Universal DocumentOpen document infrastructure
Menu

Reference architecture · proposed profile

Credential → exact state → UDS → evidence → Verify.

The credential and document have different jobs. CAC/PIV establishes a credentialed signing capability. UD defines the exact document object, lifecycle and portable evidence boundary beneath it.

Proposed technical sequence

1. Credential

Existing CAC/PIV and agency trust infrastructure remain the identity/signing credential.

2. Exact state

The signing ceremony presents and hashes one canonical UDR revision.

3. Signature evidence

The proposed adapter records certificate-chain, algorithm, signed hash, consent and ceremony evidence without copying private keys.

4. Completion

All required actions complete before the exact state becomes a sealed UDS.

5. Verify

A compatible verifier checks document integrity, signature mathematics and separately reports identity/trust/revocation status.

6. Amendment

The UDS remains unchanged; later work begins as a derived UDR with explicit lineage.

Required adapter controls

  • Never export or transmit the credential’s private key.
  • Use approved middleware and algorithms selected by the implementing organization.
  • Bind the signature to canonical exact-state bytes/hash.
  • Validate certificate path, intended key usage, time and revocation separately.
  • Represent mathematical validity, trusted credential and verified identity as separate results.
  • Fail closed when document bytes, evidence, signer set or required policy changes.

Current status

CONTROLLED TEST PROFILE ONLY. The document-side exact-state property is testable today. A real CAC/PIV integration, federal PKI chain validation and production authorization have not been established.