<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://mayckongiovani.xyz/</id>
    <title>Mayckon Giovani</title>
    <updated>2026-05-02T00:00:00.000Z</updated>
    <generator>Gatsby + feed</generator>
    <author>
        <name>Mayckon Giovani</name>
    </author>
    <link rel="alternate" href="https://mayckongiovani.xyz/pensieve/"/>
    <subtitle>Principal Systems Engineer specializing in post-quantum cryptography, distributed systems, and security-critical infrastructure.</subtitle>
    <icon>https://mayckongiovani.xyz/favicon.ico</icon>
    <entry>
        <title type="html"><![CDATA[PQC Research Series — Part 4]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-05-pqc-research-day-4-tightness-of-security-reductions</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-05-pqc-research-day-4-tightness-of-security-reductions"/>
        <updated>2026-05-02T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Reduction tightness is where PQC security meets operations: loose reductions consume margin, force parameter inflation, and turn “provably secure” into a bandwidth/RAM/latency problem.]]></summary>
        <content type="html"><![CDATA[<h2 id="tightness-of-security-reductions-why-provably-secure-does-not-mean-deployable" style="position:relative;"><a href="#tightness-of-security-reductions-why-provably-secure-does-not-mean-deployable" aria-label="tightness of security reductions why provably secure does not mean deployable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Tightness of Security Reductions: Why “Provably Secure” Does Not Mean Deployable</h2>
<p>Author: Mayckon Giovani<br>
Date: May 2, 2026<br>
Series: PQC Research Series<br>
Tags: PQC, Formal Methods, Cryptography, Systems</p>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>“Provably secure” means: <em>if</em> an adversary breaks scheme <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span>, <em>then</em> a reduction algorithm <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">R</mi></mrow><annotation encoding="application/x-tex">\mathcal{R}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">R</span></span></span></span></span> can solve an underlying problem <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span>. Tightness is the quantitative part of that implication: how much advantage and how much runtime are lost when translating an attack on <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> into a solver for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span>. If the loss factor is large (non-tight), the proof consumes security margin and forces parameter inflation. In PQC, that inflation is not cosmetic: it amplifies bandwidth, RAM, cache pressure, side-channel surface, and failure probability engineering (sampling, rejection, decoding). A reduction is not the system. It is a translation between problems, and translations have loss. <span class="citation" id="citation--bellarerogaway1996exactsecurity--1">(<a href="#bib-bellarerogaway1996exactsecurity">1</a>)</span> <span class="citation" id="citation--peikert2016decade--2">(<a href="#bib-peikert2016decade">2</a>)</span> <span class="citation" id="citation--bonehetal2010qrom--3">(<a href="#bib-bonehetal2010qrom">3</a>)</span></p>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Tightness is an <em>engineering input</em>, not a proof-theory detail: loose reductions force larger parameters to recover the target margin.</li>
<li>A reduction loss factor <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">f(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> costs about <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\log_2 f(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> bits of security headroom; at scale, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi></mrow><annotation encoding="application/x-tex">f</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span></span></span></span></span> is often driven by query counts (<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>S</mi></msub></mrow><annotation encoding="application/x-tex">q_S</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05764em;">S</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>) and multi-user/multi-target settings.</li>
<li>In ROM/QROM, common tactics (forking, rewinding, oracle programming) frequently inject explicit <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>-dependent losses; in QROM those losses are harder to avoid and often less tight. <span class="citation" id="citation--pointchevalstern1996securityproofs--4">(<a href="#bib-pointchevalstern1996securityproofs">4</a>)</span> <span class="citation" id="citation--unruh2017fiatshamir--5">(<a href="#bib-unruh2017fiatshamir">5</a>)</span> <span class="citation" id="citation--griloetal2020tightreprogrammingqrom--6">(<a href="#bib-griloetal2020tightreprogrammingqrom">6</a>)</span></li>
<li>“NIST level” labels are not proofs: they are the output of cost models (BKZ/sieving heuristics + hardware assumptions) composed with non-tight reduction chains. <span class="citation" id="citation--chennguyen2011bkz20--7">(<a href="#bib-chennguyen2011bkz20">7</a>)</span> <span class="citation" id="citation--albrechtlweestimator--8">(<a href="#bib-albrechtlweestimator">8</a>)</span></li>
<li>Formal verification can prove that an implementation refines a spec; it cannot repair a loose reduction or a wrong cost model.</li>
</ul>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>A reduction is not a security guarantee.</strong> It is a conditional implication with a quantitative loss profile. Deployability is exactly the question “does the required parameter inflation still fit the system boundary (bandwidth, RAM, latency, and leakage)?”</p>
</div>
<h2 id="0-context" style="position:relative;"><a href="#0-context" aria-label="0 context permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>0. Context</h2>
<p>The PQC conversation in production environments is still dominated by a shallow equivalence:</p>
<blockquote>
<p>scheme is “provably secure” <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>⇒</mo></mrow><annotation encoding="application/x-tex">\Rightarrow</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.3669em;"></span><span class="mrel">⇒</span></span></span></span></span> system is secure.</p>
</blockquote>
<p>That inference is invalid even before you talk about side-channels or implementation bugs. Security proofs in modern cryptography are conditional, parameterized, and mediated by reductions. The proof does not say “<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> is secure.” It says “if <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> is broken with advantage <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ε</mi></mrow><annotation encoding="application/x-tex">\varepsilon</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">ε</span></span></span></span></span> in time <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>t</mi></mrow><annotation encoding="application/x-tex">t</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord mathnormal">t</span></span></span></span></span>, then <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span> is solvable with advantage <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>ε</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">\varepsilon'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal">ε</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span> in time <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>t</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">t'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal">t</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span>.” Tightness is the gap between <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>ε</mi><mo separator="true">,</mo><mi>t</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(\varepsilon,t)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">ε</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mclose">)</span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><msup><mi>ε</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo separator="true">,</mo><msup><mi>t</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(\varepsilon',t')</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0019em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">ε</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">t</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>.</p>
<p>The operational consequence is that <em>reductions consume margin</em>. If the reduction is loose, and you want an operational claim like “128-bit confidentiality margin under my threat model,” you must inflate parameters until the reduction loss is absorbed. In lattice cryptography that inflation is paid in large public keys, large ciphertexts/signatures, higher RAM, higher cache traffic, and larger constant-time code paths. That is where “provably secure” becomes either “deployable” or “a lab artifact.”</p>
<h2 id="1-problem-statement" style="position:relative;"><a href="#1-problem-statement" aria-label="1 problem statement permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1. Problem Statement</h2>
<p>Fix a security parameter <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi><mo>∈</mo><mi mathvariant="double-struck">N</mi></mrow><annotation encoding="application/x-tex">\lambda \in \mathbb{N}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">λ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord mathbb">N</span></span></span></span></span>. Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi><mo stretchy="false">[</mo><mi>λ</mi><mo stretchy="false">]</mo></mrow><annotation encoding="application/x-tex">\Pi[\lambda]</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Π</span><span class="mopen">[</span><span class="mord mathnormal">λ</span><span class="mclose">]</span></span></span></span></span> be a scheme (KEM, signature, AKE) instantiated at security parameter <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi></mrow><annotation encoding="application/x-tex">\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">λ</span></span></span></span></span> and proven secure by reduction to an underlying problem <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi><mo stretchy="false">[</mo><mi>λ</mi><mo stretchy="false">]</mo></mrow><annotation encoding="application/x-tex">P[\lambda]</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">[</span><span class="mord mathnormal">λ</span><span class="mclose">]</span></span></span></span></span> (DL, RSA, LWE/SIS, etc).</p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="sans-serif">G</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">m</mi><mi mathvariant="sans-serif">e</mi></mrow><mi mathvariant="normal">Π</mi></msub></mrow><annotation encoding="application/x-tex">\mathsf{Game}_\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathsf">Game</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Π</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> be the security game for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> (IND-CCA, EUF-CMA, AKE, …). Define the adversary’s advantage as usual:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mo><mover><mo><mo>=</mo></mo><mrow><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">f</mi></mrow></mover></mo><mrow><mo fence="true">∣</mo><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi></mrow><mo stretchy="false">[</mo><msubsup><mrow><mi mathvariant="sans-serif">G</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">m</mi><mi mathvariant="sans-serif">e</mi></mrow><mi mathvariant="normal">Π</mi><mi>A</mi></msubsup><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo><mo>=</mo><mn>1</mn><mo stretchy="false">]</mo><mo>−</mo><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi></mrow><mo stretchy="false">[</mo><msubsup><mrow><mi mathvariant="sans-serif">G</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">m</mi><mi mathvariant="sans-serif">e</mi></mrow><mi mathvariant="normal">Π</mi><mo lspace="0em" rspace="0em">⋆</mo></msubsup><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo><mo>=</mo><mn>1</mn><mo stretchy="false">]</mo><mo fence="true">∣</mo></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\Pi}(A;\lambda)
  \stackrel{\mathrm{def}}{=}
  \left|
    \Pr[\mathsf{Game}_\Pi^{A}(1^\lambda)=1] - \Pr[\mathsf{Game}_\Pi^{\star}(1^\lambda)=1]
  \right|.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.403em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mop op-limits"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:1.153em;"><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span><span class="mop">=</span></span></span><span style="top:-3.5669em;margin-left:0em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.07778em;">def</span></span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="minner"><span class="mopen"><span class="delimsizing mult"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.15em;"><span style="top:-3.15em;"><span class="pstrut" style="height:3.8em;"></span><span style="width:0.333em;height:1.800em;"><svg xmlns="http://www.w3.org/2000/svg" width="0.333em" height="1.800em" viewBox="0 0 333 1800"><path d="M145 15 v585 v600 v585 c2.667,10,9.667,15,21,15
c10,0,16.667,-5,20,-15 v-585 v-600 v-585 c-2.667,-10,-9.667,-15,-21,-15
c-10,0,-16.667,5,-20,15z M188 15 H145 v585 v600 v585 h43z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.65em;"><span></span></span></span></span></span></span><span class="mord"><span class="mord mathrm">Pr</span></span><span class="mopen">[</span><span class="mord"><span class="mord"><span class="mord mathsf">Game</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9257em;"><span style="top:-2.453em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Π</span></span></span><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mord">1</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mord"><span class="mord mathrm">Pr</span></span><span class="mopen">[</span><span class="mord"><span class="mord"><span class="mord mathsf">Game</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.773em;"><span style="top:-2.453em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Π</span></span></span><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">⋆</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mord">1</span><span class="mclose">]</span><span class="mclose"><span class="delimsizing mult"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.15em;"><span style="top:-3.15em;"><span class="pstrut" style="height:3.8em;"></span><span style="width:0.333em;height:1.800em;"><svg xmlns="http://www.w3.org/2000/svg" width="0.333em" height="1.800em" viewBox="0 0 333 1800"><path d="M145 15 v585 v600 v585 c2.667,10,9.667,15,21,15
c10,0,16.667,-5,20,-15 v-585 v-600 v-585 c-2.667,-10,-9.667,-15,-21,-15
c-10,0,-16.667,5,-20,15z M188 15 H145 v585 v600 v585 h43z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.65em;"><span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">.</span></span></span></span></span></div>
<p>A reduction-based proof typically has the form:</p>
<blockquote>
<p>For every adversary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> that breaks <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> with advantage <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ε</mi></mrow><annotation encoding="application/x-tex">\varepsilon</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">ε</span></span></span></span></span> in time <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>t</mi></mrow><annotation encoding="application/x-tex">t</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord mathnormal">t</span></span></span></span></span> and at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><msub><mi>q</mi><mi>S</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(q_H, q_S, \dots)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05764em;">S</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span></span></span></span></span> oracle queries, there exists an algorithm <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>B</mi></mrow><annotation encoding="application/x-tex">B</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span></span></span></span></span> that solves <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span> with advantage at least <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>ε</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">\varepsilon'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal">ε</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span> in time <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>t</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">t'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal">t</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span>.</p>
</blockquote>
<p>The central quantitative question is: <strong>how much security is lost in the translation</strong> <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi><mo>↦</mo><mi>B</mi></mrow><annotation encoding="application/x-tex">A \mapsto B</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6943em;vertical-align:-0.011em;"></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">↦</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span></span></span></span></span>?</p>
<p>Concretely, suppose the reduction <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">R</mi></mrow><annotation encoding="application/x-tex">\mathcal{R}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">R</span></span></span></span></span> builds <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>B</mi></mrow><annotation encoding="application/x-tex">B</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span></span></span></span></span> with oracle access to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msup><mi>B</mi><mi>A</mi></msup><mtext>  </mtext><mo>←</mo><mtext>  </mtext><msup><mi mathvariant="script">R</mi><mi>A</mi></msup><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">B^{A} \;\gets\; \mathcal{R}^{A}(1^\lambda).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8913em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8913em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1491em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathcal">R</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8913em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>We want to track:</p>
<ol>
<li><strong>advantage loss</strong>: a function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>g</mi></mrow><annotation encoding="application/x-tex">g</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span></span></span></span></span> such that
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi>P</mi></msub><mo stretchy="false">(</mo><mi>B</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≥</mo><mtext>  </mtext><mi>g</mi><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><msub><mi>q</mi><mi>S</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{P}(B;\lambda) \;\ge\; g(\mathrm{Adv}_{\Pi}(A;\lambda), \lambda, q_H, q_S,\dots),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05764em;">S</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
</li>
<li><strong>time/query overhead</strong>: a function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>h</mi></mrow><annotation encoding="application/x-tex">h</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">h</span></span></span></span></span> such that
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>T</mi><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≤</mo><mtext>  </mtext><mi>h</mi><mo stretchy="false">(</mo><mi>T</mi><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><msub><mi>q</mi><mi>S</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">T(B) \;\le\; h(T(A), \lambda, q_H, q_S,\dots),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">h</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05764em;">S</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
</li>
<li>and the implicit assumption: that the deployed implementation matches the model in which <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">R</mi></mrow><annotation encoding="application/x-tex">\mathcal{R}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">R</span></span></span></span></span> operates (ROM vs standard model vs QROM; single-user vs multi-user; single-target vs multi-target; leakage-free vs leakage models).</li>
</ol>
<p>The proof is only operationally meaningful after you translate those functions into:</p>
<ul>
<li>concrete parameter sizes,</li>
<li>a concrete attacker cost model,</li>
<li>and system constraints (RAM/CPU/network/leakage budgets).</li>
</ul>
<h2 id="2-formal-model" style="position:relative;"><a href="#2-formal-model" aria-label="2 formal model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2. Formal Model</h2>
<h3 id="21-loss-factor-as-an-explicit-function" style="position:relative;"><a href="#21-loss-factor-as-an-explicit-function" aria-label="21 loss factor as an explicit function permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1 Loss factor as an explicit function</h3>
<p>In most cryptographic reductions, advantage loss appears as an inequality of the form:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≤</mo><mtext>  </mtext><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><msub><mi>q</mi><mi>S</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mo>⋅</mo><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi>P</mi></msub><mo stretchy="false">(</mo><mi>B</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\Pi}(A;\lambda) \;\le\; f(\lambda, q_H, q_S,\dots)\cdot \mathrm{Adv}_{P}(B;\lambda) + \Delta(\lambda),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05764em;">S</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">f(\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span> is the <strong>loss factor</strong> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\Delta(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> collects negligible/statistical terms (abort probability, simulation distance, decryption failure, etc).</p>
<p>Equivalently, rearranging the reduction:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi>P</mi></msub><mo stretchy="false">(</mo><mi>B</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≥</mo><mtext>  </mtext><mfrac><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>−</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><mrow><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><msub><mi>q</mi><mi>S</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo></mrow></mfrac><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{P}(B;\lambda) \;\ge\; \frac{\mathrm{Adv}_{\Pi}(A;\lambda) - \Delta(\lambda)}{f(\lambda, q_H, q_S,\dots)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.363em;vertical-align:-0.936em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.427em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05764em;">S</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mord">Δ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.936em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mord">.</span></span></span></span></span></div>
<p>The reduction is <strong>tight</strong> if <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">f(\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span> is close to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> (or at least a small constant / low-degree polynomial with small coefficients) in the regime that matters, and <strong>loose</strong> if <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi></mrow><annotation encoding="application/x-tex">f</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span></span></span></span></span> is large and grows in the relevant operational parameters.</p>
<p>To talk about tightness without hand-waving, define the tightness ratio:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="sans-serif">L</mi><mi mathvariant="sans-serif">o</mi><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">s</mi></mrow><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo><mover><mo><mo>=</mo></mo><mrow><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">f</mi></mrow></mover></mo><mtext>  </mtext><munder><mrow><mi>sup</mi><mo>⁡</mo></mrow><mi>A</mi></munder><mtext>  </mtext><mfrac><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi>P</mi></msub><mo stretchy="false">(</mo><msup><mi mathvariant="script">R</mi><mi>A</mi></msup><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></mfrac><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathsf{Loss}(\lambda) \;\stackrel{\mathrm{def}}{=}\;
\sup_{A}\;
\frac{\mathrm{Adv}_{\Pi}(A;\lambda)}{\mathrm{Adv}_{P}(\mathcal{R}^A;\lambda)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.403em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathsf">Loss</span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mop op-limits"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:1.153em;"><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span><span class="mop">=</span></span></span><span style="top:-3.5669em;margin-left:0em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.07778em;">def</span></span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3658em;vertical-align:-0.9388em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.4306em;"><span style="top:-2.1612em;margin-left:0em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span></span></span></span><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span><span class="mop">sup</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.9388em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.427em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathcal">R</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7673em;"><span style="top:-2.989em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">A</span></span></span></span></span></span></span></span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.936em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mord">.</span></span></span></span></span></div>
<p>This definition is deliberately adversarial: it asks “how bad can the translation be” for the class of attacks the reduction claims to cover.</p>
<h3 id="22-concrete-security-translation-loss-eats-bits" style="position:relative;"><a href="#22-concrete-security-translation-loss-eats-bits" aria-label="22 concrete security translation loss eats bits permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.2 Concrete security translation: loss eats bits</h3>
<p>Operationally we do not talk in “<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ε</mi></mrow><annotation encoding="application/x-tex">\varepsilon</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">ε</span></span></span></span></span>.” We talk in “bits.” A common concrete-security stance is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi>P</mi></msub><mo stretchy="false">(</mo><mi>B</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≤</mo><mtext>  </mtext><msup><mn>2</mn><mrow><mo>−</mo><mi>κ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{P}(B;\lambda) \;\le\; 2^{-\kappa(\lambda)}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.938em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">−</span><span class="mord mathnormal mtight">κ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span></span></span></span></span></div>
<p>for any feasible attacker <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>B</mi></mrow><annotation encoding="application/x-tex">B</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span></span></span></span></span> (where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>κ</mi></mrow><annotation encoding="application/x-tex">\kappa</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">κ</span></span></span></span></span> is an effective bit-security function induced by a cost model).</p>
<p>Combining with the reduction gives:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≲</mo><mtext>  </mtext><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mo>⋅</mo><msup><mn>2</mn><mrow><mo>−</mo><mi>κ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\Pi}(A;\lambda)
\;\lesssim\;
f(\lambda, q_H,\dots)\cdot 2^{-\kappa(\lambda)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel amsrm">≲</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.938em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">−</span><span class="mord mathnormal mtight">κ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>If you want a scheme-level bound like <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mn>2</mn><mrow><mo>−</mo><msub><mi>κ</mi><mi mathvariant="normal">Π</mi></msub></mrow></msup></mrow><annotation encoding="application/x-tex">2^{-\kappa_\Pi}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7713em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7713em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">−</span><span class="mord mtight"><span class="mord mathnormal mtight">κ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3567em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">Π</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1433em;"><span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>, you need:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mo>⋅</mo><msup><mn>2</mn><mrow><mo>−</mo><mi>κ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup><mtext>  </mtext><mo>≤</mo><mtext>  </mtext><msup><mn>2</mn><mrow><mo>−</mo><msub><mi>κ</mi><mi mathvariant="normal">Π</mi></msub></mrow></msup><mspace width="1em"></mspace><mo>⇒</mo><mspace width="1em"></mspace><mi>κ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≥</mo><mtext>  </mtext><msub><mi>κ</mi><mi mathvariant="normal">Π</mi></msub><mo>+</mo><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">f(\lambda, q_H,\dots)\cdot 2^{-\kappa(\lambda)} \;\le\; 2^{-\kappa_\Pi}
\quad\Rightarrow\quad
\kappa(\lambda) \;\ge\; \kappa_\Pi + \log_2 f(\lambda, q_H,\dots).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.074em;vertical-align:-0.136em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">−</span><span class="mord mathnormal mtight">κ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8213em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8213em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">−</span><span class="mord mtight"><span class="mord mathnormal mtight">κ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3567em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">Π</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1433em;"><span></span></span></span></span></span></span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">κ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">κ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Π</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>So the security margin you must provision at the assumption layer is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">Δ</mi><mi>κ</mi><mtext>  </mtext><mo>≈</mo><mtext>  </mtext><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mi>f</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\Delta \kappa \;\approx\; \log_2 f.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span><span class="mord mathnormal">κ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mord">.</span></span></span></span></span></div>
<p>This is the cleanest way to say what people usually avoid saying: <strong>tightness loss is paid as extra bits</strong>, and extra bits are paid as CPU/RAM/bandwidth.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If your reduction loss is driven by a term like <code>q_H</code> (hash queries) or <code>N</code> (number of users / targets), translate it immediately into bits: <code>Δκ ≈ log2(q_H)</code> or <code>Δκ ≈ log2(N)</code>. If you cannot provision that headroom, the proof is not an operational argument; it is a paper artifact.</p>
</div>
<h3 id="23-time-overhead-and-tight-lies" style="position:relative;"><a href="#23-time-overhead-and-tight-lies" aria-label="23 time overhead and tight lies permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3 Time overhead and “tight” lies</h3>
<p>Advantage is not the only axis. Many reductions amplify runtime:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>T</mi><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≈</mo><mtext>  </mtext><mi>T</mi><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>⋅</mo><mi>c</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mo>+</mo><msub><mi>T</mi><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">m</mi></mrow></msub><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">T(B) \;\approx\; T(A)\cdot c(\lambda, q_H,\dots) + T_{\mathrm{sim}}(\lambda),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">c</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3175em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">sim</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">c(\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">c</span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span> is sometimes large (multiple invocations, rewinding, “guess the right query index,” etc).</p>
<p>Two reductions can have identical advantage loss but radically different runtime overheads. In PQC deployments, runtime overhead affects <em>parameter selection</em> indirectly: if the reduction requires many replays or rewinds, the “feasible adversary” class changes, and the bound becomes meaningless for the time regime you care about.</p>
<p>This is why exact-security work matters: it forces you to write the constants and the query-dependence instead of burying it in “poly.” Bellare–Rogaway-style exact security is the discipline that makes “provable” actually consumable by engineering. <span class="citation" id="citation--bellarerogaway1996exactsecurity--9">(<a href="#bib-bellarerogaway1996exactsecurity">1</a>)</span></p>
<h2 id="3-system-constraints" style="position:relative;"><a href="#3-system-constraints" aria-label="3 system constraints permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3. System Constraints</h2>
<p>In a clean paper model, the only resource is “polynomial time.” In a deployed system, the constraint set is a vector:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi></mrow><mo>=</mo><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">B</mi><mi mathvariant="normal">W</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">R</mi><mi mathvariant="normal">T</mi><mi mathvariant="normal">T</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">R</mi><mi mathvariant="normal">A</mi><mi mathvariant="normal">M</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">P</mi><mi mathvariant="normal">U</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">h</mi><mi mathvariant="normal">e</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">f</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">y</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{budget} =
(\mathrm{BW}, \mathrm{RTT}, \mathrm{RAM}, \mathrm{CPU}, \mathrm{cache}, \mathrm{flash}, \mathrm{entropy}, \mathrm{power}, \mathrm{leakage}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">budget</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">BW</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">RTT</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">RAM</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">CPU</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">cache</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">flash</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">entropy</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">power</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">leakage</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Loose reductions push parameters up, which pushes <em>every</em> component of that budget:</p>
<ul>
<li><strong>bandwidth/packetization</strong>: larger public keys and signatures fragment handshakes and stress middleboxes;</li>
<li><strong>RAM/cache</strong>: lattice arithmetic is memory-hungry; larger parameters increase cache-miss leakage and constant-time difficulty;</li>
<li><strong>latency</strong>: slow verification/signing affects consensus nodes, IIoT gateways, VPN concentrators;</li>
<li><strong>entropy</strong>: many PQC schemes are randomness-intensive; constrained RNG becomes a first-class failure mode (especially at boot);</li>
<li><strong>side-channel surface</strong>: larger code, more branches, more table accesses, more sampling logic → more leakage opportunities;</li>
<li><strong>failure probability engineering</strong>: rejection sampling, decoding failures, and “abort on overflow” logic must be bounded and monitored.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parameter inflation is not just “bigger bytes.” It creates new operational attack planes: handshake fragmentation, parser complexity, cache-pressure leakage, and amplification of RNG-quality problems. A loose reduction pushes you toward exactly the regimes where systems break.</p>
</div>
<p>This is why the engineering question “is the reduction tight?” is not academic. It decides whether the parameters that make the theorem true still fit inside the machine you actually ship.</p>
<h2 id="4-core-argument--insight" style="position:relative;"><a href="#4-core-argument--insight" aria-label="4 core argument  insight permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4. Core Argument / Insight</h2>
<h3 id="41-why-tightness-matters-operationally-security-margin-is-a-consumable" style="position:relative;"><a href="#41-why-tightness-matters-operationally-security-margin-is-a-consumable" aria-label="41 why tightness matters operationally security margin is a consumable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.1 Why tightness matters operationally (security margin is a consumable)</h3>
<p>Assume you are targeting a concrete security bound <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>κ</mi><mi mathvariant="normal">Π</mi></msub></mrow><annotation encoding="application/x-tex">\kappa_\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">κ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Π</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> against a realistic attacker class. The proof gives you:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>κ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≥</mo><mtext>  </mtext><msub><mi>κ</mi><mi mathvariant="normal">Π</mi></msub><mo>+</mo><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\kappa(\lambda) \;\ge\; \kappa_\Pi + \log_2 f(\lambda, q_H,\dots).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">κ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">κ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Π</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Now instantiate the operational reality:</p>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> is not “small.” In protocols, hashes are everywhere: transcript hashing, domain separation, commitments, PRF/KDF usage, key schedules, prehashing, merkleization.</li>
<li>multi-user and multi-target settings are the norm: a production system runs at scale, across many sessions, many keys, many certificates, many handshakes.</li>
</ul>
<p>So <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi></mrow><annotation encoding="application/x-tex">f</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span></span></span></span></span> is often dominated by terms like:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mi>N</mi><mo stretchy="false">)</mo><mo>∈</mo><mi mathvariant="normal">Θ</mi><mo stretchy="false">(</mo><msub><mi>q</mi><mi>H</mi></msub><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><mi mathvariant="normal">Θ</mi><mo stretchy="false">(</mo><msubsup><mi>q</mi><mi>H</mi><mn>2</mn></msubsup><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><mi mathvariant="normal">Θ</mi><mo stretchy="false">(</mo><mi>N</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><mi mathvariant="normal">Θ</mi><mo stretchy="false">(</mo><mi>N</mi><mo>⋅</mo><msub><mi>q</mi><mi>H</mi></msub><mo stretchy="false">)</mo><mo separator="true">,</mo><mo>…</mo></mrow><annotation encoding="application/x-tex">f(\lambda,q_H,N) \in \Theta(q_H),\;\Theta(q_H^2),\;\Theta(N),\;\Theta(N\cdot q_H),\dots</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1141em;vertical-align:-0.25em;"></span><span class="mord">Θ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">Θ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8641em;"><span style="top:-2.453em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">Θ</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">Θ</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span></span></span></span></span></div>
<p>The punchline: <strong>the scheme’s “bit security” is not the assumption’s “bit security.”</strong> The proof spends some of it.</p>
<p>To make this concrete, consider a reduction with loss <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo>=</mo><msubsup><mi>q</mi><mi>H</mi><mn>2</mn></msubsup></mrow><annotation encoding="application/x-tex">f = q_H^2</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0894em;vertical-align:-0.2753em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8141em;"><span style="top:-2.4247em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2753em;"><span></span></span></span></span></span></span></span></span></span></span>. If a verifier in a large system induces (directly or indirectly) <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub><mo>≈</mo><msup><mn>2</mn><mn>20</mn></msup></mrow><annotation encoding="application/x-tex">q_H \approx 2^{20}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6776em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8141em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8141em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">20</span></span></span></span></span></span></span></span></span></span></span></span></span> effective oracle interactions per security epoch (not insane in transcript-heavy protocols), then:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mi>f</mi><mo>=</mo><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mo stretchy="false">(</mo><msubsup><mi>q</mi><mi>H</mi><mn>2</mn></msubsup><mo stretchy="false">)</mo><mo>=</mo><mn>2</mn><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><msub><mi>q</mi><mi>H</mi></msub><mo>≈</mo><mn>40.</mn></mrow><annotation encoding="application/x-tex">\log_2 f = \log_2(q_H^2) = 2\log_2 q_H \approx 40.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1141em;vertical-align:-0.25em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8641em;"><span style="top:-2.453em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mord">2</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">40.</span></span></span></span></span></div>
<p>Forty bits of headroom is not a rounding error. In lattices, forty bits is the difference between “fits in your MTU / fits in your L2 cache” and “now you have to redesign the protocol framing, the packetization, and the implementation strategy.”</p>
<p>If you do not do this translation explicitly, “provably secure” becomes a word that hides debt.</p>
<h3 id="42-example--fiatshamir-losses-tightness-is-often-query-driven" style="position:relative;"><a href="#42-example--fiatshamir-losses-tightness-is-often-query-driven" aria-label="42 example  fiatshamir losses tightness is often query driven permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.2 Example — Fiat–Shamir losses (tightness is often query-driven)</h3>
<p>Fiat–Shamir (FS) is a canonical place where tightness is visible because the proof must account for the adversary’s random oracle queries. This matters in PQC because a large fraction of deployed post-quantum signatures and ZK systems are FS-shaped, and Part 3 already established that QROM makes the proof obligations sharper. <span class="citation" id="citation--unruh2017fiatshamir--10">(<a href="#bib-unruh2017fiatshamir">5</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--11">(<a href="#bib-donetal2019fiatshamirqrom">9</a>)</span></p>
<h4 id="classical-rom-forking-style-losses" style="position:relative;"><a href="#classical-rom-forking-style-losses" aria-label="classical rom forking style losses permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Classical ROM: forking-style losses</h4>
<p>In ROM, security proofs for FS-based signatures often rely on the <strong>forking lemma</strong> (Pointcheval–Stern). The structure is:</p>
<ol>
<li>Run the forger <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> once, record its oracle queries.</li>
<li>Rewind <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> with the same randomness, but answer <em>one</em> targeted oracle query differently.</li>
<li>If you get two valid transcripts with different challenges, extract the witness / discrete log / solution.</li>
</ol>
<p>This almost always introduces a loss driven by the probability that you “hit the right query” and by the probability that the adversary forges at all. Exact-security analyses make this explicit; for Schnorr-type signatures, the reduction loss is at least linear in the number of hash queries <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>, and in many cases that loss is essentially optimal. <span class="citation" id="citation--pointchevalstern1996securityproofs--12">(<a href="#bib-pointchevalstern1996securityproofs">4</a>)</span> <span class="citation" id="citation--seurin2012exactschnorr--13">(<a href="#bib-seurin2012exactschnorr">10</a>)</span></p>
<p>At an abstract level, a typical bound has the shape:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">L</mi></mrow></msub><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>≳</mo><mtext>  </mtext><mfrac><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">U</mi><mi mathvariant="normal">F</mi></mrow></msub><mo stretchy="false">(</mo><mi>A</mi><msup><mo stretchy="false">)</mo><mn>2</mn></msup></mrow><msub><mi>q</mi><mi>H</mi></msub></mfrac><mspace width="1em"></mspace><mtext>or</mtext><mspace width="1em"></mspace><mfrac><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">U</mi><mi mathvariant="normal">F</mi></mrow></msub><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo></mrow><msub><mi>q</mi><mi>H</mi></msub></mfrac><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\mathrm{DL}}(B)
\;\gtrsim\;
\frac{\mathrm{Adv}_{\mathrm{EUF}}(A)^2}{q_H}
\quad\text{or}\quad
\frac{\mathrm{Adv}_{\mathrm{EUF}}(A)}{q_H},</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">DL</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel amsrm">≳</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3715em;vertical-align:-0.8804em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.4911em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">EUF</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose"><span class="mclose">)</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8141em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.8804em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">or</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.427em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">EUF</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.8804em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>depending on the exact extraction strategy, the security definition, and whether you count rewinds in time.</p>
<p>The important engineering fact is not the exact exponent. It is that <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> appears <em>in the denominator</em>. Large protocols induce large <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>.</p>
<h4 id="qrom-the-loss-profile-worsens-unless-you-change-technique" style="position:relative;"><a href="#qrom-the-loss-profile-worsens-unless-you-change-technique" aria-label="qrom the loss profile worsens unless you change technique permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>QROM: the loss profile worsens unless you change technique</h4>
<p>In QROM, the adversary can query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> in superposition. That breaks the classical mental model “record all queries and pick one to program.” Rewinding is not generic; programming the oracle is global; and the simulation must be careful about measurements and disturbance. <span class="citation" id="citation--bonehetal2010qrom--14">(<a href="#bib-bonehetal2010qrom">3</a>)</span> <span class="citation" id="citation--zhandry2018recordqueries--15">(<a href="#bib-zhandry2018recordqueries">11</a>)</span></p>
<p>That is exactly why the QROM FS literature developed new tools (measure-and-reprogram, compressed oracle, adaptive reprogramming). Those tools exist, but they move the reduction burden into more complex bounds, and tightness is often where the cost shows up. <span class="citation" id="citation--donetal2019fiatshamirqrom--16">(<a href="#bib-donetal2019fiatshamirqrom">9</a>)</span> <span class="citation" id="citation--griloetal2020tightreprogrammingqrom--17">(<a href="#bib-griloetal2020tightreprogrammingqrom">6</a>)</span></p>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>“FS is proven secure in QROM” is not the same claim as “FS is secure with a tight, deployable bound.” The former can hold while the reduction loss forces parameter inflation that collapses your system constraints (especially on constrained nodes).</p>
</div>
<p>The practical lesson is not “avoid FS.” The lesson is: <strong>treat <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> and reduction tightness as first-class protocol parameters</strong>. If you do not control oracle query surfaces (transcript structure, domain separation, protocol framing), you are implicitly paying in security margin.</p>
<h3 id="43-lattice-cryptography-and-non-tight-reduction-chains" style="position:relative;"><a href="#43-lattice-cryptography-and-non-tight-reduction-chains" aria-label="43 lattice cryptography and non tight reduction chains permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.3 Lattice cryptography and non-tight reduction chains</h3>
<p>Lattice-based schemes (ML-KEM, ML-DSA, Falcon, and many variants) inherit two distinct kinds of non-tightness:</p>
<ol>
<li><strong>worst-case/average-case reduction losses</strong> (approximation factors and parameter regimes),</li>
<li><strong>scheme-level transforms</strong> (e.g., turning CPA into CCA, ROM/QROM indirections, multi-target scaling).</li>
</ol>
<h4 id="worst-case-to-average-case-approximation-factor-inflation" style="position:relative;"><a href="#worst-case-to-average-case-approximation-factor-inflation" aria-label="worst case to average case approximation factor inflation permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Worst-case to average-case: approximation-factor inflation</h4>
<p>The foundational LWE story is “average-case LWE is as hard as worst-case lattice problems,” but the reduction does not preserve the approximation factor tightly. In a typical regime:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mtext>solve LWE</mtext><mrow><mi>n</mi><mo separator="true">,</mo><mi>q</mi><mo separator="true">,</mo><mi>α</mi></mrow></msub><mtext>  </mtext><mo>⇒</mo><mtext>  </mtext><mtext>solve </mtext><msub><mrow><mi mathvariant="sans-serif">G</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">S</mi><mi mathvariant="sans-serif">V</mi><mi mathvariant="sans-serif">P</mi></mrow><mrow><mi>γ</mi><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo></mrow></msub><mtext> with </mtext><mi>γ</mi><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo><mo>=</mo><mover accent="true"><mi>O</mi><mo>~</mo></mover><mo stretchy="false">(</mo><mi>n</mi><mi mathvariant="normal">/</mi><mi>α</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{solve LWE}_{n,q,\alpha}
\;\Rightarrow\;
\text{solve }\mathsf{GapSVP}_{\gamma(n)} \text{ with } \gamma(n)=\tilde{O}(n/\alpha).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9805em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord text"><span class="mord">solve LWE</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">n</span><span class="mpunct mtight">,</span><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span><span class="mpunct mtight">,</span><span class="mord mathnormal mtight" style="margin-right:0.0037em;">α</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1691em;vertical-align:-0.4191em;"></span><span class="mord text"><span class="mord">solve </span></span><span class="mord"><span class="mord"><span class="mord mathsf">GapSVP</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2809em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.05556em;">γ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">n</span><span class="mclose mtight">)</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.4191em;"><span></span></span></span></span></span></span><span class="mord text"><span class="mord"> with </span></span><span class="mord mathnormal" style="margin-right:0.05556em;">γ</span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1702em;vertical-align:-0.25em;"></span><span class="mord accent"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.9202em;"><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span></span><span style="top:-3.6023em;"><span class="pstrut" style="height:3em;"></span><span class="accent-body" style="left:-0.1667em;"><span class="mord">~</span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mord">/</span><span class="mord mathnormal" style="margin-right:0.0037em;">α</span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>That <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>γ</mi><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\gamma(n)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.05556em;">γ</span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mclose">)</span></span></span></span></span> term is not a constant. It is an inflation factor in the hardness statement, and it is one of the reasons “security level” estimates are not cleanly derivable from a theorem. <span class="citation" id="citation--regev2009lwe--18">(<a href="#bib-regev2009lwe">12</a>)</span> <span class="citation" id="citation--peikert2016decade--19">(<a href="#bib-peikert2016decade">2</a>)</span></p>
<h4 id="concrete-security-is-cost-model--reduction-chain" style="position:relative;"><a href="#concrete-security-is-cost-model--reduction-chain" aria-label="concrete security is cost model  reduction chain permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Concrete security is cost-model + reduction chain</h4>
<p>At the deployment layer, you do not size parameters from a reduction alone. You size them via:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>(reduction bound)</mtext><mtext>  </mtext><mo>∘</mo><mtext>  </mtext><mtext>(attack cost model)</mtext><mtext>  </mtext><mo>∘</mo><mtext>  </mtext><mtext>(hardware assumptions)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{(reduction bound)} \;\circ\; \text{(attack cost model)} \;\circ\; \text{(hardware assumptions)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">(reduction bound)</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∘</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">(attack cost model)</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∘</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">(hardware assumptions)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>For lattices, the attack model is dominated by BKZ/sieving-style heuristics, and the mapping to “bits” is done by tools like the lattice estimator. <span class="citation" id="citation--chennguyen2011bkz20--20">(<a href="#bib-chennguyen2011bkz20">7</a>)</span> <span class="citation" id="citation--albrechtlweestimator--21">(<a href="#bib-albrechtlweestimator">8</a>)</span></p>
<p>That means a PQC “security category” is not a theorem. It is a statement about a stack of assumptions:</p>
<ul>
<li>the underlying lattice problem hardness (for quantum or classical attackers),</li>
<li>the accuracy of BKZ/sieving cost models (time vs memory vs parallelism),</li>
<li>the translation from those costs to your adversary budget,</li>
<li>plus the reduction loss factors incurred by your scheme transform and protocol embedding.</li>
</ul>
<p>This is not pessimism. This is the minimum honest structure of the claim.</p>
<h3 id="44-the-security-margin-illusion-why-category-5-can-still-be-fragile" style="position:relative;"><a href="#44-the-security-margin-illusion-why-category-5-can-still-be-fragile" aria-label="44 the security margin illusion why category 5 can still be fragile permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.4 The security margin illusion (why “Category 5” can still be fragile)</h3>
<p>The industry likes crisp labels: “128-bit,” “Category 3,” “PQC-ready.” In practice:</p>
<ol>
<li>security margins move when cost models move;</li>
<li>reductions move when the oracle model changes (ROM vs QROM) or when the environment changes (single-user vs multi-user);</li>
<li>deployments move when system constraints force optimizations that violate proof assumptions (biased sampling, caching secrets, skipping constant-time discipline).</li>
</ol>
<p>Even for standardized schemes, the operational story is dominated by system budgets. ML-DSA (FIPS 204) produces signatures in the kilobyte range, and SLH-DSA (FIPS 205) produces signatures in the <em>multiple kilobyte to tens of kilobyte</em> range depending on parameter set; those are not philosophical costs, they are MTU, log storage, and firmware-update costs. <span class="citation" id="citation--nistfips204--22">(<a href="#bib-nistfips204">13</a>)</span> <span class="citation" id="citation--nistfips205--23">(<a href="#bib-nistfips205">14</a>)</span></p>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>A “higher category” scheme can be operationally <em>less safe</em> if it forces an implementation to cut corners (non-constant-time sampling, shared RNG state, partial verification shortcuts) to meet latency or RAM budgets. Loose reductions amplify exactly this failure mode by pushing parameters upward.</p>
</div>
<h3 id="45-tightness-vs-deployability-the-engineering-boundary" style="position:relative;"><a href="#45-tightness-vs-deployability-the-engineering-boundary" aria-label="45 tightness vs deployability the engineering boundary permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.5 Tightness vs deployability (the engineering boundary)</h3>
<p>If you want to treat tightness as an engineering artifact, you need to model the whole chain:</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  A<span class="token text string">["Assumption hardness (P)"]</span> <span class="token arrow operator">--></span> B<span class="token text string">["Reduction loss f(lambda, qH, N, ...)"]</span>
  B <span class="token arrow operator">--></span> C<span class="token text string">["Scheme parameters (sizes, rates, failure bounds)"]</span>
  C <span class="token arrow operator">--></span> D<span class="token text string">["Implementation artifacts (CPU, RNG, memory, constant-time)"]</span>
  D <span class="token arrow operator">--></span> E<span class="token text string">["Operational envelope (latency, MTU, telemetry, incident response)"]</span></code></pre></div>
<p>Loose reductions apply pressure at step (B). Pressure then propagates through (C) and (D) into (E). That is the honest reason “provably secure” does not mean “deployable.” Deployment is a boundary condition on parameters; tightness decides whether you can satisfy it without lying.</p>
<h3 id="46-embedded--edge-consequences-where-loose-reductions-become-safety-hazards" style="position:relative;"><a href="#46-embedded--edge-consequences-where-loose-reductions-become-safety-hazards" aria-label="46 embedded  edge consequences where loose reductions become safety hazards permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.6 Embedded / edge consequences (where loose reductions become safety hazards)</h3>
<p>Edge environments (IIoT gateways, Cortex-M-class devices, industrial controllers) do not fail gracefully under parameter inflation:</p>
<ul>
<li>RAM is measured in kilobytes; stack spills are crashes.</li>
<li>cache behavior is not noise; it is a leakage oracle.</li>
<li>timers are coarse; constant-time costs are amplified.</li>
<li>entropy at boot is weak; randomness reuse is a realistic failure mode.</li>
<li>power is a security channel (power analysis) and a reliability constraint (brownouts).</li>
</ul>
<p>So a reduction that “only” costs <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi><mi>κ</mi></mrow><annotation encoding="application/x-tex">\Delta\kappa</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span><span class="mord mathnormal">κ</span></span></span></span></span> bits often translates into:</p>
<ul>
<li>larger polynomials/NTT buffers,</li>
<li>more sampling work per signature,</li>
<li>more memory traffic per verification,</li>
<li>and a larger surface for side-channel and fault attacks.</li>
</ul>
<p>This is not theoretical. It is the lived reality of trying to ship PQC in adverse environments.</p>
<h3 id="47-formal-verification-cannot-fix-loose-reductions" style="position:relative;"><a href="#47-formal-verification-cannot-fix-loose-reductions" aria-label="47 formal verification cannot fix loose reductions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.7 Formal verification cannot fix loose reductions</h3>
<p>Formal verification is the right tool for proving:</p>
<ul>
<li>memory safety / absence of UB,</li>
<li>refinement between spec and implementation,</li>
<li>constant-time properties (under a model),</li>
<li>protocol state-machine invariants,</li>
<li>deterministic behavior under concurrency constraints.</li>
</ul>
<p>It cannot prove:</p>
<ul>
<li>that the reduction <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">f(\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span> is tight,</li>
<li>that your parameter sizing is adequate under the evolving lattice attack landscape,</li>
<li>that your threat model is aligned with the oracle interface (ROM vs QROM),</li>
<li>or that your cost model matches the attacker’s hardware and parallelism budget.</li>
</ul>
<p>Formal verification can ensure you implemented the scheme <em>you specified</em>. It does not validate the meta-assumptions that connect that scheme to a concrete “bits of security” statement. If the reduction is loose, you are still forced into parameter inflation; if the cost model is wrong, you are still exposed; if the threat model is wrong, your proof is still irrelevant.</p>
<h3 id="48-case-studies-ml-dsa-falcon-slh-dsa-different-failure-modes-same-tightness-problem" style="position:relative;"><a href="#48-case-studies-ml-dsa-falcon-slh-dsa-different-failure-modes-same-tightness-problem" aria-label="48 case studies ml dsa falcon slh dsa different failure modes same tightness problem permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.8 Case studies: ML-DSA, Falcon, SLH-DSA (different failure modes, same tightness problem)</h3>
<h4 id="ml-dsa-dilithium-lineage-reasonable-performance-big-artifacts" style="position:relative;"><a href="#ml-dsa-dilithium-lineage-reasonable-performance-big-artifacts" aria-label="ml dsa dilithium lineage reasonable performance big artifacts permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>ML-DSA (Dilithium lineage): reasonable performance, big artifacts</h4>
<p>ML-DSA is engineered for relatively efficient signing/verification compared to many alternatives, but signatures and public keys are large enough to be operationally visible. When tightness losses force parameter inflation, the first thing that breaks is not “the theorem.” It is certificate chains, protocol framing, and embedded memory budgets. <span class="citation" id="citation--nistfips204--24">(<a href="#bib-nistfips204">13</a>)</span></p>
<h4 id="falcon-smaller-signatures-fragile-implementations" style="position:relative;"><a href="#falcon-smaller-signatures-fragile-implementations" aria-label="falcon smaller signatures fragile implementations permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Falcon: smaller signatures, fragile implementations</h4>
<p>Falcon’s attraction is compact signatures, but the implementation surface is correspondingly sharper: floating-point hazards, subtle side-channel vectors, and constant-time difficulty can dominate the risk profile. Tightness does not save you if the system cannot preserve the model boundary. (This is why NIST treats Falcon as an additional standardization track rather than “the default.”) <span class="citation" id="citation--nistpqcproject--25">(<a href="#bib-nistpqcproject">15</a>)</span></p>
<h4 id="slh-dsa-sphincs-lineage-conservative-assumptions-brutal-operational-cost" style="position:relative;"><a href="#slh-dsa-sphincs-lineage-conservative-assumptions-brutal-operational-cost" aria-label="slh dsa sphincs lineage conservative assumptions brutal operational cost permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>SLH-DSA (SPHINCS+ lineage): conservative assumptions, brutal operational cost</h4>
<p>SLH-DSA is attractive as a non-lattice hedge, but it is operationally heavy. Loose reductions are not the main story here; the story is that even with conservative assumptions, the deployment cost is so high that teams will be tempted into unsafe shortcuts (truncation, caching, under-verified paths). Tightness and deployability are still linked: if your system cannot tolerate the overhead, you will violate assumptions. <span class="citation" id="citation--nistfips205--26">(<a href="#bib-nistfips205">14</a>)</span></p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>Deployability invariant:</strong> security assumptions must remain true under the operational envelope. If meeting latency/RAM/bandwidth targets forces you to violate constant-time, randomness, or verification rules, your system no longer instantiates the proven scheme.</p>
</div>
<h3 id="49-the-core-argument" style="position:relative;"><a href="#49-the-core-argument" aria-label="49 the core argument permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.9 The core argument</h3>
<p>Tightness determines whether security survives reality.</p>
<p>A proof without a deployable tightness profile is a claim about an object you cannot safely instantiate at scale. In PQC, that gap becomes visible because artifacts are big and the system boundary is tight: bandwidth, RAM, and leakage are not optional.</p>
<p>If you want a professional security claim, you must treat tightness as a first-class design constraint, and you must show how parameter sizing absorbs the loss without collapsing system safety.</p>
<h2 id="5-implications" style="position:relative;"><a href="#5-implications" aria-label="5 implications permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5. Implications</h2>
<ol>
<li><strong>Reduction loss must be part of the spec.</strong> Document <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mi>N</mi><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">f(\lambda, q_H, N, \dots)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span></span></span></span></span>, not just the underlying assumption.</li>
<li><strong>Query surfaces must be engineered.</strong> Protocol framing, transcript structure, and domain separation are not “implementation details.” They determine <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>.</li>
<li><strong>Concrete security must be treated as a living artifact.</strong> BKZ/sieving and hardware models move; you need telemetry and a reparameterization plan.</li>
<li><strong>Hardware-aware co-design is mandatory.</strong> If your target includes constrained nodes, assume that parameter inflation will push you into leakage and correctness failure modes.</li>
<li><strong>Formal verification remains necessary but insufficient.</strong> It closes the spec→binary gap; it does not validate the reduction→bits→ops gap.</li>
</ol>
<h2 id="6-continuity-hook" style="position:relative;"><a href="#6-continuity-hook" aria-label="6 continuity hook permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>6. Continuity Hook</h2>
<p>Part 5 will focus on <em>leakage-aware adversarial models</em> and the “constant-time fallacy”: how side-channel interfaces turn clean reductions into irrelevant statements, and how to treat constant-time and erasure as formal properties rather than best-effort hardening.</p>
<h2 id="7-references" style="position:relative;"><a href="#7-references" aria-label="7 references permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>7. References</h2>
<h3 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h3>
<ul>
<li>Exact-security framing and why constants/tightness matter: Bellare–Rogaway. <span class="citation" id="citation--bellarerogaway1996exactsecurity--27">(<a href="#bib-bellarerogaway1996exactsecurity">1</a>)</span></li>
<li>Forking lemma and ROM-era tightness limits in FS-shaped signatures: Pointcheval–Stern; Seurin. <span class="citation" id="citation--pointchevalstern1996securityproofs--28">(<a href="#bib-pointchevalstern1996securityproofs">4</a>)</span> <span class="citation" id="citation--seurin2012exactschnorr--29">(<a href="#bib-seurin2012exactschnorr">10</a>)</span></li>
<li>QROM shifts the proof interface and changes tightness profiles: Boneh et al.; Unruh; Don et al.; Grilo et al. <span class="citation" id="citation--bonehetal2010qrom--30">(<a href="#bib-bonehetal2010qrom">3</a>)</span> <span class="citation" id="citation--unruh2017fiatshamir--31">(<a href="#bib-unruh2017fiatshamir">5</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--32">(<a href="#bib-donetal2019fiatshamirqrom">9</a>)</span> <span class="citation" id="citation--griloetal2020tightreprogrammingqrom--33">(<a href="#bib-griloetal2020tightreprogrammingqrom">6</a>)</span></li>
<li>Concrete lattice attack cost modeling is heuristic and must be composed with reductions: Chen–Nguyen; the lattice estimator. <span class="citation" id="citation--chennguyen2011bkz20--34">(<a href="#bib-chennguyen2011bkz20">7</a>)</span> <span class="citation" id="citation--albrechtlweestimator--35">(<a href="#bib-albrechtlweestimator">8</a>)</span></li>
<li>Standardized PQC schemes have nontrivial artifact sizes that turn tightness into operations: FIPS 204 / FIPS 205. <span class="citation" id="citation--nistfips204--36">(<a href="#bib-nistfips204">13</a>)</span> <span class="citation" id="citation--nistfips205--37">(<a href="#bib-nistfips205">14</a>)</span></li>
</ul>
<h3 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h3>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> For every claim, write the full implication: attack on <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>⇒</mo></mrow><annotation encoding="application/x-tex">\Rightarrow</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.3669em;"></span><span class="mrel">⇒</span></span></span></span></span> solver for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span>, with explicit <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>ε</mi><mo separator="true">,</mo><mi>t</mi><mo separator="true">,</mo><msub><mi>q</mi><mi>H</mi></msub><mo separator="true">,</mo><mi>N</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(\varepsilon,t,q_H,N)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">ε</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mclose">)</span></span></span></span></span> dependence.</li>
<li class="task-list-item"><input type="checkbox" disabled> Compute <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi><mi>κ</mi><mo>≈</mo><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mi>f</mi></mrow><annotation encoding="application/x-tex">\Delta\kappa \approx \log_2 f</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span><span class="mord mathnormal">κ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span></span></span></span></span> and provision that headroom explicitly in parameter sizing.</li>
<li class="task-list-item"><input type="checkbox" disabled> Treat <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">q_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> as a protocol parameter (transcript structure, domain separation, aggregation strategy).</li>
<li class="task-list-item"><input type="checkbox" disabled> Validate that parameter inflation does not violate system budgets (MTU/RAM/cache) and does not force unsafe shortcuts.</li>
<li class="task-list-item"><input type="checkbox" disabled> Keep a reparameterization playbook: telemetry, versioned suite IDs, and removal deadlines for legacy parameter sets.</li>
</ul>
<h3 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h3>
<ul>
<li><a href="https://www.cs.ucdavis.edu/~rogaway/papers/exact.pdf" target="_blank" rel="nofollow noopener noreferrer">Bellare–Rogaway, “The Exact Security of Digital Signatures: How to Sign with RSA and Rabin” (1996)</a>. <span class="citation" id="citation--bellarerogaway1996exactsecurity--38">(<a href="#bib-bellarerogaway1996exactsecurity">1</a>)</span></li>
<li><a href="https://www.di.ens.fr/david.pointcheval/Documents/Papers/1996_eurocrypt.pdf" target="_blank" rel="nofollow noopener noreferrer">Pointcheval–Stern, “Security Proofs for Signature Schemes” (EUROCRYPT 1996)</a>. <span class="citation" id="citation--pointchevalstern1996securityproofs--39">(<a href="#bib-pointchevalstern1996securityproofs">4</a>)</span></li>
<li><a href="https://eprint.iacr.org/2012/029.pdf" target="_blank" rel="nofollow noopener noreferrer">Seurin, “On the Exact Security of Schnorr-Type Signatures in the ROM” (ePrint 2012/029)</a>. <span class="citation" id="citation--seurin2012exactschnorr--40">(<a href="#bib-seurin2012exactschnorr">10</a>)</span></li>
<li><a href="https://eprint.iacr.org/2010/428.pdf" target="_blank" rel="nofollow noopener noreferrer">Boneh et al., “Random Oracles in a Quantum World” (ePrint 2010/428)</a>. <span class="citation" id="citation--bonehetal2010qrom--41">(<a href="#bib-bonehetal2010qrom">3</a>)</span></li>
<li><a href="https://eprint.iacr.org/2017/398.pdf" target="_blank" rel="nofollow noopener noreferrer">Unruh, “Post-Quantum Security of Fiat-Shamir” (ePrint 2017/398)</a>. <span class="citation" id="citation--unruh2017fiatshamir--42">(<a href="#bib-unruh2017fiatshamir">5</a>)</span></li>
<li><a href="https://eprint.iacr.org/2019/190.pdf" target="_blank" rel="nofollow noopener noreferrer">Don–Fehr–Majenz–Schaffner, “Fiat-Shamir in the QROM” (ePrint 2019/190)</a>. <span class="citation" id="citation--donetal2019fiatshamirqrom--43">(<a href="#bib-donetal2019fiatshamirqrom">9</a>)</span></li>
<li><a href="https://eprint.iacr.org/2020/1361.pdf" target="_blank" rel="nofollow noopener noreferrer">Grilo–Hövelmanns–Hülsing–Majenz, “Tight Adaptive Reprogramming in the QROM” (ePrint 2020/1361)</a>. <span class="citation" id="citation--griloetal2020tightreprogrammingqrom--44">(<a href="#bib-griloetal2020tightreprogrammingqrom">6</a>)</span></li>
<li><a href="https://doi.org/10.1561/0400000074" target="_blank" rel="nofollow noopener noreferrer">Peikert, “A Decade of Lattice Cryptography” (2016)</a>. <span class="citation" id="citation--peikert2016decade--45">(<a href="#bib-peikert2016decade">2</a>)</span></li>
<li><a href="https://doi.org/10.1007/978-3-642-25385-0_1" target="_blank" rel="nofollow noopener noreferrer">Chen–Nguyen, “BKZ 2.0” (ASIACRYPT 2011)</a>. <span class="citation" id="citation--chennguyen2011bkz20--46">(<a href="#bib-chennguyen2011bkz20">7</a>)</span></li>
<li><a href="https://github.com/malb/lattice-estimator" target="_blank" rel="nofollow noopener noreferrer">LWE estimator</a>. <span class="citation" id="citation--albrechtlweestimator--47">(<a href="#bib-albrechtlweestimator">8</a>)</span></li>
<li><a href="https://csrc.nist.gov/pubs/fips/204/final" target="_blank" rel="nofollow noopener noreferrer">NIST FIPS 204 (ML-DSA)</a>. <span class="citation" id="citation--nistfips204--48">(<a href="#bib-nistfips204">13</a>)</span></li>
<li><a href="https://csrc.nist.gov/pubs/fips/205/final" target="_blank" rel="nofollow noopener noreferrer">NIST FIPS 205 (SLH-DSA)</a>. <span class="citation" id="citation--nistfips205--49">(<a href="#bib-nistfips205">14</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-bellarerogaway1996exactsecurity">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Bellare M, Rogaway P. The Exact Security of Digital Signatures: How to Sign with RSA and Rabin [Internet]. Manuscript; 1996. Available from: https://www.cs.ucdavis.edu/~rogaway/papers/exact.pdf</div>
  </div>
  <div class="csl-entry" id="bib-peikert2016decade">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Peikert C. A Decade of Lattice Cryptography [Internet]. 2016. Available from: https://doi.org/10.1561/0400000074</div>
  </div>
  <div class="csl-entry" id="bib-bonehetal2010qrom">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Boneh D, Dagdelen Ö, Fischlin M, Lehmann A, Schaffner C, Zhandry M. Random Oracles in a Quantum World [Internet]. Cryptology ePrint Archive, Paper 2010/428; 2010. Available from: https://eprint.iacr.org/2010/428.pdf</div>
  </div>
  <div class="csl-entry" id="bib-pointchevalstern1996securityproofs">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Pointcheval D, Stern J. Security Proofs for Signature Schemes. In: Advances in Cryptology – EUROCRYPT 1996 [Internet]. 1996. Available from: https://www.di.ens.fr/david.pointcheval/Documents/Papers/1996_eurocrypt.pdf</div>
  </div>
  <div class="csl-entry" id="bib-unruh2017fiatshamir">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">Unruh D. Post-Quantum Security of Fiat-Shamir [Internet]. Cryptology ePrint Archive, Paper 2017/398; 2017. Available from: https://eprint.iacr.org/2017/398.pdf</div>
  </div>
  <div class="csl-entry" id="bib-griloetal2020tightreprogrammingqrom">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">Grilo A, Hövelmanns K, Hülsing A, Majenz C. Tight Adaptive Reprogramming in the QROM [Internet]. Cryptology ePrint Archive, Paper 2020/1361; 2020. Available from: https://eprint.iacr.org/2020/1361.pdf</div>
  </div>
  <div class="csl-entry" id="bib-chennguyen2011bkz20">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">Chen Y, Nguyen PQ. BKZ 2.0: Better Lattice Security Estimates. In: Advances in Cryptology – ASIACRYPT 2011 [Internet]. 2011. Available from: https://doi.org/10.1007/978-3-642-25385-0_1</div>
  </div>
  <div class="csl-entry" id="bib-albrechtlweestimator">
    <div class="csl-left-margin">8. </div><div class="csl-right-inline">Albrecht MR, others. LWE estimator [Internet]. Web; Available from: https://github.com/malb/lattice-estimator</div>
  </div>
  <div class="csl-entry" id="bib-donetal2019fiatshamirqrom">
    <div class="csl-left-margin">9. </div><div class="csl-right-inline">Don J, Fehr S, Majenz C, Schaffner C. Security of the Fiat-Shamir Transformation in the Quantum Random-Oracle Model [Internet]. Cryptology ePrint Archive, Paper 2019/190; 2019. Available from: https://eprint.iacr.org/2019/190.pdf</div>
  </div>
  <div class="csl-entry" id="bib-seurin2012exactschnorr">
    <div class="csl-left-margin">10. </div><div class="csl-right-inline">Seurin Y. On the Exact Security of Schnorr-Type Signatures in the Random Oracle Model [Internet]. Cryptology ePrint Archive, Paper 2012/029; 2012. Available from: https://eprint.iacr.org/2012/029.pdf</div>
  </div>
  <div class="csl-entry" id="bib-zhandry2018recordqueries">
    <div class="csl-left-margin">11. </div><div class="csl-right-inline">Zhandry M. How to Record Quantum Queries, and Applications to Quantum Indifferentiability [Internet]. Cryptology ePrint Archive, Paper 2018/276; 2018. Available from: https://eprint.iacr.org/2018/276.pdf</div>
  </div>
  <div class="csl-entry" id="bib-regev2009lwe">
    <div class="csl-left-margin">12. </div><div class="csl-right-inline">Regev O. On Lattices, Learning with Errors, Random Linear Codes, and Cryptography. Journal of the ACM [Internet]. 2009;56(6). Available from: https://doi.org/10.1145/1568318.1568324</div>
  </div>
  <div class="csl-entry" id="bib-nistfips204">
    <div class="csl-left-margin">13. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/204/final</div>
  </div>
  <div class="csl-entry" id="bib-nistfips205">
    <div class="csl-left-margin">14. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/205/final</div>
  </div>
  <div class="csl-entry" id="bib-nistpqcproject">
    <div class="csl-left-margin">15. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography Standardization [Internet]. Web; 2026. Available from: https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Post-Quantum-Cryptography-Standardization?data1=v2</div>
  </div>
</div>]]></content>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="formal-methods"/>
        <category label="reductions"/>
        <category label="concrete-security"/>
        <category label="lattices"/>
        <category label="fiat-shamir"/>
        <category label="QROM"/>
        <category label="security-engineering"/>
        <category label="embedded"/>
        <category label="systems"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC Research Series — Part 3]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-pqc-research-day-3-qrom-where-classical-proofs-stop-working</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-pqc-research-day-3-qrom-where-classical-proofs-stop-working"/>
        <updated>2026-04-30T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[QROM is not “ROM but stronger.” It changes the oracle interface (superposition queries), breaks classical proof tactics (rewinding/programming), and turns Fiat–Shamir security into a tighter, system-bound claim.]]></summary>
        <content type="html"><![CDATA[<h2 id="quantum-random-oracle-model-where-classical-proofs-stop-working" style="position:relative;"><a href="#quantum-random-oracle-model-where-classical-proofs-stop-working" aria-label="quantum random oracle model where classical proofs stop working permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Quantum Random Oracle Model: Where Classical Proofs Stop Working</h2>
<p>Author: Mayckon Giovani<br>
Date: April 30, 2026<br>
Series: PQC Research Series<br>
Tags: PQC, Formal Methods, Cryptography, Systems</p>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>Security proofs built in ROM assume an oracle interface that quantum adversaries do not respect. In QROM the adversary can query the hash/KDF in superposition, which makes “record all queries,” “rewind,” and “program the oracle at <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>” fundamentally different operations. Fiat–Shamir survives in many important cases, but the proof obligations are sharper, the reductions are typically less tight, and the system boundary (what is actually quantum-queryable) becomes part of the security statement. <span class="citation" id="citation--bonehetal2010qrom--1">(<a href="#bib-bonehetal2010qrom">1</a>)</span> <span class="citation" id="citation--zhandry2018recordqueries--2">(<a href="#bib-zhandry2018recordqueries">2</a>)</span> <span class="citation" id="citation--unruh2017fiatshamir--3">(<a href="#bib-unruh2017fiatshamir">3</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--4">(<a href="#bib-donetal2019fiatshamirqrom">4</a>)</span></p>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>QROM is a <em>different oracle interface</em>, not a stronger attacker in the same interface.</li>
<li>In ROM, “lazy sampling + programming + rewinding” is a standard reduction toolbox; in QROM the same words denote operations that disturb the adversary state or require nontrivial bounds.</li>
<li>Fiat–Shamir in QROM is possible but conditional: extraction is not generic, and tightness can degrade sharply.</li>
<li>Systems matter: if your hash is public and deterministic, you should assume quantum-accessible evaluation (coherent implementation), even if the endpoints are classical.</li>
<li>If your model boundary is wrong, your proof is irrelevant.</li>
</ul>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>QROM does not just make attacks stronger.</strong> It invalidates the assumptions behind how we prove security: query transcripts are not observable, oracle programming is global, and classical rewinding is not a generic operation.</p>
</div>
<h2 id="0-context" style="position:relative;"><a href="#0-context" aria-label="0 context permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>0. Context</h2>
<p>ROM is “too useful” in practice: it turns hash functions into ideal objects and lets us prove security for transforms and protocols that are otherwise intractable. A large fraction of deployed cryptography (including most Fiat–Shamir-based signatures and many non-interactive ZK stacks) still leans on ROM-style reasoning.</p>
<p>The problem is that ROM assumes a classical interface to the oracle. In 2026 this is no longer the conservative model for any public, deterministic function (SHA-2/SHA-3/BLAKE2/BLAKE3, KDFs, transcript hashes): a quantum adversary can implement those circuits coherently and query them in superposition. That interface shift is exactly what QROM captures. <span class="citation" id="citation--bonehetal2010qrom--5">(<a href="#bib-bonehetal2010qrom">1</a>)</span></p>
<p>Security proofs built in ROM assume an interface that quantum adversaries do not respect.</p>
<h2 id="1-problem-statement" style="position:relative;"><a href="#1-problem-statement" aria-label="1 problem statement permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1. Problem Statement</h2>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi><mo>∈</mo><mi mathvariant="double-struck">N</mi></mrow><annotation encoding="application/x-tex">\lambda \in \N</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">λ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord mathbb">N</span></span></span></span></span> be the security parameter. Fix an output length <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\ell(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">ℓ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> and consider a random oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> as an idealized hash/KDF:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>H</mi><mo>:</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mo>∗</mo></msup><mo>→</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">H : \{0,1\}^\ast \to \{0,1\}^{\ell(\lambda)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7387em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">∗</span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.188em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>In classical ROM, an adversary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">A</mi></mrow><annotation encoding="application/x-tex">\adv</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">A</span></span></span></span></span> is a PPT oracle machine that makes a sequence of classical queries <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>x</mi><mn>1</mn></msub><mo separator="true">,</mo><mo>…</mo><mo separator="true">,</mo><msub><mi>x</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">x_1,\dots,x_{q}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7167em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> and receives classical answers <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><msub><mi>x</mi><mi>i</mi></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x_i)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>.</p>
<p>The security statement of a scheme <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> in ROM has the familiar shape:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi mathvariant="script">A</mi><mo>∈</mo><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">P</mi><mi mathvariant="normal">T</mi></mrow><mo>:</mo><mspace width="1em"></mspace><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi><mrow><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msubsup><mo stretchy="false">(</mo><mi mathvariant="script">A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall \adv \in \mathrm{PPT}:\quad \mathrm{Adv}^{\mathrm{ROM}}_{\Pi}(\adv;\lambda) \le \mathrm{negl}(\lambda).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord">∀</span><span class="mord mathcal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">PPT</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1757em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9257em;"><span style="top:-2.453em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">ROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathcal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">negl</span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Now change only one thing: the adversary is quantum polynomial-time and can query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> <em>coherently</em> in superposition. The right object is no longer a “function oracle” but a unitary oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>.</p>
<p>The problem is then:</p>
<blockquote>
<p>What changes when the adversary can query the oracle in superposition?</p>
</blockquote>
<p>Formally, we want to understand how the advantage bound, the reduction technique, and the proof obligations change when we move from ROM to QROM:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi><mrow><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msubsup><mo stretchy="false">(</mo><mi mathvariant="script">A</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mo><mover><mo><mo>≈</mo></mo><mo stretchy="false" lspace="0em" rspace="0em">?</mo></mover></mo><mspace width="1em"></mspace><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msubsup><mo stretchy="false">(</mo><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}^{\mathrm{ROM}}_{\Pi}(\adv) \quad\stackrel{?}{\approx}\quad \mathrm{Adv}^{\mathrm{QROM}}_{\Pi}(\adv_Q).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.5192em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9257em;"><span style="top:-2.453em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">ROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathcal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mop op-limits"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:1.2692em;"><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span><span class="mop">≈</span></span></span><span style="top:-3.6831em;margin-left:0em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mclose mtight">?</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.2528em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9592em;"><span style="top:-2.4065em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">QROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>The answer is not “add Grover factors.” The answer is: the proof techniques themselves stop being valid unless reworked. <span class="citation" id="citation--bonehetal2010qrom--6">(<a href="#bib-bonehetal2010qrom">1</a>)</span> <span class="citation" id="citation--zhandry2018recordqueries--7">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<h2 id="2-formal-model" style="position:relative;"><a href="#2-formal-model" aria-label="2 formal model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2. Formal Model</h2>
<h3 id="21-classical-rom--formal-definition" style="position:relative;"><a href="#21-classical-rom--formal-definition" aria-label="21 classical rom  formal definition permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1 Classical ROM — Formal Definition</h3>
<h4 id="211-oracle-definition-and-interaction" style="position:relative;"><a href="#211-oracle-definition-and-interaction" aria-label="211 oracle definition and interaction permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1.1 Oracle definition and interaction</h4>
<p>In ROM, the challenger samples a function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> uniformly from the set of all functions <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mo>∗</mo></msup><mo>→</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup></mrow><annotation encoding="application/x-tex">\{0,1\}^\ast \to \{0,1\}^{\ell(\lambda)}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">∗</span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.138em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.888em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span></span></span></span></span>. The adversary interacts via classical queries:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>x</mi><mo>↦</mo><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">x \mapsto H(x).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.522em;vertical-align:-0.011em;"></span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">↦</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>The standard implementation of ROM in proofs is <em>lazy sampling</em>: <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span></span></span></span></span> is defined on first query and stored in a table.</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">state T : map from {0,1}* to {0,1}^ℓ

