1. Credential
Existing CAC/PIV and agency trust infrastructure remain the identity/signing credential.
Reference architecture · proposed profile
The credential and document have different jobs. CAC/PIV establishes a credentialed signing capability. UD defines the exact document object, lifecycle and portable evidence boundary beneath it.
Existing CAC/PIV and agency trust infrastructure remain the identity/signing credential.
The signing ceremony presents and hashes one canonical UDR revision.
The proposed adapter records certificate-chain, algorithm, signed hash, consent and ceremony evidence without copying private keys.
All required actions complete before the exact state becomes a sealed UDS.
A compatible verifier checks document integrity, signature mathematics and separately reports identity/trust/revocation status.
The UDS remains unchanged; later work begins as a derived UDR with explicit lineage.
CONTROLLED TEST PROFILE ONLY. The document-side exact-state property is testable today. A real CAC/PIV integration, federal PKI chain validation and production authorization have not been established.