draft-dogru-cedulon-00
Internet-Draft seed. Category: informational. Author: Emek Can Dogru.
Full text lives in the repository at
spec/draft-dogru-cedulon-00.md.
Cedulon is an audit layer above payment rails. It is not a rail, not a
custodian, and not an arbitral award.
Sections
- Introduction — rails move value; the audit layer is missing.
- Terminology — RFC 2119; Trade Manifest, PDP, Spend Receipt, Anchor, Dispute Evidence Bundle.
- Architecture — PDP before the rail; Receipt Issuer after; optional SCITT.
- Trade Manifest — signed offer before payment; price, acceptance hash, expiry.
- Spend Receipt — signed record after a gated payment; no-manifest is explicit.
- COSE Profile — deterministic CBOR; COSE_Sign1 with alg EdDSA; claim labels 100–110.
- Reconciliation and Epoch Checkpoints — completeness: extract versus receipts; checkpoint chain; equivocation.
- Lifecycle — Manifest → Policy → Payment → Receipt → Dispute Evidence Bundle.
- Policy Semantics — limit, velocity, scope; fail-closed default deny.
- SCITT Anchoring — optional registration; this draft does not operate a service.
- Privacy Considerations — public encodings omit or hash identifiers and amounts.
- Security Considerations — T1–T11, including rail-bypass completeness (T10) and checkpoint suppression (T11).
- IANA Considerations — placeholder; no actions in -00.
- Informative Notes — x402, AP2, draft-sharif-attp, draft-bates-atp as neighbors.
Neighbor drafts: Sharif ATTP is identity and score. Bates ATP is causal
lineage. Neither defines rail-extract completeness.