Oracle H(x):
  if x ∈ dom(T): return T[x]
  y ←$ {0,1}^ℓ
  T[x] := y
  return y</code></pre></div>
<p>This is the object that enables classical ROM proof moves.</p>
<h4 id="212-classical-proof-moves-in-rom" style="position:relative;"><a href="#212-classical-proof-moves-in-rom" aria-label="212 classical proof moves in rom permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1.2 Classical proof moves in ROM</h4>
<p>ROM reductions frequently rely on three operations:</p>
<ol>
<li><strong>Observe queries.</strong> The reduction records every <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi></mrow><annotation encoding="application/x-tex">x</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">x</span></span></span></span></span> queried to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span>.</li>
<li><strong>Reprogram the oracle.</strong> The reduction sets <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><msup><mi>x</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo><mo>:</mo><mo>=</mo><msup><mi>y</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">H(x^\star) := y^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8831em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> after seeing some adversary behavior.</li>
<li><strong>Rewind.</strong> The reduction replays the adversary from a previous point with modified oracle responses to extract a witness (forking lemma style).</li>
</ol>
<p>These moves are not “syntactic conveniences.” They are model-level assumptions about the oracle interface.</p>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>When someone says “we prove it in ROM,” what they usually mean is “our reduction depends on being able to <em>observe</em> oracle queries, <em>program</em> oracle outputs, and <em>rewind</em> the adversary.” QROM changes all three.</p>
</div>
<h3 id="22-qrom--formal-shift-where-the-pain-starts" style="position:relative;"><a href="#22-qrom--formal-shift-where-the-pain-starts" aria-label="22 qrom  formal shift where the pain starts permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.2 QROM — Formal Shift (where the pain starts)</h3>
<h4 id="221-unitary-oracle-interface" style="position:relative;"><a href="#221-unitary-oracle-interface" aria-label="221 unitary oracle interface permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.2.1 Unitary oracle interface</h4>
<p>In QROM, the oracle is a unitary operation over two registers:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub><mo>:</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>x</mi><mo stretchy="false">⟩</mo><mi mathvariant="normal">∣</mi><mi>y</mi><mo stretchy="false">⟩</mo><mo>↦</mo><mi mathvariant="normal">∣</mi><mi>x</mi><mo stretchy="false">⟩</mo><mi mathvariant="normal">∣</mi><mi>y</mi><mo>⊕</mo><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mo stretchy="false">⟩</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">U_H:\ |x\rangle|y\rangle \mapsto |x\rangle|y \oplus H(x)\rangle.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal">x</span><span class="mclose">⟩</span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="mclose">⟩</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">↦</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal">x</span><span class="mclose">⟩</span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⊕</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)⟩</span><span class="mord">.</span></span></span></span></span></div>
<p>A QROM adversary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">\adv_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is a QPT algorithm (poly-size uniform quantum circuits) that can interleave its own unitaries with calls to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∣</mi><msub><mi>ψ</mi><mrow><mi>i</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">⟩</mo><mo>=</mo><msub><mi>U</mi><mrow><mi>i</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>⋅</mo><mo stretchy="false">(</mo><msub><mi>U</mi><mi>H</mi></msub><mo>⊗</mo><mi>I</mi><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><msub><mi>ψ</mi><mi>i</mi></msub><mo stretchy="false">⟩</mo><mo separator="true">,</mo><mspace width="2em"></mspace><mi>i</mi><mo>=</mo><mn>0</mn><mo separator="true">,</mo><mo>…</mo><mo separator="true">,</mo><mi>q</mi><mo>−</mo><mn>1.</mn></mrow><annotation encoding="application/x-tex">|\psi_{i+1}\rangle = U_{i+1}\cdot (U_H \otimes I)\ |\psi_i\rangle,\qquad i=0,\dots,q-1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">ψ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">i</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">⟩</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8917em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">i</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⊗</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∣</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">ψ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">⟩</span><span class="mpunct">,</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8389em;vertical-align:-0.1944em;"></span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.</span></span></span></span></span></div>
<p>The observable object is not a query transcript. It is a final classical measurement outcome after a sequence of coherent operations.</p>
<p>One subtlety that matters for proofs: in ROM, “lazy sampling” gives a concrete simulation strategy for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> without ever materializing the full random function. In QROM, you still conceptually sample a random function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span>, but the adversary’s access is through a unitary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> that must behave consistently on <em>superpositions</em>. Naively “defining <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span></span></span></span></span> on demand” is no longer a complete description of how the oracle acts, because the simulator cannot simply observe which <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi></mrow><annotation encoding="application/x-tex">x</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">x</span></span></span></span></span> values are being queried.</p>
<p>This is the gap that QROM techniques bridge: they construct simulators and hybrid arguments that bound what a <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-query quantum adversary can learn or distinguish about changes to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> without requiring an impossible transcript log. <span class="citation" id="citation--bonehetal2010qrom--8">(<a href="#bib-bonehetal2010qrom">1</a>)</span> <span class="citation" id="citation--zhandry2018recordqueries--9">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<h4 id="222-why-recording-queries-is-not-a-primitive" style="position:relative;"><a href="#222-why-recording-queries-is-not-a-primitive" aria-label="222 why recording queries is not a primitive permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.2.2 Why “recording queries” is not a primitive</h4>
<p>Consider a single query state in the <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi></mrow><annotation encoding="application/x-tex">x</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">x</span></span></span></span></span>-register:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∣</mi><mi>ϕ</mi><mo stretchy="false">⟩</mo><mo>=</mo><munder><mo>∑</mo><mi>x</mi></munder><msub><mi>α</mi><mi>x</mi></msub><mi mathvariant="normal">∣</mi><mi>x</mi><mo stretchy="false">⟩</mo><mi mathvariant="normal">∣</mi><mn>0</mn><mo stretchy="false">⟩</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">|\phi\rangle = \sum_{x} \alpha_x |x\rangle|0\rangle.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal">ϕ</span><span class="mclose">⟩</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3em;vertical-align:-1.25em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.9em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">x</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.25em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.0037em;">α</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0037em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">x</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">∣</span><span class="mord mathnormal">x</span><span class="mclose">⟩</span><span class="mord">∣0</span><span class="mclose">⟩</span><span class="mord">.</span></span></span></span></span></div>
<p>After the oracle call:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><msub><mi>U</mi><mi>H</mi></msub><mo>⊗</mo><mi>I</mi><mo stretchy="false">)</mo><mi mathvariant="normal">∣</mi><mi>ϕ</mi><mo stretchy="false">⟩</mo><mo>=</mo><munder><mo>∑</mo><mi>x</mi></munder><msub><mi>α</mi><mi>x</mi></msub><mi mathvariant="normal">∣</mi><mi>x</mi><mo stretchy="false">⟩</mo><mi mathvariant="normal">∣</mi><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mo stretchy="false">⟩</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(U_H \otimes I)|\phi\rangle = \sum_{x} \alpha_x |x\rangle|H(x)\rangle.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⊗</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mclose">)</span><span class="mord">∣</span><span class="mord mathnormal">ϕ</span><span class="mclose">⟩</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3em;vertical-align:-1.25em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.9em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">x</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.25em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.0037em;">α</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0037em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">x</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">∣</span><span class="mord mathnormal">x</span><span class="mclose">⟩</span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)⟩</span><span class="mord">.</span></span></span></span></span></div>
<p>The query register is now entangled with the answer register. If the reduction measures the query register to “see which <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi></mrow><annotation encoding="application/x-tex">x</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">x</span></span></span></span></span> was asked,” it collapses the state and changes the adversary’s future behavior. There is no free transcript.</p>
<p>You can make this quantitative with the right notion of “disturbance.”</p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> be a point you care about (e.g., the fork point, the programmed point). Define the projector <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi><mo>=</mo><mi mathvariant="normal">∣</mi><msup><mi>x</mi><mo>⋆</mo></msup><mo stretchy="false">⟩</mo><mo stretchy="false">⟨</mo><msup><mi>x</mi><mo>⋆</mo></msup><mi mathvariant="normal">∣</mi></mrow><annotation encoding="application/x-tex">P = |x^\star\rangle\langle x^\star|</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">⟩</span><span class="mopen">⟨</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mord">∣</span></span></span></span></span> on the query register and let:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>p</mi><mo>:</mo><mo>=</mo><mi mathvariant="normal">∥</mi><mo stretchy="false">(</mo><mi>P</mi><mo>⊗</mo><mi>I</mi><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>ϕ</mi><mo stretchy="false">⟩</mo><msup><mi mathvariant="normal">∥</mi><mn>2</mn></msup><mo>=</mo><mi mathvariant="normal">∣</mi><msub><mi>α</mi><msup><mi>x</mi><mo>⋆</mo></msup></msub><msup><mi mathvariant="normal">∣</mi><mn>2</mn></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">p := \| (P \otimes I)\,|\phi\rangle \|^2 = |\alpha_{x^\star}|^2.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">p</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∥</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⊗</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.1141em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∣</span><span class="mord mathnormal">ϕ</span><span class="mclose">⟩</span><span class="mord"><span class="mord">∥</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8641em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1141em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.0037em;">α</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2828em;"><span style="top:-2.55em;margin-left:-0.0037em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6183em;"><span style="top:-2.786em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord"><span class="mord">∣</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8641em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>If you measure the two-outcome POVM <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">{</mo><mi>P</mi><mo separator="true">,</mo><mi>I</mi><mo>−</mo><mi>P</mi><mo stretchy="false">}</mo></mrow><annotation encoding="application/x-tex">\{P, I-P\}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">}</span></span></span></span></span> and discard the outcome, you obtain a mixed state <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ρ</mi></mrow><annotation encoding="application/x-tex">\rho</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">ρ</span></span></span></span></span>.
The trace distance to the original state is bounded by a term on the order of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msqrt><mi>p</mi></msqrt></mrow><annotation encoding="application/x-tex">\sqrt{p}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.04em;vertical-align:-0.3369em;"></span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7031em;"><span class="svg-align" style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord" style="padding-left:0.833em;"><span class="mord mathnormal">p</span></span></span><span style="top:-2.6631em;"><span class="pstrut" style="height:3em;"></span><span class="hide-tail" style="min-width:0.853em;height:1.08em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.08em" viewBox="0 0 400000 1080" preserveAspectRatio="xMinYMin slice"><path d="M95,702
c-2.7,0,-7.17,-2.7,-13.5,-8c-5.8,-5.3,-9.5,-10,-9.5,-14
c0,-2,0.3,-3.3,1,-4c1.3,-2.7,23.83,-20.7,67.5,-54
c44.2,-33.3,65.8,-50.3,66.5,-51c1.3,-1.3,3,-2,5,-2c4.7,0,8.7,3.3,12,10
s173,378,173,378c0.7,0,35.3,-71,104,-213c68.7,-142,137.5,-285,206.5,-429
c69,-144,104.5,-217.7,106.5,-221
l0 -0
c5.3,-9.3,12,-14,20,-14
H400000v40H845.2724
s-225.272,467,-225.272,467s-235,486,-235,486c-2.7,4.7,-9,7,-19,7
c-6,0,-10,-1,-12,-3s-194,-422,-194,-422s-65,47,-65,47z
M834 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3369em;"><span></span></span></span></span></span></span></span></span></span> (formal constants depend on the exact measurement map, but the scaling is the key): if the adversary assigns negligible amplitude to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>, then “checking whether <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> was queried” can be a <em>gentle</em> operation; if it assigns non-negligible amplitude, measurement meaningfully perturbs the computation. (For the standard trace-distance/fidelity calculus underlying these bounds, see e.g. Nielsen–Chuang and the Fuchs–van de Graaf inequalities.) <span class="citation" id="citation--nielsenchuang2010--10">(<a href="#bib-nielsenchuang2010">5</a>)</span> <span class="citation" id="citation--fuchsgraaf1999--11">(<a href="#bib-fuchsgraaf1999">6</a>)</span></p>
<p>That is the deep point: in QROM, “did it query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>?” is not a boolean event. It is an amplitude question.</p>
<p>This is why ROM techniques need replacement lemmas (compressed oracle, measure-and-reprogram, quantum rewinding variants) instead of direct reuse. <span class="citation" id="citation--zhandry2018recordqueries--12">(<a href="#bib-zhandry2018recordqueries">2</a>)</span> <span class="citation" id="citation--watrous2009zk--13">(<a href="#bib-watrous2009zk">7</a>)</span></p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  A<span class="token text string">["ROM reduction"]</span> <span class="token arrow operator">--></span> T<span class="token text string">["classical transcript"]</span>
  A <span class="token arrow operator">--></span> P<span class="token text string">["point programming at x_star"]</span>
  A <span class="token arrow operator">--></span> R<span class="token text string">["rewinding / forking"]</span>
  Q<span class="token text string">["QROM adversary state (ket psi)"]</span> <span class="token arrow operator">--></span> X<span class="token text string">["measurement disturbance"]</span>
  X <span class="token arrow operator">--></span> T
  X <span class="token arrow operator">--></span> R
  Q <span class="token arrow operator">--></span> UH<span class="token text string">["unitary oracle U_H"]</span></code></pre></div>
<h3 id="23-where-classical-proof-techniques-break" style="position:relative;"><a href="#23-where-classical-proof-techniques-break" aria-label="23 where classical proof techniques break permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3 Where Classical Proof Techniques Break</h3>
<h4 id="231-rewinding-fails-in-general" style="position:relative;"><a href="#231-rewinding-fails-in-general" aria-label="231 rewinding fails in general permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3.1 Rewinding fails (in general)</h4>
<p>Classical rewinding assumes you can replay <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">A</mi></mrow><annotation encoding="application/x-tex">\adv</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">A</span></span></span></span></span> from a previous internal state. Quantum algorithms do not expose their internal state without measurement, and measurement is destructive.</p>
<p>More formally, let the adversary’s internal state at some point be <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">∣</mi><mi>ψ</mi><mo stretchy="false">⟩</mo></mrow><annotation encoding="application/x-tex">|\psi\rangle</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">ψ</span><span class="mclose">⟩</span></span></span></span></span>. Any attempt to “copy” <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">∣</mi><mi>ψ</mi><mo stretchy="false">⟩</mo></mrow><annotation encoding="application/x-tex">|\psi\rangle</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">ψ</span><span class="mclose">⟩</span></span></span></span></span> violates no-cloning, and any attempt to “observe” it induces a measurement map <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">M</mi></mrow><annotation encoding="application/x-tex">\mathcal{M}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">M</span></span></span></span></span> that changes the state.</p>
<p>There are quantum rewinding techniques (Watrous-style) that work for restricted protocol structures (public-coin, certain ZK settings), but they are not a generic replacement for the classical forking lemma pipeline used in ROM proofs. In other words: the extraction interface changes. <span class="citation" id="citation--watrous2009zk--14">(<a href="#bib-watrous2009zk">7</a>)</span></p>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>If your proof relies on a classical extractor that forks a transcript by rewinding the adversary, you must <em>explicitly</em> justify why quantum rewinding applies in your protocol class. Otherwise you are proving a property about a machine model that does not exist.</p>
</div>
<h4 id="232-programming-the-oracle-is-a-global-operation" style="position:relative;"><a href="#232-programming-the-oracle-is-a-global-operation" aria-label="232 programming the oracle is a global operation permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3.2 Programming the oracle is a global operation</h4>
<p>In ROM, reprogramming is local: define <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><msup><mi>x</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x^\star)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> late, or change it, and reason about the probability that <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">A</mi></mrow><annotation encoding="application/x-tex">\adv</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">A</span></span></span></span></span> queried <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>.</p>
<p>In QROM, reprogramming is not local in the same way because the adversary can query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> with small amplitude across many coherent queries.</p>
<p>A standard quantitative intuition is captured by “hybrid” bounds for quantum queries: if two oracles <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>H</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">H'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span> differ on a small set of inputs, then any <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-query QPT distinguisher has advantage bounded by a term that scales like <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi><msqrt><mrow><mi>t</mi><mi mathvariant="normal">/</mi><mi mathvariant="normal">∣</mi><mi>D</mi><mi mathvariant="normal">∣</mi></mrow></msqrt></mrow><annotation encoding="application/x-tex">q\sqrt{t/|D|}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.24em;vertical-align:-0.305em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.935em;"><span class="svg-align" style="top:-3.2em;"><span class="pstrut" style="height:3.2em;"></span><span class="mord" style="padding-left:1em;"><span class="mord mathnormal">t</span><span class="mord">/∣</span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span><span class="mord">∣</span></span></span><span style="top:-2.895em;"><span class="pstrut" style="height:3.2em;"></span><span class="hide-tail" style="min-width:1.02em;height:1.28em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.28em" viewBox="0 0 400000 1296" preserveAspectRatio="xMinYMin slice"><path d="M263,681c0.7,0,18,39.7,52,119
c34,79.3,68.167,158.7,102.5,238c34.3,79.3,51.8,119.3,52.5,120
c340,-704.7,510.7,-1060.3,512,-1067
l0 -0
c4.7,-7.3,11,-11,19,-11
H40000v40H1012.3
s-271.3,567,-271.3,567c-38.7,80.7,-84,175,-136,283c-52,108,-89.167,185.3,-111.5,232
c-22.3,46.7,-33.8,70.3,-34.5,71c-4.7,4.7,-12.3,7,-23,7s-12,-1,-12,-1
s-109,-253,-109,-253c-72.7,-168,-109.3,-252,-110,-252c-10.7,8,-22,16.7,-34,26
c-22,17.3,-33.3,26,-34,26s-26,-26,-26,-26s76,-59,76,-59s76,-60,76,-60z
M1001 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.305em;"><span></span></span></span></span></span></span></span></span></span> (domain size <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">∣</mi><mi>D</mi><mi mathvariant="normal">∣</mi></mrow><annotation encoding="application/x-tex">|D|</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span><span class="mord">∣</span></span></span></span></span>, difference set size <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>t</mi></mrow><annotation encoding="application/x-tex">t</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord mathnormal">t</span></span></span></span></span>). In the single-point case (<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>t</mi><mo>=</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">t=1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span>), the effect of changing one value is upper bounded by <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mover accent="true"><mi>O</mi><mo>~</mo></mover><mo stretchy="false">(</mo><mi>q</mi><mi mathvariant="normal">/</mi><msqrt><mrow><mi mathvariant="normal">∣</mi><mi>D</mi><mi mathvariant="normal">∣</mi></mrow></msqrt><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\tilde{O}(q/\sqrt{|D|})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.24em;vertical-align:-0.305em;"></span><span class="mord accent"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.9202em;"><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span></span><span style="top:-3.6023em;"><span class="pstrut" style="height:3em;"></span><span class="accent-body" style="left:-0.1667em;"><span class="mord">~</span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mord">/</span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.935em;"><span class="svg-align" style="top:-3.2em;"><span class="pstrut" style="height:3.2em;"></span><span class="mord" style="padding-left:1em;"><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span><span class="mord">∣</span></span></span><span style="top:-2.895em;"><span class="pstrut" style="height:3.2em;"></span><span class="hide-tail" style="min-width:1.02em;height:1.28em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.28em" viewBox="0 0 400000 1296" preserveAspectRatio="xMinYMin slice"><path d="M263,681c0.7,0,18,39.7,52,119
c34,79.3,68.167,158.7,102.5,238c34.3,79.3,51.8,119.3,52.5,120
c340,-704.7,510.7,-1060.3,512,-1067
l0 -0
c4.7,-7.3,11,-11,19,-11
H40000v40H1012.3
s-271.3,567,-271.3,567c-38.7,80.7,-84,175,-136,283c-52,108,-89.167,185.3,-111.5,232
c-22.3,46.7,-33.8,70.3,-34.5,71c-4.7,4.7,-12.3,7,-23,7s-12,-1,-12,-1
s-109,-253,-109,-253c-72.7,-168,-109.3,-252,-110,-252c-10.7,8,-22,16.7,-34,26
c-22,17.3,-33.3,26,-34,26s-26,-26,-26,-26s76,-59,76,-59s76,-60,76,-60z
M1001 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.305em;"><span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>. This is the same phenomenon behind Grover optimality bounds. <span class="citation" id="citation--bbbv1997--15">(<a href="#bib-bbbv1997">8</a>)</span></p>
<p>To make that concrete, fix a finite domain <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>D</mi></mrow><annotation encoding="application/x-tex">D</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span></span></span></span></span> with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">∣</mi><mi>D</mi><mi mathvariant="normal">∣</mi><mo>=</mo><mi>N</mi></mrow><annotation encoding="application/x-tex">|D|=N</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span></span></span></span></span> and consider two random oracles <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo separator="true">,</mo><msup><mi>H</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">H,H'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9463em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span> that are identical everywhere except at a single point <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><msup><mi>x</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo><mo mathvariant="normal">≠</mo><msup><mi>H</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo stretchy="false">(</mo><msup><mi>x</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x^\star)\neq H'(x^\star)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mrel"><span class="mord vbox"><span class="thinbox"><span class="rlap"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="inner"><span class="mord"><span class="mrel"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace nobreak"></span><span class="mrel">=</span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0019em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>. Then any quantum algorithm <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">\adv_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> making at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span> quantum queries to the oracle satisfies an inequality of the form:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">∣</mo><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi></mrow><mo stretchy="false">[</mo><msubsup><mi mathvariant="script">A</mi><mi>Q</mi><msub><mi>U</mi><mi>H</mi></msub></msubsup><mo>⇒</mo><mn>1</mn><mo stretchy="false">]</mo><mo>−</mo><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi></mrow><mo stretchy="false">[</mo><msubsup><mi mathvariant="script">A</mi><mi>Q</mi><msub><mi>U</mi><msup><mi>H</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></msub></msubsup><mo>⇒</mo><mn>1</mn><mo stretchy="false">]</mo><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">∣</mo><mtext>  </mtext><mo>≤</mo><mtext>  </mtext><mi>O</mi><mtext> ⁣</mtext><mrow><mo fence="true">(</mo><mfrac><mi>q</mi><msqrt><mi>N</mi></msqrt></mfrac><mo fence="true">)</mo></mrow><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\Bigl|\Pr[\adv_Q^{U_H} \Rightarrow 1] - \Pr[\adv_Q^{U_{H'}} \Rightarrow 1]\Bigr|
\;\le\; O\!\left(\frac{q}{\sqrt{N}}\right),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mopen"><span class="delimsizing mult"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.15em;"><span style="top:-3.15em;"><span class="pstrut" style="height:3.8em;"></span><span style="width:0.333em;height:1.800em;"><svg xmlns="http://www.w3.org/2000/svg" width="0.333em" height="1.800em" viewBox="0 0 333 1800"><path d="M145 15 v585 v600 v585 c2.667,10,9.667,15,21,15
c10,0,16.667,-5,20,-15 v-585 v-600 v-585 c-2.667,-10,-9.667,-15,-21,-15
c-10,0,-16.667,5,-20,15z M188 15 H145 v585 v600 v585 h43z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.65em;"><span></span></span></span></span></span></span><span class="mord"><span class="mord mathrm">Pr</span></span><span class="mopen">[</span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9234em;"><span style="top:-2.4065em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span><span style="top:-3.1451em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3567em;margin-left:-0.109em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1433em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.4296em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.4362em;vertical-align:-0.4296em;"></span><span class="mord"><span class="mord mathrm">Pr</span></span><span class="mopen">[</span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.0066em;"><span style="top:-2.4065em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span><span style="top:-3.2282em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3448em;margin-left:-0.109em;margin-right:0.0714em;"><span class="pstrut" style="height:2.6068em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8496em;"><span style="top:-2.8496em;margin-right:0.1em;"><span class="pstrut" style="height:2.5556em;"></span><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.262em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.4296em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord">1</span><span class="mclose">]</span><span class="mclose"><span class="delimsizing mult"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.15em;"><span style="top:-3.15em;"><span class="pstrut" style="height:3.8em;"></span><span style="width:0.333em;height:1.800em;"><svg xmlns="http://www.w3.org/2000/svg" width="0.333em" height="1.800em" viewBox="0 0 333 1800"><path d="M145 15 v585 v600 v585 c2.667,10,9.667,15,21,15
c10,0,16.667,-5,20,-15 v-585 v-600 v-585 c-2.667,-10,-9.667,-15,-21,-15
c-10,0,-16.667,5,-20,15z M188 15 H145 v585 v600 v585 h43z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.65em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.4em;vertical-align:-0.95em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span><span class="mspace" style="margin-right:-0.1667em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner"><span class="mopen delimcenter" style="top:0em;"><span class="delimsizing size3">(</span></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.1076em;"><span style="top:-2.1833em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9267em;"><span class="svg-align" style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord" style="padding-left:0.833em;"><span class="mord mathnormal" style="margin-right:0.10903em;">N</span></span></span><span style="top:-2.8867em;"><span class="pstrut" style="height:3em;"></span><span class="hide-tail" style="min-width:0.853em;height:1.08em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.08em" viewBox="0 0 400000 1080" preserveAspectRatio="xMinYMin slice"><path d="M95,702
c-2.7,0,-7.17,-2.7,-13.5,-8c-5.8,-5.3,-9.5,-10,-9.5,-14
c0,-2,0.3,-3.3,1,-4c1.3,-2.7,23.83,-20.7,67.5,-54
c44.2,-33.3,65.8,-50.3,66.5,-51c1.3,-1.3,3,-2,5,-2c4.7,0,8.7,3.3,12,10
s173,378,173,378c0.7,0,35.3,-71,104,-213c68.7,-142,137.5,-285,206.5,-429
c69,-144,104.5,-217.7,106.5,-221
l0 -0
c5.3,-9.3,12,-14,20,-14
H400000v40H845.2724
s-225.272,467,-225.272,467s-235,486,-235,486c-2.7,4.7,-9,7,-19,7
c-6,0,-10,-1,-12,-3s-194,-422,-194,-422s-65,47,-65,47z
M834 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1133em;"><span></span></span></span></span></span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.93em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mclose delimcenter" style="top:0em;"><span class="delimsizing size3">)</span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span></span></span></span></span></div>
<p>up to constant factors (and with extensions to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>t</mi></mrow><annotation encoding="application/x-tex">t</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord mathnormal">t</span></span></span></span></span>-point differences). This is exactly why point programming needs <em>amplitude accounting</em> in QROM rather than transcript accounting in ROM. <span class="citation" id="citation--bbbv1997--16">(<a href="#bib-bbbv1997">8</a>)</span></p>
<p>The same bound is a useful engineering sanity check: it shows when “reprogramming one point” is statistically invisible versus when it is potentially detectable.</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid">xychart-beta
    title <span class="token string">"Single-point oracle difference bound (toy scaling)"</span>
    <span class="token arrow operator">x-</span>axis <span class="token text string">["0","40","80","120","160","200","240","280","320","360","400","440","480","520","560","600","640","680","720","760","800"]</span>
    y-axis <span class="token string">"O(q/√N)"</span> 0 <span class="token arrow operator">--></span> 1
    line <span class="token string">"N = 2^20"</span> <span class="token text string">[0.0,0.039063,0.078125,0.117188,0.15625,0.195313,0.234375,0.273438,0.3125,0.351563,0.390625,0.429688,0.46875,0.507813,0.546875,0.585938,0.625,0.664063,0.703125,0.742188,0.78125]</span>
    line <span class="token string">"N = 2^40"</span> <span class="token text string">[0.0,0.000038,0.000076,0.000114,0.000153,0.000191,0.000229,0.000267,0.000305,0.000343,0.000381,0.000420,0.000458,0.000496,0.000534,0.000572,0.000610,0.000648,0.000687,0.000725,0.000763]</span></code></pre></div>
<p>This bound is both good news and bad news:</p>
<ul>
<li>good: <em>small</em> reprogrammings can be statistically invisible up to a regime,</li>
<li>bad: you cannot justify “it didn’t query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>” by reading a transcript, because there is no transcript.</li>
</ul>
<p>Zhandry’s “compressed oracle” technique is one of the key tools that makes these arguments precise: instead of logging queries, you reason about the adversary’s interaction with an evolving classical description of a quantum-accessed oracle. <span class="citation" id="citation--zhandry2018recordqueries--17">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<h4 id="233-fiatshamir-starts-to-crack" style="position:relative;"><a href="#233-fiatshamir-starts-to-crack" aria-label="233 fiatshamir starts to crack permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3.3 Fiat–Shamir starts to crack</h4>
<p>Fiat–Shamir (FS) takes an interactive proof/identification protocol and replaces the verifier’s random challenge with a hash of the transcript. In ROM this is natural: a random oracle is a model of “perfect challenge generation.”</p>
<p>In QROM, the adversary can query the oracle in superposition <em>before</em> committing to a transcript, and it can maintain quantum state that is entangled with oracle answers. This breaks the standard ROM proof skeleton:</p>
<ul>
<li>the extractor cannot reliably fork by rewinding,</li>
<li>programming <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> at one point is not a benign point change without extra reasoning,</li>
<li>and “the adversary must have queried <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> at the forgery point” is no longer a classical event you can check by inspecting a log.</li>
</ul>
<p>The result is not that FS is “broken.” The result is: classical FS proofs do not lift automatically. You need QROM-aware arguments and, often, additional conditions on the underlying protocol (special soundness, commitment structure, etc.). <span class="citation" id="citation--unruh2017fiatshamir--18">(<a href="#bib-unruh2017fiatshamir">3</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--19">(<a href="#bib-donetal2019fiatshamirqrom">4</a>)</span></p>
<h3 id="24-deep-dive--fiatshamir-in-a-quantum-world" style="position:relative;"><a href="#24-deep-dive--fiatshamir-in-a-quantum-world" aria-label="24 deep dive  fiatshamir in a quantum world permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4 Deep Dive — Fiat–Shamir in a Quantum World</h3>
<h4 id="241-sigma-protocol-model" style="position:relative;"><a href="#241-sigma-protocol-model" aria-label="241 sigma protocol model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4.1 <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Σ</mi></mrow><annotation encoding="application/x-tex">\Sigma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Σ</span></span></span></span></span>-protocol model</h4>
<p>Consider a (public-coin) <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Σ</mi></mrow><annotation encoding="application/x-tex">\Sigma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Σ</span></span></span></span></span>-protocol for relation <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">R</mi><mo>⊆</mo><mi mathvariant="script">X</mi><mo>×</mo><mi mathvariant="script">W</mi></mrow><annotation encoding="application/x-tex">\mathcal{R} \subseteq \mathcal{X}\times\mathcal{W}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8193em;vertical-align:-0.136em;"></span><span class="mord mathcal">R</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⊆</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7667em;vertical-align:-0.0833em;"></span><span class="mord mathcal" style="margin-right:0.14643em;">X</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.08222em;">W</span></span></span></span></span> where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi><mo>∈</mo><mi mathvariant="script">X</mi></mrow><annotation encoding="application/x-tex">x\in\mathcal{X}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5782em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.14643em;">X</span></span></span></span></span> is a statement and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>w</mi><mo>∈</mo><mi mathvariant="script">W</mi></mrow><annotation encoding="application/x-tex">w\in\mathcal{W}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5782em;vertical-align:-0.0391em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.08222em;">W</span></span></span></span></span> is a witness.</p>
<p>The interactive protocol is:</p>
<ol>
<li>Prover samples randomness <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ρ</mi></mrow><annotation encoding="application/x-tex">\rho</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">ρ</span></span></span></span></span> and sends commitment <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>a</mi><mo>←</mo><mtext mathvariant="sans-serif">Commit</mtext><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>w</mi><mo separator="true">;</mo><mi>ρ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">a \leftarrow \textsf{Commit}(x,w;\rho)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">a</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Commit</span></span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">ρ</span><span class="mclose">)</span></span></span></span></span>.</li>
<li>Verifier samples challenge <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo>←</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mi>k</mi></msup></mrow><annotation encoding="application/x-tex">c \leftarrow \{0,1\}^k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0991em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span></span></span></span></span></span></span></span></span> and sends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span>.</li>
<li>Prover sends response <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>z</mi><mo>←</mo><mtext mathvariant="sans-serif">Respond</mtext><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>w</mi><mo separator="true">;</mo><mi>ρ</mi><mo separator="true">,</mo><mi>c</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">z \leftarrow \textsf{Respond}(x,w;\rho,c)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Respond</span></span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">ρ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">c</span><span class="mclose">)</span></span></span></span></span>.</li>
<li>Verifier checks <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Verify</mtext><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>c</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo><mo>=</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">\textsf{Verify}(x,a,c,z)=1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Verify</span></span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">c</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span>.</li>
</ol>
<p>Special soundness (the typical extraction property) says:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext mathvariant="sans-serif">Extract</mtext><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>c</mi><mo separator="true">,</mo><mi>z</mi><mo separator="true">,</mo><msup><mi>c</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo separator="true">,</mo><msup><mi>z</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo stretchy="false">)</mo><mo>→</mo><mi>w</mi><mspace width="1em"></mspace><mtext>given two accepting transcripts </mtext><mo stretchy="false">(</mo><mi>a</mi><mo separator="true">,</mo><mi>c</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mo stretchy="false">(</mo><mi>a</mi><mo separator="true">,</mo><msup><mi>c</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo separator="true">,</mo><msup><mi>z</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext> </mtext><mi>c</mi><mo mathvariant="normal">≠</mo><msup><mi>c</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\textsf{Extract}(x,a,c,z,c',z') \to w \quad\text{given two accepting transcripts }(a,c,z),(a,c',z'),\ c\neq c'.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0519em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Extract</span></span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">c</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">c</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0519em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">given two accepting transcripts </span></span><span class="mopen">(</span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">c</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">c</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">c</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mrel"><span class="mord vbox"><span class="thinbox"><span class="rlap"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="inner"><span class="mord"><span class="mrel"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace nobreak"></span><span class="mrel">=</span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8019em;"></span><span class="mord"><span class="mord mathnormal">c</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<h4 id="242-fiatshamir-transform" style="position:relative;"><a href="#242-fiatshamir-transform" aria-label="242 fiatshamir transform permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4.2 Fiat–Shamir transform</h4>
<p>FS removes the verifier by setting:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>c</mi><mo>:</mo><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>m</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">c := H(x,a,m),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>for message <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>m</mi></mrow><annotation encoding="application/x-tex">m</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">m</span></span></span></span></span> (for signatures) or context string. The prover outputs <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>a</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(a,z)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span></span></span></span></span> and the verifier recomputes <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span> from <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span>.</p>
<p>In ROM, a standard security proof sketch for FS-based signatures is:</p>
<ol>
<li>assume a forger outputs a valid transcript <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>a</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(a,z)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span></span></span></span></span> for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">c=H(\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span>,</li>
<li>by forking (rewinding with different oracle programming) obtain two transcripts with same <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>a</mi></mrow><annotation encoding="application/x-tex">a</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">a</span></span></span></span></span> and different <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span>,</li>
<li>apply special soundness to extract <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>w</mi></mrow><annotation encoding="application/x-tex">w</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span></span></span></span></span>.</li>
</ol>
<p>This pipeline depends on an extractor that can:</p>
<ul>
<li>observe whether/when the forger queried <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> at <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>m</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(x,a,m)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mclose">)</span></span></span></span></span>,</li>
<li>program <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> at that point to force a different <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>c</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">c'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal">c</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span>,</li>
<li>rewind the forger to re-run with the modified oracle.</li>
</ul>
<h5 id="2421-a-qrom-flavored-euf-cma-game-what-you-are-actually-claiming" style="position:relative;"><a href="#2421-a-qrom-flavored-euf-cma-game-what-you-are-actually-claiming" aria-label="2421 a qrom flavored euf cma game what you are actually claiming permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4.2.1 A QROM-flavored EUF-CMA game (what you are actually claiming)</h5>
<p>To avoid hand-waving, write the security claim in a game form that matches deployment reality.</p>
<p>An FS-based signature scheme <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="normal">Σ</mi><mtext mathvariant="sans-serif">FS</mtext></msub></mrow><annotation encoding="application/x-tex">\Sigma_{\textsf{FS}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord">Σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">FS</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> (built from a <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Σ</mi></mrow><annotation encoding="application/x-tex">\Sigma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Σ</span></span></span></span></span>-protocol) is typically verified under EUF-CMA:</p>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">KeyGen</mtext><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\textsf{KeyGen}(1^\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0991em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">KeyGen</span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> outputs <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">k</mi></mrow><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(\mathsf{pk},\mathsf{sk})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathsf">sk</span></span><span class="mclose">)</span></span></span></span></span> where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><annotation encoding="application/x-tex">\mathsf{pk}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathsf">pk</span></span></span></span></span></span> is the statement and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">k</mi></mrow><annotation encoding="application/x-tex">\mathsf{sk}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathsf">sk</span></span></span></span></span></span> is the witness.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Sign</mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mi>m</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\textsf{Sign}(\mathsf{sk},m)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Sign</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mclose">)</span></span></span></span></span> runs the prover to produce <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>a</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(a,z)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span></span></span></span></span> with challenge <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo>:</mo><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>m</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">c := H(\mathsf{pk},a,m)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mclose">)</span></span></span></span></span> and outputs <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>σ</mi><mo>:</mo><mo>=</mo><mo stretchy="false">(</mo><mi>a</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\sigma := (a,z)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Verify</mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mi>m</mi><mo separator="true">,</mo><mi>σ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\textsf{Verify}(\mathsf{pk},m,\sigma)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="mclose">)</span></span></span></span></span> recomputes <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo>:</mo><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>m</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">c := H(\mathsf{pk},a,m)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mclose">)</span></span></span></span></span> and checks <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mtext mathvariant="sans-serif">Verify</mtext><mi mathvariant="normal">Σ</mi></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>c</mi><mo separator="true">,</mo><mi>z</mi><mo stretchy="false">)</mo><mo>=</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">\textsf{Verify}_\Sigma(\mathsf{pk},a,c,z)=1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord textsf">Verify</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2342em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">Σ</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">c</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span>.</li>
</ul>
<p>The QROM security game then looks like:</p>
<ol>
<li>Challenger samples <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">k</mi></mrow><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(\mathsf{pk},\mathsf{sk})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathsf">sk</span></span><span class="mclose">)</span></span></span></span></span> and a random oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">\adv_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is a QPT adversary with quantum oracle access to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> and classical access to a signing oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Sign</mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\textsf{Sign}(\mathsf{sk},\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Sign</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">\adv_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> outputs <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><msup><mi>m</mi><mo>⋆</mo></msup><mo separator="true">,</mo><msup><mi>σ</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(m^\star,\sigma^\star)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">\adv_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> wins iff <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Verify</mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">k</mi></mrow><mo separator="true">,</mo><msup><mi>m</mi><mo>⋆</mo></msup><mo separator="true">,</mo><msup><mi>σ</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo><mo>=</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">\textsf{Verify}(\mathsf{pk},m^\star,\sigma^\star)=1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>m</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">m^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> was not previously signed.</li>
</ol>
<p>Define advantage:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><msub><mi mathvariant="normal">Σ</mi><mtext mathvariant="sans-serif">FS</mtext></msub><mrow><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow><mtext>-</mtext><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">U</mi><mi mathvariant="normal">F</mi></mrow><mtext>-</mtext><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">M</mi><mi mathvariant="normal">A</mi></mrow></mrow></msubsup><mo stretchy="false">(</mo><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mtext>  </mtext><mo>:</mo><mo>=</mo><mtext>  </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi></mrow><mo stretchy="false">[</mo><msub><mi mathvariant="script">A</mi><mi>Q</mi></msub><mtext> wins in the above game</mtext><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}^{\mathrm{QROM}\text{-}\mathrm{EUF}\text{-}\mathrm{CMA}}_{\Sigma_{\textsf{FS}}}(\adv_Q;\lambda)
\;:=\;
\Pr[\adv_Q\ \text{wins in the above game}].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.3586em;vertical-align:-0.3994em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9592em;"><span style="top:-2.4065em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mtight">Σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">FS</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">QROM</span></span><span class="mord text mtight"><span class="mord mtight">-</span></span><span class="mord mtight"><span class="mord mathrm mtight">EUF</span></span><span class="mord text mtight"><span class="mord mtight">-</span></span><span class="mord mtight"><span class="mord mathrm mtight">CMA</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3994em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:=</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">Pr</span></span><span class="mopen">[</span><span class="mord"><span class="mord mathcal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">wins in the above game</span></span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>The key detail is the <em>mixed interface</em>: the adversary has quantum access to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> (because <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> is public and coherently computable) but only classical access to the signer (because signing is an external system interface). This mixed typing is not a nuance — it is what makes many reductions either possible or impossible. <span class="citation" id="citation--bonehetal2010qrom--20">(<a href="#bib-bonehetal2010qrom">1</a>)</span> <span class="citation" id="citation--unruh2017fiatshamir--21">(<a href="#bib-unruh2017fiatshamir">3</a>)</span></p>
<h4 id="243-why-the-extractor-is-not-generic-in-qrom" style="position:relative;"><a href="#243-why-the-extractor-is-not-generic-in-qrom" aria-label="243 why the extractor is not generic in qrom permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4.3 Why the extractor is not generic in QROM</h4>
<p>In QROM, the forger can query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> in superposition on <em>many</em> candidate <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>x</mi><mo separator="true">,</mo><mi>a</mi><mo separator="true">,</mo><mi>m</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(x,a,m)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">a</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mclose">)</span></span></span></span></span> values, potentially entangled with its internal randomness and commitments.</p>
<p>There is a core impossibility shape here: for general FS instantiations, black-box extractors of the classical type do not exist in QROM without additional structure. The reason is precisely that “the fork point” is not a classical observable event. Extraction requires different techniques (quantum rewinding variants, measure-and-reprogram, compressed oracle arguments) and tends to be protocol-specific. <span class="citation" id="citation--unruh2017fiatshamir--22">(<a href="#bib-unruh2017fiatshamir">3</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--23">(<a href="#bib-donetal2019fiatshamirqrom">4</a>)</span></p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>Extraction in QROM requires an extraction interface.</strong> If your transform relies on “fork the adversary at query (x,a,m),” you must prove that (x,a,m) is measurable/program-able in the relevant sense without collapsing the success probability.</p>
</div>
<h4 id="244-a-concrete-quantitative-lens-grover-style-query-economics" style="position:relative;"><a href="#244-a-concrete-quantitative-lens-grover-style-query-economics" aria-label="244 a concrete quantitative lens grover style query economics permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4.4 A concrete quantitative lens: Grover-style query economics</h4>
<p>Even before extraction, QROM changes the <em>economics</em> of oracle access. Many ROM security arguments implicitly assume a classical <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-query adversary cannot do much better than <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi><mi mathvariant="normal">/</mi><mi mathvariant="normal">∣</mi><mi>D</mi><mi mathvariant="normal">∣</mi></mrow><annotation encoding="application/x-tex">q/|D|</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mord">/∣</span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span><span class="mord">∣</span></span></span></span></span> for preimage-style events. In QROM, unstructured search admits quadratic speedup with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>O</mi><mo stretchy="false">(</mo><msqrt><mrow><mi mathvariant="normal">∣</mi><mi>D</mi><mi mathvariant="normal">∣</mi></mrow></msqrt><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">O(\sqrt{|D|})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.24em;vertical-align:-0.305em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span><span class="mopen">(</span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.935em;"><span class="svg-align" style="top:-3.2em;"><span class="pstrut" style="height:3.2em;"></span><span class="mord" style="padding-left:1em;"><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.02778em;">D</span><span class="mord">∣</span></span></span><span style="top:-2.895em;"><span class="pstrut" style="height:3.2em;"></span><span class="hide-tail" style="min-width:1.02em;height:1.28em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.28em" viewBox="0 0 400000 1296" preserveAspectRatio="xMinYMin slice"><path d="M263,681c0.7,0,18,39.7,52,119
c34,79.3,68.167,158.7,102.5,238c34.3,79.3,51.8,119.3,52.5,120
c340,-704.7,510.7,-1060.3,512,-1067
l0 -0
c4.7,-7.3,11,-11,19,-11
H40000v40H1012.3
s-271.3,567,-271.3,567c-38.7,80.7,-84,175,-136,283c-52,108,-89.167,185.3,-111.5,232
c-22.3,46.7,-33.8,70.3,-34.5,71c-4.7,4.7,-12.3,7,-23,7s-12,-1,-12,-1
s-109,-253,-109,-253c-72.7,-168,-109.3,-252,-110,-252c-10.7,8,-22,16.7,-34,26
c-22,17.3,-33.3,26,-34,26s-26,-26,-26,-26s76,-59,76,-59s76,-60,76,-60z
M1001 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.305em;"><span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> queries (Grover), and this is optimal (BBBV). <span class="citation" id="citation--grover1996--24">(<a href="#bib-grover1996">9</a>)</span> <span class="citation" id="citation--bbbv1997--25">(<a href="#bib-bbbv1997">8</a>)</span></p>
<p>This does not “break” FS by itself, but it changes the bound calculations that sit under heuristic security-level claims.</p>
<p>Below is a simulation of success probability for preimage search on a domain of size <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>N</mi><mo>=</mo><msup><mn>2</mn><mn>20</mn></msup></mrow><annotation encoding="application/x-tex">N=2^{20}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8141em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8141em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">20</span></span></span></span></span></span></span></span></span></span></span></span></span>, comparing a classical <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-query strategy (<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>p</mi><mo>≈</mo><mi>q</mi><mi mathvariant="normal">/</mi><mi>N</mi></mrow><annotation encoding="application/x-tex">p \approx q/N</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6776em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">p</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mord">/</span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span></span></span></span></span>) versus ideal Grover amplitude amplification (<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>p</mi><mo>=</mo><msup><mrow><mi>sin</mi><mo>⁡</mo></mrow><mn>2</mn></msup><mo stretchy="false">(</mo><mo stretchy="false">(</mo><mn>2</mn><mi>q</mi><mo>+</mo><mn>1</mn><mo stretchy="false">)</mo><mi>arcsin</mi><mo>⁡</mo><mo stretchy="false">(</mo><mn>1</mn><mi mathvariant="normal">/</mi><msqrt><mi>N</mi></msqrt><mo stretchy="false">)</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">p=\sin^2((2q+1)\arcsin(1/\sqrt{N}))</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">p</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1219em;vertical-align:-0.25em;"></span><span class="mop"><span class="mop">sin</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8719em;"><span style="top:-3.1208em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span></span></span></span></span><span class="mopen">((</span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.1767em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mop">arcsin</span><span class="mopen">(</span><span class="mord">1/</span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9267em;"><span class="svg-align" style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord" style="padding-left:0.833em;"><span class="mord mathnormal" style="margin-right:0.10903em;">N</span></span></span><span style="top:-2.8867em;"><span class="pstrut" style="height:3em;"></span><span class="hide-tail" style="min-width:0.853em;height:1.08em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.08em" viewBox="0 0 400000 1080" preserveAspectRatio="xMinYMin slice"><path d="M95,702
c-2.7,0,-7.17,-2.7,-13.5,-8c-5.8,-5.3,-9.5,-10,-9.5,-14
c0,-2,0.3,-3.3,1,-4c1.3,-2.7,23.83,-20.7,67.5,-54
c44.2,-33.3,65.8,-50.3,66.5,-51c1.3,-1.3,3,-2,5,-2c4.7,0,8.7,3.3,12,10
s173,378,173,378c0.7,0,35.3,-71,104,-213c68.7,-142,137.5,-285,206.5,-429
c69,-144,104.5,-217.7,106.5,-221
l0 -0
c5.3,-9.3,12,-14,20,-14
H400000v40H845.2724
s-225.272,467,-225.272,467s-235,486,-235,486c-2.7,4.7,-9,7,-19,7
c-6,0,-10,-1,-12,-3s-194,-422,-194,-422s-65,47,-65,47z
M834 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1133em;"><span></span></span></span></span></span><span class="mclose">))</span></span></span></span></span>).</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid">xychart-beta
    title <span class="token string">"Preimage search success probability (N = 2^20)"</span>
    <span class="token arrow operator">x-</span>axis <span class="token text string">["0","40","80","120","160","200","240","280","320","360","400","440","480","520","560","600","640","680","720","760","800"]</span>
    y-axis <span class="token string">"Pr[success]"</span> 0 <span class="token arrow operator">--></span> 1
    line <span class="token string">"Classical q/N"</span> <span class="token text string">[0.0,0.000038,0.000076,0.000114,0.000153,0.000191,0.000229,0.000267,0.000305,0.000343,0.000381,0.000420,0.000458,0.000496,0.000534,0.000572,0.000610,0.000648,0.000687,0.000725,0.000763]</span>
    line <span class="token string">"Grover"</span> <span class="token text string">[0.0,0.003055,0.012204,0.027373,0.048452,0.075300,0.107744,0.145579,0.188571,0.236456,0.288945,0.345723,0.406451,0.470767,0.538291,0.608624,0.681356,0.756065,0.832321,0.909688,0.987729]</span></code></pre></div>
<p>Two notes for engineers reading this:</p>
<ol>
<li>This is a <em>toy</em> curve about oracle-query economics. It is not a complete security argument for any specific scheme.</li>
<li>It is exactly the kind of difference that turns “ROM intuition” into “QROM accounting.” If the proof’s hidden constant is “adversary must query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> at <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>,” you need to reason about quantum query amplitude, not classical query events.</li>
</ol>
<h3 id="25-attempts-to-fix-the-problem-what-actually-works" style="position:relative;"><a href="#25-attempts-to-fix-the-problem-what-actually-works" aria-label="25 attempts to fix the problem what actually works permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5 Attempts to Fix the Problem (what actually works)</h3>
<p>The literature does not stop at criticism. There is a well-developed toolchain for QROM reasoning, but it is heavier and more conditional than ROM reasoning.</p>
<h4 id="251-compressed-oracle-and-query-recording" style="position:relative;"><a href="#251-compressed-oracle-and-query-recording" aria-label="251 compressed oracle and query recording permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5.1 Compressed oracle and query recording</h4>
