draft-dogru-cedulon-10
Internet-Draft, the numbered working text in this repository; the last
revision posted under this name, -09 (6 September 2026), is on the
IETF Datatracker,
where it is marked as replaced, and is carried here as its archive text.
Category: Informational. Author: Emek Can Doğru,
ORCID 0009-0005-4823-4468.
Source in the repository at
spec/draft-dogru-cedulon-10.md.
Companion profile:
draft-dogru-cedulon-decision-profile-04
(posted 5 October 2026), a second population on the same reconciler:
an agent's signed decisions against the effects a channel carried.
Source at spec/draft-dogru-cedulon-decision-profile-04.md.
Companion direction seeds:
re-attestation ·
streaming.
Posted documents. On 17 September 2026 the posted series
was split into three documents, which replaced
draft-dogru-cedulon on the Datatracker:
draft-dogru-cedulon-core
(spend receipts and payment rail reconciliation),
draft-dogru-cedulon-checkpoint
(epoch witnesses and transparency) and
draft-dogru-cedulon-threats
(threat narratives). Their revisions and dates are on those pages, not
here. Their sources are in spec/ beside the
numbered text, from which the three were cut; the section list below
follows the numbered text.
Cedulon is an audit layer above payment rails. It is not a rail, not a
custodian, and not an arbitral award.
Sections
- Introduction — rails move value; the audit layer is missing. Single-entry → double-entry → completeness proven against an authenticated rail extract.
- Terminology — RFC 2119; Trade Manifest, PDP, Spend Receipt, Decision Token (COSE_Sign1), Rail Extract.
- Architecture — PDP before the rail; Receipt Issuer after; optional SCITT.
- Trade Manifest — COSE_Sign1 offer before payment; manifestHash is SHA-256 of the COSE bytes.
- Spend Receipt — signed record after a gated payment; noManifest and outcome are explicit; optional payee countersignature is a detached COSE_Sign1.
- COSE Profile — deterministic CBOR; untagged COSE_Sign1; alg −19 (Ed25519); private-use labels below −65536; mandatory kid with a defined derivation.
- Canonical JSON encoding — RFC 8785 for everything hashed or signed that is not CBOR: the policy document, the six request fields a Decision Token binds, the Rail Extract body; and which octets are hashed.
- Decision Token — the portable encoding of a PDP allow; COSE_Sign1 with all five labels always present.
- Rail Extract Profile — authenticated settlement records; unsigned extract makes the guarantee conditional.
- Trust roots — a separate root input for every signed object; a verifier never checks an object against the key the object carries, and a missing or mismatched pin fails under its own name.
- Reconciliation and Epoch Checkpoints — 1:1 ref+amount+currency; half-open windows; equivocation; the verification algorithm and its finding codes.
- Lifecycle — Manifest → Policy → Payment → Receipt → Dispute Evidence Bundle.
- Policy Semantics — limit, velocity, scope; fail-closed default deny.
- SCITT Anchoring — optional registration; this draft does not operate a service.
- Privacy Considerations — public encodings omit or hash identifiers and amounts.
- Security Considerations — T1–T12, including rail-bypass completeness (T10) and settlement without a recorded receipt (T12).
- IANA Considerations — five RFC 6838 media-type templates, registration requested in the standards tree; claim labels stay private-use and are not requested.
- Implementation Status — RFC 7942 note; companion implementation with a runnable verification suite, and what each platform actually runs.
- Evolution and Future Work — re-attestation, streaming reconciliation, generalization (direction, not -00 code).
- Informative Notes — x402, AP2, Bates, Vauban, Schrock, Marques/Acta, Hopley; none define rail-extract completeness.
- Acknowledgments — named reviewer findings, revision by revision, and what each one changed.
- Appendix A. Test Vectors — locked byte-level receipt and manifest vectors, reproduced by the test suite.
Neighbor drafts (Vauban, Schrock, Marques/Acta, Hopley, Bates) sign
other facts. None of them define rail-extract completeness.