OpenSentience.orgUnboxed PatternsChapter 25 of 32 · Persistence and World

UP-025 · Persistence and World · STATED CHECKABLE RUNNABLE EXECUTED STAGED

Confidentiality Under Content Addressing

If the key is the hash of the content, knowing the content is knowing the key — and where confidentiality comes from is unruled.

Standing
STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
Last checked
never run
Source
none — this record cites no check
Limit
An OPEN ruling, not a pattern. studbook §10.2: if the key is the hash of the content, knowing the content is knowing the key. The book publishes the refusal.
Next rung
in_tree — A ruling on where confidentiality comes from. Until then studbook cannot hold anything with a user in it, and this page cannot become a pattern.
Why this page says STATED — the derivation, not the word
  • ✗ a witness is named
  • ✗ its evidence kind is one the ledger already uses
  • ✗ the witness path resolves in this tree
  • ✗ its rung is in_tree or above
  • ✗ a run is recorded for these exact bytes
  • ✓ no claim is cited that could be REFUTED
  • ✗ a counterexample is shipped (required once WITNESSED)
  • ✗ not staged on this site, so it cannot run from the page

WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.

Intent

Content addressing makes identity honest and access control hostile. Anyone who holds the content can derive its key and prove they hold it; a store that is keyed by content cannot hide that a given content exists. Until this is ruled, studbook cannot hold anything with a user in it. This page publishes the question, not a design.

Technical register

studbook §10.2, the named blocker: 'Where confidentiality comes from, given §6.2.' Convergent encryption and its known leaks (confirmation-of-a-file, learn-the-remaining-information) are the prior art. OPEN; the pattern registry has no label for open, so this record derives as STATED via its realizations. No invariant is stated because none has been ruled.

Problem

A store that refuses rows whose provenance does not check out needs content addressing; a store that holds a user's data needs to keep the existence of a content secret from readers who could guess it. The two requirements pull apart at exactly the key.

Solution

Not yet. What can be done: name the requirement (§6.2), name the conflict (§10.2), and refuse to hold user data until ruled.

Real-world analogy

A library that files every book by its full text. Nothing can be mis-shelved — and anyone who can recite a page can prove which book is on the shelf.

Structure — on the surface

compute surfacekey = hash(content)contentcontentreader who knows itreader who knows itreader who does notreader who does notcsecret contentContent, the key that is its hash, and two readers — one who knows the content and one who does not.

An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.

The chapter in WRL — and the chain so far

Chapter 25 of 32 — the fragment _patterns/wrl/chain/confidentiality-under-content-addressing.wrl, sealed alone by wrl.js

; CONFIDENTIALITY UNDER CONTENT ADDRESSING — OPEN. The ruling is about keys, not topology. This fragment is
; the empty world: nothing is declared until studbook §10.2 is ruled.

module + bench seal to → sem-b5bdc908d2ce549a46fc8ae95d39c34e1deb245e282075730e5436097433fae6

The empty world has no Film: there is nothing for the forge to reduce, and it says so. The seal above is the seal of nothing declared.

Composes with the 24 chapters before it

The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-fcc13008b16ec8dc32850860ac44df66bfae2c7c35eda6cfeb86732830fb1f67: 87 objects, 77 edges (was 87 / 77; every earlier object and edge is still present — checked, or the build refuses). The id did not move: this fragment adds nothing but a comment, and a comment is not meaning.

How to read this board

Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.

shapeisand so
a clock; the only source of signalEvery signal on the board starts at one of these. Nothing else can make one.
a pass-through, so signal can travelOne arrives, any number leave — a relay that fans out is the board's router.
a sink; signal arrives and stopsIt latches what reached it and passes nothing on. A door is where a path ends.
rotation: takes signal, drives a poseThe only object on the board that holds a value a claim can rewrite — and only if its config says configurable.
the thing that gets movedIt is driven, never driving: an orb is what you watch to see whether anything happened.
not a WRL role — the book's own drawing of the receipts in the epoch's FilmIt counts what the run admitted, and turns red on a Rejected outcome.
SignalWiresignal: a sig_out to a sig_inLegal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves.
SocketControlcontrol: a socket to a poseLegal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal.

Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.

compute surfaceI · The LocusII · CompositionIII · ProgressIV · Persistence and Worldal_locus · Spinneral_locusspinneral_view · Orbal_vieworbal_world · Pulseral_worldpulsercb_fixed · Spinnercb_fixedspinnercb_gate · Doorcb_gatedoorcb_in · Relaycb_inrelaycb_view · Orbcb_vieworbcc_carrier · Doorcc_carrierdoorcc_grant · Relaycc_grantrelaycm_in · Relaycm_inrelaycm_locus0 · Doorcm_locus0doorcm_locus1 · Doorcm_locus1doorcm_locus2 · Doorcm_locus2doorcm_locus3 · Doorcm_locus3doorcm_slot0 · Relaycm_slot0relaycm_slot1 · Relaycm_slot1relaycm_slot2 · Relaycm_slot2relaycm_slot3 · Relaycm_slot3relayct_in · Relayct_inrelayct_locus · Spinnerct_locusspinnerct_view · Orbct_vieworbcx_in · Relaycx_inrelaycx_machine0 · Relaycx_machine0relaycx_machine1 · Relaycx_machine1relaycx_replay0 · Doorcx_replay0doorcx_replay1 · Doorcx_replay1doordb_clock · Pulserdb_clockpulserdb_locus · Spinnerdb_locusspinnerdb_view · Orbdb_vieworber_a · Relayer_arelayer_b · Relayer_brelayer_clock · Pulserer_clockpulserer_player · Doorer_playerdooris_id · Orbis_idorbis_in · Relayis_inrelayis_seal · Spinneris_sealspinnerlc_core · Relaylc_corerelaylc_locus · Spinnerlc_locusspinnerlc_machine · Relaylc_machinerelaylc_thread · Relaylc_threadrelaylc_view · Orblc_vieworbmh_clock · Pulsermh_clockpulsermh_gate · Doormh_gatedoorop_clock · Pulserop_clockpulserop_locus · Spinnerop_locusspinnerop_view · Orbop_vieworbpj_artifact · Spinnerpj_artifactspinnerpj_in · Relaypj_inrelaypj_view_a · Orbpj_view_aorbpj_view_b · Orbpj_view_borbpp_homeA · Relaypp_homeArelaypp_homeB · Relaypp_homeBrelaypp_in · Relaypp_inrelaypp_locus · Spinnerpp_locusspinnerpp_view · Orbpp_vieworbpq_a · Relaypq_arelaypq_b · Relaypq_brelaypq_clock · Pulserpq_clockpulserpq_done · Doorpq_donedoorpu_admitted · Orbpu_admittedorbpu_busy · Pulserpu_busypulserpu_hop0 · Relaypu_hop0relaypu_hop1 · Relaypu_hop1relaypu_hop2 · Relaypu_hop2relaypu_locus · Spinnerpu_locusspinnerpu_progress · Pulserpu_progresspulserpu_sink · Doorpu_sinkdoorrb_record · Orbrb_recordorbrd_in · Relayrd_inrelayrd_real · Spinnerrd_realspinnerrd_view · Orbrd_vieworbrj_join · Doorrj_joindoorrj_r · Relayrj_rrelaysm_in · Relaysm_inrelaysm_inside · Spinnersm_insidespinnersm_outside_a · Orbsm_outside_aorbsm_outside_b · Orbsm_outside_borbso_in · Relayso_inrelayso_pose · Orbso_poseorbso_rotor · Spinnerso_rotorspinnerts_root · Doorts_rootdoorts_version · Pulserts_versionpulsertv_a · Orbtv_aorbtv_b · Orbtv_borbtv_fixed · Spinnertv_fixedspinnertv_in · Relaytv_inrelaytv_open · Spinnertv_openspinner

The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.

Syntax — quoted from the tree at build time

The blocker, verbatim (studbook §10) studbook/docs/spec/README.md:110

   is the hash of the content, then knowing the content is knowing the key.

Forces

Every mitigation — salted keys, per-user namespaces, encrypting before hashing — weakens the property that made content addressing worth having: that two holders of the same content agree on its key. The ruling is about which property to give up, for which data.

Applicability

Any content-addressed store that will hold data with a person in it.

Consequences

The data layer stays at the spec rung. The book's contribution is to publish the refusal in a pattern-shaped slot so the gap is as findable as the patterns.

Witness

No witness. This pattern is STATED — the tree has no check for its invariant.

Counterexample

No counterexample shipped (required only when WITNESSED).

What to take away

  1. from the animationThe reader who knows the content derived the key; the one who did not could not — and the first can prove it.
  2. from the syntax§10.2 is a numbered ruling the spec says must precede implementation.
  3. from the literatureConvergent encryption; Tahoe-LAFS's capability model is the closest attempt at both properties at once.
  4. from the witnessOPEN: no pattern, one ruling, published as the question.

Prior art — and what is not claimed

workrelationwhat it shareswhere it differs
Convergent encryption and its known leaksantecedentthe confirmation-of-a-file attack is exactly this tension, already describednone — the literature's answer is that the tension is real

Novelty not claimed. Everything. studbook §10.2 is an OPEN BLOCKER: if the key is the hash of the content, knowing the content is knowing the key. The book publishes the refusal, not a pattern.

Realizations in the tree

Relations with other patterns

Meaning Is a Hash WITNESSED