VHCEL specification

Short Implementation Guide

Prototype checklist for the current draft. The cryptographic binding is still open; this guide does not define an interoperable wire format.

  1. Choose a binding and profile. Specify serialization, protected fields, canonicalization, digest encoding, SCID derivation, proof coverage, authorization, and state-transition rules. Define any pre-rotation and witness requirements.
  2. Create genesis. Establish initial state and control policy. Derive and insert the mandatory scid, handling self-references according to the binding. Add required proofs. Genesis has no previousEvent.
  3. Append an event. Set previousEvent to the calculated digest of the completed preceding event. Add the operation and proofs required by prior authorization and the profile. A stored eventId is unnecessary.
  4. Verify before accepting state. Recompute the genesis SCID; compare it with the supplied value and any trusted expected SCID. Check every predecessor link, authorization proof, required external datum, rotation constraint, witness policy, and state transition. Reject updates after permanent deactivation. Commit state only after all checks pass.
  5. Report and test. Return the SCID, verified state, final event digest, and verification scope. Test valid histories plus altered genesis, broken links, unauthorized updates, and missing required data.

Trust boundary: An independently trusted expected SCID detects history replacement. A SCID obtained with an untrusted history does not. Valid history alone proves neither freshness nor absence of forks.