<p>Zhandry’s compressed oracle framework gives a way to reason about quantum queries by representing the oracle state as a compressed classical structure plus a bound on how much information a <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-query adversary can extract. This underpins a number of indifferentiability and reprogramming arguments in QROM. <span class="citation" id="citation--zhandry2018recordqueries--26">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<h4 id="252-qrom-fiatshamir-proofs-unruh-donfehrmajenzschaffner" style="position:relative;"><a href="#252-qrom-fiatshamir-proofs-unruh-donfehrmajenzschaffner" aria-label="252 qrom fiatshamir proofs unruh donfehrmajenzschaffner permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5.2 QROM Fiat–Shamir proofs (Unruh; Don–Fehr–Majenz–Schaffner)</h4>
<p>Unruh established QROM security of Fiat–Shamir under conditions that essentially replace the classical forking lemma with a quantum-aware argument (often called a “quantum forking lemma” in informal discussion). <span class="citation" id="citation--unruh2017fiatshamir--27">(<a href="#bib-unruh2017fiatshamir">3</a>)</span></p>
<p>Don et al. refine and systematize the analysis of FS in QROM, providing proofs (and clarifying limitations) for broad classes of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Σ</mi></mrow><annotation encoding="application/x-tex">\Sigma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Σ</span></span></span></span></span>-protocols and related transforms. <span class="citation" id="citation--donetal2019fiatshamirqrom--28">(<a href="#bib-donetal2019fiatshamirqrom">4</a>)</span></p>
<h4 id="253-quantum-rewinding-watrous" style="position:relative;"><a href="#253-quantum-rewinding-watrous" aria-label="253 quantum rewinding watrous permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5.3 Quantum rewinding (Watrous)</h4>
<p>Watrous showed that certain zero-knowledge proofs remain secure against quantum adversaries using specialized quantum rewinding. This is not a generic drop-in for classical rewinding, but it demonstrates that the right structure can make extraction/simulation possible. <span class="citation" id="citation--watrous2009zk--29">(<a href="#bib-watrous2009zk">7</a>)</span></p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>In QROM, don’t ask “is Fiat–Shamir secure?” Ask: “does <em>this</em> underlying protocol admit the QROM proof techniques we need, with the tightness we can afford at our parameter set?”</p>
</div>
<h2 id="3-system-constraints" style="position:relative;"><a href="#3-system-constraints" aria-label="3 system constraints permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3. System Constraints</h2>
<h3 id="systems-not-just-proofs" style="position:relative;"><a href="#systems-not-just-proofs" aria-label="systems not just proofs permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Systems, not just proofs</h3>
<p>The cryptographic statement “QROM adversary can query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> in superposition” is often misunderstood as a claim about the <em>endpoints</em> being quantum.</p>
<p>It is not. Endpoints can remain classical.</p>
<p>QROM is a claim about the adversary’s ability to implement the oracle coherently given a public description. Hash functions are public, deterministic circuits. If an attacker has a quantum computer, it can run <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> as a quantum circuit and query it on a superposition. That is true regardless of whether your server is classical, embedded, or IIoT.</p>
<p>This is why QROM is not optional for long-lived infrastructure. If your security boundary assumes “the attacker cannot evaluate <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> coherently,” you need to justify that assumption at the system level (rate-limited remote oracles, hardware-enforced classical interfaces, etc.). Otherwise you are not in ROM; you are in QROM by default.</p>
<h3 id="31-system-constraints-that-proofs-ignore" style="position:relative;"><a href="#31-system-constraints-that-proofs-ignore" aria-label="31 system constraints that proofs ignore permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.1 System constraints that proofs ignore</h3>
<p>Formal QROM proofs also assume an idealized interface on the <em>defender</em> side:</p>
<ul>
<li>unbiased randomness for keygen and masking,</li>
<li>constant-time behavior where required,</li>
<li>memory erasure where ephemerality is assumed,</li>
<li>and no side-channel observation beyond what the model states.</li>
</ul>
<p>In PQC implementations, the gap between proof model and deployed system can be larger than in classical ECC/RSA code because state and bandwidth are larger and performance pressure is higher.</p>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>When QROM makes your reductions less tight, engineers compensate by inflating parameters. Parameter inflation increases code complexity, state volume, and bandwidth — which increases side-channel and operational risk. This feedback loop is real in production.</p>
</div>
<h2 id="4-core-argument--insight" style="position:relative;"><a href="#4-core-argument--insight" aria-label="4 core argument  insight permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4. Core Argument / Insight</h2>
<p>QROM does not just make attacks stronger. It invalidates the assumptions behind how we prove security.</p>
<p>If your proof relies on:</p>
<ul>
<li>query observability,</li>
<li>transcript extraction,</li>
<li>point programming without global entanglement analysis,</li>
<li>classical rewinding / forking,</li>
</ul>
<p>then your ROM proof is not evidence of security against quantum-capable adversaries. You need an explicit QROM argument, or you need to explicitly justify that your system boundary makes only classical oracle access relevant.</p>
<h2 id="5-implications" style="position:relative;"><a href="#5-implications" aria-label="5 implications permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5. Implications</h2>
<h3 id="51-pq-signatures-rom-proofs-are-not-the-end-of-the-story" style="position:relative;"><a href="#51-pq-signatures-rom-proofs-are-not-the-end-of-the-story" aria-label="51 pq signatures rom proofs are not the end of the story permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5.1 PQ signatures: ROM proofs are not the end of the story</h3>
<p>Many modern signature schemes (including lattice-based families) are structurally tied to FS-style transforms. Even when standards documents present security arguments, the long-term claim you care about is a QROM claim, not a ROM claim.</p>
<p>This is not panic. It is model hygiene:</p>
<blockquote>
<p>A proof in ROM is not evidence of security in a quantum-capable world.</p>
</blockquote>
<h3 id="52-zk-and-blockchain-the-fiatshamir-heuristic-is-infrastructure" style="position:relative;"><a href="#52-zk-and-blockchain-the-fiatshamir-heuristic-is-infrastructure" aria-label="52 zk and blockchain the fiatshamir heuristic is infrastructure permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5.2 ZK and blockchain: the Fiat–Shamir heuristic is infrastructure</h3>
<p>Most deployed ZK proof systems in blockchains are non-interactive by applying Fiat–Shamir to interactive protocols. If your security story assumes ROM and you deploy into a 10–20 year horizon where quantum adversaries are plausible, you need to understand which parts of your system are actually proven in QROM and which are heuristic.</p>
<h3 id="53-protocol-design-treat-the-oracle-interface-as-a-first-class-spec-object" style="position:relative;"><a href="#53-protocol-design-treat-the-oracle-interface-as-a-first-class-spec-object" aria-label="53 protocol design treat the oracle interface as a first class spec object permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5.3 Protocol design: treat the oracle interface as a first-class spec object</h3>
<p>At the protocol level, the correct engineering move is to define the oracle model explicitly:</p>
<ul>
<li>what functions are modeled as random oracles (hash/KDF/transcript),</li>
<li>what the adversary interface is (classical evaluation vs coherent evaluation),</li>
<li>what the resource budgets are (query bounds, time, memory, coherence),</li>
<li>what the system boundary prevents (if anything).</li>
</ul>
<p>Without that, “post-quantum” becomes a label rather than a claim.</p>
<h3 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h3>
<ul>
<li>Treating QROM as “ROM + Grover factor” and carrying ROM proofs forward unchanged.</li>
<li>Assuming rewinding-based extractors still work because “we can just rerun the adversary.”</li>
<li>Treating oracle programming as a harmless point change without a QROM reprogramming bound.</li>
<li>Confusing “adversary is quantum” with “endpoints are quantum,” and therefore under-modeling oracle access.</li>
</ul>
<h3 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h3>
<ul>
<li>Where your stack uses Fiat–Shamir (signatures, transcripts, ZK proofs, aggregations).</li>
<li>Which proofs are explicitly QROM (and what the tightness/assumptions are) versus “ROM only.”</li>
<li>Whether the system boundary truly enforces classical oracle access (it usually does not for hash functions).</li>
<li>Implementation regressions that invalidate model assumptions (randomness bias, timing leakage, memory non-erasure).</li>
</ul>
<h3 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h3>
<p>If you deploy primitives/protocols whose story changes materially between ROM and QROM, treat that as an agility requirement:</p>
<ul>
<li>version suite IDs explicitly (no aliasing of “equivalent” constructions),</li>
<li>bind suite choice into transcript authentication,</li>
<li>keep a deprecation window and telemetry for legacy behavior,</li>
<li>and pre-plan re-keying / credential rollover paths.</li>
</ul>
<h2 id="6-continuity-hook" style="position:relative;"><a href="#6-continuity-hook" aria-label="6 continuity hook permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>6. Continuity Hook</h2>
<p>Part 4 will be about <em>tightness and parameter inflation</em>: how QROM-aware proofs often introduce additional loss factors, how those losses map (or fail to map) into concrete parameter sizing, and why “Category 5” language can hide fragile reductions.</p>
<h2 id="7-references" style="position:relative;"><a href="#7-references" aria-label="7 references permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>7. References</h2>
<h3 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h3>
<ul>
<li>The formal distinction between ROM and QROM and the oracle interface shift is made explicit in Boneh et al. <span class="citation" id="citation--bonehetal2010qrom--30">(<a href="#bib-bonehetal2010qrom">1</a>)</span></li>
<li>Concrete QROM techniques (recording queries / compressed oracle) are developed by Zhandry. <span class="citation" id="citation--zhandry2018recordqueries--31">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></li>
<li>The limits and conditions of Fiat–Shamir in QROM are analyzed by Unruh and by Don et al. <span class="citation" id="citation--unruh2017fiatshamir--32">(<a href="#bib-unruh2017fiatshamir">3</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--33">(<a href="#bib-donetal2019fiatshamirqrom">4</a>)</span></li>
<li>Grover/BBBV quantify the structural query-economics shift that sits underneath many ROM intuitions. <span class="citation" id="citation--grover1996--34">(<a href="#bib-grover1996">9</a>)</span> <span class="citation" id="citation--bbbv1997--35">(<a href="#bib-bbbv1997">8</a>)</span></li>
<li>Watrous gives a canonical example of when quantum rewinding works and when it does not generalize. <span class="citation" id="citation--watrous2009zk--36">(<a href="#bib-watrous2009zk">7</a>)</span></li>
</ul>
<h3 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h3>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> For every security claim, state whether it is ROM, QROM, or “quantum computation with classical oracle access.”</li>
<li class="task-list-item"><input type="checkbox" disabled> For every FS usage, identify the extraction/simulation proof technique (and whether it is QROM-valid).</li>
<li class="task-list-item"><input type="checkbox" disabled> Document query/time/memory/coherence budgets as part of the security target.</li>
<li class="task-list-item"><input type="checkbox" disabled> Track proof tightness losses and map them into concrete parameter sizing.</li>
<li class="task-list-item"><input type="checkbox" disabled> Treat parameter inflation as a side-channel and ops-risk amplifier.</li>
</ul>
<h3 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h3>
<ul>
<li><a href="https://eprint.iacr.org/2010/428.pdf" target="_blank" rel="nofollow noopener noreferrer">Boneh et al., “Random Oracles in a Quantum World” (ePrint 2010/428)</a>. <span class="citation" id="citation--bonehetal2010qrom--37">(<a href="#bib-bonehetal2010qrom">1</a>)</span></li>
<li><a href="https://eprint.iacr.org/2018/276.pdf" target="_blank" rel="nofollow noopener noreferrer">Zhandry, “How to Record Quantum Queries…” (ePrint 2018/276)</a>. <span class="citation" id="citation--zhandry2018recordqueries--38">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></li>
<li><a href="https://eprint.iacr.org/2017/398.pdf" target="_blank" rel="nofollow noopener noreferrer">Unruh, “Post-Quantum Security of Fiat-Shamir” (ePrint 2017/398)</a>. <span class="citation" id="citation--unruh2017fiatshamir--39">(<a href="#bib-unruh2017fiatshamir">3</a>)</span></li>
<li><a href="https://eprint.iacr.org/2019/190.pdf" target="_blank" rel="nofollow noopener noreferrer">Don–Fehr–Majenz–Schaffner, “Security of the Fiat-Shamir Transformation in the QROM” (ePrint 2019/190)</a>. <span class="citation" id="citation--donetal2019fiatshamirqrom--40">(<a href="#bib-donetal2019fiatshamirqrom">4</a>)</span></li>
<li><a href="https://cs.uwaterloo.ca/~watrous/Papers/ZeroKnowledgeAgainstQuantum.pdf" target="_blank" rel="nofollow noopener noreferrer">Watrous, “Zero-Knowledge Against Quantum Attacks” (SIAM J. Comput., 2009)</a>. <span class="citation" id="citation--watrous2009zk--41">(<a href="#bib-watrous2009zk">7</a>)</span></li>
<li><a href="https://arxiv.org/abs/quant-ph/9605043" target="_blank" rel="nofollow noopener noreferrer">Grover, “A fast quantum mechanical algorithm for database search” (1996)</a>. <span class="citation" id="citation--grover1996--42">(<a href="#bib-grover1996">9</a>)</span></li>
<li><a href="https://arxiv.org/abs/quant-ph/9701001" target="_blank" rel="nofollow noopener noreferrer">BBBV, “Strengths and Weaknesses of Quantum Computing” (1997)</a>. <span class="citation" id="citation--bbbv1997--43">(<a href="#bib-bbbv1997">8</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-bonehetal2010qrom">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Boneh D, Dagdelen Ö, Fischlin M, Lehmann A, Schaffner C, Zhandry M. Random Oracles in a Quantum World [Internet]. Cryptology ePrint Archive, Paper 2010/428; 2010. Available from: https://eprint.iacr.org/2010/428.pdf</div>
  </div>
  <div class="csl-entry" id="bib-zhandry2018recordqueries">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Zhandry M. How to Record Quantum Queries, and Applications to Quantum Indifferentiability [Internet]. Cryptology ePrint Archive, Paper 2018/276; 2018. Available from: https://eprint.iacr.org/2018/276.pdf</div>
  </div>
  <div class="csl-entry" id="bib-unruh2017fiatshamir">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Unruh D. Post-Quantum Security of Fiat-Shamir [Internet]. Cryptology ePrint Archive, Paper 2017/398; 2017. Available from: https://eprint.iacr.org/2017/398.pdf</div>
  </div>
  <div class="csl-entry" id="bib-donetal2019fiatshamirqrom">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Don J, Fehr S, Majenz C, Schaffner C. Security of the Fiat-Shamir Transformation in the Quantum Random-Oracle Model [Internet]. Cryptology ePrint Archive, Paper 2019/190; 2019. Available from: https://eprint.iacr.org/2019/190.pdf</div>
  </div>
  <div class="csl-entry" id="bib-nielsenchuang2010">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">Nielsen MA, Chuang IL. Quantum Computation and Quantum Information: 10th Anniversary Edition. Cambridge University Press; 2010.</div>
   </div>
  <div class="csl-entry" id="bib-fuchsgraaf1999">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">Fuchs CA, van de Graaf J. Cryptographic distinguishability measures for quantum-mechanical states [Internet]. arXiv:quant-ph/9712048; 1999. Available from: https://arxiv.org/abs/quant-ph/9712048</div>
  </div>
  <div class="csl-entry" id="bib-watrous2009zk">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">Watrous J. Zero-Knowledge Against Quantum Attacks. SIAM Journal on Computing [Internet]. 2009; Available from: https://cs.uwaterloo.ca/~watrous/Papers/ZeroKnowledgeAgainstQuantum.pdf</div>
  </div>
  <div class="csl-entry" id="bib-bbbv1997">
    <div class="csl-left-margin">8. </div><div class="csl-right-inline">Bennett CH, Bernstein E, Brassard G, Vazirani U. Strengths and Weaknesses of Quantum Computing [Internet]. arXiv:quant-ph/9701001; 1997. Available from: https://arxiv.org/abs/quant-ph/9701001</div>
  </div>
  <div class="csl-entry" id="bib-grover1996">
    <div class="csl-left-margin">9. </div><div class="csl-right-inline">Grover LK. A fast quantum mechanical algorithm for database search [Internet]. arXiv:quant-ph/9605043; 1996. Available from: https://arxiv.org/abs/quant-ph/9605043</div>
  </div>
</div>]]></content>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="formal-methods"/>
        <category label="QROM"/>
        <category label="random-oracle-model"/>
        <category label="fiat-shamir"/>
        <category label="signatures"/>
        <category label="zero-knowledge"/>
        <category label="security-engineering"/>
        <category label="systems"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC Research Series — Part 2]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-pqc-research-day-2-complexity-assumptions-lwe-sis</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-pqc-research-day-2-complexity-assumptions-lwe-sis"/>
        <updated>2026-04-26T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[LWE/SIS are not “magic hardness.” They are interface contracts with worst-case/average-case reductions, structural trade-offs (Ring/Module), and concrete security heuristics (BKZ/sieving) that real systems routinely violate.]]></summary>
        <content type="html"><![CDATA[<h2 id="complexity-assumptions-in-post-quantum-cryptography-lwe-sis-and-the-limits-of-reductionist-security" style="position:relative;"><a href="#complexity-assumptions-in-post-quantum-cryptography-lwe-sis-and-the-limits-of-reductionist-security" aria-label="complexity assumptions in post quantum cryptography lwe sis and the limits of reductionist security permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Complexity Assumptions in Post-Quantum Cryptography: LWE, SIS, and the Limits of Reductionist Security</h2>
<p>Author: Mayckon Giovani<br>
Date: April 26, 2026<br>
Series: PQC Research Series<br>
Tags: PQC, Formal Methods, Cryptography, Systems</p>
<h2 id="0-context" style="position:relative;"><a href="#0-context" aria-label="0 context permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>0. Context</h2>
<p>Post-quantum cryptography is usually discussed as a migration exercise: replace ECDH with ML-KEM, replace RSA/ECDSA with ML-DSA / SLH-DSA, keep the rest. That framing is operationally convenient and mathematically incomplete.</p>
<p>Underneath the primitives, PQC is a statement about <em>complexity assumptions</em>: not only that certain lattice problems are hard, but that the <em>particular distributions and structures we deploy</em> are hard under the <em>resource model we actually face</em>. That “under” clause is the whole problem.</p>
<p>Reductionist security tends to overfit to the cleanest layer: “scheme <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>⇒</mo></mrow><annotation encoding="application/x-tex">\Rightarrow</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.3669em;"></span><span class="mrel">⇒</span></span></span></span></span> LWE/SIS <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>⇒</mo></mrow><annotation encoding="application/x-tex">\Rightarrow</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.3669em;"></span><span class="mrel">⇒</span></span></span></span></span> worst-case lattice hardness.” Systems security fails one layer earlier: the implementation and the operational environment frequently step outside the model (biased noise, correlated randomness, side-channel traces, non-atomic erasure, misconfigured parameters). If the reduction is a refinement map, those violations are breaking refinement.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>LWE/SIS are interface contracts.</strong> The reduction buys you something only if the implementation preserves the distributional and leakage assumptions the reduction lives inside.</p>
</div>
<h2 id="1-problem-statement" style="position:relative;"><a href="#1-problem-statement" aria-label="1 problem statement permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1. Problem Statement</h2>
<p>Fix a security parameter <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi><mo>∈</mo><mi mathvariant="double-struck">N</mi></mrow><annotation encoding="application/x-tex">\secpar \in \N</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">λ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord mathbb">N</span></span></span></span></span>. Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="normal">Π</mi><mi>P</mi></msub></mrow><annotation encoding="application/x-tex">\proto_P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> be a PQC primitive instantiated at a concrete parameter set <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span> (dimensions, modulus, noise distribution, ring/module structure, compression rules, etc).</p>
<p>We would like a statement of the form:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi mathvariant="script">A</mi><mo>∈</mo><mi mathvariant="script">C</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>:</mo><mspace width="1em"></mspace><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><msub><mi mathvariant="normal">Π</mi><mi>P</mi></msub><mrow><mi mathvariant="sans-serif">g</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">m</mi><mi mathvariant="sans-serif">e</mi></mrow></msubsup><mo stretchy="false">(</mo><mi mathvariant="script">A</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\forall \adv \in \mathcal{C}(\secpar):\quad \mathrm{Adv}^{\mathsf{game}}_{\proto_P}(\adv) \le \mathrm{negl}(\secpar),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord">∀</span><span class="mord mathcal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1859em;vertical-align:-0.3938em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.792em;"><span style="top:-2.4065em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mtight">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3567em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1433em;"><span></span></span></span></span></span></span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathsf mtight">game</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3938em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathcal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">negl</span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>under a hardness assumption <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mrow><mi mathvariant="sans-serif">H</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">r</mi><mi mathvariant="sans-serif">d</mi></mrow><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathsf{Hard}(P)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathsf">Hard</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">)</span></span></span></span></span> such as LWE or SIS.</p>
<p>In theory, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mrow><mi mathvariant="sans-serif">H</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">r</mi><mi mathvariant="sans-serif">d</mi></mrow><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathsf{Hard}(P)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathsf">Hard</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">)</span></span></span></span></span> is defined in an idealized sampling and oracle model. In production, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="normal">Π</mi><mi>P</mi></msub></mrow><annotation encoding="application/x-tex">\proto_P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> is realized by a stateful implementation <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>I</mi><mi>P</mi></msub></mrow><annotation encoding="application/x-tex">I_P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0785em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> running under system constraints (entropy sources, memory limits, microarchitectural leakage, concurrency schedules, firmware quirks). The real question is therefore not “is LWE hard?” but:</p>
<ol>
<li><strong>Which exact assumption is the proof actually using?</strong> (search-LWE vs decision-LWE, secret distribution, error distribution, structure, number of samples, oracle model). <span class="citation" id="citation--regev2009lwe--1">(<a href="#bib-regev2009lwe">1</a>)</span> <span class="citation" id="citation--micciancioregev2007gaussian--2">(<a href="#bib-micciancioregev2007gaussian">2</a>)</span></li>
<li><strong>What is the reduction loss and how does it translate to concrete parameters?</strong> Non-tightness is not a theoretical footnote; it is a sizing input. <span class="citation" id="citation--peikert2016decade--3">(<a href="#bib-peikert2016decade">3</a>)</span> <span class="citation" id="citation--chennguyen2011bkz20--4">(<a href="#bib-chennguyen2011bkz20">4</a>)</span></li>
<li><strong>Does the implementation preserve the model boundary?</strong> If <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>I</mi><mi>P</mi></msub></mrow><annotation encoding="application/x-tex">I_P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0785em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> does not sample from <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>χ</mi></mrow><annotation encoding="application/x-tex">\chi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">χ</span></span></span></span></span>, leaks timing, reuses randomness, or fails to erase secrets, then “security under LWE” is not even a well-posed claim.</li>
</ol>
<p>So the formal problem is:</p>
<blockquote>
<p>Define a model boundary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">B</mi><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathcal{B}(P)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal" style="margin-right:0.03041em;">B</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">)</span></span></span></span></span> for the deployed primitive, and prove (or at least bound) that the deployed system <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><msub><mi>I</mi><mi>P</mi></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(I_P)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0785em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> refines the ideal model required by the reduction.</p>
</blockquote>
<p>This is the same engineering move you make when you prove a protocol implementation refines a TLA+ spec: you do not get correctness from a spec; you get correctness from a refinement argument that survives the real machine.</p>
<h2 id="2-formal-model" style="position:relative;"><a href="#2-formal-model" aria-label="2 formal model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2. Formal Model</h2>
<h3 id="21-lattices-and-worst-case-problems" style="position:relative;"><a href="#21-lattices-and-worst-case-problems" aria-label="21 lattices and worst case problems permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1 Lattices and worst-case problems</h3>
<p>A (full-rank) lattice <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Λ</mi><mo>⊂</mo><msup><mi mathvariant="double-struck">R</mi><mi>n</mi></msup></mrow><annotation encoding="application/x-tex">\Lambda \subset \R^n</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7224em;vertical-align:-0.0391em;"></span><span class="mord">Λ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⊂</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord"><span class="mord mathbb">R</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span></span></span></span></span> can be represented by a basis matrix <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>B</mi><mo>∈</mo><msup><mi mathvariant="double-struck">R</mi><mrow><mi>n</mi><mo>×</mo><mi>n</mi></mrow></msup></mrow><annotation encoding="application/x-tex">B \in \R^{n \times n}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7224em;vertical-align:-0.0391em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7713em;"></span><span class="mord"><span class="mord mathbb">R</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7713em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">n</span><span class="mbin mtight">×</span><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span></span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">Λ</mi><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mo>=</mo><mo stretchy="false">{</mo><mi>B</mi><mi>z</mi><mo>:</mo><mi>z</mi><mo>∈</mo><msup><mi mathvariant="double-struck">Z</mi><mi>n</mi></msup><mo stretchy="false">}</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\Lambda(B) = \{ B z : z \in \Z^n \}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Λ</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.5782em;vertical-align:-0.0391em;"></span><span class="mord mathnormal" style="margin-right:0.04398em;">z</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span><span class="mclose">}</span><span class="mord">.</span></span></span></span></span></div>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>λ</mi><mn>1</mn></msub><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\lambda_1(\Lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal">λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose">)</span></span></span></span></span> be the length of the shortest non-zero vector in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Λ</mi></mrow><annotation encoding="application/x-tex">\Lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Λ</span></span></span></span></span>, and let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>λ</mi><mi>i</mi></msub><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\lambda_i(\Lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal">λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose">)</span></span></span></span></span> denote the <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span>-th successive minimum.</p>
<p>Two canonical worst-case approximation problems are:</p>
<ul>
<li><strong><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="sans-serif">G</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">S</mi><mi mathvariant="sans-serif">V</mi><mi mathvariant="sans-serif">P</mi></mrow><mi>γ</mi></msub></mrow><annotation encoding="application/x-tex">\mathsf{GapSVP}_\gamma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0747em;vertical-align:-0.3802em;"></span><span class="mord"><span class="mord"><span class="mord mathsf">GapSVP</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05556em;">γ</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3802em;"><span></span></span></span></span></span></span></span></span></span></span></strong>: decide whether <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>λ</mi><mn>1</mn></msub><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><mo stretchy="false">)</mo><mo>≤</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">\lambda_1(\Lambda) \le 1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal">λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> or <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>λ</mi><mn>1</mn></msub><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><mo stretchy="false">)</mo><mo>></mo><mi>γ</mi></mrow><annotation encoding="application/x-tex">\lambda_1(\Lambda) > \gamma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal">λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05556em;">γ</span></span></span></span></span> for approximation factor <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>γ</mi></mrow><annotation encoding="application/x-tex">\gamma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05556em;">γ</span></span></span></span></span>.</li>
<li><strong><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="sans-serif">S</mi><mi mathvariant="sans-serif">I</mi><mi mathvariant="sans-serif">V</mi><mi mathvariant="sans-serif">P</mi></mrow><mi>γ</mi></msub></mrow><annotation encoding="application/x-tex">\mathsf{SIVP}_\gamma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9805em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord"><span class="mord mathsf">SIVP</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05556em;">γ</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span></strong>: find <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>n</mi></mrow><annotation encoding="application/x-tex">n</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">n</span></span></span></span></span> linearly independent vectors in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Λ</mi></mrow><annotation encoding="application/x-tex">\Lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Λ</span></span></span></span></span> each of length at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>γ</mi><mo>⋅</mo><msub><mi>λ</mi><mi>n</mi></msub><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\gamma \cdot \lambda_n(\Lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6389em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05556em;">γ</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal">λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose">)</span></span></span></span></span>.</li>
</ul>
<p>These are not just academic artifacts; they are the anchor points of worst-case/average-case reductions.</p>
<p>One additional object appears constantly in the LWE/SIS reduction chain: <strong><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-ary lattices</strong> induced by modular linear constraints. Given <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi><mo>∈</mo><msubsup><mi mathvariant="double-struck">Z</mi><mi>q</mi><mrow><mi>m</mi><mo>×</mo><mi>n</mi></mrow></msubsup></mrow><annotation encoding="application/x-tex">A \in \Z_q^{m \times n}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7224em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1544em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7713em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="mbin mtight">×</span><span class="mord mathnormal mtight">n</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span></span></span></span></span>, define:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msubsup><mi mathvariant="normal">Λ</mi><mi>q</mi><mo>⊥</mo></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>=</mo><mo stretchy="false">{</mo><mi>x</mi><mo>∈</mo><msup><mi mathvariant="double-struck">Z</mi><mi>m</mi></msup><mo>:</mo><msup><mi>A</mi><mi mathvariant="sans-serif">T</mi></msup><mi>x</mi><mo>≡</mo><mn>0</mn><mspace></mspace><mspace width="1em"></mspace><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">m</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">d</mi></mrow><mspace width="0.3333em"></mspace><mi>q</mi><mo stretchy="false">)</mo><mo stretchy="false">}</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\Lambda_q^\perp(A) = \{ x \in \Z^m : A^\mathsf{T} x \equiv 0 \pmod q \}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.2822em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord">Λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mrel mtight">⊥</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7144em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">m</span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8991em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathsf mtight">T</span></span></span></span></span></span></span></span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">0</span><span class="mspace allowbreak"></span><span class="mspace" style="margin-right:1em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">mod</span></span></span><span class="mspace" style="margin-right:0.3333em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mclose">)}</span><span class="mord">.</span></span></span></span></span></div>
<p>This is the lattice-theoretic view of “solutions to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi><mi>x</mi><mo>=</mo><mn>0</mn><mtext> </mtext><mo lspace="0.22em" rspace="0.22em"><mrow><mi mathvariant="normal">m</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">d</mi></mrow></mo><mtext> </mtext><mi>q</mi></mrow><annotation encoding="application/x-tex">Ax=0 \bmod q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">0</span><span class="mspace" style="margin-right:0.0556em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin"><span class="mord"><span class="mord mathrm">mod</span></span></span><span class="mspace" style="margin-right:0.0556em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>,” and it is the bridge between average-case modular samples and worst-case geometric statements.</p>
<h3 id="22-learning-with-errors-lwe" style="position:relative;"><a href="#22-learning-with-errors-lwe" aria-label="22 learning with errors lwe permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.2 Learning With Errors (LWE)</h3>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>n</mi><mo separator="true">,</mo><mi>m</mi><mo>∈</mo><mi mathvariant="double-struck">N</mi></mrow><annotation encoding="application/x-tex">n, m \in \N</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">n</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord mathbb">N</span></span></span></span></span>, modulus <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi><mo>≥</mo><mn>2</mn></mrow><annotation encoding="application/x-tex">q \ge 2</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8304em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">2</span></span></span></span></span>, and an error distribution <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>χ</mi></mrow><annotation encoding="application/x-tex">\chi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">χ</span></span></span></span></span> over <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="double-struck">Z</mi></mrow><annotation encoding="application/x-tex">\Z</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord mathbb">Z</span></span></span></span></span> (typically a discrete Gaussian or a centered bounded distribution). Sample:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>A</mi><mo>←</mo><msubsup><mi mathvariant="double-struck">Z</mi><mi>q</mi><mrow><mi>m</mi><mo>×</mo><mi>n</mi></mrow></msubsup><mo separator="true">,</mo><mspace width="1em"></mspace><mi>s</mi><mo>←</mo><msubsup><mi mathvariant="double-struck">Z</mi><mi>q</mi><mi>n</mi></msubsup><mo separator="true">,</mo><mspace width="1em"></mspace><mi>e</mi><mo>←</mo><msup><mi>χ</mi><mi>m</mi></msup><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">A \gets \Z_q^{m \times n},\quad s \gets \Z_q^n,\quad e \gets \chi^m,</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.2044em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8213em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="mbin mtight">×</span><span class="mord mathnormal mtight">n</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">s</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0975em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">e</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9088em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal">χ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">m</span></span></span></span></span></span></span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>and define:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>b</mi><mo>=</mo><mi>A</mi><mi>s</mi><mo>+</mo><mi>e</mi><mspace></mspace><mspace width="1em"></mspace><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">m</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">d</mi></mrow><mspace width="0.3333em"></mspace><mi>q</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">b = A s + e \pmod q.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">b</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7667em;vertical-align:-0.0833em;"></span><span class="mord mathnormal">A</span><span class="mord mathnormal">s</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">e</span><span class="mspace allowbreak"></span><span class="mspace" style="margin-right:1em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">mod</span></span></span><span class="mspace" style="margin-right:0.3333em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>The <strong>search-LWE</strong> problem is: given <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">,</mo><mi>b</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(A,b)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">b</span><span class="mclose">)</span></span></span></span></span> sampled as above, recover <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>s</mi></mrow><annotation encoding="application/x-tex">s</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">s</span></span></span></span></span>.</p>
<p>The <strong>decision-LWE</strong> problem is: distinguish <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">,</mo><mi>A</mi><mi>s</mi><mo>+</mo><mi>e</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(A, A s + e)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">A</span><span class="mord mathnormal">s</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">e</span><span class="mclose">)</span></span></span></span></span> from uniform <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">,</mo><mi>u</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(A, u)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">u</span><span class="mclose">)</span></span></span></span></span> where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>u</mi><mo>←</mo><msubsup><mi mathvariant="double-struck">Z</mi><mi>q</mi><mi>m</mi></msubsup></mrow><annotation encoding="application/x-tex">u \gets \Z_q^m</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">u</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.072em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">m</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span></span></span></span></span>.</p>
<p>Regev’s foundational result (and its refinements) relate average-case LWE to worst-case lattice problems in an explicit parameter regime. A usable engineering summary is:</p>
<blockquote>
<p>For <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi><mo>=</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">q=\mathrm{poly}(n)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">poly</span></span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mclose">)</span></span></span></span></span> and noise rate <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>α</mi></mrow><annotation encoding="application/x-tex">\alpha</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.0037em;">α</span></span></span></span></span> with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>α</mi><mi>q</mi><mo>≳</mo><msqrt><mi>n</mi></msqrt></mrow><annotation encoding="application/x-tex">\alpha q \gtrsim \sqrt{n}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9592em;vertical-align:-0.2296em;"></span><span class="mord mathnormal" style="margin-right:0.0037em;">α</span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel amsrm">≳</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.04em;vertical-align:-0.2397em;"></span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8003em;"><span class="svg-align" style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord" style="padding-left:0.833em;"><span class="mord mathnormal">n</span></span></span><span style="top:-2.7603em;"><span class="pstrut" style="height:3em;"></span><span class="hide-tail" style="min-width:0.853em;height:1.08em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.08em" viewBox="0 0 400000 1080" preserveAspectRatio="xMinYMin slice"><path d="M95,702
c-2.7,0,-7.17,-2.7,-13.5,-8c-5.8,-5.3,-9.5,-10,-9.5,-14
c0,-2,0.3,-3.3,1,-4c1.3,-2.7,23.83,-20.7,67.5,-54
c44.2,-33.3,65.8,-50.3,66.5,-51c1.3,-1.3,3,-2,5,-2c4.7,0,8.7,3.3,12,10
s173,378,173,378c0.7,0,35.3,-71,104,-213c68.7,-142,137.5,-285,206.5,-429
c69,-144,104.5,-217.7,106.5,-221
l0 -0
c5.3,-9.3,12,-14,20,-14
H400000v40H845.2724
s-225.272,467,-225.272,467s-235,486,-235,486c-2.7,4.7,-9,7,-19,7
c-6,0,-10,-1,-12,-3s-194,-422,-194,-422s-65,47,-65,47z
M834 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2397em;"><span></span></span></span></span></span></span></span></span></span>, an efficient LWE solver would imply an efficient worst-case lattice solver for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="sans-serif">G</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">p</mi><mi mathvariant="sans-serif">S</mi><mi mathvariant="sans-serif">V</mi><mi mathvariant="sans-serif">P</mi></mrow><annotation encoding="application/x-tex">\mathsf{GapSVP}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathsf">GapSVP</span></span></span></span></span></span> / <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="sans-serif">S</mi><mi mathvariant="sans-serif">I</mi><mi mathvariant="sans-serif">V</mi><mi mathvariant="sans-serif">P</mi></mrow><annotation encoding="application/x-tex">\mathsf{SIVP}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathsf">SIVP</span></span></span></span></span></span> at approximation factor roughly <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mover accent="true"><mi>O</mi><mo>~</mo></mover><mo stretchy="false">(</mo><mi>n</mi><mi mathvariant="normal">/</mi><mi>α</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\tilde{O}(n/\alpha)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.1702em;vertical-align:-0.25em;"></span><span class="mord accent"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.9202em;"><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span></span><span style="top:-3.6023em;"><span class="pstrut" style="height:3em;"></span><span class="accent-body" style="left:-0.1667em;"><span class="mord">~</span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mord">/</span><span class="mord mathnormal" style="margin-right:0.0037em;">α</span><span class="mclose">)</span></span></span></span></span>. <span class="citation" id="citation--regev2009lwe--5">(<a href="#bib-regev2009lwe">1</a>)</span> <span class="citation" id="citation--micciancioregev2007gaussian--6">(<a href="#bib-micciancioregev2007gaussian">2</a>)</span></p>
</blockquote>
<p>Regev’s original reduction is quantum; later work establishes comparable hardness under classical reductions in relevant regimes. <span class="citation" id="citation--brakerski2013classicallwe--7">(<a href="#bib-brakerski2013classicallwe">5</a>)</span></p>
<p>Two details matter more than people admit:</p>
<ol>
<li><strong>Which distribution is assumed.</strong> Proofs typically state <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>χ</mi></mrow><annotation encoding="application/x-tex">\chi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">χ</span></span></span></span></span> as a discrete Gaussian or a distribution with explicit tail bounds. Implementations often use centered binomial or other efficient samplers, which must be justified as “close enough” in the right sense for the <em>specific proof obligations you are relying on</em>. <span class="citation" id="citation--peikert2016decade--8">(<a href="#bib-peikert2016decade">3</a>)</span></li>
<li><strong>Which LWE flavor is assumed.</strong> Search/decision equivalences exist in many regimes, but they are not a magical black box; they can depend on <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>, on the secret distribution, and on how you treat noise. If your implementation deviates (small secret, compressed samples, non-i.i.d. noise), you need to know what you are implicitly assuming.</li>
</ol>
<blockquote>
<p>efficient LWE solvers imply efficient worst-case lattice solvers (for certain approximation factors), under explicit distributional assumptions. <span class="citation" id="citation--regev2009lwe--9">(<a href="#bib-regev2009lwe">1</a>)</span> <span class="citation" id="citation--micciancioregev2007gaussian--10">(<a href="#bib-micciancioregev2007gaussian">2</a>)</span> <span class="citation" id="citation--brakerski2013classicallwe--11">(<a href="#bib-brakerski2013classicallwe">5</a>)</span></p>
</blockquote>
<h3 id="23-short-integer-solution-sis" style="position:relative;"><a href="#23-short-integer-solution-sis" aria-label="23 short integer solution sis permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3 Short Integer Solution (SIS)</h3>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi><mo>←</mo><msubsup><mi mathvariant="double-struck">Z</mi><mi>q</mi><mrow><mi>m</mi><mo>×</mo><mi>n</mi></mrow></msubsup></mrow><annotation encoding="application/x-tex">A \gets \Z_q^{m \times n}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1544em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7713em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="mbin mtight">×</span><span class="mord mathnormal mtight">n</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span></span></span></span></span>. The <strong>SIS</strong> problem with bound <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>β</mi></mrow><annotation encoding="application/x-tex">\beta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span></span></span></span></span> is to find a non-zero vector <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi><mo>∈</mo><msup><mi mathvariant="double-struck">Z</mi><mi>n</mi></msup><mo>∖</mo><mo stretchy="false">{</mo><mn>0</mn><mo stretchy="false">}</mo></mrow><annotation encoding="application/x-tex">x \in \Z^n \setminus \{0\}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5782em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathbb">Z</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∖</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mclose">}</span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>A</mi><mi>x</mi><mo>≡</mo><mn>0</mn><mspace></mspace><mspace width="1em"></mspace><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">m</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">d</mi></mrow><mspace width="0.3333em"></mspace><mi>q</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mspace width="2em"></mspace><mi mathvariant="normal">∥</mi><mi>x</mi><mi mathvariant="normal">∥</mi><mo>≤</mo><mi>β</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">A x \equiv 0 \pmod q,\qquad \|x\| \le \beta.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">0</span><span class="mspace allowbreak"></span><span class="mspace" style="margin-right:1em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">mod</span></span></span><span class="mspace" style="margin-right:0.3333em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∥</span><span class="mord mathnormal">x</span><span class="mord">∥</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span><span class="mord">.</span></span></span></span></span></div>
<p>Equivalently, SIS asks for a short non-zero vector in the <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span>-ary lattice <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi mathvariant="normal">Λ</mi><mi>q</mi><mo>⊥</mo></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\Lambda_q^\perp(A)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.2322em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord">Λ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-2.453em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mrel mtight">⊥</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span></span></span></span></span>.</p>
<p>SIS is the canonical collision / relation-finding hardness backbone for lattice-based hash functions and commitment-style components. Ajtai’s work is the root of the worst-case/average-case connection here: average-case short relations in random modular constraints imply worst-case hardness in lattice geometry. <span class="citation" id="citation--ajtai1996hardinstances--12">(<a href="#bib-ajtai1996hardinstances">6</a>)</span></p>
<h3 id="24-structured-variants-ring-lwe-and-module-lwe" style="position:relative;"><a href="#24-structured-variants-ring-lwe-and-module-lwe" aria-label="24 structured variants ring lwe and module lwe permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4 Structured variants: Ring-LWE and Module-LWE</h3>
<p>Efficiency demands structure; security pays for it.</p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>R</mi><mo>=</mo><mi mathvariant="double-struck">Z</mi><mo stretchy="false">[</mo><mi>x</mi><mo stretchy="false">]</mo><mi mathvariant="normal">/</mi><mo stretchy="false">(</mo><mi>f</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">R = \Z[x]/(f(x))</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.00773em;">R</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathbb">Z</span><span class="mopen">[</span><span class="mord mathnormal">x</span><span class="mclose">]</span><span class="mord">/</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">))</span></span></span></span></span> with cyclotomic choices common in practice (e.g., <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mo>=</mo><msup><mi>x</mi><mi>N</mi></msup><mo>+</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">f(x)=x^N+1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9247em;vertical-align:-0.0833em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8413em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.10903em;">N</span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> for power-of-two <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>N</mi></mrow><annotation encoding="application/x-tex">N</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span></span></span></span></span>), and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>R</mi><mi>q</mi></msub><mo>=</mo><mi>R</mi><mi mathvariant="normal">/</mi><mi>q</mi><mi>R</mi></mrow><annotation encoding="application/x-tex">R_q = R / qR</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.00773em;">R</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0077em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.00773em;">R</span><span class="mord">/</span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mord mathnormal" style="margin-right:0.00773em;">R</span></span></span></span></span>.</p>
<ul>
<li><strong>Ring-LWE</strong> samples <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi><mo separator="true">,</mo><mi>s</mi><mo separator="true">,</mo><mi>e</mi></mrow><annotation encoding="application/x-tex">A,s,e</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">A</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">e</span></span></span></span></span> in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>R</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">R_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.00773em;">R</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0077em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> and defines <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>b</mi><mo>=</mo><mi>A</mi><mi>s</mi><mo>+</mo><mi>e</mi></mrow><annotation encoding="application/x-tex">b = A s + e</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">b</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7667em;vertical-align:-0.0833em;"></span><span class="mord mathnormal">A</span><span class="mord mathnormal">s</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">e</span></span></span></span></span> in the ring. The hardness reductions are to worst-case problems on <em>ideal lattices</em>, which is a narrower and more structured family than arbitrary lattices. <span class="citation" id="citation--lyubashevsky2010ringlwe--13">(<a href="#bib-lyubashevsky2010ringlwe">7</a>)</span></li>
<li><strong>Module-LWE</strong> lives in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>R</mi><mi>q</mi><mi>k</mi></msubsup></mrow><annotation encoding="application/x-tex">R_q^k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.2322em;vertical-align:-0.3831em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.00773em;">R</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-2.453em;margin-left:-0.0077em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span></span></span></span></span> (a module of rank <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span>), interpolating between unstructured LWE (large <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span>, less structure) and Ring-LWE (<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi><mo>=</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">k=1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span>, maximal structure). This is exactly the reason the NIST standards emphasize “module-lattice-based” constructions: it is the efficiency/security Pareto surface the community has converged on. <span class="citation" id="citation--nistfips203--14">(<a href="#bib-nistfips203">8</a>)</span></li>
</ul>
<p>The engineering takeaway is not “Ring bad, Module good.” The takeaway is: <strong>structure is an attack surface</strong> and the reduction story becomes more delicate as structure increases.</p>
<p>Concrete example: the ML-KEM parameter sets standardized in FIPS 203 instantiate a Module-LWE lineage over <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>R</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">R_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.00773em;">R</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0077em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>N</mi><mo>=</mo><mn>256</mn></mrow><annotation encoding="application/x-tex">N=256</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">256</span></span></span></span></span>, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi><mo>=</mo><mn>3329</mn></mrow><annotation encoding="application/x-tex">q=3329</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">3329</span></span></span></span></span>, and module ranks <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi><mo>∈</mo><mo stretchy="false">{</mo><mn>2</mn><mo separator="true">,</mo><mn>3</mn><mo separator="true">,</mo><mn>4</mn><mo stretchy="false">}</mo></mrow><annotation encoding="application/x-tex">k \in \{2,3,4\}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">2</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">3</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">4</span><span class="mclose">}</span></span></span></span></span> (corresponding to ML-KEM-512/768/1024). They do not use an “ideal discrete Gaussian”; they use efficient bounded samplers and explicit compression/rounding rules. Those are engineering choices, and they are part of the <em>assumption surface area</em>. <span class="citation" id="citation--nistfips203--15">(<a href="#bib-nistfips203">8</a>)</span></p>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p><strong>Algebraic structure is leverage.</strong> You introduce it for performance, but it also creates new statistical tests, new subspace hypotheses, and new families of special instances you now have to rule out.</p>
</div>
<h3 id="25-reduction-loss-and-concrete-security-why-parameters-get-fat" style="position:relative;"><a href="#25-reduction-loss-and-concrete-security-why-parameters-get-fat" aria-label="25 reduction loss and concrete security why parameters get fat permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5 Reduction loss and concrete security (why parameters get fat)</h3>
<p>Reductions are rarely tight. In schematic form, a typical security proof looks like:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><msub><mi mathvariant="normal">Π</mi><mi>P</mi></msub></msub><mo stretchy="false">(</mo><mi mathvariant="script">A</mi><mo stretchy="false">)</mo><mo>≤</mo><mi>c</mi><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo><mo>⋅</mo><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mrow><mrow><mi mathvariant="sans-serif">L</mi><mi mathvariant="sans-serif">W</mi><mi mathvariant="sans-serif">E</mi></mrow><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo></mrow></msub><mo stretchy="false">(</mo><mi mathvariant="script">B</mi><mo stretchy="false">)</mo><mo>+</mo><mi>ε</mi><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\proto_P}(\adv) \le c(n)\cdot \mathrm{Adv}_{\mathsf{LWE}(P)}(\mathcal{B}) + \varepsilon(P),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0003em;vertical-align:-0.2503em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mtight">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3567em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1433em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2503em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathcal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">c</span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.1052em;vertical-align:-0.3552em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.5198em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathsf mtight">LWE</span></span><span class="mopen mtight">(</span><span class="mord mathnormal mtight" style="margin-right:0.13889em;">P</span><span class="mclose mtight">)</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3552em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathcal" style="margin-right:0.03041em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">ε</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">c(n)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">c</span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mclose">)</span></span></span></span></span> is polynomial and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ε</mi><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\varepsilon(P)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">ε</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">)</span></span></span></span></span> collects statistical distance terms, failure probabilities (e.g., decryption failures), and other “small” terms.</p>
<p>In asymptopia, “polynomial” is harmless. In production, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi><mo stretchy="false">(</mo><mi>n</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">c(n)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">c</span><span class="mopen">(</span><span class="mord mathnormal">n</span><span class="mclose">)</span></span></span></span></span> forces you to inflate parameters to recover a desired concrete margin. If you want to reason about bit-security, you need:</p>
<ol>
<li>a reduction (often non-tight),</li>
<li>an attack cost model (heuristic),</li>
<li>and a mapping from that model to operational budgets (time, memory, parallelism, side-channel surface).</li>
</ol>
<p>This is where the lattice estimator ecosystem exists: it is not part of the theorem, but it is part of deployment reality. <span class="citation" id="citation--chennguyen2011bkz20--16">(<a href="#bib-chennguyen2011bkz20">4</a>)</span> <span class="citation" id="citation--albrechtlweestimator--17">(<a href="#bib-albrechtlweestimator">9</a>)</span></p>
<p>To make this concrete, the backbone of many classical lattice attacks is BKZ reduction. The quality of a reduced basis is often summarized by the <strong>root Hermite factor</strong> <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>δ</mi><mn>0</mn></msub></mrow><annotation encoding="application/x-tex">\delta_0</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0379em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">0</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> such that (heuristically):</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∥</mi><msub><mi>b</mi><mn>1</mn></msub><mi mathvariant="normal">∥</mi><mo>≈</mo><msub><mi>δ</mi><mn>0</mn></msub><mo stretchy="false">(</mo><mi>β</mi><msup><mo stretchy="false">)</mo><mrow><mtext> </mtext><mi>n</mi></mrow></msup><mo>⋅</mo><mi>det</mi><mo>⁡</mo><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><msup><mo stretchy="false">)</mo><mrow><mn>1</mn><mi mathvariant="normal">/</mi><mi>n</mi></mrow></msup><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\|b_1\| \approx \delta_0(\beta)^{\,n} \cdot \det(\Lambda)^{1/n},</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∥</span><span class="mord"><span class="mord mathnormal">b</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">∥</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0379em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">0</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span><span class="mclose"><span class="mclose">)</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mspace mtight" style="margin-right:0.1952em;"></span><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.188em;vertical-align:-0.25em;"></span><span class="mop">det</span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose"><span class="mclose">)</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">1/</span><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>β</mi></mrow><annotation encoding="application/x-tex">\beta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span></span></span></span></span> is the BKZ block size and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>det</mi><mo>⁡</mo><mo stretchy="false">(</mo><mi mathvariant="normal">Λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\det(\Lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mop">det</span><span class="mopen">(</span><span class="mord">Λ</span><span class="mclose">)</span></span></span></span></span> is the lattice determinant. Under standard heuristics (GSA), a common approximation is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>δ</mi><mn>0</mn></msub><mo stretchy="false">(</mo><mi>β</mi><mo stretchy="false">)</mo><mo>≈</mo><msup><mrow><mo fence="true">(</mo><mfrac><mi>β</mi><mrow><mn>2</mn><mi>π</mi><mi>e</mi></mrow></mfrac><mo>⋅</mo><mo stretchy="false">(</mo><mi>π</mi><mi>β</mi><msup><mo stretchy="false">)</mo><mrow><mn>1</mn><mi mathvariant="normal">/</mi><mi>β</mi></mrow></msup><mo fence="true">)</mo></mrow><mfrac><mn>1</mn><mrow><mn>2</mn><mo stretchy="false">(</mo><mi>β</mi><mo>−</mo><mn>1</mn><mo stretchy="false">)</mo></mrow></mfrac></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\delta_0(\beta) \approx
