scope dimensions and classification policies, and publishing a deployment manifest

T

threshold signing
cryptographic protocol in which at least T of N designated key holders cooperate to produce a single aggregate signature under the group's aggregate key, without any individual holder possessing the full signing capability
→aggregate key
time key
signing key representing a time authority, used to produce a dimension attestation of type time === Verification
→dimension attestation
transparency log
append-only, cryptographically verifiable log (typically a Merkle tree) that records all issued end certificate and trusted artifact for public audit
→end certificate·trusted artifact
trust anchor (root anchor)
public key of a root trust authority that a verifier accepts as the starting point for verification paths in the trust graph
→root trust authority·trust graph
trust anchor bundle
self-contained set of trust anchor (root aggregate key or their fingerprints) sufficient for offline verification of any trusted artifact within the bundle's recognized scope
→trust anchor·aggregate key·trusted artifact
trust authority
entity that holds signing authority within a trust graph under an authorization scope, and is represented by an aggregate key
→trust graph·authorization scope·aggregate key
trust chain
ordered sequence of delegations from a root trust authority through one or more delegated trust authority to an end certificate
→root trust authority·delegated trust authority·end certificate
trust dimension
independently verifiable aspect of reality attested by a co-signature on a trusted artifact
→co-signature·trusted artifact
trust graph (trust DAG)
directed acyclic graph of all trust authority and their delegation relationships, generalizing the linear trust chain to admit multiple paths, cross-hierarchy edges, and federated trust authority
→trust authority·trust chain·federated trust authority
trust infrastructure
shared set of trust anchors, transparency logs, and registries that multiple applications rely on when verifying artifacts
trust repudiation (repudiation)
formal revocation of previously-granted trust, executed by authorized parties through threshold-gated revocation mechanisms, in response to key compromise, scope violation, or fraud
trusted artifact
signed data object produced under the authorization of an end certificate, carrying one or more co-signature from one or more trust dimension
→end certificate·co-signature·trust dimension

V

verification pipeline
ordered sequence of checks applied to a trusted artifact, including signature validation, trust chain or trust graph path-finding, authorization scope enforcement, transparency log inclusion proof, revocation status, coverage report production, and classification policy application
→trusted artifact·trust chain·trust graph·authorization scope·transparency log

Source: clause 2 of the Signatif standard —CalConnect/cc-signatif