Confidentiality Under Content Addressing
If the key is the hash of the content, knowing the content is knowing the key — and where confidentiality comes from is unruled.
- Standing
- STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- never run
- Source
- none — this record cites no check
- Limit
- An OPEN ruling, not a pattern. studbook §10.2: if the key is the hash of the content, knowing the content is knowing the key. The book publishes the refusal.
- Next rung
in_tree— A ruling on where confidentiality comes from. Until then studbook cannot hold anything with a user in it, and this page cannot become a pattern.
Why this page says STATED — the derivation, not the word
- ✗ a witness is named
- ✗ its evidence kind is one the ledger already uses
- ✗ the witness path resolves in this tree
- ✗ its rung is in_tree or above
- ✗ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✗ a counterexample is shipped (required once WITNESSED)
- ✗ not staged on this site, so it cannot run from the page
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
Content addressing makes identity honest and access control hostile. Anyone who holds the content can derive its key and prove they hold it; a store that is keyed by content cannot hide that a given content exists. Until this is ruled, studbook cannot hold anything with a user in it. This page publishes the question, not a design.
Technical register
studbook §10.2, the named blocker: 'Where confidentiality comes from, given §6.2.' Convergent encryption and its known leaks (confirmation-of-a-file, learn-the-remaining-information) are the prior art. OPEN; the pattern registry has no label for open, so this record derives as STATED via its realizations. No invariant is stated because none has been ruled.
Problem
A store that refuses rows whose provenance does not check out needs content addressing; a store that holds a user's data needs to keep the existence of a content secret from readers who could guess it. The two requirements pull apart at exactly the key.
Solution
Not yet. What can be done: name the requirement (§6.2), name the conflict (§10.2), and refuse to hold user data until ruled.
Real-world analogy
A library that files every book by its full text. Nothing can be mis-shelved — and anyone who can recite a page can prove which book is on the shelf.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 25 of 32 — the fragment _patterns/wrl/chain/confidentiality-under-content-addressing.wrl, sealed alone by wrl.js
; CONFIDENTIALITY UNDER CONTENT ADDRESSING — OPEN. The ruling is about keys, not topology. This fragment is ; the empty world: nothing is declared until studbook §10.2 is ruled.
module + bench seal to → sem-b5bdc908d2ce549a46fc8ae95d39c34e1deb245e282075730e5436097433fae6
The empty world has no Film: there is nothing for the forge to reduce, and it says so. The seal above is the seal of nothing declared.
Composes with the 24 chapters before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-fcc13008b16ec8dc32850860ac44df66bfae2c7c35eda6cfeb86732830fb1f67: 87 objects, 77 edges (was 87 / 77; every earlier object and edge is still present — checked, or the build refuses). The id did not move: this fragment adds nothing but a comment, and a comment is not meaning.
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The blocker, verbatim (studbook §10) studbook/docs/spec/README.md:110
is the hash of the content, then knowing the content is knowing the key.
Forces
Every mitigation — salted keys, per-user namespaces, encrypting before hashing — weakens the property that made content addressing worth having: that two holders of the same content agree on its key. The ruling is about which property to give up, for which data.
Applicability
Any content-addressed store that will hold data with a person in it.
Consequences
The data layer stays at the spec rung. The book's contribution is to publish the refusal in a pattern-shaped slot so the gap is as findable as the patterns.
Witness
No witness. This pattern is STATED — the tree has no check for its invariant.
Counterexample
No counterexample shipped (required only when WITNESSED).
What to take away
- from the animationThe reader who knows the content derived the key; the one who did not could not — and the first can prove it.
- from the syntax§10.2 is a numbered ruling the spec says must precede implementation.
- from the literatureConvergent encryption; Tahoe-LAFS's capability model is the closest attempt at both properties at once.
- from the witnessOPEN: no pattern, one ruling, published as the question.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| Convergent encryption and its known leaks | antecedent | the confirmation-of-a-file attack is exactly this tension, already described | none — the literature's answer is that the tension is real |
Novelty not claimed. Everything. studbook §10.2 is an OPEN BLOCKER: if the key is the hash of the content, knowing the content is knowing the key. The book publishes the refusal, not a pattern.
Realizations in the tree
- studbook/docs/spec/README.md:260
Relations with other patterns
Meaning Is a Hash WITNESSED