\left(
\frac{\beta}{2\pi e}\cdot(\pi\beta)^{1/\beta}
\right)^{\frac{1}{2(\beta-1)}}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0379em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">0</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.744em;vertical-align:-0.95em;"></span><span class="minner"><span class="minner"><span class="mopen delimcenter" style="top:0em;"><span class="delimsizing size3">(</span></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.3714em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.03588em;">π</span><span class="mord mathnormal">e</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05278em;">β</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.03588em;">π</span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span><span class="mclose"><span class="mclose">)</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">1/</span><span class="mord mathnormal mtight" style="margin-right:0.05278em;">β</span></span></span></span></span></span></span></span></span><span class="mclose delimcenter" style="top:0em;"><span class="delimsizing size3">)</span></span></span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:1.7939em;"><span style="top:-4.2029em;margin-right:0.05em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mopen nulldelimiter sizing reset-size3 size6"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8443em;"><span style="top:-2.6408em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight"><span class="mord mtight">2</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight" style="margin-right:0.05278em;">β</span><span class="mbin mtight">−</span><span class="mord mtight">1</span><span class="mclose mtight">)</span></span></span></span><span style="top:-3.2255em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line mtight" style="border-bottom-width:0.049em;"></span></span><span style="top:-3.384em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight"><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.5378em;"><span></span></span></span></span></span><span class="mclose nulldelimiter sizing reset-size3 size6"></span></span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">.</span></span></span></span></span></div>
<p>The deployment-level problem is that <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>β</mi></mrow><annotation encoding="application/x-tex">\beta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05278em;">β</span></span></span></span></span> is not just a parameter in a paper; it is an attacker knob trading time vs memory vs parallelism, and your “bit-security” estimate is a projection of that multidimensional optimization into a single scalar. That projection is where most engineering overconfidence lives. <span class="citation" id="citation--chennguyen2011bkz20--18">(<a href="#bib-chennguyen2011bkz20">4</a>)</span> <span class="citation" id="citation--albrechtlweestimator--19">(<a href="#bib-albrechtlweestimator">9</a>)</span></p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  A<span class="token text string">["Worst-case lattice hardness (GapSVP/SIVP)"]</span> <span class="token arrow operator">--></span><span class="token label property">|reduction|</span> B<span class="token text string">["Average-case assumption (LWE/SIS distribution)"]</span>
  B <span class="token arrow operator">--></span><span class="token label property">|construction|</span> C<span class="token text string">["Primitive (KEM / Signature)"]</span>
  C <span class="token arrow operator">--></span><span class="token label property">|implementation|</span> D<span class="token text string">["System artifact (CPU + RNG + memory + concurrency)"]</span>
  D <span class="token arrow operator">--></span><span class="token label property">|observable traces|</span> E<span class="token text string">["Adversary view"]</span>
  E <span class="token arrow operator">--></span><span class="token label property">|attack selection|</span> F<span class="token text string">["Concrete cost model (BKZ / sieving / BKW / hybrids)"]</span>
  F <span class="token arrow operator">--></span><span class="token label property">|security margin|</span> G<span class="token text string">["Operational claim ('128-bit', etc.)"]</span>
  D <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">-.</span> <span class="token label property">breaks</span> <span class="token arrow operator">.-></span></span> B
  D <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">-.</span> <span class="token label property">breaks</span> <span class="token arrow operator">.-></span></span> C</code></pre></div>
<h2 id="3-system-constraints" style="position:relative;"><a href="#3-system-constraints" aria-label="3 system constraints permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3. System Constraints</h2>
<p>This is the part formal papers cannot carry for you. If you operate in IIoT, distributed control planes, VPN endpoints, or globally deployed backend services, you do not get the “ideal sampler + ideal CPU + ideal leakage” model for free.</p>
<h3 id="31-distribution-preservation-is-a-correctness-property" style="position:relative;"><a href="#31-distribution-preservation-is-a-correctness-property" aria-label="31 distribution preservation is a correctness property permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.1 Distribution preservation is a correctness property</h3>
<p>Suppose the proof requires error distribution <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>χ</mi></mrow><annotation encoding="application/x-tex">\chi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">χ</span></span></span></span></span> but the implementation samples <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>χ</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">\chi'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9463em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal">χ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span>. Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi><mo>=</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">D</mi></mrow><mo stretchy="false">(</mo><mi>χ</mi><mo separator="true">,</mo><msup><mi>χ</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\Delta = \mathrm{SD}(\chi,\chi')</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0019em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">SD</span></span><span class="mopen">(</span><span class="mord mathnormal">χ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">χ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> be the statistical distance between the two single-sample distributions.</p>
<p>By a standard hybrid argument, for <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>m</mi></mrow><annotation encoding="application/x-tex">m</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">m</span></span></span></span></span> independent samples:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">D</mi></mrow><mo stretchy="false">(</mo><msup><mi>χ</mi><mi>m</mi></msup><mo separator="true">,</mo><mo stretchy="false">(</mo><msup><mi>χ</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><msup><mo stretchy="false">)</mo><mi>m</mi></msup><mo stretchy="false">)</mo><mo>≤</mo><mi>m</mi><mi mathvariant="normal">Δ</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{SD}(\chi^m, (\chi')^m) \le m\Delta.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0519em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">SD</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">χ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">m</span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">χ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mclose"><span class="mclose">)</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">m</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">m</span><span class="mord">Δ.</span></span></span></span></span></div>
<p>This is a <em>hard bound</em> on how much your implementation can drift before you have materially changed the assumed problem distribution.</p>
<p>In other words: sampler bias is not “implementation detail.” It is a parameter in the adversary’s distinguishing advantage.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>Distributional refinement:</strong> the deployed sampler must stay within negligible statistical distance of the distribution assumed by the proof. If not, you are no longer reducing to the stated problem.</p>
</div>
<h3 id="32-memory-and-cache-behavior-are-part-of-the-attacker-interface" style="position:relative;"><a href="#32-memory-and-cache-behavior-are-part-of-the-attacker-interface" aria-label="32 memory and cache behavior are part of the attacker interface permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.2 Memory and cache behavior are part of the attacker interface</h3>
<p>The LWE/SIS hardness games assume the adversary sees algebraic samples, not microarchitectural traces. Real code runs on CPUs that leak via timing, cache, branch predictors, and transient execution. This induces a leakage channel:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="sans-serif">L</mi><mi mathvariant="sans-serif">e</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">k</mi></mrow><mo>:</mo><mo stretchy="false">(</mo><mtext>state</mtext><mo separator="true">,</mo><mtext>inputs</mtext><mo separator="true">,</mo><mtext>schedule</mtext><mo stretchy="false">)</mo><mo>→</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mo>∗</mo></msup><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathsf{Leak} : (\text{state}, \text{inputs}, \text{schedule}) \to \{0,1\}^*,</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathsf">Leak</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord text"><span class="mord">state</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">inputs</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">schedule</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7387em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">∗</span></span></span></span></span></span></span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>and the attacker’s observation is no longer <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">,</mo><mi>b</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(A,b)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">b</span><span class="mclose">)</span></span></span></span></span>; it is <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">,</mo><mi>b</mi><mo separator="true">,</mo><mrow><mi mathvariant="sans-serif">L</mi><mi mathvariant="sans-serif">e</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">k</mi></mrow><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(A,b,\mathsf{Leak}(\cdot))</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">b</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathsf">Leak</span></span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">))</span></span></span></span></span>.</p>
<p>You do not get to hand-wave this away by calling it “side-channel hardening.” If leakage depends on secret-dependent control flow or memory access, the problem you are solving is not LWE; it is “LWE with a leakage oracle,” which is a different assumption.</p>
<p>Operationally, this forces concrete constraints:</p>
<ul>
<li>constant-time arithmetic for NTT/multiplication paths,</li>
<li>constant-time sampling and rejection logic,</li>
<li>no secret-dependent table indices,</li>
<li>explicit zeroization of ephemeral secrets and intermediate buffers,</li>
<li>avoiding shared mutable RNG state across concurrent sessions.</li>
</ul>
<h3 id="33-determinism-concurrency-and-entropy-budgets" style="position:relative;"><a href="#33-determinism-concurrency-and-entropy-budgets" aria-label="33 determinism concurrency and entropy budgets permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.3 Determinism, concurrency, and entropy budgets</h3>
<p>Distributed systems want determinism (reproducible builds, deterministic state machines) and often run in constrained environments (IIoT gateways, embedded devices, enclaves, containers with weak entropy at boot). That collides with lattice schemes in predictable ways:</p>
<ul>
<li><strong>Entropy</strong>: ML-KEM-style primitives need fresh randomness per encapsulation; “reuse because it’s faster” is a catastrophe. <span class="citation" id="citation--nistfips203--20">(<a href="#bib-nistfips203">8</a>)</span></li>
<li><strong>Concurrency</strong>: shared RNG state across goroutines/threads becomes a correlation gadget.</li>
<li><strong>Crash consistency</strong>: erasure is not atomic; you must treat “crash after keygen but before zeroization” as part of the adversary model.</li>
</ul>
<p>If you want to be honest, the system boundary must state which of these are assumed and which are enforced.</p>
<h2 id="4-core-argument--insight" style="position:relative;"><a href="#4-core-argument--insight" aria-label="4 core argument  insight permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4. Core Argument / Insight</h2>
<p>The deep failure mode in PQC deployments is not that LWE/SIS become easy. The failure mode is that teams confuse:</p>
<ul>
<li><strong>a reduction</strong> (a conditional implication in an ideal model),</li>
<li><strong>a parameter choice</strong> (a concrete instantiation sized using heuristic cost models),</li>
<li><strong>an implementation</strong> (a program that must preserve distribution and hide secrets),</li>
<li>and <strong>a system</strong> (a stateful, concurrent, observable artifact operating under failure).</li>
</ul>
<p>When those layers are collapsed into “we use lattice crypto, therefore quantum-safe,” the security claim becomes meaningless.</p>
<p>So the right way to think about LWE/SIS in systems engineering is to treat them as <em>assumption interfaces</em> with explicit obligations. A minimal obligation set looks like this:</p>
<ol>
<li><strong>Sampling obligations</strong>: error/secret sampling matches the assumed distribution within negligible distance; compression does not introduce exploitable bias; decryption failures are bounded and monitored.</li>
<li><strong>Leakage obligations</strong>: constant-time boundaries for secrets; avoidance of secret-dependent memory access; hardened error paths.</li>
<li><strong>Lifecycle obligations</strong>: keys and intermediate secrets are erased promptly; crash behavior does not leave long-lived secrets resident; “ephemeral” is enforced, not asserted.</li>
<li><strong>Agility obligations</strong>: parameters and algorithms are versioned protocol objects; rollout and rollback are engineered, not improvised.</li>
</ol>
<p>The reason this matters is that <em>concrete security</em> is not a theorem; it is an adversarial optimization problem.</p>
<p>You can write it as:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="sans-serif">C</mi><mi mathvariant="sans-serif">o</mi><mi mathvariant="sans-serif">s</mi><mi mathvariant="sans-serif">t</mi></mrow><mo stretchy="false">(</mo><mi>P</mi><mo stretchy="false">)</mo><mo>=</mo><munder><mrow><mi>min</mi><mo>⁡</mo></mrow><mrow><mrow><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">l</mi><mi mathvariant="sans-serif">g</mi></mrow><mo>∈</mo><mrow><mi mathvariant="sans-serif">A</mi><mi mathvariant="sans-serif">t</mi><mi mathvariant="sans-serif">t</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">c</mi><mi mathvariant="sans-serif">k</mi><mi mathvariant="sans-serif">s</mi></mrow></mrow></munder><mtext>  </mtext><msub><mrow><mi mathvariant="sans-serif">W</mi><mi mathvariant="sans-serif">o</mi><mi mathvariant="sans-serif">r</mi><mi mathvariant="sans-serif">k</mi></mrow><mrow><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">l</mi><mi mathvariant="sans-serif">g</mi></mrow></msub><mo stretchy="false">(</mo><mi>P</mi><mo separator="true">;</mo><mtext>model</mtext><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathsf{Cost}(P) = \min_{\mathsf{alg} \in \mathsf{Attacks}} \; \mathsf{Work}_{\mathsf{alg}}(P;\text{model}),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathsf">Cost</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.6382em;vertical-align:-0.8882em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.6679em;"><span style="top:-2.3479em;margin-left:0em;"><span class="pstrut" style="height:3em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathsf mtight" style="margin-right:0.01389em;">alg</span></span><span class="mrel mtight">∈</span><span class="mord mtight"><span class="mord mathsf mtight">Attacks</span></span></span></span></span><span style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span><span class="mop">min</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.8882em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathsf">Work</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathsf mtight" style="margin-right:0.01389em;">alg</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">model</span></span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext>model</mtext></mrow><annotation encoding="application/x-tex">\text{model}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord">model</span></span></span></span></span></span> encodes time, memory, parallelism, and (increasingly) quantum speedups. The uncomfortable point: <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="sans-serif">W</mi><mi mathvariant="sans-serif">o</mi><mi mathvariant="sans-serif">r</mi><mi mathvariant="sans-serif">k</mi></mrow><mrow><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">l</mi><mi mathvariant="sans-serif">g</mi></mrow></msub></mrow><annotation encoding="application/x-tex">\mathsf{Work}_{\mathsf{alg}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9805em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord"><span class="mord mathsf">Work</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathsf mtight" style="margin-right:0.01389em;">alg</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is heuristic for the best attacks we know, and it changes over time. <span class="citation" id="citation--peikert2016decade--21">(<a href="#bib-peikert2016decade">3</a>)</span> <span class="citation" id="citation--chennguyen2011bkz20--22">(<a href="#bib-chennguyen2011bkz20">4</a>)</span></p>
<p>The resulting posture should be adversarial and operational:</p>
<ul>
<li>assume estimator drift (new BKZ/sieving improvements),</li>
<li>assume implementation faults (timing, RNG, error oracles),</li>
<li>and design rollback paths as if you will need them.</li>
</ul>
<h2 id="5-implications" style="position:relative;"><a href="#5-implications" aria-label="5 implications permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5. Implications</h2>
<p>For production systems, treating LWE/SIS correctly implies specific engineering decisions:</p>
<ol>
<li><strong>Treat parameter sets as part of the protocol version.</strong> If you cannot unambiguously name <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>P</mi></mrow><annotation encoding="application/x-tex">P</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span></span></span></span></span> (including compression rules, domain separation, and failure semantics), you cannot reason about interoperability or downgrade surfaces.</li>
<li><strong>Make distributional correctness testable.</strong> Sampler tests, statistical checks, and CI gates are not “nice-to-have.” They are how you maintain the refinement boundary.</li>
<li><strong>Budget for memory-hardness and DoS.</strong> Lattice operations are attacker-triggerable (handshakes, key exchanges). Your availability model must treat expensive crypto as an attack surface, especially under packet loss and retries.</li>
<li><strong>Formalize lifecycle invariants.</strong> “Ephemeral” means <em>erased before the next adversarial event</em>. Specify it like an invariant and enforce it like one.</li>
<li><strong>Be explicit about structure.</strong> Ring/Module structure buys you performance. It must be treated as an explicit risk trade-off, with monitoring and agility, not as free security.</li>
</ol>
<h2 id="6-continuity-hook" style="position:relative;"><a href="#6-continuity-hook" aria-label="6 continuity hook permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>6. Continuity Hook</h2>
<p>Part 1 defined adversary models (classical vs quantum vs QROM) by specifying <em>interfaces and resource vectors</em>. Part 2 defined LWE/SIS as assumption interfaces with concrete system obligations.</p>
<p>The next step is inevitable:</p>
<blockquote>
<p>how do lattice hardness and reduction arguments change once the attacker is quantum, and how should we account for quantum time–memory trade-offs (and QROM interfaces) when sizing parameters for real systems?</p>
</blockquote>
<p>That is Part 3: <em>quantum cost models, coherence budgets, and what “post-quantum hardness” actually means in operational terms</em>.</p>
<h2 id="7-references" style="position:relative;"><a href="#7-references" aria-label="7 references permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>7. References</h2>
<ul>
<li>Regev, “On Lattices, Learning with Errors, Random Linear Codes, and Cryptography” (<a href="https://doi.org/10.1145/1568318.1568324" target="_blank" rel="nofollow noopener noreferrer">JACM</a>). <span class="citation" id="citation--regev2009lwe--23">(<a href="#bib-regev2009lwe">1</a>)</span></li>
<li>Ajtai, “Generating Hard Instances of Lattice Problems” (<a href="https://doi.org/10.1145/237814.237838" target="_blank" rel="nofollow noopener noreferrer">STOC '96</a>). <span class="citation" id="citation--ajtai1996hardinstances--24">(<a href="#bib-ajtai1996hardinstances">6</a>)</span></li>
<li>Micciancio &#x26; Regev, “Worst-Case to Average-Case Reductions Based on Gaussian Measures” (<a href="https://doi.org/10.1137/S0097539705447360" target="_blank" rel="nofollow noopener noreferrer">SIAM J. Comput.</a>). <span class="citation" id="citation--micciancioregev2007gaussian--25">(<a href="#bib-micciancioregev2007gaussian">2</a>)</span></li>
<li>Brakerski et al., “Classical Hardness of Learning with Errors” (<a href="https://doi.org/10.1145/2488608.2488680" target="_blank" rel="nofollow noopener noreferrer">STOC '13</a>). <span class="citation" id="citation--brakerski2013classicallwe--26">(<a href="#bib-brakerski2013classicallwe">5</a>)</span></li>
<li>Lyubashevsky, Peikert &#x26; Regev, “On Ideal Lattices and Learning with Errors over Rings” (<a href="https://doi.org/10.1007/978-3-642-13190-5_1" target="_blank" rel="nofollow noopener noreferrer">EUROCRYPT 2010</a>). <span class="citation" id="citation--lyubashevsky2010ringlwe--27">(<a href="#bib-lyubashevsky2010ringlwe">7</a>)</span></li>
<li>Chen &#x26; Nguyen, “BKZ 2.0: Better Lattice Security Estimates” (<a href="https://doi.org/10.1007/978-3-642-25385-0_1" target="_blank" rel="nofollow noopener noreferrer">ASIACRYPT 2011</a>). <span class="citation" id="citation--chennguyen2011bkz20--28">(<a href="#bib-chennguyen2011bkz20">4</a>)</span></li>
<li>Peikert, “A Decade of Lattice Cryptography” (<a href="https://doi.org/10.1561/0400000074" target="_blank" rel="nofollow noopener noreferrer">FnT TCS</a>). <span class="citation" id="citation--peikert2016decade--29">(<a href="#bib-peikert2016decade">3</a>)</span></li>
<li>NIST, “FIPS 203: ML-KEM” (<a href="https://csrc.nist.gov/pubs/fips/203/final" target="_blank" rel="nofollow noopener noreferrer">CSRC</a>). <span class="citation" id="citation--nistfips203--30">(<a href="#bib-nistfips203">8</a>)</span></li>
<li>Albrecht et al., “LWE estimator” (<a href="https://github.com/malb/lattice-estimator" target="_blank" rel="nofollow noopener noreferrer">GitHub</a>). <span class="citation" id="citation--albrechtlweestimator--31">(<a href="#bib-albrechtlweestimator">9</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-regev2009lwe">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Regev O. On Lattices, Learning with Errors, Random Linear Codes, and Cryptography. Journal of the ACM [Internet]. 2009;56(6). Available from: https://doi.org/10.1145/1568318.1568324</div>
  </div>
  <div class="csl-entry" id="bib-micciancioregev2007gaussian">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Micciancio D, Regev O. Worst-Case to Average-Case Reductions Based on Gaussian Measures. SIAM Journal on Computing [Internet]. 2007;37(1):267–302. Available from: https://doi.org/10.1137/S0097539705447360</div>
  </div>
  <div class="csl-entry" id="bib-peikert2016decade">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Peikert C. A Decade of Lattice Cryptography [Internet]. 2016. Available from: https://doi.org/10.1561/0400000074</div>
  </div>
  <div class="csl-entry" id="bib-chennguyen2011bkz20">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Chen Y, Nguyen PQ. BKZ 2.0: Better Lattice Security Estimates. In: Advances in Cryptology – ASIACRYPT 2011 [Internet]. 2011. Available from: https://doi.org/10.1007/978-3-642-25385-0_1</div>
  </div>
  <div class="csl-entry" id="bib-brakerski2013classicallwe">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">Brakerski Z, Langlois A, Peikert C, Regev O, Stehlé D. Classical Hardness of Learning with Errors. In: Proceedings of the Forty-Fifth Annual ACM Symposium on Theory of Computing (STOC ’13) [Internet]. 2013. Available from: https://doi.org/10.1145/2488608.2488680</div>
  </div>
  <div class="csl-entry" id="bib-ajtai1996hardinstances">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">Ajtai M. Generating Hard Instances of Lattice Problems (Extended Abstract). In: Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing (STOC ’96) [Internet]. 1996. Available from: https://doi.org/10.1145/237814.237838</div>
  </div>
  <div class="csl-entry" id="bib-lyubashevsky2010ringlwe">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">Lyubashevsky V, Peikert C, Regev O. On Ideal Lattices and Learning with Errors over Rings. In: Advances in Cryptology – EUROCRYPT 2010 [Internet]. 2010. Available from: https://doi.org/10.1007/978-3-642-13190-5_1</div>
  </div>
  <div class="csl-entry" id="bib-nistfips203">
    <div class="csl-left-margin">8. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/203/final</div>
  </div>
  <div class="csl-entry" id="bib-albrechtlweestimator">
    <div class="csl-left-margin">9. </div><div class="csl-right-inline">Albrecht MR, others. LWE estimator [Internet]. Web; Available from: https://github.com/malb/lattice-estimator</div>
  </div>
</div>]]></content>
        <category label="post-quantum-cryptography"/>
        <category label="formal-methods"/>
        <category label="cryptography"/>
        <category label="lattices"/>
        <category label="LWE"/>
        <category label="SIS"/>
        <category label="reductions"/>
        <category label="security-engineering"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC Research Series — Part 1]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-pqc-research-day-1-formal-threat-models</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-pqc-research-day-1-formal-threat-models"/>
        <updated>2026-04-24T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[A formal adversary taxonomy for PQC deployments: classical vs quantum vs QROM, with explicit resource accounting (queries, memory, time) and system-boundary assumptions.]]></summary>
        <content type="html"><![CDATA[<h2 id="formal-threat-models-for-post-quantum-systems" style="position:relative;"><a href="#formal-threat-models-for-post-quantum-systems" aria-label="formal threat models for post quantum systems permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Formal Threat Models for Post-Quantum Systems</h2>
<p>Author: Mayckon Giovani<br>
Date: April 24, 2026<br>
Series: PQC Research Series<br>
Tags: PQC, Formal Methods, Cryptography, Systems</p>
<h2 id="0-context" style="position:relative;"><a href="#0-context" aria-label="0 context permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>0. Context</h2>
<p>This article formalizes the adversary models that actually sit underneath “post-quantum security” claims.</p>
<p>Most production discussions about PQC are framed as a primitive replacement problem: swap an ECDH group for an ML-KEM parameter set; swap RSA/ECDSA for ML-DSA or SLH-DSA; keep the rest unchanged.</p>
<p>That framing is incomplete. A security statement is only meaningful relative to a threat model that specifies:</p>
<ul>
<li><em>what computation model the attacker runs</em> (classical PPT vs quantum polynomial-time),</li>
<li><em>what interfaces the attacker has</em> (classical vs quantum/superposition oracle access),</li>
<li><em>what resources are bounded</em> (time, memory, and query budgets),</li>
<li>and <em>what the system boundary is</em> (what is and is not coherently queryable, what leaks, what must be erased).</li>
</ul>
<p>Post-quantum migration fails silently when these are left implicit. This is not philosophical; it is a specification error. In particular, the Quantum Random Oracle Model (QROM) is not “ROM but stronger.” It is a different oracle interface and forces different proof techniques, different failure modes, and different deployment assumptions. <span class="citation" id="citation--bonehetal2010qrom--1">(<a href="#bib-bonehetal2010qrom">1</a>)</span></p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>
    In PQC, <em>the adversary is not just faster</em>. The attacker’s interface to your “idealized” components can change (superposition queries), and the attacker’s cost model changes (time–space tradeoffs, coherence budgets). If you do not specify the interface and the resource accounting, the proof obligation is ill-posed.
  </p>
</div>
<h2 id="1-problem-statement" style="position:relative;"><a href="#1-problem-statement" aria-label="1 problem statement permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1. Problem Statement</h2>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi><mo>∈</mo><mi mathvariant="double-struck">N</mi></mrow><annotation encoding="application/x-tex">\lambda \in \mathbb{N}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">λ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6889em;"></span><span class="mord mathbb">N</span></span></span></span></span> be a security parameter. A cryptographic <em>system</em> <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> is a set of algorithms and stateful components composed into a protocol:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">Π</mi><mo>=</mo><mo stretchy="false">(</mo><mtext mathvariant="sans-serif">KeyGen</mtext><mo separator="true">,</mo><mtext mathvariant="sans-serif">Encaps/Decaps</mtext><mo separator="true">,</mo><mtext mathvariant="sans-serif">Sign/Verify</mtext><mo separator="true">,</mo><mtext mathvariant="sans-serif">KDF</mtext><mo separator="true">,</mo><mtext mathvariant="sans-serif">Handshake</mtext><mo separator="true">,</mo><mtext mathvariant="sans-serif">State</mtext><mo separator="true">,</mo><mtext mathvariant="sans-serif">Erase</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\Pi = (\textsf{KeyGen}, \textsf{Encaps/Decaps}, \textsf{Sign/Verify}, \textsf{KDF}, \textsf{Handshake}, \textsf{State}, \textsf{Erase}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord text"><span class="mord textsf">KeyGen</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Encaps/Decaps</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Sign/Verify</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">KDF</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Handshake</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">State</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Erase</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>We want a threat model that supports <em>machine-checkable security claims</em> of the form:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>A</mi><mo>∈</mo><mi mathvariant="script">C</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>:</mo><mspace width="1em"></mspace><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi><mi mathvariant="script">M</mi></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo separator="true">;</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\forall A \in \mathcal{C}(\lambda):\quad \mathrm{Adv}^{\mathcal{M}}_{\Pi}(A;\lambda) \le \mathrm{negl}(\lambda),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord">∀</span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1757em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9257em;"><span style="top:-2.453em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathcal mtight">M</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">negl</span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where:</p>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">M</mi></mrow><annotation encoding="application/x-tex">\mathcal{M}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">M</span></span></span></span></span> is the oracle model / interface regime (e.g., ROM vs QROM),</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> is an adversary whose capabilities belong to an admissible class <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">C</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathcal{C}(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span>,</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span></span></span></span></span> is the advantage of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> in some security game (IND-CCA, EUF-CMA, AKE, etc),</li>
<li>and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">C</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathcal{C}(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> encodes explicit resource bounds.</li>
</ul>
<p>The core modeling problem is to define <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">C</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathcal{C}(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> such that it captures the operational adversary we must assume in PQC deployments:</p>
<ol>
<li>Classical adversaries (probabilistic polynomial-time, classical oracle access).</li>
<li>Quantum adversaries with <em>classical</em> oracle access (quantum computation, but the environment only answers classical queries).</li>
<li>Quantum adversaries with <em>quantum</em> oracle access (superposition queries), which induces QROM-style analysis.</li>
</ol>
<p>Then we must define a <em>resource vector</em> that is explicit enough to be operationally relevant:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>=</mo><mo fence="true" stretchy="true" minsize="1.2em" maxsize="1.2em">(</mo><mi>T</mi><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><msub><mi>M</mi><mi>c</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><msub><mi>M</mi><mi>q</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><msubsup><mi>q</mi><mi>H</mi><mi>c</mi></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext>  </mtext><mo stretchy="false">{</mo><msub><mi>q</mi><mi>O</mi></msub><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><msub><mo stretchy="false">}</mo><mrow><mi>O</mi><mo>∈</mo><mi mathvariant="script">O</mi></mrow></msub><mo fence="true" stretchy="true" minsize="1.2em" maxsize="1.2em">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathrm{cap}(A) =
\bigl(
T(A),\; M_c(A),\; M_q(A),\; q^{c}_{H}(A),\; q^{q}_{H}(A),\; \{q_{O}(A)\}_{O\in \mathcal{O}}
\bigr),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">cap</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.2em;vertical-align:-0.35em;"></span><span class="mopen"><span class="delimsizing size1">(</span></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-2.453em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">c</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">{</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">O</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">O</span><span class="mrel mtight">∈</span><span class="mord mathcal mtight" style="margin-right:0.02778em;">O</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1774em;"><span></span></span></span></span></span></span><span class="mclose"><span class="delimsizing size1">)</span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>T</mi></mrow><annotation encoding="application/x-tex">T</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span></span></span></span></span> is time, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>c</mi></msub></mrow><annotation encoding="application/x-tex">M_c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> is classical memory, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">M_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is quantum memory (qubits), <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>c</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9397em;vertical-align:-0.2753em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-2.4247em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2753em;"><span></span></span></span></span></span></span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span></span></span></span></span> are classical vs quantum queries to a hash/oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span>, and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">O</mi></mrow><annotation encoding="application/x-tex">\mathcal{O}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.02778em;">O</span></span></span></span></span> is the set of other interfaces (e.g., signing oracle, decapsulation oracle, network endpoints).</p>
<p>The reason to insist on this vector is that PQC security often collapses into “it’s 128-bit” language without any statement about <em>what</em> costs 128-bit under quantum constraints, and which part of the system gives the attacker those costs.</p>
<h2 id="2-formal-model" style="position:relative;"><a href="#2-formal-model" aria-label="2 formal model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2. Formal Model</h2>
<h3 id="21-notation-and-conventions" style="position:relative;"><a href="#21-notation-and-conventions" aria-label="21 notation and conventions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1 Notation and conventions</h3>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi></mrow><annotation encoding="application/x-tex">\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">λ</span></span></span></span></span> is the security parameter.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\ell(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">ℓ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> is an output length (typically <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>=</mo><mi>λ</mi></mrow><annotation encoding="application/x-tex">\ell(\lambda)=\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">ℓ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">λ</span></span></span></span></span> or <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo><mo>=</mo><mn>2</mn><mi>λ</mi></mrow><annotation encoding="application/x-tex">\ell(\lambda)=2\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">ℓ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">2</span><span class="mord mathnormal">λ</span></span></span></span></span>).</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo>:</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mo lspace="0em" rspace="0em">∗</mo></msup><mo>→</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup></mrow><annotation encoding="application/x-tex">H: \{0,1\}^{\ast}\rightarrow \{0,1\}^{\ell(\lambda)}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">∗</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.138em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.888em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span></span></span></span></span> denotes a random oracle.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathrm{negl}(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">negl</span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> denotes a negligible function.</li>
<li>“PPT” is probabilistic polynomial-time.</li>
<li>“QPT” is quantum polynomial-time (uniform family of poly-size quantum circuits).</li>
</ul>
<p>I will write security games in the standard game-based style: the challenger samples secrets, exposes oracles, the adversary outputs a bit, and advantage is the distinguishing gap.</p>
<h3 id="22-classical-adversary-ppt--classical-oracle-access" style="position:relative;"><a href="#22-classical-adversary-ppt--classical-oracle-access" aria-label="22 classical adversary ppt  classical oracle access permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.2 Classical adversary (PPT + classical oracle access)</h3>
<p>A classical adversary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> is a PPT algorithm. In the ROM, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> can query the random oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> on classical inputs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup><mspace width="1em"></mspace><mtext>for </mtext><mi>x</mi><mo>∈</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mo lspace="0em" rspace="0em">∗</mo></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">H(x) \in \{0,1\}^{\ell(\lambda)}\quad\text{for }x\in\{0,1\}^{\ast}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.188em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">for </span></span><span class="mord mathnormal">x</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7387em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">∗</span></span></span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Formally, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> is an oracle algorithm <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>A</mi><mrow><mi>H</mi><mo separator="true">,</mo><mi mathvariant="script">O</mi></mrow></msup><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">A^{H,\mathcal{O}}(1^\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0991em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8413em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span><span class="mpunct mtight">,</span><span class="mord mathcal mtight" style="margin-right:0.02778em;">O</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> that can make at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>c</mi></msubsup><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">q_H^c(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0253em;vertical-align:-0.2753em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-2.4247em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2753em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> classical queries to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> and at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>O</mi></msub><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">q_O(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">O</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> classical queries to each oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>O</mi><mo>∈</mo><mi mathvariant="script">O</mi></mrow><annotation encoding="application/x-tex">O\in\mathcal{O}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7224em;vertical-align:-0.0391em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.02778em;">O</span></span></span></span></span>, running in time <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>T</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">T(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span>.</p>
<p>The ROM proof toolbox relies on:</p>
<ul>
<li>lazy sampling (define <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span></span></span></span></span> on first query),</li>
<li>programming (set <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><msup><mi>x</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x^\star)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> to a chosen value),</li>
<li>and transcript extraction via recorded queries.</li>
</ul>
<p>These are not generic moves in the quantum setting.</p>
<h3 id="23-quantum-adversary-qpt-with-classical-oracle-access" style="position:relative;"><a href="#23-quantum-adversary-qpt-with-classical-oracle-access" aria-label="23 quantum adversary qpt with classical oracle access permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.3 Quantum adversary (QPT) with classical oracle access</h3>
<p>The first quantum strengthening is <em>computational</em>, not <em>interface</em>.</p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> be a QPT adversary. Concretely, for each <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi></mrow><annotation encoding="application/x-tex">\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">λ</span></span></span></span></span>, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is a quantum circuit <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>C</mi><mi>λ</mi></msub></mrow><annotation encoding="application/x-tex">C_\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> with polynomially many gates, acting on a polynomial number of qubits, with access to classical oracles.</p>
<p>In this model, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> can run quantum algorithms (Shor, Grover, quantum walks, etc.) but can only query the oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> by measuring an input <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi></mrow><annotation encoding="application/x-tex">x</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">x</span></span></span></span></span> and receiving a classical output <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span></span></span></span></span>. This is a meaningful model for certain deployments where an oracle is only accessible through an inherently classical interface (e.g., rate-limited remote services that do not provide coherent access).</p>
<p>However, it is not a safe default for hash functions, because a public hash function is not a remote service: it is an algorithm. If its description is public, a quantum adversary can implement it coherently. That is why QROM exists.</p>
<h3 id="24-quantum-adversary-with-quantum-oracle-access-qrom" style="position:relative;"><a href="#24-quantum-adversary-with-quantum-oracle-access-qrom" aria-label="24 quantum adversary with quantum oracle access qrom permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.4 Quantum adversary with quantum oracle access (QROM)</h3>
<p>In QROM, the random oracle is not an abstract lookup table that returns values. It is a unitary transformation that can be queried on superpositions of inputs. <span class="citation" id="citation--bonehetal2010qrom--2">(<a href="#bib-bonehetal2010qrom">1</a>)</span> <span class="citation" id="citation--zhandry2018recordqueries--3">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<p>Fix an output length <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\ell(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">ℓ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span>. Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> be sampled uniformly at random from all functions <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mi>n</mi></msup><mo>→</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup></mrow><annotation encoding="application/x-tex">\{0,1\}^{n}\rightarrow \{0,1\}^{\ell(\lambda)}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">n</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.138em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.888em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span></span></span></span></span> for some fixed input length <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>n</mi></mrow><annotation encoding="application/x-tex">n</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">n</span></span></span></span></span> (or use a prefix-free encoding to reduce variable-length inputs to fixed-length blocks).</p>
<p>Define the oracle unitary:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub><mo>:</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>x</mi><mo stretchy="false">⟩</mo><mi mathvariant="normal">∣</mi><mi>y</mi><mo stretchy="false">⟩</mo><mtext> </mtext><mo>↦</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>x</mi><mo stretchy="false">⟩</mo><mi mathvariant="normal">∣</mi><mi>y</mi><mo>⊕</mo><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo><mo stretchy="false">⟩</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">U_H:\ |x\rangle|y\rangle\ \mapsto\ |x\rangle|y \oplus H(x)\rangle,</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal">x</span><span class="mclose">⟩</span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="mclose">⟩</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">↦</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal">x</span><span class="mclose">⟩</span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⊕</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)⟩</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>⊕</mo></mrow><annotation encoding="application/x-tex">\oplus</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6667em;vertical-align:-0.0833em;"></span><span class="mord">⊕</span></span></span></span></span> is bitwise XOR in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mn>1</mn><msup><mo stretchy="false">}</mo><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup></mrow><annotation encoding="application/x-tex">\{0,1\}^{\ell(\lambda)}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.138em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">1</span><span class="mclose"><span class="mclose">}</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.888em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span></span></span></span></span> (and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">∣</mi><mi>y</mi><mo stretchy="false">⟩</mo></mrow><annotation encoding="application/x-tex">|y\rangle</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="mclose">⟩</span></span></span></span></span> is an <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\ell(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">ℓ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span>-qubit register).</p>
<p>A QROM adversary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is allowed to interleave its own unitaries <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mn>1</mn></msub><mo separator="true">,</mo><mo>…</mo><mo separator="true">,</mo><msub><mi>U</mi><mi>k</mi></msub></mrow><annotation encoding="application/x-tex">U_1,\dots,U_k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> with calls to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∣</mi><msub><mi>ψ</mi><mrow><mi>i</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">⟩</mo><mo>=</mo><msub><mi>U</mi><mrow><mi>i</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>⋅</mo><mo stretchy="false">(</mo><msub><mi>U</mi><mi>H</mi></msub><mo>⊗</mo><mi>I</mi><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><msub><mi>ψ</mi><mi>i</mi></msub><mo stretchy="false">⟩</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">|\psi_{i+1}\rangle = U_{i+1} \cdot (U_H \otimes I)\ |\psi_i\rangle,</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∣</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">ψ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">i</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">⟩</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8917em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">i</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⊗</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∣</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">ψ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">⟩</span><span class="mpunct">,</span></span></span></span></span></div>
<p>for at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">q_H^q(\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mclose">)</span></span></span></span></span> oracle calls. The final measurement produces the adversary’s output.</p>
<p>This single change (from classical query to coherent oracle access) breaks the ROM reduction move “record all random oracle queries and reprogram one point,” because:</p>
<ul>
<li>there is no classical transcript of queries (queries are quantum states),</li>
<li>measuring the query register disturbs the adversary’s state,</li>
<li>and the adversary can query <em>many points at once</em> in a superposition state.</li>
</ul>
<p>This is not a nuisance detail. It is a structural change in what “knowing <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mi>x</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(x)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord mathnormal">x</span><span class="mclose">)</span></span></span></span></span>” means.</p>
<h3 id="25-resource-accounting-queries-memory-time" style="position:relative;"><a href="#25-resource-accounting-queries-memory-time" aria-label="25 resource accounting queries memory time permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5 Resource accounting: queries, memory, time</h3>
<p>The statement “secure against quantum adversaries” is incomplete until we pin down the resource regime.</p>
<p>In practice, we need a resource accounting that is explicit enough to:</p>
<ol>
<li>map to parameter choices,</li>
<li>map to operational constraints (HSM/IIoT/embedded),</li>
<li>survive protocol composition.</li>
</ol>
<p>I use the following canonical resource vector:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>=</mo><mo stretchy="false">(</mo><mi>T</mi><mo separator="true">,</mo><mtext> </mtext><msub><mi>M</mi><mi>q</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mi>M</mi><mi>c</mi></msub><mo separator="true">,</mo><mtext> </mtext><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo separator="true">,</mo><mtext> </mtext><msubsup><mi>q</mi><mi>H</mi><mi>c</mi></msubsup><mo separator="true">,</mo><mtext> </mtext><msub><mi>q</mi><mtext mathvariant="sans-serif">Sign</mtext></msub><mo separator="true">,</mo><mtext> </mtext><msub><mi>q</mi><mtext mathvariant="sans-serif">Decaps</mtext></msub><mo separator="true">,</mo><mtext> </mtext><msub><mi>q</mi><mtext mathvariant="sans-serif">Net</mtext></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{cap}(A) = (T,\ M_q,\ M_c,\ q_H^q,\ q_H^c,\ q_{\textsf{Sign}},\ q_{\textsf{Decaps}},\ q_{\textsf{Net}},\dots).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">cap</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-2.453em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">Sign</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">Decaps</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">Net</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Interpretations:</p>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>T</mi></mrow><annotation encoding="application/x-tex">T</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span></span></span></span></span> (time) is gate complexity: the number of elementary quantum gates in the circuit description of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> (or a conservative upper bound).</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">M_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> is the maximum number of qubits kept coherent at any time (quantum workspace + oracle query registers).</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>c</mi></msub></mrow><annotation encoding="application/x-tex">M_c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> is classical memory (bits or words) used by <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span></span></span></span></span> is the number of quantum oracle calls to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>c</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9397em;vertical-align:-0.2753em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-2.4247em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2753em;"><span></span></span></span></span></span></span></span></span></span></span> is the number of classical evaluations of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> (which a quantum adversary can simulate by measuring its input register and computing).</li>
<li>other <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>q</mi><mi>O</mi></msub></mrow><annotation encoding="application/x-tex">q_O</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">O</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> correspond to protocol or hardware interfaces (e.g., a signing oracle can represent a compromised signing service; a decapsulation oracle can model error-oracle exposure; a network oracle can model active MitM capability).</li>
</ul>
<p>This matters because quantum attacks are often <em>query-bounded</em>.</p>
<p>For example, for brute-force search in an unstructured space of size <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>N</mi><mo>=</mo><msup><mn>2</mn><mi>k</mi></msup></mrow><annotation encoding="application/x-tex">N=2^k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.10903em;">N</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8491em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span></span></span></span></span></span></span></span></span>, Grover’s algorithm achieves <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>O</mi><mo stretchy="false">(</mo><msqrt><mi>N</mi></msqrt><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">O(\sqrt{N})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.1767em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">O</span><span class="mopen">(</span><span class="mord sqrt"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9267em;"><span class="svg-align" style="top:-3em;"><span class="pstrut" style="height:3em;"></span><span class="mord" style="padding-left:0.833em;"><span class="mord mathnormal" style="margin-right:0.10903em;">N</span></span></span><span style="top:-2.8867em;"><span class="pstrut" style="height:3em;"></span><span class="hide-tail" style="min-width:0.853em;height:1.08em;"><svg xmlns="http://www.w3.org/2000/svg" width="400em" height="1.08em" viewBox="0 0 400000 1080" preserveAspectRatio="xMinYMin slice"><path d="M95,702
c-2.7,0,-7.17,-2.7,-13.5,-8c-5.8,-5.3,-9.5,-10,-9.5,-14
c0,-2,0.3,-3.3,1,-4c1.3,-2.7,23.83,-20.7,67.5,-54
c44.2,-33.3,65.8,-50.3,66.5,-51c1.3,-1.3,3,-2,5,-2c4.7,0,8.7,3.3,12,10
s173,378,173,378c0.7,0,35.3,-71,104,-213c68.7,-142,137.5,-285,206.5,-429
c69,-144,104.5,-217.7,106.5,-221
l0 -0
c5.3,-9.3,12,-14,20,-14
H400000v40H845.2724
s-225.272,467,-225.272,467s-235,486,-235,486c-2.7,4.7,-9,7,-19,7
c-6,0,-10,-1,-12,-3s-194,-422,-194,-422s-65,47,-65,47z
M834 80h400000v40h-400000z"></path></svg></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1133em;"><span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> oracle queries and is optimal up to constant factors. <span class="citation" id="citation--grover1996--4">(<a href="#bib-grover1996">3</a>)</span> <span class="citation" id="citation--bbbv1997--5">(<a href="#bib-bbbv1997">4</a>)</span></p>
<p>Thus, when a system claims “<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span>-bit security,” the model must specify what oracle is being queried and how the query complexity maps to the system’s real interface.</p>
<h4 id="251-adversary-classes-as-explicit-sets" style="position:relative;"><a href="#251-adversary-classes-as-explicit-sets" aria-label="251 adversary classes as explicit sets permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.5.1 Adversary classes as explicit sets</h4>
<p>Define the admissible adversary classes as <em>sets</em> parameterized by <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi></mrow><annotation encoding="application/x-tex">\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">λ</span></span></span></span></span> and by a budget vector <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>B</mi></mrow><annotation encoding="application/x-tex">B</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>B</mi><mo>=</mo><mo stretchy="false">(</mo><msub><mi>T</mi><mi>max</mi><mo>⁡</mo></msub><mo separator="true">,</mo><mtext> </mtext><msub><mi>M</mi><mrow><mi>q</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow></msub><mo separator="true">,</mo><mtext> </mtext><msub><mi>M</mi><mrow><mi>c</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow></msub><mo separator="true">,</mo><mtext> </mtext><msubsup><mi>q</mi><mrow><mi>H</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow><mi>q</mi></msubsup><mo separator="true">,</mo><mtext> </mtext><msubsup><mi>q</mi><mrow><mi>H</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow><mi>c</mi></msubsup><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">B = (T_{\max},\ M_{q,\max},\ M_{c,\max},\ q_{H,\max}^q,\ q_{H,\max}^c,\dots).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.2119em;vertical-align:-0.4296em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">c</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.4296em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7144em;"><span style="top:-2.453em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3831em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Then:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi mathvariant="script">C</mi><mrow><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msub><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">;</mo><mi>B</mi><mo stretchy="false">)</mo><mo>=</mo><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">{</mo><mi>A</mi><mo>∈</mo><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">P</mi><mi mathvariant="normal">T</mi></mrow><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><mi>B</mi><mtext> </mtext><mo>∧</mo><mtext> </mtext><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>=</mo><mn>0</mn><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">}</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathcal{C}_{\mathrm{ROM}}(\lambda;B) =
\Bigl\{A \in \mathrm{PPT}:\ \mathrm{cap}(A)\le B\ \wedge\ q_H^q(A)=0\Bigr\},</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0583em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">ROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mopen"><span class="delimsizing size2">{</span></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">PPT</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">cap</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord">0</span><span class="mclose"><span class="delimsizing size2">}</span></span><span class="mpunct">,</span></span></span></span></span></div>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi mathvariant="script">C</mi><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">P</mi><mi mathvariant="normal">T</mi></mrow></msub><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">;</mo><mi>B</mi><mo stretchy="false">)</mo><mo>=</mo><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">{</mo><mi>A</mi><mo>∈</mo><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">P</mi><mi mathvariant="normal">T</mi></mrow><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><mi>B</mi><mtext> </mtext><mo>∧</mo><mtext> </mtext><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>=</mo><mn>0</mn><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">}</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathcal{C}_{\mathrm{QPT}}(\lambda;B) =
\Bigl\{A \in \mathrm{QPT}:\ \mathrm{cap}(A)\le B\ \wedge\ q_H^q(A)=0\Bigr\},</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0583em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">QPT</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mopen"><span class="delimsizing size2">{</span></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">QPT</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">cap</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord">0</span><span class="mclose"><span class="delimsizing size2">}</span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>and, crucially,</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi mathvariant="script">C</mi><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msub><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">;</mo><mi>B</mi><mo stretchy="false">)</mo><mo>=</mo><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">{</mo><mi>A</mi><mo>∈</mo><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">P</mi><mi mathvariant="normal">T</mi></mrow><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><mi>B</mi><mtext> </mtext><mo>∧</mo><mtext> </mtext><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><msubsup><mi>q</mi><mrow><mi>H</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow><mi>q</mi></msubsup><mo fence="true" stretchy="true" minsize="1.8em" maxsize="1.8em">}</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathcal{C}_{\mathrm{QROM}}(\lambda;B) =
\Bigl\{A \in \mathrm{QPT}:\ \mathrm{cap}(A)\le B\ \wedge\ q_H^q(A)\le q_{H,\max}^q\Bigr\},</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0583em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">QROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mopen"><span class="delimsizing size2">{</span></span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">QPT</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">cap</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.4296em;"><span></span></span></span></span></span></span><span class="mclose"><span class="delimsizing size2">}</span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> is explicitly allowed to invoke <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> coherently.</p>
