Docs / Protocol

Protocol

The plain-language explanation is How PubPhys proves what and when. This page is the technical summary; the normative text is protocol/SPEC.md (version 1, frozen), published with the schemas and the verifier in the mirror repository Galitski-group/pubphys-log.

Objects

From content to the transparency log Content and files are referenced from the record by content_sha256 and file entries. The record hash is the SHA-256 of the record's canonical JSON and goes into the attested record. The envelope carries the attested hash with an Ed25519 platform signature. The log leaf is built from the envelope hash and the record type and joins an RFC 9162 Merkle tree. The checkpoint, a C2SP signed note, states the tree size and root hash; its SHA-256 is logged in Rekor v2, and once that entry verifies, the checkpoint note and the Rekor entry are committed to the public mirror. The attested hash, the envelope hash and the checkpoint's SHA-256 are all stamped with OpenTimestamps, and the anchored checkpoint proofs go to the mirror. Content and files the text and attachments content_sha256, file entries Record pubphys.record/2 record_hash = SHA-256(canonical JSON) Attested record pubphys.attested/1 attested_hash + Ed25519 signature Envelope pubphys.envelope/1 leaf = {envelope_hash, record_type} Log leaf RFC 9162 Merkle tree tree size and root hash Checkpoint C2SP signed note SHA-256 of the checkpoint Rekor v2, then the mirror Rekor entry first, then a git commit OpenTimestamps Bitcoin dates for all three
Each arrow names what carries the step forward. A bundle (bundle.json) holds everything from the content down to the checkpoint, the inclusion proof and every OpenTimestamps proof.

Transparency log

Keys

Records of the seed collection

The genesis key record, the import manifest (its content and the exact items.json bytes), one topic record per topic and one revision record per problem, with declared parents and the manifest among its parents. Each record page links its bundle: /records/<record hash>/bundle.json.