<p>This is the right shape for engineering because it makes the theorem boundary a function of <em>explicit</em> parameters:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>A</mi><mo>∈</mo><msub><mi mathvariant="script">C</mi><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msub><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">;</mo><mi>B</mi><mo stretchy="false">)</mo><mo>:</mo><mspace width="1em"></mspace><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><mi>ϵ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo separator="true">;</mo><mi>B</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall A \in \mathcal{C}_{\mathrm{QROM}}(\lambda;B):\quad \mathrm{Adv}(A)\le \epsilon(\lambda;B).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord">∀</span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathcal" style="margin-right:0.05834em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0583em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">QROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">ϵ</span><span class="mopen">(</span><span class="mord mathnormal">λ</span><span class="mpunct">;</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>If you cannot state <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>B</mi></mrow><annotation encoding="application/x-tex">B</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span></span></span></span></span>, you do not have a security target; you have a slogan.</p>
<h3 id="26-a-concrete-game-qrom-euf-cma-for-fiatshamir-signatures" style="position:relative;"><a href="#26-a-concrete-game-qrom-euf-cma-for-fiatshamir-signatures" aria-label="26 a concrete game qrom euf cma for fiatshamir signatures permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.6 A concrete game: QROM-EUF-CMA for Fiat–Shamir signatures</h3>
<p>It is useful to anchor the model in a game where the ROM/QROM difference is not cosmetic.</p>
<p>Consider a Fiat–Shamir-style signature scheme <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi mathvariant="normal">Σ</mi><mtext mathvariant="sans-serif">FS</mtext></msub></mrow><annotation encoding="application/x-tex">\Sigma_{\textsf{FS}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord">Σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">FS</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> constructed from a <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Σ</mi></mrow><annotation encoding="application/x-tex">\Sigma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Σ</span></span></span></span></span>-protocol with hash <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> providing the challenge.</p>
<p>The (simplified) QROM-EUF-CMA game is:</p>
<ol>
<li>Challenger samples <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><mi>p</mi><mi>k</mi><mo separator="true">,</mo><mi>s</mi><mi>k</mi><mo stretchy="false">)</mo><mo>←</mo><mtext mathvariant="sans-serif">KeyGen</mtext><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(pk,sk)\leftarrow \textsf{KeyGen}(1^\lambda)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord mathnormal">p</span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">s</span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0991em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">KeyGen</span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>.</li>
<li>Adversary <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> gets <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>p</mi><mi>k</mi></mrow><annotation encoding="application/x-tex">pk</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">p</span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span> and oracle access to:
<ul>
<li>quantum random oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>U</mi><mi>H</mi></msub></mrow><annotation encoding="application/x-tex">U_H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>,</li>
<li>classical signing oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Sign</mtext><mo stretchy="false">(</mo><mi>s</mi><mi>k</mi><mo separator="true">,</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\textsf{Sign}(sk,\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Sign</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span>.</li>
</ul>
</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> outputs <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo stretchy="false">(</mo><msup><mi>m</mi><mo>⋆</mo></msup><mo separator="true">,</mo><msup><mi>σ</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">(m^\star,\sigma^\star)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span>.</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mi>Q</mi></msub></mrow><annotation encoding="application/x-tex">A_Q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> wins if <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Verify</mtext><mo stretchy="false">(</mo><mi>p</mi><mi>k</mi><mo separator="true">,</mo><msup><mi>m</mi><mo>⋆</mo></msup><mo separator="true">,</mo><msup><mi>σ</mi><mo>⋆</mo></msup><mo stretchy="false">)</mo><mo>=</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">\textsf{Verify}(pk,m^\star,\sigma^\star)=1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord textsf">Verify</span></span><span class="mopen">(</span><span class="mord mathnormal">p</span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>m</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">m^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span> was not asked to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Sign</mtext></mrow><annotation encoding="application/x-tex">\textsf{Sign}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord textsf">Sign</span></span></span></span></span></span>.</li>
</ol>
<p>The QROM complication is that the reduction cannot simply “look at the query <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi><mo stretchy="false">(</mo><mtext>transcript</mtext><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">H(\text{transcript})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord text"><span class="mord">transcript</span></span><span class="mclose">)</span></span></span></span></span> where the adversary fixed the challenge,” because there is no discrete query event.</p>
<p>This is why QROM proofs for Fiat–Shamir require specialized techniques (e.g., measure-and-reprogram, compressed oracle methodology). <span class="citation" id="citation--unruh2017fiatshamir--6">(<a href="#bib-unruh2017fiatshamir">5</a>)</span> <span class="citation" id="citation--donetal2019fiatshamirqrom--7">(<a href="#bib-donetal2019fiatshamirqrom">6</a>)</span> <span class="citation" id="citation--zhandry2018recordqueries--8">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>
    Any protocol that relies on “programming” a hash oracle in a proof (Fiat–Shamir, certain extractors, certain ZK transformations) is an immediate QROM touchpoint. If you ship it in production without stating whether your security claim is ROM-only or QROM-valid, you are shipping an underspecified system.
  </p>
</div>
<h3 id="27-a-reprogramming-bound-why-qrom-proofs-are-delicate" style="position:relative;"><a href="#27-a-reprogramming-bound-why-qrom-proofs-are-delicate" aria-label="27 a reprogramming bound why qrom proofs are delicate permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.7 A reprogramming bound (why QROM proofs are delicate)</h3>
<p>A common ROM move is to replace <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>H</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">H'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span> that differs on one input <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>x</mi><mo>⋆</mo></msup></mrow><annotation encoding="application/x-tex">x^\star</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mbin mtight">⋆</span></span></span></span></span></span></span></span></span></span></span></span>, and argue the adversary cannot notice. In QROM, this needs explicit query-bounds.</p>
<p>One generic form of bound (suppressing constants and depending on the exact modeling) is that for an adversary making at most <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>q</mi></mrow><annotation encoding="application/x-tex">q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span></span></span></span></span> quantum queries to a random function, the distinguishing advantage between two oracles that differ on a single point is upper-bounded on the order of:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">Δ</mi><mtext> </mtext><mo>≲</mo><mtext> </mtext><mfrac><msup><mi>q</mi><mn>2</mn></msup><msup><mn>2</mn><mrow><mi mathvariant="normal">ℓ</mi><mo stretchy="false">(</mo><mi>λ</mi><mo stretchy="false">)</mo></mrow></msup></mfrac><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\Delta \ \lesssim\ \frac{q^2}{2^{\ell(\lambda)}}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9592em;vertical-align:-0.2296em;"></span><span class="mord">Δ</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel amsrm">≲</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.1951em;vertical-align:-0.704em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.4911em;"><span style="top:-2.296em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.814em;"><span style="top:-2.989em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">ℓ</span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">λ</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8141em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.704em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mord">.</span></span></span></span></span></div>
<p>The point is not the exact constant; the point is the structure:</p>
<ul>
<li>the bound depends <em>quadratically</em> on the quantum query budget,</li>
<li>it depends exponentially on the output length,</li>
<li>and therefore you cannot reprogram “for free.”</li>
</ul>
<p>This is what forces QROM proofs to explicitly track <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span></span></span></span></span> and forces systems engineers to treat oracle query count as an explicit resource assumption, not an implicit “polynomial.”</p>
<h2 id="3-system-constraints" style="position:relative;"><a href="#3-system-constraints" aria-label="3 system constraints permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3. System Constraints</h2>
<p>Threat models that stop at “PPT vs QPT” are insufficient for systems work. They do not distinguish <em>interfaces</em>, and interfaces are where systems break.</p>
<p>I model system constraints as an explicit boundary condition on what the adversary can query <em>coherently</em> and what the adversary can only observe <em>classically</em>.</p>
<h3 id="31-interface-classification-what-is-quantum-queryable" style="position:relative;"><a href="#31-interface-classification-what-is-quantum-queryable" aria-label="31 interface classification what is quantum queryable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.1 Interface classification: what is quantum-queryable?</h3>
<p>In an actual PQC system, we have multiple classes of “oracles,” and only some are plausibly quantum accessible.</p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">I</mi></mrow><annotation encoding="application/x-tex">\mathcal{I}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.07382em;">I</span></span></span></span></span> be the set of interfaces exposed by the system:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="script">I</mi><mo>=</mo><mo stretchy="false">{</mo><mtext mathvariant="sans-serif">Hash</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">KDF</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">Sign</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">Decaps</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">Net</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">Clock</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">Leak</mtext><mo stretchy="false">}</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathcal{I} = \{\textsf{Hash},\ \textsf{KDF},\ \textsf{Sign},\ \textsf{Decaps},\ \textsf{Net},\ \textsf{Clock},\ \textsf{Leak}\}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.07382em;">I</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord text"><span class="mord textsf">Hash</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">KDF</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Sign</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Decaps</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Net</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Clock</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">Leak</span></span><span class="mclose">}</span><span class="mord">.</span></span></span></span></span></div>
<p>For each interface <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>I</mi><mo>∈</mo><mi mathvariant="script">I</mi></mrow><annotation encoding="application/x-tex">I\in\mathcal{I}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7224em;vertical-align:-0.0391em;"></span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.07382em;">I</span></span></span></span></span>, define an access mode:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">m</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>I</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">{</mo><mtext mathvariant="sans-serif">classical</mtext><mo separator="true">,</mo><mtext> </mtext><mtext mathvariant="sans-serif">quantum</mtext><mo stretchy="false">}</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{mode}(I) \in \{\textsf{classical},\ \textsf{quantum}\}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">mode</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.07847em;">I</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord text"><span class="mord textsf">classical</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord textsf">quantum</span></span><span class="mclose">}</span><span class="mord">.</span></span></span></span></span></div>
<p>Examples:</p>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Hash</mtext></mrow><annotation encoding="application/x-tex">\textsf{Hash}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">Hash</span></span></span></span></span></span> is typically <strong>quantum</strong> (public deterministic algorithm, implementable coherently).</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Net</mtext></mrow><annotation encoding="application/x-tex">\textsf{Net}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">Net</span></span></span></span></span></span> is typically <strong>classical</strong> (network endpoints do not provide coherent oracle access).</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Sign</mtext></mrow><annotation encoding="application/x-tex">\textsf{Sign}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord textsf">Sign</span></span></span></span></span></span> is <strong>classical</strong> unless the signing key is fully exposed in a way that allows coherent queries (rare in real systems; if it happens you already lost).</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Leak</mtext></mrow><annotation encoding="application/x-tex">\textsf{Leak}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">Leak</span></span></span></span></span></span> is <strong>classical</strong> (side-channel leakage is measured data).</li>
</ul>
<p>This interface typing lets you state something precise:</p>
<blockquote>
<p>The adversary is QPT overall, but only has quantum access to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">Hash</mtext></mrow><annotation encoding="application/x-tex">\textsf{Hash}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">Hash</span></span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mtext mathvariant="sans-serif">KDF</mtext></mrow><annotation encoding="application/x-tex">\textsf{KDF}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">KDF</span></span></span></span></span></span>; all other interfaces are classical.</p>
</blockquote>
<p>Without this typing, people accidentally assume QROM where it is irrelevant, or worse, assume ROM where it is unsafe.</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
    A<span class="token text string">["Adversary A_Q (QPT)"]</span> <span class="token arrow operator">--></span><span class="token label property">|quantum queries q_H^q|</span> H<span class="token text string">["Hash/KDF (U_H)"]</span>
    A <span class="token arrow operator">--></span><span class="token label property">|classical messages|</span> N<span class="token text string">["Network / protocol endpoints"]</span>
    A <span class="token arrow operator">--></span><span class="token label property">|classical oracle queries|</span> S<span class="token text string">["Signing / decapsulation services"]</span>
    A <span class="token arrow operator">--></span><span class="token label property">|observations|</span> L<span class="token text string">["Leakage channel (timing/cache/power)"]</span>
    H <span class="token arrow operator">--></span> A
    N <span class="token arrow operator">--></span> A
    S <span class="token arrow operator">--></span> A
    L <span class="token arrow operator">--></span> A</code></pre></div>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>
    Treat any public deterministic function as quantum-accessible unless you can argue that the attacker cannot implement it coherently. “It runs on a CPU today” is not that argument; “it is only accessible through a rate-limited classical interface” is.
  </p>
</div>
<h3 id="32-bounded-coherence-as-a-first-class-constraint" style="position:relative;"><a href="#32-bounded-coherence-as-a-first-class-constraint" aria-label="32 bounded coherence as a first class constraint permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.2 Bounded coherence as a first-class constraint</h3>
<p>Even when an interface is quantum accessible in principle, coherence budgets matter.</p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>τ</mi></mrow><annotation encoding="application/x-tex">\tau</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.1132em;">τ</span></span></span></span></span> be a coherence-time parameter and let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">M_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> be the coherent qubit budget. For many practical quantum attack pipelines, the feasible query depth is bounded by error correction overhead:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>T</mi><mtext mathvariant="sans-serif">depth</mtext></msub><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><mi>f</mi><mo stretchy="false">(</mo><mi>τ</mi><mo separator="true">,</mo><msub><mi>M</mi><mi>q</mi></msub><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">T_{\textsf{depth}}(A) \le f(\tau, M_q),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord textsf mtight">depth</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.1132em;">τ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>for some system-dependent function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi></mrow><annotation encoding="application/x-tex">f</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span></span></span></span></span>.</p>
<p>Pure complexity-theoretic models intentionally abstract this away. Systems engineering cannot.</p>
<p>If you are selecting parameters for a protocol deployed over a 10-year lifecycle, you need to express the security target in the form:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>A</mi><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><mo stretchy="false">(</mo><msub><mi>T</mi><mi>max</mi><mo>⁡</mo></msub><mo separator="true">,</mo><msub><mi>M</mi><mrow><mi>q</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow></msub><mo separator="true">,</mo><mo>…</mo><mtext> </mtext><mo stretchy="false">)</mo><mtext> </mtext><mo>⇒</mo><mtext> </mtext><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><msup><mn>2</mn><mrow><mo>−</mo><mi>k</mi></mrow></msup><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall A:\ \mathrm{cap}(A) \le (T_{\max}, M_{q,\max}, \dots)\ \Rightarrow\ \mathrm{Adv}(A) \le 2^{-k}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">A</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">cap</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8991em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">−</span><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>The budget must be stated because it is what “<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span>-bit security” cashes out to in a world where quantum resources are not symmetric with classical ones.</p>
<h3 id="33-determinism-erasure-and-state" style="position:relative;"><a href="#33-determinism-erasure-and-state" aria-label="33 determinism erasure and state permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.3 Determinism, erasure, and state</h3>
<p>PQC deployments often increase state volume: larger public keys, larger ciphertexts, more transcript data. That increases the amount of secret-dependent material that must be erased to preserve forward secrecy and reduce post-compromise exposure.</p>
<p>I treat erasure as an explicit system component:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext mathvariant="sans-serif">Erase</mtext><mo>:</mo><mtext mathvariant="sans-serif">State</mtext><mo>→</mo><msup><mtext mathvariant="sans-serif">State</mtext><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\textsf{Erase}: \textsf{State} \rightarrow \textsf{State}',</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">Erase</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">State</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0307em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord text"><span class="mord textsf">State</span></span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8362em;"><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mpunct">,</span></span></span></span></span></div>
<p>and I require it as a <em>proof obligation</em> for any security claim that depends on ephemerality.</p>
<p>This is not theoretical hygiene. If your formal model assumes ephemeral secret keys are erased but your implementation does not actually erase (or cannot erase because of allocator behavior, crash dumps, or debug cores), then your security claim is false even if the primitive is post-quantum.</p>
<h3 id="34-leakage-the-missing-axis-in-post-quantum-claims" style="position:relative;"><a href="#34-leakage-the-missing-axis-in-post-quantum-claims" aria-label="34 leakage the missing axis in post quantum claims permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.4 Leakage: the missing axis in “post-quantum” claims</h3>
<p>The standard QROM definition does not model side channels. Real systems leak.</p>
<p>To make this explicit, introduce a leakage oracle <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">L</mi></mrow><annotation encoding="application/x-tex">\mathcal{L}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">L</span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="script">L</mi><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>x</mi><mo stretchy="false">)</mo><mo>=</mo><mi>g</mi><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>x</mi><mo stretchy="false">)</mo><mo>+</mo><mi>η</mi><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathcal{L}(s, x) = g(s, x) + \eta,</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathcal">L</span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">η</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>s</mi></mrow><annotation encoding="application/x-tex">s</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">s</span></span></span></span></span> is secret state, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>x</mi></mrow><annotation encoding="application/x-tex">x</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">x</span></span></span></span></span> is an input/control variable, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>g</mi></mrow><annotation encoding="application/x-tex">g</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span></span></span></span></span> is a leakage function (timing, cache, power), and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>η</mi></mrow><annotation encoding="application/x-tex">\eta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">η</span></span></span></span></span> is noise.</p>
<p>Then “post-quantum secure” becomes a claim about the <em>joint</em> model:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msubsup><mi>A</mi><mi>Q</mi><mrow><msub><mi>U</mi><mi>H</mi></msub><mo separator="true">,</mo><mi mathvariant="script">L</mi><mo separator="true">,</mo><mi mathvariant="script">O</mi></mrow></msubsup><mo stretchy="false">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">A_Q^{U_H,\mathcal{L},\mathcal{O}}(1^\lambda).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.3889em;vertical-align:-0.4296em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9592em;"><span style="top:-2.4065em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">Q</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.10903em;">U</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3567em;margin-left:-0.109em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1433em;"><span></span></span></span></span></span></span><span class="mpunct mtight">,</span><span class="mord mathcal mtight">L</span><span class="mpunct mtight">,</span><span class="mord mathcal mtight" style="margin-right:0.02778em;">O</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.4296em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord">1</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8991em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">λ</span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>This is where academic proofs and systems reality diverge. Most PQC breakages in deployed environments will not be lattice breaks; they will be:</p>
<ul>
<li>RNG failures,</li>
<li>side-channel leakage,</li>
<li>state reuse,</li>
<li>parser differentials,</li>
<li>and operational misconfiguration.</li>
</ul>
<p>If the threat model does not represent <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">L</mi></mrow><annotation encoding="application/x-tex">\mathcal{L}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal">L</span></span></span></span></span>, it is incomplete for high-assurance work.</p>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>
    Treating “QROM security proof” as a blanket statement about deployed systems is category error. QROM is a model for hash-oracle interaction under quantum queries. It says nothing about erasure, concurrency, memory disclosure, or side channels unless those appear as explicit interfaces in the model.
  </p>
</div>
<h2 id="4-core-argument--insight" style="position:relative;"><a href="#4-core-argument--insight" aria-label="4 core argument  insight permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4. Core Argument / Insight</h2>
<p>The classical-to-quantum transition breaks systems in one predictable way: it invalidates <em>implicit</em> assumptions.</p>
<p>If you read a security proof and you cannot locate (in the statement of the theorem) all three of the following:</p>
<ol>
<li>the computation class of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>A</mi></mrow><annotation encoding="application/x-tex">A</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">A</span></span></span></span></span> (PPT vs QPT),</li>
<li>the oracle access mode for each interface (classical vs quantum),</li>
<li>the resource bounds that the reduction depends on (especially <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span></span></span></span></span>, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">M_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span>, and time depth),</li>
</ol>
<p>then the proof is not a usable engineering artifact. It is a conditional statement missing its conditions.</p>
<p>This is not pedantry. It is the only way to avoid shipping “post-quantum” protocols that:</p>
<ul>
<li>are proven secure only in ROM but instantiated with public deterministic hash functions (making QROM the relevant model),</li>
<li>assume ephemerality without enforcing erasure,</li>
<li>assume bounded query counts while building an interface that enables unbounded offline hashing,</li>
<li>or assume an adversary that cannot exploit time–memory tradeoffs while deploying hardware that makes those tradeoffs favorable.</li>
</ul>
<h3 id="41-why-qrom-is-structurally-different-from-rom" style="position:relative;"><a href="#41-why-qrom-is-structurally-different-from-rom" aria-label="41 why qrom is structurally different from rom permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.1 Why QROM is structurally different from ROM</h3>
<p>ROM is a model where the adversary sees a sequence:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><msub><mi>x</mi><mn>1</mn></msub><mo separator="true">,</mo><mi>H</mi><mo stretchy="false">(</mo><msub><mi>x</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo stretchy="false">)</mo><mo separator="true">,</mo><mtext> </mtext><mo stretchy="false">(</mo><msub><mi>x</mi><mn>2</mn></msub><mo separator="true">,</mo><mi>H</mi><mo stretchy="false">(</mo><msub><mi>x</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo stretchy="false">)</mo><mo separator="true">,</mo><mo>…</mo></mrow><annotation encoding="application/x-tex">(x_1, H(x_1)),\ (x_2, H(x_2)),\dots</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">))</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">))</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span></span></span></span></span></div>
<p>QROM is a model where the adversary’s interaction with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> is a sequence of unitary evolutions; there is no classical transcript. The adversary’s “knowledge” about <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> is encoded in a quantum state that can represent correlations across exponentially many inputs.</p>
<p>That destroys reduction strategies that depend on transcript surgery.</p>
<p>Zhandry’s compressed oracle methodology exists because it is the replacement for lazy sampling in the presence of quantum queries: you need a way to represent “what the adversary has learned” without measuring. <span class="citation" id="citation--zhandry2018recordqueries--9">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></p>
<h3 id="42-a-system-level-invariance-principle" style="position:relative;"><a href="#42-a-system-level-invariance-principle" aria-label="42 a system level invariance principle permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4.2 A system-level invariance principle</h3>
<p>For systems work, I enforce the following invariance principle:</p>
<blockquote>
<p>A security claim must be invariant under changes in implementation <em>that preserve the modeled interfaces</em>, and must explicitly fail (by assumption violation) under changes that expand the interface.</p>
</blockquote>
<p>Concretely:</p>
<ul>
<li>If your model assumes <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mrow><mi mathvariant="normal">m</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mtext mathvariant="sans-serif">Hash</mtext><mo stretchy="false">)</mo><mo>=</mo><mtext mathvariant="sans-serif">classical</mtext></mrow><annotation encoding="application/x-tex">\mathrm{mode}(\textsf{Hash})=\textsf{classical}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">mode</span></span><span class="mopen">(</span><span class="mord text"><span class="mord textsf">Hash</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord text"><span class="mord textsf">classical</span></span></span></span></span></span>, then “replace <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>H</mi></mrow><annotation encoding="application/x-tex">H</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span></span></span></span></span> by a public deterministic hash function” is an interface expansion (now quantum access is plausible), and your proof obligation must be revisited.</li>
<li>If your model assumes erasure, then “switch allocators and stop zeroizing” is an assumption violation, and your proof obligation must fail by construction.</li>
</ul>
<p>This is how you prevent the common failure where a proof remains “true” on paper while the deployed system drifts out of the theorem’s scope.</p>
<h2 id="5-implications" style="position:relative;"><a href="#5-implications" aria-label="5 implications permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5. Implications</h2>
<h3 id="51-for-protocol-specifications-publish-a-threat-model-matrix" style="position:relative;"><a href="#51-for-protocol-specifications-publish-a-threat-model-matrix" aria-label="51 for protocol specifications publish a threat model matrix permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5.1 For protocol specifications: publish a threat-model matrix</h3>
<p>Every PQC-facing protocol spec should publish a threat-model matrix that looks like:</p>
<table>
<thead>
<tr>
<th>Component</th>
<th>Claim</th>
<th>Adversary</th>
<th>Oracle access</th>
<th>Required resource bounds</th>
</tr>
</thead>
<tbody>
<tr>
<td>KEM</td>
<td>IND-CCA</td>
<td>QPT</td>
<td>classical</td>
<td><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>T</mi><mo>≤</mo><msub><mi>T</mi><mi>max</mi><mo>⁡</mo></msub></mrow><annotation encoding="application/x-tex">T \le T_{\max}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8193em;vertical-align:-0.136em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>M</mi><mi>q</mi></msub><mo>≤</mo><msub><mi>M</mi><mrow><mi>q</mi><mo separator="true">,</mo><mi>max</mi><mo>⁡</mo></mrow></msub></mrow><annotation encoding="application/x-tex">M_q \le M_{q,\max}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9694em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.10903em;">M</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.109em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span><span class="mpunct mtight">,</span><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span></td>
</tr>
<tr>
<td>Signatures</td>
<td>EUF-CMA</td>
<td>QPT</td>
<td>classical</td>
<td>signing oracle query bound, side-channel assumptions</td>
</tr>
<tr>
<td>Hash/KDF</td>
<td>PRF/RO</td>
<td>QPT</td>
<td>quantum (QROM)</td>
<td><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo>≤</mo><msub><mi>q</mi><mi>max</mi><mo>⁡</mo></msub></mrow><annotation encoding="application/x-tex">q_H^q \le q_{\max}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>, output length <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">ℓ</mi></mrow><annotation encoding="application/x-tex">\ell</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">ℓ</span></span></span></span></span></td>
</tr>
<tr>
<td>Handshake</td>
<td>AKE</td>
<td>QPT</td>
<td>mixed</td>
<td>network attacker + transcript binding</td>
</tr>
</tbody>
</table>
<p>If this table is absent, the system is underspecified.</p>
<h3 id="52-for-primitive-selection-quantum-security-level-is-not-a-scalar" style="position:relative;"><a href="#52-for-primitive-selection-quantum-security-level-is-not-a-scalar" aria-label="52 for primitive selection quantum security level is not a scalar permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5.2 For primitive selection: “quantum security level” is not a scalar</h3>
<p>NIST-style “categories” are useful, but operationally you must still define what the attacker can do:</p>
<ul>
<li>Is the hash used in Fiat–Shamir modeled in QROM?</li>
<li>Are you relying on tightness bounds that depend on <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span></span></span></span></span>?</li>
<li>Are you assuming that the attacker cannot get decryption/decapsulation oracles (in practice: error oracles)?</li>
</ul>
<p>If a proof gives a reduction of the form:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msubsup><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mi mathvariant="normal">Π</mi><mrow><mi mathvariant="normal">Q</mi><mi mathvariant="normal">R</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">M</mi></mrow></msubsup><mo stretchy="false">(</mo><mi>A</mi><mo stretchy="false">)</mo><mo>≤</mo><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mrow><mi mathvariant="sans-serif">H</mi><mi mathvariant="sans-serif">a</mi><mi mathvariant="sans-serif">r</mi><mi mathvariant="sans-serif">d</mi></mrow></msub><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mo>+</mo><mi>ϵ</mi><mo stretchy="false">(</mo><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup><mo separator="true">,</mo><mi>λ</mi><mo stretchy="false">)</mo><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\Pi}^{\mathrm{QROM}}(A) \le
\mathrm{Adv}_{\mathsf{Hard}}(B) + \epsilon(q_H^q,\lambda),</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.2528em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.9592em;"><span style="top:-2.4065em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">QROM</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">A</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathsf mtight">Hard</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord mathnormal">ϵ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">λ</span><span class="mclose">)</span><span class="mpunct">,</span></span></span></span></span></div>
<p>then your deployment must treat <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msubsup><mi>q</mi><mi>H</mi><mi>q</mi></msubsup></mrow><annotation encoding="application/x-tex">q_H^q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0758em;vertical-align:-0.2935em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.7823em;"><span style="top:-2.4065em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.08125em;">H</span></span></span><span style="top:-3.1809em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2935em;"><span></span></span></span></span></span></span></span></span></span></span> as a real security budget variable, not “some polynomial.”</p>
<h3 id="53-for-high-assurance-systems-integrate-system-constraints-as-obligations" style="position:relative;"><a href="#53-for-high-assurance-systems-integrate-system-constraints-as-obligations" aria-label="53 for high assurance systems integrate system constraints as obligations permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5.3 For high-assurance systems: integrate system constraints as obligations</h3>
<p>For security-critical deployments (IIoT, control planes, global backends, blockchain consensus):</p>
<ul>
<li>add explicit erasure obligations,</li>
<li>model leakage oracles for realistic side channels,</li>
<li>model concurrency/state reuse constraints,</li>
<li>and enforce configuration invariants (no silent downgrade of PQ components).</li>
</ul>
<p>Otherwise “post-quantum” becomes a label attached to primitives while the system remains vulnerable through the same operational paths that already break classical systems.</p>
<h2 id="6-continuity-hook" style="position:relative;"><a href="#6-continuity-hook" aria-label="6 continuity hook permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>6. Continuity Hook</h2>
<p>This leads directly to the next problem: hardness assumptions and parameter regimes under quantum constraints are not just “LWE but with a quantum attacker.”</p>
<p>Part 2 will formalize a lattice-based hardness statement (LWE / Module-LWE) under QPT adversaries and connect it to a <em>systems-meaningful</em> cost model: time depth, memory, and realistic attack surfaces (including where the quantum speedups actually apply and where they do not).</p>
<h2 id="7-references" style="position:relative;"><a href="#7-references" aria-label="7 references permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>7. References</h2>
<ul>
<li>Boneh, Dagdelen, Fischlin, Lehmann, Schaffner, Zhandry — <em>Random Oracles in a Quantum World</em>. (<a href="https://eprint.iacr.org/2010/428.pdf" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2010/428</a>) <span class="citation" id="citation--bonehetal2010qrom--10">(<a href="#bib-bonehetal2010qrom">1</a>)</span></li>
<li>Grover — <em>A fast quantum mechanical algorithm for database search</em>. (<a href="https://arxiv.org/abs/quant-ph/9605043" target="_blank" rel="nofollow noopener noreferrer">arXiv:quant-ph/9605043</a>) <span class="citation" id="citation--grover1996--11">(<a href="#bib-grover1996">3</a>)</span></li>
<li>Bennett, Bernstein, Brassard, Vazirani — <em>Strengths and Weaknesses of Quantum Computing</em> (quantum query lower bounds). (<a href="https://arxiv.org/abs/quant-ph/9701001" target="_blank" rel="nofollow noopener noreferrer">arXiv:quant-ph/9701001</a>) <span class="citation" id="citation--bbbv1997--12">(<a href="#bib-bbbv1997">4</a>)</span></li>
<li>Unruh — <em>Post-Quantum Security of Fiat–Shamir</em>. (<a href="https://eprint.iacr.org/2017/398.pdf" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2017/398</a>) <span class="citation" id="citation--unruh2017fiatshamir--13">(<a href="#bib-unruh2017fiatshamir">5</a>)</span></li>
<li>Don, Fehr, Majenz, Schaffner — <em>Security of the Fiat–Shamir Transformation in the Quantum Random-Oracle Model</em>. (<a href="https://eprint.iacr.org/2019/190.pdf" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2019/190</a>) <span class="citation" id="citation--donetal2019fiatshamirqrom--14">(<a href="#bib-donetal2019fiatshamirqrom">6</a>)</span></li>
<li>Zhandry — <em>How to Record Quantum Queries, and Applications to Quantum Indifferentiability</em> (compressed oracle methodology). (<a href="https://eprint.iacr.org/2018/276.pdf" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2018/276</a>) <span class="citation" id="citation--zhandry2018recordqueries--15">(<a href="#bib-zhandry2018recordqueries">2</a>)</span></li>
<li>Watrous — <em>Zero-Knowledge Against Quantum Attacks</em> (quantum rewinding constraints). (<a href="https://cs.uwaterloo.ca/~watrous/Papers/ZeroKnowledgeAgainstQuantum.pdf" target="_blank" rel="nofollow noopener noreferrer">PDF</a>) <span class="citation" id="citation--watrous2009zk--16">(<a href="#bib-watrous2009zk">7</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-bonehetal2010qrom">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Boneh D, Dagdelen Ö, Fischlin M, Lehmann A, Schaffner C, Zhandry M. Random Oracles in a Quantum World [Internet]. Cryptology ePrint Archive, Paper 2010/428; 2010. Available from: https://eprint.iacr.org/2010/428.pdf</div>
  </div>
  <div class="csl-entry" id="bib-zhandry2018recordqueries">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Zhandry M. How to Record Quantum Queries, and Applications to Quantum Indifferentiability [Internet]. Cryptology ePrint Archive, Paper 2018/276; 2018. Available from: https://eprint.iacr.org/2018/276.pdf</div>
  </div>
  <div class="csl-entry" id="bib-grover1996">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Grover LK. A fast quantum mechanical algorithm for database search [Internet]. arXiv:quant-ph/9605043; 1996. Available from: https://arxiv.org/abs/quant-ph/9605043</div>
  </div>
  <div class="csl-entry" id="bib-bbbv1997">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Bennett CH, Bernstein E, Brassard G, Vazirani U. Strengths and Weaknesses of Quantum Computing [Internet]. arXiv:quant-ph/9701001; 1997. Available from: https://arxiv.org/abs/quant-ph/9701001</div>
  </div>
  <div class="csl-entry" id="bib-unruh2017fiatshamir">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">Unruh D. Post-Quantum Security of Fiat-Shamir [Internet]. Cryptology ePrint Archive, Paper 2017/398; 2017. Available from: https://eprint.iacr.org/2017/398.pdf</div>
  </div>
  <div class="csl-entry" id="bib-donetal2019fiatshamirqrom">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">Don J, Fehr S, Majenz C, Schaffner C. Security of the Fiat-Shamir Transformation in the Quantum Random-Oracle Model [Internet]. Cryptology ePrint Archive, Paper 2019/190; 2019. Available from: https://eprint.iacr.org/2019/190.pdf</div>
  </div>
  <div class="csl-entry" id="bib-watrous2009zk">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">Watrous J. Zero-Knowledge Against Quantum Attacks. SIAM Journal on Computing [Internet]. 2009; Available from: https://cs.uwaterloo.ca/~watrous/Papers/ZeroKnowledgeAgainstQuantum.pdf</div>
  </div>
</div>]]></content>
        <category label="post-quantum-cryptography"/>
        <category label="formal-methods"/>
        <category label="cryptography"/>
        <category label="systems"/>
        <category label="threat-modeling"/>
        <category label="QROM"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[The KelpDAO Exploit Was Not a Bug]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-kelpdao-exploit-was-not-a-bug</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-kelpdao-exploit-was-not-a-bug"/>
        <updated>2026-04-19T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Incident memo (April 2026): the 116,500 rsETH release via LayerZero EndpointV2 was a semantic guard failure. Signatures are not truth unless they bind to a unique, finalized source-chain debit.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Incident note. Theme: <strong>signatures are not semantics</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>On April 18, 2026, at 17:35 UTC, a transaction routed through the LayerZero EndpointV2 contract on Ethereum released 116,500 rsETH from the Kelp bridge to an attacker-controlled address. The transaction was successful, emitted <code class="language-text">Transfer</code>, <code class="language-text">OFTReceived</code>, and <code class="language-text">PacketDelivered</code> events, and carried a claimed source EID of <code class="language-text">30320</code>. Kelp later acknowledged “suspicious cross-chain activity,” said it had paused rsETH contracts across mainnet and several L2s, and Aave disclosed that its Guardian began freezing rsETH and wrsETH markets at 18:52 UTC. As of April 19, 2026, LayerZero said it was still investigating the root cause with Kelp and SEAL, and had not yet published a full joint post-mortem. That means some implementation details remain provisional, but the core exploit path is already publicly verifiable. <span class="citation" id="citation--etherscantxkelprseth20260418--1">(<a href="#bib-etherscantxkelprseth20260418">1</a>)</span> <span class="citation" id="citation--credshieldskelprsethexploit2026--2">(<a href="#bib-credshieldskelprsethexploit2026">2</a>)</span> <span class="citation" id="citation--aaversethincident20260418--3">(<a href="#bib-aaversethincident20260418">3</a>)</span> <span class="citation" id="citation--lookonchainlayerzerorseth2026--4">(<a href="#bib-lookonchainlayerzerorseth2026">4</a>)</span></p>
<p>The technical thesis is simple and brutal: this was not fundamentally a “bridge hack” in the colloquial sense, and it was not merely “bad luck.” It was a specification failure. LayerZero’s own documentation makes clear that an application’s security stack is configurable: DVNs verify a message payload hash, and once the configured threshold is met, the message can be committed and executed on the destination chain. The question, then, is not whether a signature existed. The question is whether the executed destination transition was semantically justified by a real, unique, finalized source-chain debit event. In the Kelp path that failed, public on-chain analysis indicates the rsETH OFT adapter was effectively operating with a one-of-one DVN configuration, turning “a valid attestation exists” into “release funds.” That is a catastrophic mismatch between cryptographic verification and protocol correctness. <span class="citation" id="citation--layerzerosecuritystackdvns--5">(<a href="#bib-layerzerosecuritystackdvns">5</a>)</span> <span class="citation" id="citation--layerzerowhitepaperv2--6">(<a href="#bib-layerzerowhitepaperv2">6</a>)</span> <span class="citation" id="citation--defiprimekelprsethexploit2026--7">(<a href="#bib-defiprimekelprsethexploit2026">7</a>)</span></p>
<p>A widely circulated investigator claim held that the Unichain-side rsETH float was only 49 tokens at the time, or at least in that neighborhood, which is why the incident has been summarized as “116,500 rsETH withdrawn against 49 on the source.” I have not seen an official post-mortem or immutable primary-source snapshot from KelpDAO or LayerZero that conclusively proves the exact pre-attack “49” figure. What is beyond dispute is the order-of-magnitude mismatch: a successful Ethereum-side release of 116,500 rsETH was executed and logged on-chain, and contemporary investigator posts framed the source-side inventory as trivial by comparison. For engineering purposes, the exact scalar is less important than the violated invariant: the destination transition consumed more economic entitlement than the source side could plausibly have produced. <span class="citation" id="citation--etherscantxkelprseth20260418--8">(<a href="#bib-etherscantxkelprseth20260418">1</a>)</span></p>
<p>The blast radius was not created by the bridge alone. It was created by composability. The attacker turned the unbacked or provenance-corrupted rsETH into borrow power across lending venues, exploiting the fact that lending protocols reason primarily about collateral valuation, caps, and liquidation thresholds, not about whether a bridged token’s source-chain transition was semantically valid. Aave’s own documentation describes health-factor- and liquidation-threshold-based risk control; the Compound III documentation similarly describes collateral factors, borrow collateralization, and pause-guardian controls. Those are necessary controls, but they are not provenance proofs. When Kelp failed, those protocols inherited toxic state. <span class="citation" id="citation--aavehealthfactorliquidations--9">(<a href="#bib-aavehealthfactorliquidations">8</a>)</span> <span class="citation" id="citation--compoundiiigovernancedocs--10">(<a href="#bib-compoundiiigovernancedocs">9</a>)</span></p>
<p>The conclusion of this article is deliberately adversarial: DeFi in 2026 is still too willing to confuse signatures with truth, audits with assurance, and emergency multisigs with engineering. A serious remediation strategy has to start from invariants, temporal semantics, and refinement proofs. It has to move cross-chain execution from “attested packet delivery” to “proof-carrying state transition.” It has to treat economic safety properties as first-class formal predicates, not as after-the-fact risk commentary. That is exactly the direction suggested by recent formal-methods work such as KindHML and the original proof-carrying code literature. <span class="citation" id="citation--kindhml2026--11">(<a href="#bib-kindhml2026">10</a>)</span> <span class="citation" id="citation--necula1997pcc--12">(<a href="#bib-necula1997pcc">11</a>)</span></p>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Destination execution must be gated by <em>semantic entitlement</em> (a unique, finalized source debit), not by “some attestation exists.”</li>
<li>A 1-of-1 security stack turns protocol messaging into a single-point-of-failure oracle; it is a trust downgrade, not “decentralization.”</li>
<li>Composability is an amplifier: once provenance-corrupted collateral is admissible, lending venues inherit toxic state regardless of their own local correctness.</li>
<li>The remediation is invariant-driven design + proof-carrying transitions + operational circuit breakers; “add another signer” is not a spec.</li>
<li>Treat every exploit as a counterexample trace; ship the fix as a <em>smaller language of reachable bad states</em>, enforced in CI.</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some incident details remain provisional until Kelp/LayerZero publish a joint RCA; the analysis is constrained to publicly verifiable chain data + primary docs. <span class="citation" id="citation--etherscantxkelprseth20260418--13">(<a href="#bib-etherscantxkelprseth20260418">1</a>)</span> <span class="citation" id="citation--layerzerosecuritystackdvns--14">(<a href="#bib-layerzerosecuritystackdvns">5</a>)</span></li>
<li>The effective trust boundary is the destination adapter’s release guard; once it accepts a packet, the system treats the resulting state transition as truth.</li>
<li>“DVN threshold satisfied” is modeled as a cryptographic predicate over a payload hash; it is <em>not</em> assumed to imply source-state membership.</li>
<li>Downstream lending protocols are assumed to be locally correct with respect to their own specs (oracle valuation, health factor, liquidation rules) while being provenance-agnostic by design. <span class="citation" id="citation--aavehealthfactorliquidations--15">(<a href="#bib-aavehealthfactorliquidations">8</a>)</span> <span class="citation" id="citation--compoundiiigovernancedocs--16">(<a href="#bib-compoundiiigovernancedocs">9</a>)</span></li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>This is not a final RCA, and it does not claim attribution for the root cause beyond the observable invariant breach.</li>
<li>This does not attempt a loss allocation analysis across venues; that is governance + accounting, not protocol correctness.</li>
<li>This is not an argument that LayerZero-style messaging is “inherently insecure”; it is an argument that <em>semantic settlement</em> cannot be reduced to packet attestation.</li>
</ul>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<h3 id="p1--supply-conservation-economic-safety" style="position:relative;"><a href="#p1--supply-conservation-economic-safety" aria-label="p1  supply conservation economic safety permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P1 — Supply conservation (economic safety)</h3>
<p>For each channel <code class="language-text">c</code> and message identifier <code class="language-text">guid</code>, the destination release must be bounded by the entitled amount induced by a unique, finalized source debit:</p>
<p><code class="language-text">release_amount(c, guid) ≤ entitled_amount_from_source(c, guid)</code>.</p>
<h3 id="p2--provenance-unique-finalized-debit" style="position:relative;"><a href="#p2--provenance-unique-finalized-debit" aria-label="p2  provenance unique finalized debit permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P2 — Provenance (unique finalized debit)</h3>
<p>Every destination release implies existence of <em>exactly one</em> corresponding source event in canonical finalized state:</p>
<p><code class="language-text">release(guid, a, r) → ∃! burn_or_lock(guid, a, r) ∈ FinalizedSource</code>.</p>
<h3 id="p3--replay-safety-single-consumption" style="position:relative;"><a href="#p3--replay-safety-single-consumption" aria-label="p3  replay safety single consumption permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P3 — Replay safety (single consumption)</h3>
<p>Execution is idempotent and consumes <code class="language-text">guid</code> exactly once:</p>
<p><code class="language-text">execute(guid) → verified(guid) ∧ ¬consumed(guid)</code> and <code class="language-text">execute(guid) → X(consumed(guid))</code>.</p>
<h3 id="p4--negotiation--config-integrity-no-silent-trust-downgrade" style="position:relative;"><a href="#p4--negotiation--config-integrity-no-silent-trust-downgrade" aria-label="p4  negotiation  config integrity no silent trust downgrade permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P4 — Negotiation / config integrity (no silent trust downgrade)</h3>
<p>Security-stack parameters (required/optional DVNs, thresholds, receive libraries) must be explicit, authenticated, versioned, and observable. “Equivalent” legacy spellings are downgrade gadgets. <span class="citation" id="citation--layerzerosecuritystackdvns--17">(<a href="#bib-layerzerosecuritystackdvns">5</a>)</span></p>
<h3 id="p5--blast-radius-containment-compositional-safety" style="position:relative;"><a href="#p5--blast-radius-containment-compositional-safety" aria-label="p5  blast radius containment compositional safety permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P5 — Blast-radius containment (compositional safety)</h3>
<p>If provenance cannot be verified cheaply, the system must isolate risk domains (caps/silos/spokes) such that a provenance failure cannot drain shared liquidity.</p>
<h2 id="incident-reconstruction" style="position:relative;"><a href="#incident-reconstruction" aria-label="incident reconstruction permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Incident reconstruction</h2>
<p>There are two constraints on honest analysis here. First, the exploit is recent and some public numbers are still moving. Second, neither KelpDAO nor LayerZero has published the full formal RCA yet. So the right posture is not false certainty. It is disciplined reconstruction from public chain data, official protocol statements, and primary documentation. The timeline below reflects that standard. <span class="citation" id="citation--etherscantxkelprseth20260418--18">(<a href="#bib-etherscantxkelprseth20260418">1</a>)</span> <span class="citation" id="citation--credshieldskelprsethexploit2026--19">(<a href="#bib-credshieldskelprsethexploit2026">2</a>)</span> <span class="citation" id="citation--aaversethincident20260418--20">(<a href="#bib-aaversethincident20260418">3</a>)</span></p>
<table>
<thead>
<tr>
<th>Time</th>
<th>Event</th>
<th>Why it matters</th>
</tr>
</thead>
<tbody>
<tr>
<td>17:35 UTC</td>
<td>Successful <code class="language-text">lzReceive</code>-mediated release of 116,500 rsETH on Ethereum</td>
<td>This is the invalid state transition that should have been unreachable</td>
</tr>
<tr>
<td>~17:52 UTC</td>
<td>Public flagging of suspicious outflows</td>
<td>Detection moved from private anomaly to public incident</td>
</tr>
<tr>
<td>18:21 UTC</td>
<td>Kelp emergency pause</td>
<td>Human intervention bounded the exploit window</td>
</tr>
<tr>
<td>18:26 and 18:28 UTC</td>
<td>Follow-up transactions attempted after the pause window</td>
<td>Demonstrates repeated exploitability of the same path</td>
</tr>
<tr>
<td>18:52 UTC</td>
<td>Aave Guardian freezes rsETH and wrsETH markets</td>
<td>Containment shifted downstream into lending infrastructure</td>
</tr>
<tr>
<td>20:10 UTC</td>
<td>Kelp public acknowledgment</td>
<td>Official confirmation of cross-chain anomaly</td>
</tr>
<tr>
<td>April 19</td>
<td>LayerZero says investigation continues; Aave says Ethereum mainnet rsETH appears fully backed and exposure is capped</td>
<td>The recovery question is now about provenance, contagion, and loss allocation</td>
</tr>
</tbody>
</table>
<p>The transaction itself is unusually revealing. On Etherscan, the exploit transaction shows a direct interaction with LayerZero EndpointV2, successful execution status, a timestamp of April 18, 2026 at 17:35:35 UTC, and a transfer of exactly 116,500 rsETH from the Kelp bridge contract to the attacker. The decoded log shows <code class="language-text">OFTReceived</code> with <code class="language-text">srcEid = 30320</code>, followed by <code class="language-text">PacketDelivered</code>. That is not a vague “possible exploit.” It is a concrete destination-side state transition that the system admitted as valid. <span class="citation" id="citation--etherscantxkelprseth20260418--21">(<a href="#bib-etherscantxkelprseth20260418">1</a>)</span></p>
<p>Public on-chain analysis published within hours of the incident described the active security stack as effectively one required DVN, zero optional DVNs, and no meaningful redundancy. LayerZero’s own documentation explains why that matters: DVNs independently verify the payload hash, and once the required DVNs and optional threshold are satisfied, an executor or other authorized caller can commit the nonce and drive execution on the destination endpoint. LayerZero also documents that the default security stacks for new channels are multi-DVN presets, not single-signer production assumptions for high-value pathways. If a nine-figure bridge path was running as one-of-one in practice, that was not the protocol “being decentralized.” It was a brittle trust downgrade. <span class="citation" id="citation--layerzerosecuritystackdvns--22">(<a href="#bib-layerzerosecuritystackdvns">5</a>)</span> <span class="citation" id="citation--defiprimekelprsethexploit2026--23">(<a href="#bib-defiprimekelprsethexploit2026">7</a>)</span></p>
<p>The follow-up attempts matter almost as much as the initial drain. CredShields reconstructed a 46-minute interval from the first drain to Kelp’s <code class="language-text">pauseAll</code>, and reported two later attempts at roughly 18:26 UTC and 18:28 UTC that did not succeed. That means the failure mode was not singular or self-limiting. It remained reachable until a human emergency control intervened. In other words, the system’s actual safety property was not “invalid releases are impossible.” It was “invalid releases remain possible until a multisig wakes up.” <span class="citation" id="citation--credshieldskelprsethexploit2026--24">(<a href="#bib-credshieldskelprsethexploit2026">2</a>)</span></p>
<p>The architecture of the vulnerable path can be expressed plainly:</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
    A<span class="token text string">[Unichain-side sender context]</span> <span class="token arrow operator">--></span> B<span class="token text string">[Packet claims source burn]</span>
    B <span class="token arrow operator">--></span> C<span class="token text string">[DVN attestation over payloadHash]</span>
    C <span class="token arrow operator">--></span> D<span class="token text string">[Receive library threshold satisfied]</span>
    D <span class="token arrow operator">--></span> E<span class="token text string">[LayerZero EndpointV2 lzReceive]</span>
    E <span class="token arrow operator">--></span> F<span class="token text string">[Kelp bridge adapter on Ethereum]</span>
    F <span class="token arrow operator">--></span> G<span class="token text string">[Escrow release of 116,500 rsETH]</span>
    G <span class="token arrow operator">--></span> H<span class="token text string">[Attacker]</span>
    X<span class="token text string">[Missing control]</span> <span class="token arrow operator">-.-></span> F
    X["No proof of canonical source-state membership,
    no uniqueness proof, no semantic entitlement proof"]</code></pre></div>
<p>The public timeline is equally stark. The following is an analytical reconstruction of blast-radius expansion from public timestamps and protocol responses. The y-axis is not “dollars lost.” It is the count of trust domains that had now become active incident participants: bridge, public detection, issuer controls, lending markets, and ecosystem governance. <span class="citation" id="citation--credshieldskelprsethexploit2026--25">(<a href="#bib-credshieldskelprsethexploit2026">2</a>)</span> <span class="citation" id="citation--aaversethincident20260418--26">(<a href="#bib-aaversethincident20260418">3</a>)</span></p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid">xychart-beta
    title <span class="token string">"Attack propagation versus time"</span>
    <span class="token arrow operator">x-</span>axis <span class="token text string">["17:35","17:52","18:21","18:26","18:52","20:10","Apr 19"]</span>
    y-axis <span class="token string">"Incident domains activated"</span> 0 <span class="token arrow operator">--></span> 6
    line <span class="token text string">[1,2,3,3,4,5,6]</span></code></pre></div>
<p>And the time sequence itself, rendered as a directly reusable timeline:</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid">timeline
    title KelpDAO exploit reconstruction
    17<span class="token operator">:</span>35 UTC <span class="token operator">:</span> Exploit transaction succeeds on Ethereum
              <span class="token operator">:</span> 116,500 rsETH released
    ~17<span class="token operator">:</span>52 UTC <span class="token operator">:</span> Public on-chain alerting begins
    18<span class="token operator">:</span>21 UTC <span class="token operator">:</span> Kelp emergency pause executes
    18<span class="token operator">:</span>26 UTC <span class="token operator">:</span> Follow-up attempt observed
    18<span class="token operator">:</span>28 UTC <span class="token operator">:</span> Additional follow-up attempt observed
    18<span class="token operator">:</span>52 UTC <span class="token operator">:</span> Aave Guardian starts market freezes
    20<span class="token operator">:</span>10 UTC <span class="token operator">:</span> Kelp publicly confirms suspicious cross-chain activity
    Apr 19 <span class="token operator">:</span> LayerZero says RCA still in progress
            <span class="token operator">:</span> Aave says mainnet rsETH appears fully backed and exposure is capped</code></pre></div>
<h2 id="the-invalid-state-was-reachable" style="position:relative;"><a href="#the-invalid-state-was-reachable" aria-label="the invalid state was reachable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The invalid state was reachable</h2>
<p>The right abstraction for this exploit is not a bug report. It is a counterexample trace in a state machine. That framing is standard in serious formal work on smart contracts and temporal properties: the system is a stateful transition system, and vulnerability means the existence of an execution trace reaching a forbidden state. KindHML explicitly models contracts as stateful systems and targets temporal properties that unfold across multiple transactions; SmartPulse makes the same point from an adjacent direction. <span class="citation" id="citation--kindhml2026--27">(<a href="#bib-kindhml2026">10</a>)</span> <span class="citation" id="citation--smartpulse2021--28">(<a href="#bib-smartpulse2021">12</a>)</span></p>
<p>For this class of bridge, a minimum semantic model is:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">State s =
  (escrow_eth,
   remote_supply[chain],
   executed_guids,
   finalized_roots[chain],
   bridge_config,
   risk_limits)

Input m =
  (src_chain, dst_chain, guid, amount, receiver,
   claimed_sender, claimed_root, proof_or_attestation)</code></pre></div>
<p>The safety of the system is governed by a small set of invariants. If these had been specified, checked, and made gate conditions for execution, the exploit path would have been mechanically rejected.</p>
<table>
<thead>
<tr>
<th>Invariant</th>
<th>Plain definition</th>
<th>What it forbids</th>
<th>What happened here</th>
</tr>
</thead>
<tbody>
<tr>
<td>Conservation of supply</td>
<td>A destination release cannot exceed economically justified source-side debits plus any explicitly prefunded allowance</td>
<td>Printing claims from nowhere</td>
<td>116,500 rsETH was released against a source-side position reported to be trivial</td>
</tr>
<tr>
<td>Provenance</td>
<td>Every destination release must correspond to one unique, finalized source-chain burn or lock event</td>
<td>Fabricated packets and false origin claims</td>
<td>The admitted condition was attestation, not source-state membership</td>
</tr>
<tr>
<td>Atomicity</td>
<td>A release either consumes one valid source event exactly once, or it does not happen</td>
<td>Replays, duplicate claims, partial semantics</td>
<td>Follow-up attempts show the path remained reusable until paused</td>
</tr>
<tr>
<td>Temporal ordering</td>
<td>Burn or lock must precede release in the accepted trace</td>
<td>Out-of-order settlement</td>
<td>Destination execution was treated as self-justifying once verification threshold fired</td>
</tr>
<tr>
<td>Economic admissibility</td>
<td>The transition must preserve solvency and bounded exposure under local risk rules</td>
<td>Toxic collateral entering shared liquidity systems</td>
<td>Downstream lenders accepted provenance-corrupted collateral</td>
</tr>
</tbody>
</table>
<p>In ASCII temporal notation, those properties look like this:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Conservation:
  release_amount(channel, guid) &#x3C;= entitled_amount_from_source(channel, guid)

Provenance:
  release(guid, a, r) -> exists unique burn_or_lock(guid, a, r) in finalized source state

Atomicity:
  execute(guid) -> verified(guid) and not consumed(guid)
  execute(guid) implies next(consumed(guid) = true)

Temporal ordering:
  G( release(guid) -> P source_debit(guid) )

Economic admissibility:
  G( transition -> preserves_solvency and preserves_risk_limits )</code></pre></div>
<p>The critical observation is that the exploit trace is easy to write down once the guards are written honestly.</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">s0:
  source-side rsETH float is tiny
  Ethereum escrow contains substantial rsETH
  bridge_config.requiredDVNCount = 1
  no source-state proof is required at release time

a1:
  attacker submits forged or otherwise invalid attested packet
  claiming srcEid = 30320, amount = 116,500, receiver = attacker

a2:
  verification threshold is considered satisfied

a3:
  EndpointV2 calls lzReceive on destination path

a4:
  Kelp bridge adapter releases 116,500 rsETH from escrow

s1:
  executed release exists without semantically sufficient source debit
  conservation fails
  provenance fails
  invalid state is reached</code></pre></div>
<p>That is the exploit. Not “someone signed something bad.” The exploit is that the transition guard was too weak to preserve the intended invariant set.</p>
<p>The flawed guard can be summarized as follows:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">flawed_release_guard(message):
    require attestation_threshold_satisfied(message.payloadHash)
    require not consumed(message.guid)
    release(message.amount, message.receiver)
    consumed(message.guid) = true</code></pre></div>
<p>The fixed guard has to be materially stronger:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">proof_carrying_release_guard(message, proof):
    require verify_attestation_threshold(message.payloadHash)
    require verify_source_state_root(message.src_chain, proof.root)
    require verify_inclusion_of_debit_event(
        proof.root,
        proof.guid,
        proof.amount,
        proof.receiver,
        proof.source_sender
    )
    require proof.amount == message.amount
    require not consumed(message.guid)
    require within_local_risk_limits(message.amount, message.src_chain)
    release(message.amount, message.receiver)
    consumed(message.guid) = true</code></pre></div>
<p>This is where proof-carrying execution becomes the right mental model. The original proof-carrying code result made the principle explicit: do not trust the producer’s authority, require an efficiently checkable proof that the artifact satisfies the consumer’s safety policy. The same principle should govern cross-chain settlement. A signature over a payload hash is not enough when the safety policy is “this transfer corresponds to a real source-side debit in the formal bridge semantics.” The proof presented to the destination should carry that statement, not just a weaker cryptographic acknowledgment that some worker saw a packet. <span class="citation" id="citation--necula1997pcc--29">(<a href="#bib-necula1997pcc">11</a>)</span></p>
<p>The desired destination path therefore looks like this:</p>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
    A<span class="token text string">[Source chain burn or lock event]</span> <span class="token arrow operator">--></span> B<span class="token text string">[Finalized source state root]</span>
    B <span class="token arrow operator">--></span> C<span class="token text string">[Proof package]</span>
    C <span class="token arrow operator">--></span> D<span class="token text string">[Destination verifier]</span>
    D <span class="token arrow operator">--></span> E<span class="token text string">{Check all obligations}</span>
    E <span class="token arrow operator">--></span><span class="token label property">|Valid|</span> F<span class="token text string">[Release exactly entitled amount]</span>
    E <span class="token arrow operator">--></span><span class="token label property">|Invalid|</span> G<span class="token text string">[Reject]</span>
    C <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">-.</span> <span class="token label property">includes</span> <span class="token arrow operator">.-></span></span> H<span class="token text string">[Event inclusion proof]</span>
    C <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">-.</span> <span class="token label property">includes</span> <span class="token arrow operator">.-></span></span> I<span class="token text string">[Uniqueness and anti-replay proof]</span>
    C <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">-.</span> <span class="token label property">includes</span> <span class="token arrow operator">.-></span></span> J<span class="token text string">[Economic admissibility proof]</span>
    C <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">-.</span> <span class="token label property">includes</span> <span class="token arrow operator">.-></span></span> K<span class="token text string">[Threshold witness attestation]</span></code></pre></div>
<h2 id="composability-turned-failure-into-bad-debt" style="position:relative;"><a href="#composability-turned-failure-into-bad-debt" aria-label="composability turned failure into bad debt permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Composability turned failure into bad debt</h2>
<p>The attacker did not need to dump 116,500 rsETH directly into spot liquidity and eat the slippage. The more sophisticated route was to treat the stolen tranche as borrow power. Contemporary on-chain analyses put the Aave-specific borrow exposure at roughly 52,834 WETH on Ethereum and 29,782 WETH plus 821 wstETH on Arbitrum, with smaller positions also opened in Compound V3 and Euler before markets tightened and freezes propagated. Reporting across that first day placed total extracted borrow value across venues around the <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>236</mn><mi>m</mi><mi>i</mi><mi>l</mi><mi>l</mi><mi>i</mi><mi>o</mi><mi>n</mi><mi>r</mi><mi>a</mi><mi>n</mi><mi>g</mi><mi>e</mi><mo separator="true">,</mo><mi>w</mi><mi>h</mi><mi>i</mi><mi>l</mi><mi>e</mi><mi>e</mi><mi>s</mi><mi>t</mi><mi>i</mi><mi>m</mi><mi>a</mi><mi>t</mi><mi>e</mi><mi>s</mi><mi>o</mi><mi>f</mi><mi>A</mi><mi>a</mi><mi>v</mi><mi>e</mi><mo>−</mo><mi>s</mi><mi>p</mi><mi>e</mi><mi>c</mi><mi>i</mi><mi>f</mi><mi>i</mi><mi>c</mi><mi>b</mi><mi>a</mi><mi>d</mi><mi>d</mi><mi>e</mi><mi>b</mi><mi>t</mi><mi>r</mi><mi>a</mi><mi>n</mi><mi>g</mi><mi>e</mi><mi>d</mi><mi>r</mi><mi>o</mi><mi>u</mi><mi>g</mi><mi>h</mi><mi>l</mi><mi>y</mi><mi>f</mi><mi>r</mi><mi>o</mi><mi>m</mi><mi>t</mi><mi>h</mi><mi>e</mi><mi>h</mi><mi>i</mi><mi>g</mi><mi>h</mi></mrow><annotation encoding="application/x-tex">236 million range, while estimates of Aave-specific bad debt ranged roughly from the high </annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">236</span><span class="mord mathnormal">mi</span><span class="mord mathnormal" style="margin-right:0.01968em;">l</span><span class="mord mathnormal" style="margin-right:0.01968em;">l</span><span class="mord mathnormal">i</span><span class="mord mathnormal">o</span><span class="mord mathnormal">n</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mord mathnormal">an</span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span><span class="mord mathnormal">e</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mord mathnormal">hi</span><span class="mord mathnormal" style="margin-right:0.01968em;">l</span><span class="mord mathnormal">ees</span><span class="mord mathnormal">t</span><span class="mord mathnormal">ima</span><span class="mord mathnormal">t</span><span class="mord mathnormal">eso</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mord mathnormal">A</span><span class="mord mathnormal">a</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">e</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">s</span><span class="mord mathnormal">p</span><span class="mord mathnormal">ec</span><span class="mord mathnormal">i</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mord mathnormal">i</span><span class="mord mathnormal">c</span><span class="mord mathnormal">ba</span><span class="mord mathnormal">dd</span><span class="mord mathnormal">e</span><span class="mord mathnormal">b</span><span class="mord mathnormal">t</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mord mathnormal">an</span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span><span class="mord mathnormal">e</span><span class="mord mathnormal">d</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mord mathnormal">o</span><span class="mord mathnormal" style="margin-right:0.03588em;">ug</span><span class="mord mathnormal">h</span><span class="mord mathnormal" style="margin-right:0.01968em;">l</span><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mord mathnormal">o</span><span class="mord mathnormal">m</span><span class="mord mathnormal">t</span><span class="mord mathnormal">h</span><span class="mord mathnormal">e</span><span class="mord mathnormal">hi</span><span class="mord mathnormal" style="margin-right:0.03588em;">g</span><span class="mord mathnormal">h</span></span></span></span></span>100 millions into about $200 million depending on mark assumptions and unwind treatment. Those figures should still be treated as provisional because the joint RCA is not out yet, but the systemic point is already clear. <span class="citation" id="citation--credshieldskelprsethexploit2026--30">(<a href="#bib-credshieldskelprsethexploit2026">2</a>)</span></p>
<p>Aave’s documented model is to let users borrow by posting collateral, with risk tracked through health factor, liquidation thresholds, and oracle-valued collateralization. Compound III documents the same basic structure in different language: collateral increases borrowing capacity through borrow collateral factors, and the system checks whether an account is borrow-collateralized. I am making an inference here, but it is a straightforward one from the docs: these engines are specified to reason about value and collateralization, not to prove source-chain provenance for every bridged collateral unit at borrow time. If an attacker can place a token into the eligible collateral state while the system still believes the token has acceptable value characteristics, shared liquidity is at risk. <span class="citation" id="citation--aavehealthfactorliquidations--31">(<a href="#bib-aavehealthfactorliquidations">8</a>)</span> <span class="citation" id="citation--compoundiiigovernancedocs--32">(<a href="#bib-compoundiiigovernancedocs">9</a>)</span></p>
<p>That is why the phrase “mainnet rsETH appears fully backed,” which Aave later used in its public update, is not enough to dissolve the engineering problem. Even if the broader Ethereum mainnet rsETH supply remains asset-backed in aggregate, the specific tranche released by the exploit is still provenance-corrupted with respect to the source-to-destination bridge semantics. Lending markets do not survive by knowing that the category of asset is usually fine. They survive by knowing that the specific collateral units against a live debt position are actually realizable at liquidation time under the system’s settlement semantics. This is a subtle but decisive distinction, and it is exactly why composability failures are so vicious. <span class="citation" id="citation--aaversethincident20260418--33">(<a href="#bib-aaversethincident20260418">3</a>)</span></p>
<p>The governance response was rational and still damning. Aave’s Guardian froze relevant rsETH and wrsETH markets starting at 18:52 UTC, later freezing WETH on several affected markets as a precaution. Compound III, by design, has a pause guardian with authority to halt supply, transfer, withdraw, absorb, and buy-collateral operations if an unforeseen vulnerability emerges. Those are necessary emergency tools. They are not substitutes for proof of correctness. They are social-consensus arrest powers. They exist because the underlying contracts are not fully self-defending against semantically invalid external state. <span class="citation" id="citation--aaversethincident20260418--34">(<a href="#bib-aaversethincident20260418">3</a>)</span> <span class="citation" id="citation--compoundiiigovernancedocs--35">(<a href="#bib-compoundiiigovernancedocs">9</a>)</span></p>
<p>That is the architectural indictment. DeFi keeps advertising “code is law,” but under stress it reverts to social consensus at human speed. Humans freeze markets. Humans negotiate recovery. Humans decide who gets socialized losses. Humans interpret whether one wrapped asset should be made whole at the expense of another. None of that is illegitimate in a crisis. It is simply proof that the system failed to encode its own admissibility conditions up front.</p>
<p>The answer is not to abandon composability. It is to localize it. Shared-liquidity systems can be efficient, but efficiency without local semantic verification makes bad state mobile. The right direction is deterministic local verification: every collateral domain should be required to prove its own correctness locally before it is allowed to contaminate shared liquidity globally. Where that is too expensive, the system should fall back to local isolation: separate vaults, separate caps, or separate spoke risk buckets whose failure cannot drain shared liquidity. Energy should be spent minimizing blast radius, not defending the ideology of seamless composability at all costs.</p>
<h2 id="what-rigorous-remediation-looks-like" style="position:relative;"><a href="#what-rigorous-remediation-looks-like" aria-label="what rigorous remediation looks like permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What rigorous remediation looks like</h2>
<p>The remediation program for a protocol like this cannot be “commission another audit and add another signer.” Audits are useful. They are not enough for cross-domain systems whose failure modes are semantic, temporal, and compositional. What is needed is a verification-aware architecture in which invariants are design inputs, not post-incident commentary.</p>
<p>The first design rule is invariant-driven architecture. That means every asset path should begin with a protocol-level invariant catalog: conservation, provenance, uniqueness, atomicity, ordering, bounded exposure, liquidity admissibility, and system-composition constraints. Every external call path and every privileged role must be mapped to the invariants it is allowed to affect. If a bridge path cannot state its invariants in unambiguous machine-checkable form, it is not mature enough to secure nine figures.</p>
<p>The second design rule is layered verification, because no single technique is enough. Model checking is excellent for state machines, temporal properties, and counterexample generation. SMT-based provers are excellent for transaction-level safety properties and bounded symbolic reasoning over code. Theorem provers are where refinement proofs and semantic equivalence arguments become trustworthy. Symbolic execution and invariant fuzzing remain indispensable because they generate adversarial witnesses and operationalize the threat model that the other layers specify. Recent smart-contract research and tooling reflect exactly this division of labor. KindHML targets temporal multi-transaction properties and leverages Kind2; SmartPulse targets temporal properties via instrumentation and checking; Solidity’s SMTChecker and commercial provers operate in the SMT-verification space; Foundry invariant testing and symbolic-execution tools provide aggressive counterexample search. <span class="citation" id="citation--kindhml2026--36">(<a href="#bib-kindhml2026">10</a>)</span> <span class="citation" id="citation--smartpulse2021--37">(<a href="#bib-smartpulse2021">12</a>)</span></p>
<table>
<thead>
<tr>
<th>Tool or class</th>
<th>Best use in this problem class</th>
<th>Strengths</th>
<th>Limitations</th>
<th>Adoption effort</th>
<th>Recommended role</th>
</tr>
</thead>
<tbody>
<tr>
<td>KindHML</td>
<td>Temporal bridge and lending properties across transaction sequences</td>
<td>Expressive temporal specifications, counterexample traces, good fit for liquidity and ordering failures</td>
<td>Research-stage scope; focuses on a Solidity fragment and not yet full production stack breadth</td>
<td>Medium to high</td>
<td>Use to prove “no invalid release trace exists” and “toxic collateral cannot reach borrowable state”</td>
</tr>
<tr>
<td>Kind2 or TLA+ model checking</td>
<td>Bridge state machines, event ordering, replay rules, pause semantics</td>
<td>Excellent counterexample generation and temporal reasoning</td>
<td>Abstracts away implementation detail unless carefully linked</td>
<td>Medium</td>
<td>Use during design, before code, to eliminate impossible-yet-reachable states</td>
</tr>
<tr>
<td>SMT-based verification</td>
<td>Contract-level proof of guards, bounds, role constraints, arithmetic safety</td>
<td>Strong automation, good CI integration, practical for many safety properties</td>
<td>Temporal and cross-system semantics can be awkward or bounded</td>
<td>Medium</td>
<td>Use for release guards, replay prevention, and solvency preconditions</td>
</tr>
<tr>
<td>Theorem provers</td>
<td>Refinement proofs from abstract semantics to implementation or circuit</td>
<td>Highest assurance for semantic preservation arguments</td>
<td>Expensive in expertise and time</td>
<td>High to very high</td>
<td>Reserve for custody-critical paths, proof-system bindings, and refinement theorems</td>
</tr>
<tr>
<td>Stateful symbolic execution and invariant fuzzing</td>
<td>Adversarial witness generation and regression testing</td>
<td>Finds concrete exploits and operational counterexamples</td>
<td>Not a proof of absence</td>
<td>Low to medium</td>
<td>Use continuously in CI to attack invariants and validate fixes</td>
</tr>
</tbody>
</table>
<p>The third design rule is proof-carrying state transitions. A cross-chain release should be accompanied by a proof object carrying at least the following facts:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">ProofCarryingRelease =
  {
    src_chain,
    dst_chain,
    guid,
    finalized_src_root,
    debit_event = (token, amount, sender, receiver, nonce),
    inclusion_proof,
    anti_replay_proof,
    threshold_witness_attestation,
    economic_admissibility_commitment
  }</code></pre></div>
<p>The destination verifier should accept a release only if the proof establishes that the source-side debit event exists in canonical finalized state, maps uniquely to the claimed destination release, has not already been consumed, and does not violate local risk limits. This is not just “use more signatures.” It is change the admissibility predicate. Threshold witnesses still matter, but as attestations over finalized state and semantic facts, not as a replacement for those facts.</p>
<p>The fourth design rule is threshold witness governance. LayerZero’s documentation explicitly supports an X-of-Y-of-N model for DVNs and recognizes multiple implementation types, including multisignature, zero-knowledge proof, oracle, protocol-adapter, and light-client approaches. For a pathway securing nine-figure collateral, one-of-one is not a security budget; it is a confession. A sane minimum would require independent witness domains, explicit liveness and disagreement handling, and a hard separation between governance authority and execution authority. Governance can change parameters under delay. Governance must not be the thing that semantically certifies whether a release is real. <span class="citation" id="citation--layerzerosecuritystackdvns--38">(<a href="#bib-layerzerosecuritystackdvns">5</a>)</span></p>
<p>The fifth design rule is deterministic local verification. If a bridge-delivered asset is admitted as lending collateral, then the lending venue should be able to verify, locally and deterministically, that the collateral unit belongs to a class of semantically valid claims. Where that is too expensive, the system should fall back to local isolation: separate vaults, separate caps, or separate spoke risk buckets whose failure cannot drain shared liquidity globally.</p>
<p>The sixth design rule is verification-aware CI. A serious CI/CD pipeline for a protocol exposed to this class of risk should include:</p>
<ul>
<li>invariant inventories as version-controlled artifacts;</li>
<li>model checks on abstract bridge and settlement machines;</li>
<li>SMT checks on release guards and role transitions;</li>
<li>invariant suites over randomized transaction sequences;</li>
<li>symbolic execution over attacker-controlled sequences;</li>
<li>differential tests between abstract semantics and concrete implementations;</li>
<li>regression suites for every discovered counterexample;</li>
<li>policy checks preventing one-of-one security stacks or uncapped collateral onboarding in production.</li>
</ul>
<p>This must become build hygiene, not a special engagement after a hack.</p>
<p>Finally, the offensive cost model changed. Anthropic’s own disclosures around Mythos Preview and Project Glasswing state that frontier models are being used to find vulnerabilities faster, and the 2025 “Prompt to Pwn” work showed LLM-based systems generating functional smart-contract proof-of-concept exploits with high success rates on benchmarked tasks. That does not mean models autonomously break every cross-contract economic system today. It does mean the cost of invariant hunting has collapsed, and protocol teams that still rely on “it passed audit” are now facing machine-scale adversarial search. Formal specifications are no longer academic overhead. They are increasingly the only way to keep the offense-defense economics from becoming absurdly one-sided. <span class="citation" id="citation--anthropicglasswing2026--39">(<a href="#bib-anthropicglasswing2026">13</a>)</span> <span class="citation" id="citation--anthropicmythospreview2026--40">(<a href="#bib-anthropicmythospreview2026">14</a>)</span> <span class="citation" id="citation--prompttopwn2025--41">(<a href="#bib-prompttopwn2025">15</a>)</span></p>
<h2 id="the-mandate-serious-protocols-should-fund" style="position:relative;"><a href="#the-mandate-serious-protocols-should-fund" aria-label="the mandate serious protocols should fund permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The mandate serious protocols should fund</h2>
<p>If I were brought in to harden a protocol against the exact class of failure exposed here, I would not start with patching one adapter and declaring victory. I would start by forcing the protocol to state, in machine-checkable form, what transitions are actually allowed to move value. Then I would force the implementation, the proof layer, and the risk layer to refine that specification. The deliverables below are not theoretical. They are what a competent protocol should now consider table stakes.</p>
<table>
<thead>
<tr>
<th>Phase</th>
<th>Estimated effort</th>
<th>Primary deliverables</th>
</tr>
</thead>
<tbody>
<tr>
<td>Threat-model and invariant extraction</td>
<td>1 to 2 weeks</td>
<td>Trust-boundary map, asset-path graph, invariant catalog, failure taxonomy, assumptions register</td>
</tr>
<tr>
<td>Executable formal specification</td>
<td>2 to 3 weeks</td>
<td>Bridge and settlement state machines, temporal properties, counterexample reconstruction of the Kelp class of failure, local and global economic predicates</td>
</tr>
<tr>
<td>Implementation hardening</td>
<td>3 to 5 weeks</td>
<td>Proof-carrying release schema, threshold witness redesign, replay- and provenance-safe settlement contracts, deterministic local-verification hooks</td>
</tr>
<tr>
<td>Verification integration</td>
<td>2 to 4 weeks</td>
<td>CI gates using model checking, SMT verification, invariant testing, symbolic execution, negative regression cases from known exploit traces</td>
</tr>
<tr>
<td>Composability containment and governance redesign</td>
<td>2 to 3 weeks</td>
<td>Isolation policies, collateral admissibility framework, emergency controls with formally bounded authority, operational incident runbooks</td>
</tr>
<tr>
<td>External assurance package</td>
<td>1 to 2 weeks</td>
<td>Reviewer-ready verification artifacts, proofs and proof obligations ledger, threat review memo, deployment acceptance checklist</td>
</tr>
</tbody>
</table>
<p>The concrete work products I would want a protocol to walk away with are these:</p>
<p>First, an executable bridge specification that states, in one place, the semantics of debit, settlement, replay prevention, ordering, cancellation, timeout, and pause behavior.</p>
<p>Second, a proof obligation ledger mapping every security claim to one of three states: formally proven, empirically stress-tested, or assumed but not yet discharged. Most protocols would find that far too much of their current “security” lives in the third column.</p>
<p>Third, a proof-carrying transition format for every high-value cross-domain release path, so that the destination accepts a transition because it is semantically justified, not because some signer stack emitted an acceptable packet hash.</p>
<p>Fourth, local admissibility rules for collateral. If a token cannot prove provenance cheaply, it should not have access to shared liquidity in the same way as assets with fully verifiable provenance.</p>
<p>Fifth, a CI system that treats every discovered exploit trace as a first-class regression artifact. The objective is not merely to fix the specific bug. It is to make the counterexample language smaller with every release.</p>
<p>Sixth, governance boundaries that are explicit and formally bounded. Emergency roles should be able to stop the system, not silently redefine truth.</p>
<p>That is the practical roadmap. The deeper verdict is harsher.</p>
<p>The KelpDAO exploit should end a certain style of DeFi thinking. The style I mean is the one that says modularity absolves responsibility, that bridge security is a parameter, that signatures are “decentralization,” that audits stand in for semantics, and that it is acceptable to let downstream protocols discover your trust assumptions only after they have already accepted your asset as collateral.</p>
<p>It should also end the lazy way people talk about formal verification. Formal methods are not a luxury reserved for aerospace or consensus code. They are what you reach for when a wrong transition can destroy nine figures in under a second and then metastasize through shared liquidity before a human can finish reading the alert.</p>
<p>The KelpDAO incident is DeFi’s Chernobyl moment only if the industry learns the right lesson from it. The right lesson is not “bridges are risky.” Everyone already knew that. The right lesson is that DeFi still builds systems whose safety depends on unstated semantics, human interpretation, and emergency governance after the fact. That is not high-assurance infrastructure. That is leveraged ambiguity.</p>
<p>If a protocol wants to become serious infrastructure, it has to do three things. It has to define correctness mathematically. It has to force every high-value transition to carry evidence of that correctness. And it has to contain failure locally when correctness cannot be established cheaply enough.</p>
<p>Until then, DeFi is not replacing fragile finance. It is digitalizing fragility and calling it innovation.</p>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li><strong>Attestation-as-truth:</strong> a destination release guard equates payload-hash attestation with semantic entitlement (no source-state membership proof).</li>
<li><strong>Configuration downgrade:</strong> security-stack defaults are bypassed (1-of-1 DVN; optional threshold set to 0; unpinned receive library), creating a single oracle.</li>
<li><strong>Replay / duplication:</strong> message identifiers are not consumed correctly, or the same semantic debit is claimable multiple times under different identifiers.</li>
<li><strong>Finality confusion:</strong> a non-finalized, reorgable, or non-canonical source event is treated as final, enabling reversible debits to back irreversible releases.</li>
<li><strong>Composability contagion:</strong> a provenance failure escapes into shared-liquidity venues where the admissibility predicate is valuation, not provenance.</li>
<li><strong>Human-speed safety:</strong> the true invariant is “invalid release remains possible until a multisig pauses,” which is not a safety property.</li>
</ul>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li><strong>Per-channel outflow invariants:</strong> <code class="language-text">released(dst) − debited(src)</code> bounds, tracked per asset + channel with alerting on divergence growth.</li>
<li><strong>Security-stack drift:</strong> required/optional DVNs, thresholds, receive library identifiers, and any governance-controlled parameters (detect silent downgrades).</li>
<li><strong>First-flight anomalies:</strong> bursty <code class="language-text">lzReceive</code> execution counts, unusual <code class="language-text">srcEid</code> distributions, and repeated <code class="language-text">guid</code> failures/successes.</li>
<li><strong>Collateral admission telemetry:</strong> bridged-asset collateralization share, borrow utilization, and liquidation pipeline health (especially during incident windows).</li>
<li><strong>Circuit-breaker activation time:</strong> minutes-to-pause is a KPI; target seconds, not “46 minutes to multisig.”</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<p>For operators running high-value cross-domain settlement paths:</p>
<ol>
<li><strong>Fail-closed:</strong> pause releases on the destination adapter, freeze mint/redeem paths, and block unknown <code class="language-text">srcEid</code> routes.</li>
<li><strong>Quarantine collateral domains:</strong> isolate affected bridged assets in lending (caps to zero, freeze borrows, halt transfers if supported).</li>
<li><strong>Invalidate and re-pin configs:</strong> redeploy or reconfigure to remove 1-of-1 stacks, pin receive libraries, and require explicit multi-witness thresholds.</li>
<li><strong>Reconcile entitlement:</strong> compute a deterministic ledger of source debits vs destination releases; mark provenance-corrupted units for unwind or socialized resolution.</li>
<li><strong>Ship a guard upgrade:</strong> require proof-carrying release objects (finalized root + inclusion + uniqueness + anti-replay) before unpausing.</li>
</ol>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li>Exploit transaction (<code class="language-text">lzReceive</code> on LayerZero EndpointV2 releasing 116,500 rsETH): <a href="https://etherscan.io/tx/0x1ae232da212c45f35c1525f851e4c41d529bf18af862d9ce9fd40bf709db4222" target="_blank" rel="nofollow noopener noreferrer">etherscan.io/tx/0x1ae232da...</a>. <span class="citation" id="citation--etherscantxkelprseth20260418--42">(<a href="#bib-etherscantxkelprseth20260418">1</a>)</span></li>
<li>Aave Guardian freeze timeline (rsETH/wrsETH frozen starting 18:52 UTC): <a href="https://governance.aave.com/t/rseth-incident-2026-04-18/24481" target="_blank" rel="nofollow noopener noreferrer">governance.aave.com/t/rseth-incident-2026-04-18</a>. <span class="citation" id="citation--aaversethincident20260418--43">(<a href="#bib-aaversethincident20260418">3</a>)</span></li>
<li>Incident reconstruction and follow-up attempts (18:26 / 18:28): <a href="https://discover.credshields.com/incident-report-kelp-dao-rseth-bridge-exploit/" target="_blank" rel="nofollow noopener noreferrer">discover.credshields.com/incident-report-kelp-dao-rseth-bridge-exploit</a>. <span class="citation" id="citation--credshieldskelprsethexploit2026--44">(<a href="#bib-credshieldskelprsethexploit2026">2</a>)</span></li>
<li>LayerZero security stack semantics (required DVNs, optional threshold, default configs): <a href="https://docs.layerzero.network/v2/concepts/modular-security/security-stack-dvns" target="_blank" rel="nofollow noopener noreferrer">docs.layerzero.network/.../security-stack-dvns</a>. <span class="citation" id="citation--layerzerosecuritystackdvns--45">(<a href="#bib-layerzerosecuritystackdvns">5</a>)</span></li>
<li>One-of-one DVN configuration details and addresses: <a href="https://defiprime.com/kelpdao-rseth-exploit" target="_blank" rel="nofollow noopener noreferrer">defiprime.com/kelpdao-rseth-exploit</a>. <span class="citation" id="citation--defiprimekelprsethexploit2026--46">(<a href="#bib-defiprimekelprsethexploit2026">7</a>)</span></li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul>
<li>Treat “attestation verified” as <em>necessary but not sufficient</em>; the guard must bind to a unique, finalized source debit.</li>
<li>Make supply conservation explicit and enforce it at the destination transition boundary.</li>
<li>Require multi-witness verification by policy (no one-of-one stacks for high-value channels) and hash+pin configs on-chain.</li>
<li>Add proof-carrying release objects (event inclusion + uniqueness + anti-replay + economic admissibility).</li>
<li>Isolate bridged-collateral risk domains by default (caps, spoke vaults, or per-asset silos) when provenance cannot be verified cheaply.</li>
<li>Add outflow circuit breakers (seconds, not “46 minutes to multisig”).</li>
<li>Version and regression-test every incident counterexample trace in CI.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li>KindHML (temporal verification of smart contracts via Kind2): <a href="https://arxiv.org/abs/2604.14038" target="_blank" rel="nofollow noopener noreferrer">arxiv.org/abs/2604.14038</a>. <span class="citation" id="citation--kindhml2026--47">(<a href="#bib-kindhml2026">10</a>)</span></li>
<li>SmartPulse (temporal checking of smart contracts): <a href="https://www.microsoft.com/en-us/research/uploads/prod/2021/02/SmartPulse-Oakland21-preprint.pdf" target="_blank" rel="nofollow noopener noreferrer">microsoft.com/.../SmartPulse-Oakland21-preprint.pdf</a>. <span class="citation" id="citation--smartpulse2021--48">(<a href="#bib-smartpulse2021">12</a>)</span></li>
<li>Proof-Carrying Code (original principle): <a href="https://www.cs.cmu.edu/~necula/papers/pcc-pldi97.pdf" target="_blank" rel="nofollow noopener noreferrer">cs.cmu.edu/~necula/papers/pcc-pldi97.pdf</a>. <span class="citation" id="citation--necula1997pcc--49">(<a href="#bib-necula1997pcc">11</a>)</span></li>
<li>Prompt-to-Pwn (LLM-driven exploit synthesis + validation): <a href="https://arxiv.org/abs/2508.01371" target="_blank" rel="nofollow noopener noreferrer">arxiv.org/abs/2508.01371</a>. <span class="citation" id="citation--prompttopwn2025--50">(<a href="#bib-prompttopwn2025">15</a>)</span></li>
<li>Anthropic Project Glasswing: <a href="https://www.anthropic.com/glasswing" target="_blank" rel="nofollow noopener noreferrer">anthropic.com/glasswing</a>. <span class="citation" id="citation--anthropicglasswing2026--51">(<a href="#bib-anthropicglasswing2026">13</a>)</span></li>
<li>Anthropic Mythos Preview (security implications): <a href="https://red.anthropic.com/2026/mythos-preview/" target="_blank" rel="nofollow noopener noreferrer">red.anthropic.com/2026/mythos-preview</a>. <span class="citation" id="citation--anthropicmythospreview2026--52">(<a href="#bib-anthropicmythospreview2026">14</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-etherscantxkelprseth20260418">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Etherscan. Ethereum Transaction 0x1ae232da... (LayerZero EndpointV2 lzReceive releasing 116,500 rsETH) [Internet]. Web; 2026. Available from: https://etherscan.io/tx/0x1ae232da212c45f35c1525f851e4c41d529bf18af862d9ce9fd40bf709db4222</div>
  </div>
  <div class="csl-entry" id="bib-credshieldskelprsethexploit2026">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Berry S. Incident Report: Kelp DAO rsETH Bridge Exploit [Internet]. Web; 2026. Available from: https://discover.credshields.com/incident-report-kelp-dao-rseth-bridge-exploit/</div>
  </div>
  <div class="csl-entry" id="bib-aaversethincident20260418">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Aave Governance (LlamaRisk). rsETH incident — 2026-04-18 [Internet]. Web; 2026. Available from: https://governance.aave.com/t/rseth-incident-2026-04-18/24481</div>
  </div>
  <div class="csl-entry" id="bib-lookonchainlayerzerorseth2026">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Lookonchain. LayerZero Response to rsETH Vulnerability (quoted statement + ongoing investigation) [Internet]. Web; 2026. Available from: https://www.lookonchain.com/feeds/54213</div>
  </div>
  <div class="csl-entry" id="bib-layerzerosecuritystackdvns">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">LayerZero. Security Stack (DVNs) [Internet]. Web; 2026. Available from: https://docs.layerzero.network/v2/concepts/modular-security/security-stack-dvns</div>
  </div>
  <div class="csl-entry" id="bib-layerzerowhitepaperv2">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">Zarick R, Pellegrino B, Zhang I. LayerZero Whitepaper V2.0 [Internet]. PDF; 2026. Available from: https://layerzero.network/publications/LayerZero_Whitepaper_V2.0.pdf</div>
  </div>
  <div class="csl-entry" id="bib-defiprimekelprsethexploit2026">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">Sawinyh N. The KelpDAO rsETH Exploit: 292M Minted From a 1-of-1 Bridge, and Who Actually Pays [Internet]. Web; 2026. Available from: https://defiprime.com/kelpdao-rseth-exploit</div>
  </div>
  <div class="csl-entry" id="bib-aavehealthfactorliquidations">
    <div class="csl-left-margin">8. </div><div class="csl-right-inline">Aave. Health Factor &#x26; Liquidations [Internet]. Web; 2026. Available from: https://aave.com/help/borrowing/liquidations</div>
  </div>
  <div class="csl-entry" id="bib-compoundiiigovernancedocs">
    <div class="csl-left-margin">9. </div><div class="csl-right-inline">Compound. Compound III Docs: Governance (Pause Guardian) [Internet]. Web; 2026. Available from: https://docs.compound.finance/governance/</div>
  </div>
  <div class="csl-entry" id="bib-kindhml2026">
    <div class="csl-left-margin">10. </div><div class="csl-right-inline">Bartoletti M, Ferrando A, Lipparini E, Malvone V. KindHML: formal verification of smart contracts based on Hennessy-Milner logic [Internet]. arXiv:2604.14038; 2026. Available from: https://arxiv.org/abs/2604.14038</div>
  </div>
  <div class="csl-entry" id="bib-necula1997pcc">
    <div class="csl-left-margin">11. </div><div class="csl-right-inline">Necula GC. Proof-Carrying Code. In: Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI) [Internet]. 1997. Available from: https://www.cs.cmu.edu/~necula/papers/pcc-pldi97.pdf</div>
  </div>
  <div class="csl-entry" id="bib-smartpulse2021">
    <div class="csl-left-margin">12. </div><div class="csl-right-inline">Stephens J, Ferles K, Mariano B, Lahiri S, Dillig I. SmartPulse: Automated Checking of Temporal Properties in Smart Contracts [Internet]. Preprint; 2021. Available from: https://www.microsoft.com/en-us/research/uploads/prod/2021/02/SmartPulse-Oakland21-preprint.pdf</div>
  </div>
  <div class="csl-entry" id="bib-anthropicglasswing2026">
    <div class="csl-left-margin">13. </div><div class="csl-right-inline">Anthropic. Project Glasswing: Securing critical software for the AI era [Internet]. Web; 2026. Available from: https://www.anthropic.com/glasswing</div>
  </div>
  <div class="csl-entry" id="bib-anthropicmythospreview2026">
    <div class="csl-left-margin">14. </div><div class="csl-right-inline">Anthropic. Claude Mythos Preview [Internet]. Web; 2026. Available from: https://red.anthropic.com/2026/mythos-preview/</div>
  </div>
  <div class="csl-entry" id="bib-prompttopwn2025">
    <div class="csl-left-margin">15. </div><div class="csl-right-inline">Xiao Z, Wang Q, Li Y, Chen S. Prompt to Pwn: Automated Exploit Generation for Smart Contracts [Internet]. arXiv:2508.01371; 2025. Available from: https://arxiv.org/abs/2508.01371</div>
  </div>
</div>]]></content>
        <category label="incident-analysis"/>
        <category label="security"/>
        <category label="DeFi"/>
        <category label="cross-chain"/>
        <category label="distributed-infrastructure"/>
        <category label="formal-methods"/>
        <category label="protocol-design"/>
        <category label="Ethereum"/>
        <category label="LayerZero"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Hybrid Schemes and Protocol Agility]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-hybrid-schemes-protocol-agility</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-hybrid-schemes-protocol-agility"/>
        <updated>2026-04-16T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Deep dive (April 2026): hybrid key establishment is a narrow hedge (HNDL), not “post-quantum TLS”. The hard part is suite identity, transcript binding, and AND-semantics for dual signatures.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Systems note. Theme: <strong>hybrid crypto is a protocol design problem</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>Hybrid key establishment is not “post-quantum TLS” in the broad sense; it is a very specific hedge against harvest-now-decrypt-later (HNDL).</p>
<p>In the dominant <code class="language-text">X25519MLKEM768</code> design for TLS 1.3, the client sends an X25519 ephemeral share plus an ML-KEM-768 encapsulation key in one <code class="language-text">key_share</code>. The server replies with an X25519 share plus an ML-KEM ciphertext. The two component secrets are concatenated and fed into the existing TLS 1.3 key schedule via HKDF extraction. The intended confidentiality claim is conditional: <strong>the session secret remains secure as long as at least one component remains secure</strong> and the combiner / schedule is sound. Authentication, however, remains whatever certificate/signature system the deployment already uses; hybrid KEX upgrades key establishment first — it does <strong>not</strong> automatically provide post-quantum authentication. <span class="citation" id="citation--rfc8446--1">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--rfc5869--2">(<a href="#bib-rfc5869">2</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--3">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span> <span class="citation" id="citation--ietfdrafttlsmlkem--4">(<a href="#bib-ietfdrafttlsmlkem">4</a>)</span> <span class="citation" id="citation--nistfips203--5">(<a href="#bib-nistfips203">5</a>)</span></p>
<p>In Noise-style systems, the practical split is between (a) “minimal graft” hybrids (HFS-style extensions that add an additional forward-secrecy contribution) and (b) KEM-token hybrids (PQNoise-style designs) that are cleaner when <strong>post-quantum authentication</strong> becomes the objective. The engineering trade-off is straightforward: HFS is easier to bolt onto a classical design; KEM-token hybrids are harder to deploy but remove ambiguity about what is protected at each stage.</p>
<p>Protocol agility decides whether hybrid deployment is a manageable migration or a flag day. Robust designs expose suites and versions explicitly, authenticate the negotiated choice in the transcript, bind keys to suite identifiers and version identifiers, and treat legacy codepoints as distinct algorithms rather than “equivalent spellings.” TLS 1.3 already demonstrates the core pattern: offer a capability vector, select one suite, bind the selection into the transcript, and abort if the peer selects something outside policy. <span class="citation" id="citation--rfc8446--6">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--7">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span> <span class="citation" id="citation--nistsp800227--8">(<a href="#bib-nistsp800227">6</a>)</span></p>
<p>Dual-signature transition schemes need the same discipline. The safe semantics are logical <strong>AND</strong>, not <strong>OR</strong>: both component signatures cover the same canonical context, both must verify, and the signed context must bind protocol version, suite identifier, key identifier, and replay state. Anything weaker turns “hybrid” into a downgrade gadget.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>Hybrid is a combiner + transcript story.</strong> If suite identity is not explicit and authenticated, you didn’t build “agility” — you built an algorithm-confusion surface.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Hybrid KEX protects confidentiality against HNDL; it does not automatically fix authentication.</li>
<li>“Secure if at least one survives” only holds if the combiner is versioned and context-bound.</li>
<li>Agility must be negotiated, transcript-bound, and fail-closed; aliases are downgrade oracles.</li>
<li>Dual signatures must be <strong>AND</strong> semantics with a canonical signed context; anything else is compat glue.</li>
<li>MTU/first-flight growth is an availability hazard; measure packetization, loss, and middlebox behavior.</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<p>The relevant adversary is not “Shor” in isolation. It is a composite attacker who can:</p>
<ul>
<li>record traffic today and attempt cryptanalysis later (HNDL),</li>
<li>actively interfere with negotiation during migration (downgrade/algorithm confusion),</li>
<li>exploit implementation failures (timing leakage, RNG failure, malformed-input oracles),</li>
<li>and use operational behavior (retries, fallbacks, legacy code paths) as attack surface. <span class="citation" id="citation--nistpqc--9">(<a href="#bib-nistpqc">7</a>)</span> <span class="citation" id="citation--nistsp800227--10">(<a href="#bib-nistsp800227">6</a>)</span></li>
</ul>
<p>On the systems side, assume:</p>
<ul>
<li>partial deployments happen (mixed versions, mixed suites),</li>
<li>middleboxes exist and still break things,</li>
<li>and availability is a security property because handshakes are attacker-triggerable compute. <span class="citation" id="citation--rfc8446--11">(<a href="#bib-rfc8446">1</a>)</span></li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving the cryptographic security of TLS 1.3 itself (done elsewhere). <span class="citation" id="citation--rfc8446--12">(<a href="#bib-rfc8446">1</a>)</span></li>
<li>Replacing PKI / certificate models; the focus is KEX + protocol agility boundaries.</li>
<li>Exhaustive benchmarking; the objective is correctness constraints and operational failure modes.</li>
</ul>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<p>Hybrid deployments only make sense if you state the security goal precisely enough that you can falsify it.</p>
<h3 id="p1--hybrid-confidentiality-under-hndl-conditional" style="position:relative;"><a href="#p1--hybrid-confidentiality-under-hndl-conditional" aria-label="p1  hybrid confidentiality under hndl conditional permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P1 — Hybrid confidentiality under HNDL (conditional)</h3>
<p>Let the two component shared secrets be <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>s</mi><mn>1</mn></msub></mrow><annotation encoding="application/x-tex">s_1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>s</mi><mn>2</mn></msub></mrow><annotation encoding="application/x-tex">s_2</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> (e.g., X25519 and ML-KEM), and let the combiner be the TLS 1.3 extraction step.</p>
<p>In the simplest model:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>s</mi><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">E</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mtext>  </mtext><msub><mi>s</mi><mn>1</mn></msub><mi mathvariant="normal">∥</mi><msub><mi>s</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s = \mathrm{HKDF\_Extract}(\mathrm{salt},\; s_1 \Vert s_2).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">s</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm">HKDF_Extract</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">salt</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">∥</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>The intended claim is:</p>
<blockquote>
<p>If at least one of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>s</mi><mn>1</mn></msub></mrow><annotation encoding="application/x-tex">s_1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> or <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>s</mi><mn>2</mn></msub></mrow><annotation encoding="application/x-tex">s_2</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> remains computationally indistinguishable from random, then <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>s</mi></mrow><annotation encoding="application/x-tex">s</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">s</span></span></span></span></span> is indistinguishable from random (under the extractor’s assumptions) and session confidentiality holds. <span class="citation" id="citation--rfc5869--13">(<a href="#bib-rfc5869">2</a>)</span> <span class="citation" id="citation--rfc8446--14">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--15">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span> <span class="citation" id="citation--nistsp800227--16">(<a href="#bib-nistsp800227">6</a>)</span></p>
</blockquote>
<p>That claim is not “marketing”. It is a conditional reduction that depends on <strong>context binding</strong>: which schemes, which parameters, which order, which transcript.</p>
<h3 id="p2--negotiation-soundness-no-silent-downgrade" style="position:relative;"><a href="#p2--negotiation-soundness-no-silent-downgrade" aria-label="p2  negotiation soundness no silent downgrade permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P2 — Negotiation soundness (no silent downgrade)</h3>
<p>Algorithm agility is only safe if the negotiation is part of the authenticated transcript. TLS 1.3’s shape is the reference:</p>
<ul>
<li>client offers <code class="language-text">supported_groups</code> / <code class="language-text">key_share</code>,</li>
<li>server selects one,</li>
<li><code class="language-text">Finished</code> authenticates the transcript (including selection),</li>
<li>abort if selection violates policy or isn’t in the offered set. <span class="citation" id="citation--rfc8446--17">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--18">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span></li>
</ul>
<h3 id="p3--authentication-separation-dont-lie-to-yourself" style="position:relative;"><a href="#p3--authentication-separation-dont-lie-to-yourself" aria-label="p3  authentication separation dont lie to yourself permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P3 — Authentication separation (don’t lie to yourself)</h3>
<p>Hybrid KEX can preserve secrecy of the handshake secret even if a classical KEX breaks later — but if the certificate signature scheme is breakable, active impersonation remains possible.</p>
<p>This separation is operationally non-negotiable: <strong>a post-quantum key agreement does not imply post-quantum authentication</strong>. <span class="citation" id="citation--rfc8446--19">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--nistfips204--20">(<a href="#bib-nistfips204">8</a>)</span> <span class="citation" id="citation--nistfips205--21">(<a href="#bib-nistfips205">9</a>)</span></p>
<h3 id="p4--dual-signature-correctness-and-semantics" style="position:relative;"><a href="#p4--dual-signature-correctness-and-semantics" aria-label="p4  dual signature correctness and semantics permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P4 — Dual-signature correctness (AND semantics)</h3>
<p>For a signed context <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="sans-serif">c</mi><mi mathvariant="sans-serif">t</mi><mi mathvariant="sans-serif">x</mi></mrow><annotation encoding="application/x-tex">\mathsf{ctx}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5714em;"></span><span class="mord"><span class="mord mathsf">ctx</span></span></span></span></span></span> and two signature algorithms <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>A</mi><mn>2</mn></msub></mrow><annotation encoding="application/x-tex">A_1, A_2</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">c</mi><mi mathvariant="sans-serif">t</mi><mi mathvariant="sans-serif">x</mi></mrow><mo separator="true">,</mo><msub><mi>σ</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>σ</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo>≡</mo><msub><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><msub><mi>A</mi><mn>1</mn></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">c</mi><mi mathvariant="sans-serif">t</mi><mi mathvariant="sans-serif">x</mi></mrow><mo separator="true">,</mo><msub><mi>σ</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mtext>  </mtext><mo>∧</mo><mtext>  </mtext><msub><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><msub><mi>A</mi><mn>2</mn></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="sans-serif">c</mi><mi mathvariant="sans-serif">t</mi><mi mathvariant="sans-serif">x</mi></mrow><mo separator="true">,</mo><msub><mi>σ</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Accept}(\mathsf{ctx}, \sigma_1, \sigma_2) \equiv
\mathrm{Verify}_{A_1}(\mathsf{ctx}, \sigma_1)\;\wedge\;\mathrm{Verify}_{A_2}(\mathsf{ctx}, \sigma_2).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Accept</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">ctx</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0942em;vertical-align:-0.3442em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2342em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3442em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">ctx</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0942em;vertical-align:-0.3442em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2342em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.3442em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathsf">ctx</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Anything weaker (e.g., OR semantics, or signatures over different contexts) is a downgrade gadget.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>Suite-bound transcript:</strong> keys and signatures are derived/verified over a context that binds (version, suite_id, component order, parameter sets). If that binding is not explicit, “hybrid” becomes algorithm confusion.</p>
</div>
<h2 id="hybrid-x25519-and-ml-kem-in-tls-13" style="position:relative;"><a href="#hybrid-x25519-and-ml-kem-in-tls-13" aria-label="hybrid x25519 and ml kem in tls 13 permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Hybrid X25519 and ML-KEM in TLS 1.3</h2>
<p>The modern standardized vocabulary is different from legacy deployment vocabulary. What many operators still call “Kyber” is standardized as ML-KEM (FIPS 203). Treat standardized and draft codepoints as distinct negotiated algorithms, not silent aliases. <span class="citation" id="citation--nistfips203--22">(<a href="#bib-nistfips203">5</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--23">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span> <span class="citation" id="citation--ietfdrafttlsmlkem--24">(<a href="#bib-ietfdrafttlsmlkem">4</a>)</span></p>
<p>In TLS 1.3 hybrid design, the construction is intentionally conservative. A hybrid construction is represented as a single <code class="language-text">NamedGroup</code>. The client and server transmit component public values by concatenating them inside a normal <code class="language-text">KeyShareEntry.key_exchange</code>, and component shared secrets are concatenated before being fed into the TLS 1.3 HKDF extraction flow. <span class="citation" id="citation--rfc8446--25">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--rfc5869--26">(<a href="#bib-rfc5869">2</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--27">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span></p>
<p>For <code class="language-text">X25519MLKEM768</code>, the draft specifies:</p>
<ul>
<li>client <code class="language-text">key_exchange</code> size: <strong>1216 bytes</strong> (32-byte X25519 share + 1184-byte ML-KEM encapsulation key)</li>
<li>server <code class="language-text">key_exchange</code> size: <strong>1120 bytes</strong> (32-byte X25519 share + 1088-byte ML-KEM ciphertext) <span class="citation" id="citation--ietfdrafttlshybriddesign--28">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span> <span class="citation" id="citation--ietfdrafttlsmlkem--29">(<a href="#bib-ietfdrafttlsmlkem">4</a>)</span></li>
</ul>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
    <span class="token keyword">participant</span> C as Client
    <span class="token keyword">participant</span> S as Server

    C<span class="token arrow operator">->></span>S<span class="token operator">:</span> ClientHello
    <span class="token keyword">Note over</span> C,S<span class="token operator">:</span> supported_groups = <span class="token text string">[X25519MLKEM768, X25519, ...]</span>
    <span class="token keyword">Note over</span> C,S<span class="token operator">:</span> key_share<span class="token text string">[X25519MLKEM768]</span> = x25519_pub_C || mlkem_ek_C

    S<span class="token arrow operator">->></span>S<span class="token operator">:</span> ss_x = X25519<span class="token text string">(x25519_sk_S, x25519_pub_C)</span>
    S<span class="token arrow operator">->></span>S<span class="token operator">:</span> <span class="token text string">(mlkem_ct_S, ss_m)</span> = ML-KEM.Encaps<span class="token text string">(mlkem_ek_C)</span>

    S<span class="token arrow operator">->></span>C<span class="token operator">:</span> ServerHello
    <span class="token keyword">Note over</span> C,S<span class="token operator">:</span> selected_group = X25519MLKEM768
    <span class="token keyword">Note over</span> C,S<span class="token operator">:</span> key_share = x25519_pub_S || mlkem_ct_S

    C<span class="token arrow operator">->></span>C<span class="token operator">:</span> ss_x = X25519<span class="token text string">(x25519_sk_C, x25519_pub_S)</span>
    C<span class="token arrow operator">->></span>C<span class="token operator">:</span> ss_m = ML-KEM.Decaps<span class="token text string">(mlkem_dk_C, mlkem_ct_S)</span>
    C<span class="token arrow operator">->></span>C<span class="token operator">:</span> ss = ss_x || ss_m
    S<span class="token arrow operator">->></span>S<span class="token operator">:</span> ss = ss_x || ss_m

    <span class="token keyword">Note over</span> C,S<span class="token operator">:</span> HandshakeSecret = HKDF-Extract<span class="token punctuation">(</span>DeriveSecret<span class="token text string">(...)</span>, ss<span class="token punctuation">)</span>

    S<span class="token arrow operator">->></span>C<span class="token operator">:</span> EncryptedExtensions
    S<span class="token arrow operator">->></span>C<span class="token operator">:</span> Certificate
    S<span class="token arrow operator">->></span>C<span class="token operator">:</span> CertificateVerify<span class="token text string">(transcript)</span>
    S<span class="token arrow operator">->></span>C<span class="token operator">:</span> Finished
    C<span class="token arrow operator">->></span>S<span class="token operator">:</span> Finished</code></pre></div>
<p>The consequence is subtle but operationally critical:</p>
<ul>
<li>the <strong>confidentiality</strong> of session keys is intended to survive a break of either X25519 (RFC 7748) or ML-KEM (FIPS 203),</li>
<li>but <strong>authentication</strong> remains the usual TLS 1.3 transcript authentication: <code class="language-text">CertificateVerify</code> and <code class="language-text">Finished</code> bind negotiated choices through the transcript hash. If your certificate signature is not post-quantum secure, active impersonation remains possible under that failure model. <span class="citation" id="citation--rfc8446--30">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--rfc7748--31">(<a href="#bib-rfc7748">10</a>)</span> <span class="citation" id="citation--nistfips203--32">(<a href="#bib-nistfips203">5</a>)</span> <span class="citation" id="citation--nistfips204--33">(<a href="#bib-nistfips204">8</a>)</span> <span class="citation" id="citation--nistfips205--34">(<a href="#bib-nistfips205">9</a>)</span></li>
</ul>
<p>TLS 1.3 also provides the downgrade defenses custom protocols should emulate. Negotiation is safe only because the negotiation itself is bound into the authenticated transcript. <span class="citation" id="citation--rfc8446--35">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--36">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span></p>
<h2 id="protocol-agility-without-hard-forks" style="position:relative;"><a href="#protocol-agility-without-hard-forks" aria-label="protocol agility without hard forks permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Protocol agility without hard forks</h2>
<p>The objective is not “support many algorithms”. The objective is to make <strong>algorithm selection a versioned, authenticated protocol object</strong>.</p>
<p>Minimal wire requirements:</p>
<ul>
<li>explicit protocol version,</li>
<li>offered capability set,</li>
<li>unambiguous selected suite,</li>
<li>transcript binding: authentication covers offer + selection,</li>
<li>fail-closed on negotiation failure. <span class="citation" id="citation--rfc8446--37">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--nistsp800227--38">(<a href="#bib-nistsp800227">6</a>)</span></li>
</ul>
<p>A sound rollover strategy follows concrete rules:</p>
<ol>
<li><strong>Suite identifiers encode ordered composition</strong>, not unordered bags. <code class="language-text">X25519MLKEM768</code> is not the same as <code class="language-text">MLKEM768X25519</code> unless specified.</li>
<li>The selected suite is one element of the offered capability vector, never inferred.</li>
<li>Key identifiers and version identifiers are bound into transcript and KDF context.</li>
<li>Negotiation failure is fail-closed.</li>
<li>Fallback is explicit policy, never a silent parser trick. <span class="citation" id="citation--rfc8446--39">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--nistsp800227--40">(<a href="#bib-nistsp800227">6</a>)</span></li>
</ol>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
    A<span class="token text string">["Client: version list + capability vector"]</span> <span class="token arrow operator">--></span> B<span class="token text string">["Server: select one suite and echo exact choice"]</span>
    B <span class="token arrow operator">--></span> C<span class="token text string">["Both: transcript hash over offer + selection"]</span>
    C <span class="token arrow operator">--></span> D<span class="token text string">["Authenticator binds (suite_id, key_id, version)"]</span>
    D <span class="token arrow operator">--></span> E<span class="token text string">{"Selection in offer and policy satisfied?"}</span>
    E <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">--</span> <span class="token label property">No</span> <span class="token arrow operator">--></span></span> F<span class="token text string">["Abort"]</span>
    E <span class="token inter-arrow-label"><span class="token arrow-head arrow operator">--</span> <span class="token label property">Yes</span> <span class="token arrow operator">--></span></span> G<span class="token text string">["Derive traffic keys with suite-bound context"]</span>
    G <span class="token arrow operator">--></span> H<span class="token text string">["Emit telemetry: negotiated suite + fallback count"]</span></code></pre></div>
<p>Two constraints that bite in production:</p>
<ul>
<li><strong>Message bloat during capability advertisement.</strong> Over-advertising hybrid suites can duplicate large PQ material inside one offer. Prefer a short, policy-driven ordered list and use retry mechanisms (like <code class="language-text">HelloRetryRequest</code>) when you must. <span class="citation" id="citation--rfc8446--41">(<a href="#bib-rfc8446">1</a>)</span> <span class="citation" id="citation--ietfdrafttlshybriddesign--42">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span></li>
<li><strong>Legacy draft compatibility.</strong> Treat draft codepoints as separate suites with separate policy and telemetry. Normalizing them internally creates downgrade oracles. <span class="citation" id="citation--ietfdrafttlshybriddesign--43">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span> <span class="citation" id="citation--ietfdrafttlsmlkem--44">(<a href="#bib-ietfdrafttlsmlkem">4</a>)</span></li>
</ul>
<h2 id="dual-signature-packet-and-header-design" style="position:relative;"><a href="#dual-signature-packet-and-header-design" aria-label="dual signature packet and header design permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Dual-signature packet and header design</h2>
<p>Transition schemes that attach both classical and PQ signatures must preserve acceptance semantics.</p>
<p>The safe semantics are AND: both signatures verify over the same canonical context.</p>
<p>For transport and application protocols, the safest wire format is a must-understand TLV signature block and a canonical signed context that includes:</p>
<ul>
<li>protocol identifier,</li>
<li>protocol version,</li>
<li>suite identifier,</li>
<li>sender key identifier,</li>
<li>sequence number / epoch,</li>
<li>replay state,</li>
<li>a hash of the payload,</li>
<li>and (when relevant) hashes of both verification credentials (to prevent replay across mixed bundles). <span class="citation" id="citation--nistsp800227--45">(<a href="#bib-nistsp800227">6</a>)</span> <span class="citation" id="citation--rfc5869--46">(<a href="#bib-rfc5869">2</a>)</span></li>
</ul>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">struct SignedRecord {
    uint8  version_major;
    uint8  version_minor;
    uint16 suite_id;
    uint32 key_id;
    uint64 seq_no;
    uint16 flags;          // includes must_understand_dual_sig
    uint16 payload_len;
    opaque payload[payload_len];

    uint8  sig_count;      // 1 in shadow mode, 2 in enforced dual mode
    repeated SignatureTLV {
        uint16 alg_id;
        uint16 sig_len;
        opaque signature[sig_len];
    }
}</code></pre></div>
<p>DoS management: verify the cheaper signature first as reject-fast, then verify the second signature and accept only if both succeed. The correctness rule never changes: success is AND.</p>
<p>Raw algorithm sizes matter for packetization. These are primitive sizes, not certificate-chain overhead: <span class="citation" id="citation--rfc8032--47">(<a href="#bib-rfc8032">11</a>)</span> <span class="citation" id="citation--nistfips204--48">(<a href="#bib-nistfips204">8</a>)</span> <span class="citation" id="citation--nistfips205--49">(<a href="#bib-nistfips205">9</a>)</span></p>
<table>
<thead>
<tr>
<th>Signature profile</th>
<th align="right">Classical key+sig</th>
<th align="right">PQ key+sig</th>
<th align="right">Combined raw overhead</th>
<th>Migration assessment</th>
</tr>
</thead>
<tbody>
<tr>
<td>Ed25519 only</td>
<td align="right">32 + 64 bytes</td>
<td align="right">—</td>
<td align="right">96 bytes</td>
<td>Baseline classical profile</td>
</tr>
<tr>
<td>Ed25519 + ML-DSA-65</td>
<td align="right">32 + 64 bytes</td>
<td align="right">1952 + 3309 bytes</td>
<td align="right">5357 bytes</td>
<td>Practical general-purpose dual-signature profile</td>
</tr>
<tr>
<td>Ed25519 + ML-DSA-44</td>
<td align="right">32 + 64 bytes</td>
<td align="right">1312 + 2420 bytes</td>
<td align="right">3828 bytes</td>
<td>Smaller but lower security category than ML-DSA-65</td>
</tr>
<tr>
<td>Ed25519 + SLH-DSA-128s</td>
<td align="right">32 + 64 bytes</td>
<td align="right">32 + 7856 bytes</td>
<td align="right">7984 bytes</td>
<td>Conservative hash-based hedge; significant MTU pressure</td>
</tr>
</tbody>
</table>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li><strong>Algorithm confusion:</strong> treating draft and standardized codepoints as aliases. This creates downgrade gadgets in “compatibility” code.</li>
<li><strong>Unbound suite identity:</strong> the KDF transcript doesn’t bind suite id, version, or component order → cross-protocol key reuse risks.</li>
<li><strong>OR semantics for dual signatures:</strong> accepting either signature is not “hybrid”; it is a unilateral downgrade.</li>
<li><strong>Ambiguous canonicalization:</strong> “sign raw packet as received” + multiple encodings → replay across versions/suites.</li>
<li><strong>First-flight fragmentation:</strong> PQ material pushes handshake flights across packets; packet loss + retransmits amplify latency.</li>
<li><strong>Randomness reuse / secret retention:</strong> caching ephemeral KEM keys or keeping decapsulation keys alive beyond session lifetime.</li>
<li><strong>Silent fallback under incident pressure:</strong> “temporary compatibility” becomes the permanent weakest link.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Agility that isn’t measurable becomes folklore. If you can’t answer “which suites were negotiated, where, and why?” you can’t manage migration or incident response.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Negotiated suite distribution (by endpoint/cohort/region).</li>
<li>Fallback counts and reasons (policy vs interop vs parsing failure).</li>
<li>Handshake flight sizes, fragmentation rate, retransmit rate.</li>
<li>Verification and signing CPU time per handshake/record (cheap vs expensive signature order).</li>
<li>Error budgets: p95/p99 handshake latency and timeout rates.</li>
<li>Rate-limit effectiveness on handshake paths (DoS resilience).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Feature-flag suite acceptance (per cohort), not just global toggles.</li>
<li>Shadow mode for dual signatures: generate+verify both, enforce one, log mismatch, then flip to AND enforcement.</li>
<li>Emergency compatibility policy is explicit, logged, and time-boxed (no silent downgrade).</li>
<li>Remove legacy draft suites deliberately with telemetry-driven cutoff.</li>
<li>Document “kill switches” that do not require multi-day PKI ceremonies.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://datatracker.ietf.org/doc/draft-ietf-tls-hybrid-design/" target="_blank" rel="nofollow noopener noreferrer">Hybrid key exchange in TLS 1.3 (IETF draft)</a> <span class="citation" id="citation--ietfdrafttlshybriddesign--50">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span>
<ul>
<li><strong>Evidence:</strong> <code class="language-text">X25519MLKEM768</code> is represented as one <code class="language-text">NamedGroup</code>; shares are concatenated; secrets are combined via the TLS key schedule.</li>
</ul>
</li>
<li><a href="https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/" target="_blank" rel="nofollow noopener noreferrer">ML-KEM for TLS 1.3 (IETF draft)</a> <span class="citation" id="citation--ietfdrafttlsmlkem--51">(<a href="#bib-ietfdrafttlsmlkem">4</a>)</span>
<ul>
<li><strong>Evidence:</strong> standardized naming/codepoint discipline matters; draft vs final identifiers are distinct negotiated objects.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">TLS 1.3 (RFC 8446)</a> <span class="citation" id="citation--rfc8446--52">(<a href="#bib-rfc8446">1</a>)</span>
<ul>
<li><strong>Evidence:</strong> the negotiation is bound into the authenticated transcript via <code class="language-text">Finished</code>; downgrade defenses are structural, not optional.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">HKDF (RFC 5869)</a> <span class="citation" id="citation--rfc5869--53">(<a href="#bib-rfc5869">2</a>)</span>
<ul>
<li><strong>Evidence:</strong> extraction gives a principled combiner; ad hoc concatenation without context binding is not defensible.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/pubs/fips/203/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 203 (ML-KEM)</a> <span class="citation" id="citation--nistfips203--54">(<a href="#bib-nistfips203">5</a>)</span>
<ul>
<li><strong>Evidence:</strong> ML-KEM is standardized; composite constructions require explicit design discipline.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/pubs/sp/800/227/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-227 (KEM recommendations)</a> <span class="citation" id="citation--nistsp800227--55">(<a href="#bib-nistsp800227">6</a>)</span>
<ul>
<li><strong>Evidence:</strong> multi-algorithm KEM establishment needs explicit, context-bound combiners; implementation hygiene is not “nice to have”.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/pubs/fips/204/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 204/205 (ML-DSA / SLH-DSA)</a> <span class="citation" id="citation--nistfips204--56">(<a href="#bib-nistfips204">8</a>)</span>
<ul>
<li><strong>Evidence:</strong> signature size and compute profiles are not interchangeable; placement matters.</li>
</ul>
</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Inventory algorithm touchpoints (suite ids, version fields, validators, telemetry).</li>
<li class="task-list-item"><input type="checkbox" disabled> Introduce a suite registry: composition is named, ordered, and versioned.</li>
<li class="task-list-item"><input type="checkbox" disabled> Bind negotiation into authentication (offer + selection in transcript).</li>
<li class="task-list-item"><input type="checkbox" disabled> Bind suite id + version into KDF / combiner context (domain separation).</li>
<li class="task-list-item"><input type="checkbox" disabled> Deploy hybrid KEX explicitly as confidentiality hedge; document auth status honestly.</li>
<li class="task-list-item"><input type="checkbox" disabled> Run dual signatures in shadow mode first; then enforce AND semantics.</li>
<li class="task-list-item"><input type="checkbox" disabled> Treat MTU/first-flight growth as a release blocker; test middleboxes.</li>
<li class="task-list-item"><input type="checkbox" disabled> Ban randomness reuse; enforce erasure of ephemeral material.</li>
<li class="task-list-item"><input type="checkbox" disabled> Limit advertised combinations; prefer policy-driven short lists + retry.</li>
<li class="task-list-item"><input type="checkbox" disabled> Sunset legacy draft suites deliberately, with telemetry and dates.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--57">(<a href="#bib-rfc8446">1</a>)</span></li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--58">(<a href="#bib-rfc5869">2</a>)</span></li>
<li><a href="https://www.rfc-editor.org/rfc/rfc7748" target="_blank" rel="nofollow noopener noreferrer">RFC 7748: X25519</a> <span class="citation" id="citation--rfc7748--59">(<a href="#bib-rfc7748">10</a>)</span></li>
<li><a href="https://csrc.nist.gov/pubs/fips/203/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 203: ML-KEM</a> <span class="citation" id="citation--nistfips203--60">(<a href="#bib-nistfips203">5</a>)</span></li>
<li><a href="https://csrc.nist.gov/pubs/sp/800/227/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-227: KEM Recommendations</a> <span class="citation" id="citation--nistsp800227--61">(<a href="#bib-nistsp800227">6</a>)</span></li>
<li><a href="https://datatracker.ietf.org/doc/draft-ietf-tls-hybrid-design/" target="_blank" rel="nofollow noopener noreferrer">IETF: Hybrid key exchange in TLS 1.3</a> <span class="citation" id="citation--ietfdrafttlshybriddesign--62">(<a href="#bib-ietfdrafttlshybriddesign">3</a>)</span></li>
<li><a href="https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/" target="_blank" rel="nofollow noopener noreferrer">IETF: ML-KEM for TLS 1.3</a> <span class="citation" id="citation--ietfdrafttlsmlkem--63">(<a href="#bib-ietfdrafttlsmlkem">4</a>)</span></li>
<li><a href="https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/" target="_blank" rel="nofollow noopener noreferrer">IETF: ECDHE-MLKEM for TLS 1.3</a> <span class="citation" id="citation--ietfdrafttlsecdhemlkem--64">(<a href="#bib-ietfdrafttlsecdhemlkem">12</a>)</span></li>
<li><a href="https://datatracker.ietf.org/doc/draft-connolly-cfrg-xwing-kem/" target="_blank" rel="nofollow noopener noreferrer">IETF: X-Wing hybrid KEM</a> <span class="citation" id="citation--ietfdraftxwing--65">(<a href="#bib-ietfdraftxwing">13</a>)</span></li>
<li><a href="https://github.com/open-quantum-safe/oqs-provider" target="_blank" rel="nofollow noopener noreferrer">Open Quantum Safe: oqs-provider</a> <span class="citation" id="citation--oqsprovider--66">(<a href="#bib-oqsprovider">14</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-ietfdrafttlshybriddesign">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">IETF. Hybrid key exchange in TLS 1.3 [Internet]. Internet-Draft; 2026. Available from: https://datatracker.ietf.org/doc/draft-ietf-tls-hybrid-design/</div>
  </div>
  <div class="csl-entry" id="bib-ietfdrafttlsmlkem">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">IETF. ML-KEM Post-Quantum Key Agreement for TLS 1.3 [Internet]. Internet-Draft; 2026. Available from: https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/</div>
  </div>
  <div class="csl-entry" id="bib-nistfips203">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/203/final</div>
  </div>
  <div class="csl-entry" id="bib-nistsp800227">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Recommendations for Key-Encapsulation Mechanisms [Internet]. 2025. Report No.: 800–227. Available from: https://csrc.nist.gov/pubs/sp/800/227/final</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
  <div class="csl-entry" id="bib-nistfips204">
    <div class="csl-left-margin">8. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/204/final</div>
  </div>
  <div class="csl-entry" id="bib-nistfips205">
    <div class="csl-left-margin">9. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/205/final</div>
  </div>
  <div class="csl-entry" id="bib-rfc7748">
    <div class="csl-left-margin">10. </div><div class="csl-right-inline">Langley A, Hamburg M, Turner S. Elliptic Curves for Security [Internet]. RFC Editor; 2016. Report No.: 7748. Available from: https://www.rfc-editor.org/rfc/rfc7748</div>
  </div>
  <div class="csl-entry" id="bib-rfc8032">
    <div class="csl-left-margin">11. </div><div class="csl-right-inline">Josefsson S, Liusvaara I. Edwards-Curve Digital Signature Algorithm (EdDSA) [Internet]. RFC Editor; 2017. Report No.: 8032. Available from: https://www.rfc-editor.org/rfc/rfc8032</div>
  </div>
  <div class="csl-entry" id="bib-ietfdrafttlsecdhemlkem">
    <div class="csl-left-margin">12. </div><div class="csl-right-inline">IETF. Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3 [Internet]. Internet-Draft; 2026. Available from: https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/</div>
  </div>
  <div class="csl-entry" id="bib-ietfdraftxwing">
    <div class="csl-left-margin">13. </div><div class="csl-right-inline">IETF. X-Wing: general-purpose hybrid post-quantum KEM [Internet]. Internet-Draft; 2026. Available from: https://datatracker.ietf.org/doc/draft-connolly-cfrg-xwing-kem/</div>
  </div>
  <div class="csl-entry" id="bib-oqsprovider">
    <div class="csl-left-margin">14. </div><div class="csl-right-inline">Open Quantum Safe. Open Quantum Safe: oqs-provider [Internet]. Web; Available from: https://github.com/open-quantum-safe/oqs-provider</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="protocol-design"/>
        <category label="security-critical-infrastructure"/>
        <category label="devsecops"/>
        <category label="distributed-systems"/>
        <category label="TLS"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[The Leaf Is the Hot Path: Signature Placement in Post-Quantum TLS (ML-DSA vs SLH-DSA)]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-pq-tls-signature-placement-ml-dsa-slh-dsa</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-pq-tls-signature-placement-ml-dsa-slh-dsa"/>
        <updated>2026-04-08T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Paper note (April 2026): experiments show SLH-DSA in the server leaf collapses TLS 1.3 handshakes by ~10^3×. PQ migration is a certificate-hierarchy and cost-concentration problem, not an algorithm swap.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Paper-driven research note. Theme: <strong>PQC migration that fails at the certificate boundary</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>If you read post-quantum TLS plans as “replace ECDSA with some PQ signature”, you will build the wrong system.</p>
<p>In TLS 1.3, the end-entity (leaf) certificate key is not just an identity anchor — it is the key that signs the live handshake transcript (<code class="language-text">CertificateVerify</code>). That single design fact turns “which signature algorithm lives in the leaf” into a hot-path engineering decision with direct DoS consequences.</p>
<p>Delgado Jiménez (arXiv:2604.06100) runs a clean local experiment matrix on OpenSSL 3 + <code class="language-text">oqsprovider</code>, varying where ML-DSA and SLH-DSA appear in the certificate hierarchy. The result is a discontinuity you cannot hand-wave away:</p>
<ul>
<li>a fully-ML baseline is <strong>~0.809 ms</strong> mean handshake latency, <strong>~0.562 ms</strong> server task-clock per handshake</li>
<li>moving SLH-DSA into the server leaf produces <strong>~1402 ms</strong> mean latency, <strong>~1401 ms</strong> server task-clock per handshake (≈ <strong>1733×</strong> the baseline)</li>
<li>the bytes transferred only grow ~<strong>1.69×</strong>, so the collapse is not “just bigger certificates” — it is online signing cost. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--1">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
</ul>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>In PQ TLS, “placement” is a performance and security boundary.</strong> The leaf algorithm determines online server signing cost; upper-layer algorithms mostly shift validation work to clients. This is cost concentration, not algorithm substitution.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li><strong>Leaf SLH-DSA is an online CPU collapse.</strong> In the paper’s matrix, leaf-SLH jumps from ~0.8 ms to ~1400 ms mean latency (≈ 1733×). <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--2">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>Upper-layer SLH-DSA is penalized but plausible.</strong> Root-SLH / leaf-ML increases latency to ~2.133 ms (≈ 2.64×) while server task-clock rises only ~1.19×. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--3">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>Transport size is a second-order effect in the heavy regime.</strong> Leaf-SLH reads ~27,015 bytes vs ~16,008 baseline (≈ 1.69×) while server CPU rises ≈ 2494×. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--4">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>Client/server work distribution changes by placement.</strong> Upper-layer SLH shifts active work toward client validation; leaf-SLH becomes overwhelmingly server-bound. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--5">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>PQC rollout must be evaluated as PKI+TLS design.</strong> Chain exposure, depth, caching, compression, and resumption interact with cryptographic cost in ways primitive benchmarks cannot predict. <span class="citation" id="citation--rfc8446--6">(<a href="#bib-rfc8446">2</a>)</span> <span class="citation" id="citation--rfc5280--7">(<a href="#bib-rfc5280">3</a>)</span> <span class="citation" id="citation--rfc8879--8">(<a href="#bib-rfc8879">4</a>)</span></li>
</ul>
<h2 id="introduction-pragmatic-abstract-the-infrastructure-problem" style="position:relative;"><a href="#introduction-pragmatic-abstract-the-infrastructure-problem" aria-label="introduction pragmatic abstract the infrastructure problem permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Introduction (pragmatic abstract: the infrastructure problem)</h2>
<p>The real question your pager asks is not “is ML-DSA post-quantum secure?”.</p>
<p>It is: <em>“Can my TLS front-end authenticate at peak load without becoming a self-inflicted CPU DoS?”</em></p>
<p>In classical TLS deployments, RSA/ECDSA/Ed25519 signing costs are low enough that we tend to blame handshakes on network RTT, certificate chain size, or cache misses. Post-quantum signatures break that mental model because they are not a single family with smooth tradeoffs:</p>
<ul>
<li><strong>ML-DSA</strong> (FIPS 204) is lattice-based and engineered to be deployable in interactive authentication. <span class="citation" id="citation--nistfips204--9">(<a href="#bib-nistfips204">5</a>)</span></li>
<li><strong>SLH-DSA</strong> (FIPS 205) is stateless hash-based and conservative, but its performance profile is fundamentally different. <span class="citation" id="citation--nistfips205--10">(<a href="#bib-nistfips205">6</a>)</span></li>
</ul>
<p>The paper’s claim is not theoretical: it is deployment-shaped.</p>
<blockquote>
<p>“Post-quantum migration in TLS 1.3 should not be understood as a flat substitution problem … [it] depends on where it appears in the certification hierarchy … and how cryptographic burden is distributed across client and server roles.” <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--11">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></p>
</blockquote>
<p>That is the right framing. TLS is not “a signature benchmark”; it is an authenticated key-establishment protocol with roles, state, and adversaries.</p>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>TLS 1.3 full handshakes with certificate-based server authentication. <span class="citation" id="citation--rfc8446--12">(<a href="#bib-rfc8446">2</a>)</span></li>
<li>X.509 certification hierarchies (root → intermediate → leaf). <span class="citation" id="citation--rfc5280--13">(<a href="#bib-rfc5280">3</a>)</span></li>
<li>Threat model includes <strong>adversarial handshakes</strong> (flooding, forced full handshakes, cache bypass). Availability is a security property.</li>
<li>I treat the paper’s lab measurements as a signal, not as a universal constant: implementation quality and hardware matter, but order-of-magnitude discontinuities are not noise.</li>
<li>Focus is on server-authentication (no mutual TLS), because that is where “internet scale” lives.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Re-proving TLS 1.3 security. This is about operational correctness under PQ parameter sets.</li>
<li>Modeling global internet pathologies (loss, reordering, congestion collapse). The paper’s lab is local; I’ll critique that explicitly.</li>
<li>Claiming “SLH-DSA is unusable”. The claim is narrower: <strong>SLH-DSA in the interactive leaf is operationally toxic for front-ends</strong> in the measured regimes.</li>
</ul>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<p>TLS security is not only confidentiality/authenticity. Under active adversaries, <strong>availability is a cryptographic boundary</strong> because authentication work is attacker-triggerable.</p>
<h3 id="s1--authentication-correctness" style="position:relative;"><a href="#s1--authentication-correctness" aria-label="s1  authentication correctness permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>S1 — Authentication correctness</h3>
<p>The server must prove possession of the private key corresponding to the presented leaf certificate during the handshake:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">)</mo><mo>∧</mo><msub><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi></mrow><msub><mi>A</mi><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi></mrow></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><msub><mi>σ</mi><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">V</mi></mrow></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\mathrm{Verify}(\mathrm{cert\_chain}) \wedge \mathrm{VerifySig}_{A_{\mathrm{leaf}}}(\mathrm{transcript}, \sigma_{\mathrm{CV}})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">cert_chain</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">VerifySig</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2342em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.07778em;">leaf</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">CV</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>A</mi><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi></mrow></msub></mrow><annotation encoding="application/x-tex">A_{\mathrm{leaf}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.07778em;">leaf</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> is the leaf signature algorithm and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>σ</mi><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">V</mi></mrow></msub></mrow><annotation encoding="application/x-tex">\sigma_{\mathrm{CV}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">CV</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> is the <code class="language-text">CertificateVerify</code> signature. <span class="citation" id="citation--rfc8446--14">(<a href="#bib-rfc8446">2</a>)</span></p>
<h3 id="s2--bounded-attacker-triggerable-work-dos-resilience-invariant" style="position:relative;"><a href="#s2--bounded-attacker-triggerable-work-dos-resilience-invariant" aria-label="s2  bounded attacker triggerable work dos resilience invariant permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>S2 — Bounded attacker-triggerable work (DoS-resilience invariant)</h3>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>C</mi><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">v</mi></mrow></msub></mrow><annotation encoding="application/x-tex">C_{\mathrm{srv}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">srv</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> be the server CPU time spent in cryptographic operations per full handshake. A front-end that must survive adversarial connection rates needs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mtext>handshakes </mtext><mi>h</mi><mo>:</mo><mtext>  </mtext><mtext>  </mtext><msub><mi>C</mi><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">v</mi></mrow></msub><mo stretchy="false">(</mo><mi>h</mi><mo stretchy="false">)</mo><mo>≤</mo><msub><mi>C</mi><mi>max</mi><mo>⁡</mo></msub></mrow><annotation encoding="application/x-tex">\forall \text{handshakes } h:\;\; C_{\mathrm{srv}}(h) \le C_{\max}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord text"><span class="mord">handshakes </span></span><span class="mord mathnormal">h</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">srv</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">h</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span></div>
<p>and the system-level stability constraint (multi-core queueing approximation):</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>ρ</mi><mo>≡</mo><mfrac><mrow><mi>λ</mi><mo>⋅</mo><mi mathvariant="double-struck">E</mi><mo stretchy="false">[</mo><msub><mi>C</mi><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">v</mi></mrow></msub><mo stretchy="false">]</mo></mrow><mi>k</mi></mfrac><mo>&#x3C;</mo><mn>1</mn><mo separator="true">,</mo></mrow><annotation encoding="application/x-tex">\rho \equiv \frac{\lambda \cdot \E[C_{\mathrm{srv}}]}{k} &#x3C; 1,</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6582em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">ρ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.113em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.427em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">λ</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">⋅</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mord mathbb">E</span><span class="mopen">[</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">srv</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">]</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">&#x3C;</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8389em;vertical-align:-0.1944em;"></span><span class="mord">1</span><span class="mpunct">,</span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>λ</mi></mrow><annotation encoding="application/x-tex">\lambda</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">λ</span></span></span></span></span> is handshake arrival rate and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span> is effective parallelism (cores dedicated to handshake crypto).</p>
<p>This is the invariant leaf-SLH breaks: it moves <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="double-struck">E</mi><mo stretchy="false">[</mo><msub><mi>C</mi><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">v</mi></mrow></msub><mo stretchy="false">]</mo></mrow><annotation encoding="application/x-tex">\E[C_{\mathrm{srv}}]</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathbb">E</span><span class="mopen">[</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">srv</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">]</span></span></span></span></span> from sub-millisecond to ~1.4 seconds in the paper’s measurements. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--15">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>Hot-path crypto budget:</strong> the signature algorithm used for <code>CertificateVerify</code> must keep server per-handshake CPU under a fixed bound; otherwise availability collapses under adversarial handshakes.</p>
</div>
<h3 id="s3--cryptographic-agility-without-silent-downgrade" style="position:relative;"><a href="#s3--cryptographic-agility-without-silent-downgrade" aria-label="s3  cryptographic agility without silent downgrade permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>S3 — Cryptographic agility without silent downgrade</h3>
<p>PQC migration in TLS is long-lived and mixed-mode. The negotiation must prevent “compatibility” from becoming a downgrade vector:</p>
<ul>
<li>explicit policy for acceptable signature algorithms,</li>
<li>telemetry that reveals negotiated algorithms,</li>
<li>rollback that preserves safety properties (no “enable PQ in prod” without escape hatch).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li><strong>CPU collapse at the leaf:</strong> server spends ~1400 ms signing/verifying per handshake; handshake rate collapses; queue grows; timeouts cascade. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--16">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>Client validation overload:</strong> upper-layer SLH increases client task-clock materially (validation-skewed regime); low-end clients and IIoT gateways regress first. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--17">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>Size-induced latency amplification:</strong> certificate chains grow; slow-start, fragmentation, retransmits, and handshake flighting add RTTs (the paper’s local setup underestimates this). <span class="citation" id="citation--rfc8879--18">(<a href="#bib-rfc8879">4</a>)</span></li>
<li><strong>Cache illusions:</strong> resumption hides cost only for honest traffic. An attacker can force full handshakes by rotating SNI, disabling tickets, or exploiting client diversity.</li>
<li><strong>Mixed deployment drift:</strong> partial rollouts and heterogeneous client capabilities force policy forks; “support both” becomes “accept the weakest under pressure”.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Handshake authentication is attacker-triggerable compute. If you put an expensive signer in the leaf, you have built a CPU amplification primitive into your perimeter.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li><strong>Per-handshake crypto time</strong> split by phase: chain validation vs <code class="language-text">CertificateVerify</code> signing/verification.</li>
<li><strong>Negotiated signature algorithm</strong> distribution (by SNI, region, client cohort).</li>
<li><strong>Handshake latency</strong> (p50/p95/p99) and <strong>timeout/retry rates</strong>.</li>
<li><strong>CPU saturation signatures</strong>: run-queue length, softirq pressure, context switch rate.</li>
<li><strong>Handshake queue depth</strong> at the load balancer / accept queue.</li>
<li><strong>Bytes per handshake</strong> and certificate chain lengths (especially with PQ chains).</li>
<li><strong>Resumption ratio</strong> vs full handshake ratio; alert on drops.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li><strong>Feature-flag placement policy:</strong> ability to move SLH-DSA out of the interactive leaf without redeploying the entire fleet.</li>
<li><strong>Dual chain strategy (operationally plausible):</strong> keep ML-DSA in the leaf and place SLH-DSA in upper trust layers (root/intermediate), matching the “bounded penalty” regime observed in the paper. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--19">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></li>
<li><strong>Client capability gating:</strong> enforce per-cohort policies; do not let “one legacy client” dictate global acceptance rules.</li>
<li><strong>Emergency mode:</strong> prefer classical leaf fallback only as a last resort (explicitly logged and time-boxed), because “availability now” often becomes “downgrade forever”.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Rollback has to be faster than the incident. If changing the leaf algorithm requires a CA ceremony and multi-day issuance, you do not have an operational rollback plan.</p>
</div>
<h2 id="the-mathematical-anatomy-of-the-problem" style="position:relative;"><a href="#the-mathematical-anatomy-of-the-problem" aria-label="the mathematical anatomy of the problem permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The Mathematical Anatomy of the Problem</h2>
<p>The paper’s core point can be expressed as a simple decomposition: <strong>not all certificate signatures are equal in the TLS protocol</strong>.</p>
<p>Let a chain be <code class="language-text">root → intermediate → leaf</code>.</p>
<p>During a TLS 1.3 full handshake, the client does:</p>
<ol>
<li>verify the certificate chain signatures (issuer algorithms),</li>
<li>verify the live handshake signature <code class="language-text">CertificateVerify</code> (leaf algorithm).</li>
</ol>
<p>The server does:</p>
<ol>
<li>generate the live <code class="language-text">CertificateVerify</code> signature (leaf algorithm).</li>
</ol>
<p>Abstract the per-handshake costs:</p>
<ul>
<li><code class="language-text">Sign(A)</code> = cost to sign using algorithm <code class="language-text">A</code></li>
<li><code class="language-text">Verify(A)</code> = cost to verify using algorithm <code class="language-text">A</code></li>
</ul>
<p>Then, ignoring key exchange and symmetric crypto:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>C</mi><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">v</mi></mrow></msub><mo>≈</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><msub><mi>A</mi><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi></mrow></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">C_{\mathrm{srv}} \approx \mathrm{Sign}(A_{\mathrm{leaf}})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.01389em;">srv</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Sign</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.07778em;">leaf</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span></div>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>C</mi><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi></mrow></msub><mo>≈</mo><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><msub><mi>A</mi><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi></mrow></msub><mo stretchy="false">)</mo><mo>+</mo><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><msub><mi>A</mi><mrow><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi></mrow></msub><mo stretchy="false">)</mo><mo>+</mo><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><msub><mi>A</mi><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">C_{\mathrm{cli}} \approx \mathrm{Verify}(A_{\mathrm{leaf}}) + \mathrm{Verify}(A_{\mathrm{int}}) + \mathrm{Verify}(A_{\mathrm{root}})</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.07153em;">C</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0715em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">cli</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight" style="margin-right:0.07778em;">leaf</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3175em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">int</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">A</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathrm mtight">root</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span></div>
<p>That is the placement lever. Putting SLH-DSA at the root or intermediate raises <code class="language-text">Verify(SLH)</code> costs on the client side. Putting SLH-DSA at the leaf raises <code class="language-text">Sign(SLH)</code> on the server side — and that hits your perimeter at scale.</p>
<h3 id="evidence-from-the-papers-strategy-matrix" style="position:relative;"><a href="#evidence-from-the-papers-strategy-matrix" aria-label="evidence from the papers strategy matrix permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence from the paper’s strategy matrix</h3>
<p>Under a common hybrid key-establishment baseline (x25519 + ML-KEM-768), the paper reports (Campaign B): <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--20">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></p>
<table>
<thead>
<tr>
<th>Scenario</th>
<th>Placement</th>
<th>Mean latency</th>
<th>Mean server task-clock</th>
<th>Bytes read</th>
</tr>
</thead>
<tbody>
<tr>
<td><code class="language-text">x25519mlkem768__ml_root__ml_int__ml_leaf</code></td>
<td>ML/ML/ML</td>
<td>0.809 ms</td>
<td>0.562 ms</td>
<td>16,008</td>
</tr>
<tr>
<td><code class="language-text">x25519mlkem768__slh_root__ml_int__ml_leaf</code></td>
<td>SLH/ML/ML</td>
<td>2.133 ms</td>
<td>0.667 ms</td>
<td>28,947</td>
</tr>
<tr>
<td><code class="language-text">x25519mlkem768__ml_root__ml_int__slh_leaf</code></td>
<td>ML/ML/SLH</td>
<td>1402.486 ms</td>
<td>1401.169 ms</td>
<td>27,015</td>
</tr>
</tbody>
</table>
<p>Two points matter operationally:</p>
<ol>
<li><strong>Upper-layer SLH increases latency without collapsing server CPU.</strong> That is a validation-skewed regime.</li>
<li><strong>Leaf SLH is a server-dominated regime.</strong> The system is not “a bit slower”; it is in a different stability class.</li>
</ol>
<h3 id="service-capacity-as-an-invariant" style="position:relative;"><a href="#service-capacity-as-an-invariant" aria-label="service capacity as an invariant permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Service capacity as an invariant</h3>
<p>If the mean server crypto time per full handshake is <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>S</mi></mrow><annotation encoding="application/x-tex">S</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span></span></span></span></span> seconds, a single core can sustain at most:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>μ</mi><mtext>core</mtext></msub><mo>≤</mo><mfrac><mn>1</mn><mi>S</mi></mfrac><mtext>  </mtext><mtext>handshakes/sec</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mu_{\text{core}} \le \frac{1}{S}\;\text{handshakes/sec}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8304em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal">μ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord mtight">core</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.0074em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.3214em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mord text"><span class="mord">handshakes/sec</span></span><span class="mord">.</span></span></span></span></span></div>
<p>With <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>S</mi><mo>≈</mo><mn>1.401</mn></mrow><annotation encoding="application/x-tex">S \approx 1.401</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.401</span></span></span></span></span> seconds (leaf-SLH server task-clock), that is <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>μ</mi><mtext>core</mtext></msub><mo>≈</mo><mn>0.71</mn></mrow><annotation encoding="application/x-tex">\mu_{\text{core}} \approx 0.71</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6776em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal">μ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord text mtight"><span class="mord mtight">core</span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">0.71</span></span></span></span></span> handshakes/sec. Even with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi><mo>=</mo><mn>32</mn></mrow><annotation encoding="application/x-tex">k=32</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">32</span></span></span></span></span> effective cores, you are in the tens of handshakes per second regime — below the baseline assumptions of modern TLS termination.</p>
<p>This is why the paper’s conclusion is correct: the collapse is not explained by chain size, but by <strong>where the expensive signer lives</strong>. <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--21">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span></p>
<h2 id="from-measurements-to-deployment-the-engineering-gap" style="position:relative;"><a href="#from-measurements-to-deployment-the-engineering-gap" aria-label="from measurements to deployment the engineering gap permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>From Measurements to Deployment: the engineering gap</h2>
<p>The paper is experimental, but the deployment implication is structural:</p>
<ul>
<li><code class="language-text">CertificateVerify</code> is a live signature over a transcript; you cannot precompute it.</li>
<li>resumption reduces exposure but does not eliminate attacker-triggerable full handshakes.</li>
<li>certificate compression reduces bytes, not signing cost. <span class="citation" id="citation--rfc8879--22">(<a href="#bib-rfc8879">4</a>)</span></li>
</ul>
<p>So the migration strategy must treat the certificate hierarchy as a design surface:</p>
<ul>
<li>keep a conservative (hash-based) algorithm in long-lived trust anchors,</li>
<li>keep a performant algorithm in the interactive leaf,</li>
<li>and plan for key agility with short-lived leaf certificates.</li>
</ul>
<h2 id="critique-what-the-paper-does-not-prove" style="position:relative;"><a href="#critique-what-the-paper-does-not-prove" aria-label="critique what the paper does not prove permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Critique (what the paper does not prove)</h2>
<ul>
<li><strong>Local lab ≠ internet.</strong> The paper’s results isolate compute effects, but the real internet will make PQ chain size penalties worse via RTT amplification. This strengthens (not weakens) the “don’t do leaf-SLH” conclusion for front-ends.</li>
<li><strong>Implementation quality matters.</strong> <code class="language-text">oqsprovider</code> and OpenSSL integration are moving targets. But the observed 10^3× gap is too large to dismiss as mere optimization debt. <span class="citation" id="citation--oqsprovider--23">(<a href="#bib-oqsprovider">7</a>)</span></li>
<li><strong>Client heterogeneity is under-modeled.</strong> Many clients are constrained (mobile, embedded, IIoT gateways). Validation-skewed regimes can still be unacceptable in those populations.</li>
<li><strong>Mutual TLS will magnify costs.</strong> If both sides sign, the placement problem becomes bilateral; you must reason about who signs online and under what rate limits.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://arxiv.org/abs/2604.06100" target="_blank" rel="nofollow noopener noreferrer">Signature Placement in Post-Quantum TLS Certificate Hierarchies (arXiv:2604.06100)</a> <span class="citation" id="citation--delgadojimenez2026pqtlsplacement--24">(<a href="#bib-delgadojimenez2026pqtlsplacement">1</a>)</span>
<ul>
<li><strong>Evidence:</strong> leaf-SLH produces ≈ 1733× latency and ≈ 2494× server CPU relative to an all-ML baseline, while bytes grow only ≈ 1.69×.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">TLS 1.3 (RFC 8446)</a> <span class="citation" id="citation--rfc8446--25">(<a href="#bib-rfc8446">2</a>)</span>
<ul>
<li><strong>Evidence:</strong> <code class="language-text">CertificateVerify</code> is a live signature over the handshake transcript, binding the leaf algorithm to the hot path.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5280" target="_blank" rel="nofollow noopener noreferrer">X.509 PKI Profile (RFC 5280)</a> <span class="citation" id="citation--rfc5280--26">(<a href="#bib-rfc5280">3</a>)</span>
<ul>
<li><strong>Evidence:</strong> certification hierarchies separate offline issuance from online authentication; that separation is the placement lever.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/pubs/fips/204/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 204 (ML-DSA)</a> <span class="citation" id="citation--nistfips204--27">(<a href="#bib-nistfips204">5</a>)</span>
<ul>
<li><strong>Evidence:</strong> ML-DSA is explicitly standardized for interactive deployments.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/pubs/fips/205/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 205 (SLH-DSA)</a> <span class="citation" id="citation--nistfips205--28">(<a href="#bib-nistfips205">6</a>)</span>
<ul>
<li><strong>Evidence:</strong> SLH-DSA is conservative but its performance profile requires careful placement.</li>
</ul>
</li>
<li><a href="https://github.com/open-quantum-safe/oqs-provider" target="_blank" rel="nofollow noopener noreferrer"><code class="language-text">oqs-provider</code></a> <span class="citation" id="citation--oqsprovider--29">(<a href="#bib-oqsprovider">7</a>)</span>
<ul>
<li><strong>Evidence:</strong> real PQ TLS experiments depend on provider quality and integration details, which are still evolving.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the cleanest “PQ root + fast leaf” strategy that preserves long-term trust while keeping hot-path CPU bounded?</li>
<li>Can we formalize a deployment constraint language: “these algorithms are allowed in offline issuance vs online authentication”?</li>
<li>How do we make downgrade resistance auditable at scale (per-cohort policy + telemetry + enforcement)?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Leaf algorithm chosen with an explicit per-handshake CPU budget.</li>
<li class="task-list-item"><input type="checkbox" disabled> Chain design separates offline issuance from online authentication costs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Certificate compression evaluated (bytes) but not used as a proxy for CPU. <span class="citation" id="citation--rfc8879--30">(<a href="#bib-rfc8879">4</a>)</span></li>
<li class="task-list-item"><input type="checkbox" disabled> Rate limiting and handshake queuing modeled under adversarial load.</li>
<li class="task-list-item"><input type="checkbox" disabled> Negotiated algorithms logged and monitored (per cohort / SNI).</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan does not require a multi-day CA ceremony.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--31">(<a href="#bib-rfc8446">2</a>)</span></li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5280" target="_blank" rel="nofollow noopener noreferrer">RFC 5280: X.509 PKI Profile</a> <span class="citation" id="citation--rfc5280--32">(<a href="#bib-rfc5280">3</a>)</span></li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8879" target="_blank" rel="nofollow noopener noreferrer">RFC 8879: TLS Certificate Compression</a> <span class="citation" id="citation--rfc8879--33">(<a href="#bib-rfc8879">4</a>)</span></li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST PQC Project</a> <span class="citation" id="citation--nistpqc--34">(<a href="#bib-nistpqc">8</a>)</span></li>
<li><a href="https://csrc.nist.gov/pubs/fips/204/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 204: ML-DSA</a> <span class="citation" id="citation--nistfips204--35">(<a href="#bib-nistfips204">5</a>)</span></li>
<li><a href="https://csrc.nist.gov/pubs/fips/205/final" target="_blank" rel="nofollow noopener noreferrer">FIPS 205: SLH-DSA</a> <span class="citation" id="citation--nistfips205--36">(<a href="#bib-nistfips205">6</a>)</span></li>
<li><a href="https://github.com/open-quantum-safe/oqs-provider" target="_blank" rel="nofollow noopener noreferrer">Open Quantum Safe: oqs-provider</a> <span class="citation" id="citation--oqsprovider--37">(<a href="#bib-oqsprovider">7</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-delgadojimenez2026pqtlsplacement">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Delgado Jiménez JL. Signature Placement in Post-Quantum TLS Certificate Hierarchies: An Experimental Study of ML-DSA and SLH-DSA in TLS 1.3 Authentication [Internet]. arXiv:2604.06100; 2026. Available from: https://arxiv.org/abs/2604.06100</div>
  </div>
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-rfc5280">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Cooper D, Santesson S, Farrell S, Boeyen S, Housley R, Polk T. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile [Internet]. RFC Editor; 2008. Report No.: 5280. Available from: https://www.rfc-editor.org/rfc/rfc5280</div>
  </div>
  <div class="csl-entry" id="bib-rfc8879">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Ghedini A, Muthukuru VK, Goessens R. TLS Certificate Compression [Internet]. RFC Editor; 2021. Report No.: 8879. Available from: https://www.rfc-editor.org/rfc/rfc8879</div>
  </div>
  <div class="csl-entry" id="bib-nistfips204">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/204/final</div>
  </div>
  <div class="csl-entry" id="bib-nistfips205">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) [Internet]. Web; 2024. Available from: https://csrc.nist.gov/pubs/fips/205/final</div>
  </div>
  <div class="csl-entry" id="bib-oqsprovider">
    <div class="csl-left-margin">7. </div><div class="csl-right-inline">Open Quantum Safe. Open Quantum Safe: oqs-provider [Internet]. Web; Available from: https://github.com/open-quantum-safe/oqs-provider</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">8. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="protocol-design"/>
        <category label="security-critical-infrastructure"/>
        <category label="devsecops"/>
        <category label="distributed-systems"/>
        <category label="TLS"/>
        <category label="PKI"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Stateful Signatures Are a Distributed Systems Problem: XMSS/LMS Without Index Reuse]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-04-stateful-signatures-xmss-lms-without-index-reuse</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-04-stateful-signatures-xmss-lms-without-index-reuse"/>
        <updated>2026-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Deep dive (April 2026): stateful hash-based signatures look like “just PQC”, but one index reuse is a catastrophic key-management failure. Model the invariant, then build the allocator like a consensus component.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Paper/spec-driven systems note. Theme: <strong>PQC that fails because of systems engineering, not math</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>Stateful hash-based signatures (XMSS, LMS/HSS) are attractive in post-quantum migrations because their security rests on hash functions and conservative assumptions. But they hide a non-negotiable constraint: <strong>each one-time signing key must be used at most once</strong>. In practice that means: <em>your signature scheme is only as strong as your crash-consistency and concurrency control</em>. If you cannot guarantee “no index reuse” under retries, rollbacks, snapshots, and partial deployment, you are not deploying PQC — you are deploying a latent signing-key compromise.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>For XMSS/LMS, correctness is an invariant on durable state.</strong> The cryptography is only the leaf function; the security boundary is the state machine that allocates and commits leaf indices.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li><strong>Index reuse is catastrophic, not “degraded security”.</strong> Treat it like key exfiltration.</li>
<li><strong>The signing counter is a replicated state machine.</strong> Build it with linearizability, not best-effort databases.</li>
<li><strong>Crash consistency beats cleverness.</strong> Burning indices is acceptable; reusing indices is not.</li>
<li><strong>Rollback attacks are real in cloud/edge fleets.</strong> Snapshots, restores, and imaging are an adversary primitive.</li>
<li><strong>Operational evidence is part of the scheme.</strong> If you can’t prove which indices were used, you can’t prove you’re still secure.</li>
</ul>
<h2 id="introduction-pragmatic-abstract-why-you-should-care-today" style="position:relative;"><a href="#introduction-pragmatic-abstract-why-you-should-care-today" aria-label="introduction pragmatic abstract why you should care today permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Introduction (pragmatic abstract: why you should care today)</h2>
<p>The supply-chain incident is not “someone broke SHA-256”. It’s usually one of:</p>
<ul>
<li>a compromised CI signer,</li>
<li>a leaked code-signing key,</li>
<li>a rollback to an old firmware image and a forged update chain,</li>
<li>or an operator restoring a “known good” backup that accidentally rewinds signing state.</li>
</ul>
<p>In PQC migration programs, stateful hash-based signatures are often proposed for the conservative path: they are standardized, their assumptions are narrow, and they are plausible even under aggressive quantum timelines. <span class="citation" id="citation--rfc8391--1">(<a href="#bib-rfc8391">1</a>)</span> <span class="citation" id="citation--rfc8554--2">(<a href="#bib-rfc8554">2</a>)</span> <span class="citation" id="citation--nistsp800208--3">(<a href="#bib-nistsp800208">3</a>)</span></p>
<p>But stateful signatures demand that you treat the signing key as a <em>protocol state</em>.</p>
<p>If you are signing firmware for IIoT devices, you’re signing into an adversarial lifecycle: devices get cloned, images get restored, regional partitions happen, and “just retry” becomes policy. That is exactly the environment where index reuse happens unless you engineer against it.</p>
<p>I’m writing this the way I operate in Chile: fewer slogans, more invariants. If the system can’t fail, you don’t “enable PQC” — you <strong>prove</strong> that your allocator cannot reuse a leaf index under the failure model you actually have.</p>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your signing state <em>exactly</em> (counter, tree id, subtree, key epoch)?</li>
<li>Is index allocation linearizable across all signers?</li>
<li>What happens if a signer crashes <strong>after</strong> producing a signature but <strong>before</strong> persisting state?</li>
<li>Can an attacker force a rollback of signing state (snapshot restore, disk imaging, DB restore)?</li>
<li>Do you have evidence (logs, receipts, transparency) that binds each signature to a unique index?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<p>I’ll be explicit because “implicit assumptions” become production incidents.</p>
<ul>
<li>Hash functions behave as modeled (preimage/second-preimage resistance).</li>
<li>Adversary can observe signatures and choose messages (EUF-CMA setting).</li>
<li>Operators can and will restore from backups; edge devices can and will be imaged.</li>
<li>Failures include process crashes, disk-full, partial writes, timeouts, and retries.</li>
<li>Some components may be malicious or compromised (CI worker, signing host), but <em>we still require</em> the non-reuse invariant to hold.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Designing a brand new signature scheme. Use standardized constructions. <span class="citation" id="citation--rfc8391--4">(<a href="#bib-rfc8391">1</a>)</span> <span class="citation" id="citation--rfc8554--5">(<a href="#bib-rfc8554">2</a>)</span> <span class="citation" id="citation--nistsp800208--6">(<a href="#bib-nistsp800208">3</a>)</span></li>
<li>Proving detailed cryptographic bounds here. I focus on the systems invariant the proofs depend on.</li>
<li>Solving global supply chain security. I’m isolating the signer state problem.</li>
</ul>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<p>This is what “secure deployment” means in operational terms.</p>
<h3 id="p1--unforgeability-euf-cma-in-the-intended-threat-model" style="position:relative;"><a href="#p1--unforgeability-euf-cma-in-the-intended-threat-model" aria-label="p1  unforgeability euf cma in the intended threat model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P1 — Unforgeability (EUF-CMA, in the intended threat model)</h3>
<p>An attacker who sees signatures <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>σ</mi><mn>1</mn></msub><mo separator="true">,</mo><mo>…</mo><mo separator="true">,</mo><msub><mi>σ</mi><mi>q</mi></msub></mrow><annotation encoding="application/x-tex">\sigma_1,\dots,\sigma_q</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7167em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03588em;">q</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span> for chosen messages should not be able to produce a valid signature <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>σ</mi><mo lspace="0em" rspace="0em">∗</mo></msup></mrow><annotation encoding="application/x-tex">\sigma^{*}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">∗</span></span></span></span></span></span></span></span></span></span></span></span></span> for a new message <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>m</mi><mo lspace="0em" rspace="0em">∗</mo></msup></mrow><annotation encoding="application/x-tex">m^{*}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6887em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6887em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">∗</span></span></span></span></span></span></span></span></span></span></span></span></span> with non-negligible probability.</p>
<h3 id="p2--no-index-reuse-deployment-invariant" style="position:relative;"><a href="#p2--no-index-reuse-deployment-invariant" aria-label="p2  no index reuse deployment invariant permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P2 — No index reuse (deployment invariant)</h3>
<p>For each keypair and each leaf index <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span>, at most one signature is ever produced using the one-time key at <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span>.</p>
<p>In words: <strong>the key is stateful</strong>. If you cannot enforce P2, P1 is not a meaningful claim.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>NoReuse:</strong> For a given signing key <code>kid</code>, every leaf index <code>i</code> is used at most once, across all replicas, across all time, including after crash recovery and restores.</p>
</div>
<h3 id="p3--rollback-resistance-or-rollback-detection" style="position:relative;"><a href="#p3--rollback-resistance-or-rollback-detection" aria-label="p3  rollback resistance or rollback detection permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>P3 — Rollback resistance (or rollback detection)</h3>
<p>You must prevent or detect state rollback that could cause index reuse. “Detect” is acceptable only if your response is “treat as compromise; rotate; revoke”.</p>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<p>These are the places where teams get hurt: not on paper, but in production.</p>
<ul>
<li><strong>Concurrent signers racing on the same counter</strong> (eventual-consistency DB, stale caches).</li>
<li><strong>Crash after signing but before committing state</strong> → the system “forgets” it used an index.</li>
<li><strong>Backup restore / snapshot rollback</strong> rewinds the counter.</li>
<li><strong>Partial deployment</strong> where old/new versions interpret state differently (range reservation, burn semantics).</li>
<li><strong>Sharded state without coordination</strong> (two regions allocate overlapping index ranges).</li>
<li><strong>Opaque evidence</strong>: you cannot answer “which indices were used?” during incident response.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>“We store the counter in Postgres” is not a design. The question is: <strong>what isolation level, what recovery semantics, what rollback story, what evidence?</strong></p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<p>Operability is part of correctness for stateful signatures: you need signals that correspond to proof obligations.</p>
<ul>
<li><strong>Current index / remaining capacity</strong> (per key id, per subtree).</li>
<li><strong>Signature rate vs index burn rate</strong> (burn spikes indicate retries/crashes).</li>
<li><strong>Allocator linearizability signals</strong>: leader changes, term changes, commit lag (if Raft/Paxos).</li>
<li><strong>Duplicate detection</strong>: any reuse event must page immediately (treat as key compromise).</li>
<li><strong>State durability health</strong>: fsync latency, WAL lag, disk-full events, snapshot restore events.</li>
<li><strong>Fleet drift</strong>: which signer version and which state schema is active.</li>
</ul>
<h2 id="the-mathematical-anatomy-of-the-problem" style="position:relative;"><a href="#the-mathematical-anatomy-of-the-problem" aria-label="the mathematical anatomy of the problem permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The Mathematical Anatomy of the Problem</h2>
<p>Stateful signatures are not hard because Merkle trees are hard. They are hard because <strong>one-time signatures are not “one-time-ish”</strong>.</p>
<p>I’ll use the XMSS/LMS family (Merkle tree over OTS keys) because that’s the shared shape. <span class="citation" id="citation--rfc8391--7">(<a href="#bib-rfc8391">1</a>)</span> <span class="citation" id="citation--rfc8554--8">(<a href="#bib-rfc8554">2</a>)</span></p>
<h3 id="merkle-signatures-in-one-page" style="position:relative;"><a href="#merkle-signatures-in-one-page" aria-label="merkle signatures in one page permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Merkle signatures in one page</h3>
<p>You have:</p>
<ul>
<li>A Merkle tree of height <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>h</mi></mrow><annotation encoding="application/x-tex">h</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">h</span></span></span></span></span> with <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mn>2</mn><mi>h</mi></msup></mrow><annotation encoding="application/x-tex">2^h</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8491em;"></span><span class="mord"><span class="mord">2</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8491em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">h</span></span></span></span></span></span></span></span></span></span></span></span> leaves.</li>
<li>Each leaf <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span> commits to a one-time public key <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mi>i</mi></msub></mrow><annotation encoding="application/x-tex">\mathrm{pk}_i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">pk</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2175em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span></span></span></span></span>.</li>
<li>The global public key is the Merkle root <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><annotation encoding="application/x-tex">\mathrm{root}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">root</span></span></span></span></span></span>.</li>
</ul>
<p>A signature on message <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>m</mi></mrow><annotation encoding="application/x-tex">m</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">m</span></span></span></span></span> at index <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span> contains:</p>
<ol>
<li>an OTS signature <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>σ</mi><mi>i</mi></msub></mrow><annotation encoding="application/x-tex">\sigma_i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> proving knowledge of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mi>i</mi></msub></mrow><annotation encoding="application/x-tex">\mathrm{sk}_i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">sk</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> for message <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>m</mi></mrow><annotation encoding="application/x-tex">m</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">m</span></span></span></span></span>,</li>
<li>an authentication path <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>π</mi><mi>i</mi></msub></mrow><annotation encoding="application/x-tex">\pi_i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.5806em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span> proving that <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mi>i</mi></msub></mrow><annotation encoding="application/x-tex">\mathrm{pk}_i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">pk</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2175em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span></span></span></span></span> is in the tree under <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><annotation encoding="application/x-tex">\mathrm{root}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">root</span></span></span></span></span></span>.</li>
</ol>
<p>Verification is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mi>m</mi><mo separator="true">,</mo><mi>i</mi><mo separator="true">,</mo><msub><mi>σ</mi><mi>i</mi></msub><mo separator="true">,</mo><msub><mi>π</mi><mi>i</mi></msub><mo stretchy="false">)</mo><mo>=</mo><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">O</mi><mi mathvariant="normal">T</mi><mi mathvariant="normal">S</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mi>i</mi></msub><mo separator="true">,</mo><mi>m</mi><mo separator="true">,</mo><msub><mi>σ</mi><mi>i</mi></msub><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">M</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><msub><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mi>i</mi></msub><mo separator="true">,</mo><mi>i</mi><mo separator="true">,</mo><msub><mi>π</mi><mi>i</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Verify}(\mathrm{root}, m, i, \sigma_i, \pi_i) =
\mathrm{VerifyOTS}(\mathrm{pk}_i, m, \sigma_i) \wedge
\mathrm{VerifyMerkle}(\mathrm{root}, \mathrm{pk}_i, i, \pi_i).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Verify</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">root</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">i</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">VerifyOTS</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">pk</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2175em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">m</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">VerifyMerkle</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">root</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">pk</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2175em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">i</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>The only secret that changes across signatures is the <em>choice of leaf index</em>.</p>
<h3 id="why-one-time-is-an-invariant-not-a-suggestion" style="position:relative;"><a href="#why-one-time-is-an-invariant-not-a-suggestion" aria-label="why one time is an invariant not a suggestion permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why “one-time” is an invariant, not a suggestion</h3>
<p>In WOTS+/LM-OTS-style constructions, the signature leaks structured information about the secret key. The security proof assumes you leak that structure <strong>once</strong>. Twice is a different game.</p>
<p>Here’s the minimal intuition using a Winternitz-like chain view (XMSS uses WOTS+): <span class="citation" id="citation--rfc8391--9">(<a href="#bib-rfc8391">1</a>)</span></p>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>F</mi></mrow><annotation encoding="application/x-tex">F</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">F</span></span></span></span></span> be a one-way function (modeled as a hash). For each chain position <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>j</mi><mo>∈</mo><mo stretchy="false">{</mo><mn>1</mn><mo separator="true">,</mo><mo>…</mo><mo separator="true">,</mo><mi mathvariant="normal">ℓ</mi><mo stretchy="false">}</mo></mrow><annotation encoding="application/x-tex">j \in \{1,\dots,\ell\}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.854em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05724em;">j</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">1</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">ℓ</span><span class="mclose">}</span></span></span></span></span>:</p>
<ul>
<li>secret seed: <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>x</mi><mi>j</mi></msub></mrow><annotation encoding="application/x-tex">x_j</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7167em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span></span></span></span></span></li>
<li>public value: <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>y</mi><mi>j</mi></msub><mo>=</mo><msup><mi>F</mi><mi>w</mi></msup><mo stretchy="false">(</mo><msub><mi>x</mi><mi>j</mi></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">y_j = F^{w}(x_j)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7167em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">y</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">F</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.6644em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.02691em;">w</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span> for some chain length <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>w</mi></mrow><annotation encoding="application/x-tex">w</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span></span></span></span></span></li>
</ul>
<p>For a message <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>m</mi></mrow><annotation encoding="application/x-tex">m</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">m</span></span></span></span></span>, you compute a base-<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>w</mi></mrow><annotation encoding="application/x-tex">w</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span></span></span></span></span> representation that yields digits <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>a</mi><mi>j</mi></msub><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">{</mo><mn>0</mn><mo separator="true">,</mo><mo>…</mo><mo separator="true">,</mo><mi>w</mi><mo stretchy="false">}</mo></mrow><annotation encoding="application/x-tex">a_j(m) \in \{0,\dots,w\}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">a</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">{</span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="minner">…</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mclose">}</span></span></span></span></span>.</p>
<p>The signature reveals:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>s</mi><mi>j</mi></msub><mo>=</mo><msup><mi>F</mi><mrow><msub><mi>a</mi><mi>j</mi></msub><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo></mrow></msup><mo stretchy="false">(</mo><msub><mi>x</mi><mi>j</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s_j = F^{a_j(m)}(x_j).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7167em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.2241em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">F</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">a</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3281em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2819em;"><span></span></span></span></span></span></span><span class="mopen mtight">(</span><span class="mord mathnormal mtight">m</span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>If the same one-time key is used twice for messages <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>m</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>m</mi><mn>2</mn></msub></mrow><annotation encoding="application/x-tex">m_1, m_2</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">m</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span>, the attacker learns:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msup><mi>F</mi><mrow><msub><mi>a</mi><mi>j</mi></msub><mo stretchy="false">(</mo><msub><mi>m</mi><mn>1</mn></msub><mo stretchy="false">)</mo></mrow></msup><mo stretchy="false">(</mo><msub><mi>x</mi><mi>j</mi></msub><mo stretchy="false">)</mo><mo separator="true">,</mo><mspace width="1em"></mspace><msup><mi>F</mi><mrow><msub><mi>a</mi><mi>j</mi></msub><mo stretchy="false">(</mo><msub><mi>m</mi><mn>2</mn></msub><mo stretchy="false">)</mo></mrow></msup><mo stretchy="false">(</mo><msub><mi>x</mi><mi>j</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">F^{a_j(m_1)}(x_j),\quad F^{a_j(m_2)}(x_j).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.2241em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">F</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">a</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3281em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2819em;"><span></span></span></span></span></span></span><span class="mopen mtight">(</span><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">F</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight">a</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3281em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2819em;"><span></span></span></span></span></span></span><span class="mopen mtight">(</span><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span><span class="mclose mtight">)</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Since hashing forward is easy, the attacker can compute:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msup><mi>F</mi><mrow><mi>max</mi><mo>⁡</mo><mo stretchy="false">(</mo><msub><mi>a</mi><mi>j</mi></msub><mo stretchy="false">(</mo><msub><mi>m</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo separator="true">,</mo><msub><mi>a</mi><mi>j</mi></msub><mo stretchy="false">(</mo><msub><mi>m</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo stretchy="false">)</mo></mrow></msup><mo stretchy="false">(</mo><msub><mi>x</mi><mi>j</mi></msub><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">F^{\max(a_j(m_1), a_j(m_2))}(x_j)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.2241em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">F</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.938em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mop mtight"><span class="mtight">m</span><span class="mtight">a</span><span class="mtight">x</span></span><span class="mopen mtight">(</span><span class="mord mtight"><span class="mord mathnormal mtight">a</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3281em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2819em;"><span></span></span></span></span></span></span><span class="mopen mtight">(</span><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span><span class="mclose mtight">)</span><span class="mpunct mtight">,</span><span class="mord mtight"><span class="mord mathnormal mtight">a</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3281em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2819em;"><span></span></span></span></span></span></span><span class="mopen mtight">(</span><span class="mord mtight"><span class="mord mathnormal mtight">m</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span><span class="mclose mtight">))</span></span></span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">x</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.05724em;">j</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mclose">)</span></span></span></span></span></div>
<p>for every chain <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>j</mi></mrow><annotation encoding="application/x-tex">j</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.854em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.05724em;">j</span></span></span></span></span> by hashing forward from the smaller revealed value to the larger. With enough reuse and chosen messages, this becomes a practical forging path.</p>
<p>You do not need to memorize the exact attack to engineer correctly. You need to internalize the operational conclusion:</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>For XMSS/LMS, a single index reuse is a “stop the world” event. Rotate keys, revoke certificates, and treat all artifacts since the last known-good index as suspect.</p>
</div>
<h3 id="the-invariant-as-a-formal-predicate" style="position:relative;"><a href="#the-invariant-as-a-formal-predicate" aria-label="the invariant as a formal predicate permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The invariant as a formal predicate</h3>
<p>Model the signer as a state machine with durable state:</p>
<ul>
<li><code class="language-text">next : Nat</code> (the next unused index)</li>
<li><code class="language-text">used : SUBSET Nat</code> (or, more realistically, an append-only log)</li>
</ul>
<p>The deployment invariant is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">N</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">R</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">e</mi></mrow><mo>≡</mo><mi mathvariant="normal">∀</mi><mi>i</mi><mi mathvariant="normal">.</mi><mtext>  </mtext><mi>i</mi><mo>∈</mo><mrow><mi mathvariant="normal">u</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi></mrow><mo>⇒</mo><mi>i</mi><mo>&#x3C;</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">t</mi></mrow><mtext>  </mtext><mtext>  </mtext><mo>∧</mo><mtext>  </mtext><mtext>  </mtext><mrow><mi mathvariant="normal">u</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi></mrow><mtext> is monotone</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{NoReuse} \equiv \forall i.\; i \in \mathrm{used} \Rightarrow i &#x3C; \mathrm{next}\;\;\wedge\;\;
\mathrm{used}\ \text{is monotone}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">NoReuse</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mord">.</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm">used</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6986em;vertical-align:-0.0391em;"></span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">&#x3C;</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">next</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm">used</span></span><span class="mspace"> </span><span class="mord text"><span class="mord">is monotone</span></span><span class="mord">.</span></span></span></span></span></div>
<p>In TLA+-style pseudocode:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">VARIABLES next, used

Init ==
  /\ next = 0
  /\ used = {}

Reserve ==
  /\ LET i == next IN
     /\ next' = next + 1
     /\ used' = used \cup {i}

Inv_NoReuse ==
  /\ used \subseteq 0..(next-1)
  /\ used' \supseteq used</code></pre></div>
<p>This looks trivial until you map it onto real failures:</p>
<ul>
<li><code class="language-text">Reserve</code> must be linearizable across signers.</li>
<li><code class="language-text">used</code> must be durable across crashes.</li>
<li>state must not roll back.</li>
</ul>
<p>That is where systems engineering starts.</p>
<h2 id="from-proofs-to-binaries-the-implementation-challenge" style="position:relative;"><a href="#from-proofs-to-binaries-the-implementation-challenge" aria-label="from proofs to binaries the implementation challenge permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>From Proofs to Binaries: The Implementation Challenge</h2>
<p>Formal models talk about “steps”. Your deployment talks about:</p>
<ul>
<li>scheduler jitter,</li>
<li>fsync latency,</li>
<li>retries under timeouts,</li>
<li>backups and restores,</li>
<li>region-level partitions,</li>
<li>and adversaries who turn those into weapons.</li>
</ul>
<h3 id="1-concurrency-allocation-must-be-linearizable" style="position:relative;"><a href="#1-concurrency-allocation-must-be-linearizable" aria-label="1 concurrency allocation must be linearizable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1) Concurrency: allocation must be linearizable</h3>
<p>If you have more than one signing worker, you need a single source of truth for <code class="language-text">next</code>.</p>
<p>Correct solutions:</p>
<ul>
<li>a dedicated allocator replicated with Raft/Paxos (linearizable log) <span class="citation" id="citation--ongaro2014raft--10">(<a href="#bib-ongaro2014raft">4</a>)</span>,</li>
<li>an HSM with an internal monotonic counter (if it exists and is trustworthy),</li>
<li>a single leader signer with strict fencing + durable WAL.</li>
</ul>
<p>Incorrect solutions (common in the wild):</p>
<ul>
<li>eventually consistent caches,</li>
<li>“best effort” database updates without serializable semantics,</li>
<li>“allocate ranges per region” without a global coordination story.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Index reuse is not only a bug. It is an adversary primitive: force retries + partitions + restores until your allocator violates linearizability.</p>
</div>
<h3 id="2-crash-consistency-durability-must-happen-before-you-return-success" style="position:relative;"><a href="#2-crash-consistency-durability-must-happen-before-you-return-success" aria-label="2 crash consistency durability must happen before you return success permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2) Crash consistency: durability must happen before you return success</h3>
<p>The hardest bug is:</p>
<ol>
<li>signer produces signature <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>σ</mi></mrow><annotation encoding="application/x-tex">\sigma</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.03588em;">σ</span></span></span></span></span> for index <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span>,</li>
<li>process crashes before persisting “i was used”,</li>
<li>on restart, the signer reuses <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span>.</li>
</ol>
<p>The safe pattern is intentionally boring:</p>
<ul>
<li><strong>Reserve</strong> index <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span> by appending to durable log and fsync.</li>
<li><strong>Sign</strong> message using <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>i</mi></mrow><annotation encoding="application/x-tex">i</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6595em;"></span><span class="mord mathnormal">i</span></span></span></span></span>.</li>
<li><strong>Record</strong> signature receipt (message hash, artifact id, timestamp, index) for evidence.</li>
<li>If signing fails mid-flight, <strong>burn</strong> the index anyway.</li>
</ul>
<p>Burning indices reduces capacity. Reusing an index destroys security.</p>
<h3 id="3-rollback-attacks-snapshots-are-an-adversary-tool" style="position:relative;"><a href="#3-rollback-attacks-snapshots-are-an-adversary-tool" aria-label="3 rollback attacks snapshots are an adversary tool permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3) Rollback attacks: snapshots are an adversary tool</h3>
<p>If your signing state lives on disk and you restore an old snapshot, your counter goes backwards. That is equivalent to index reuse.</p>
<p>Mitigations, in increasing order of strength:</p>
<ul>
<li><strong>Detect rollbacks</strong>: remote transparency log of <code class="language-text">(kid, index, artifact-hash)</code>; alert on non-monotone indices.</li>
<li><strong>Prevent rollbacks</strong>: store the counter in tamper-resistant hardware (TPM monotonic counters, HSM state) — with skepticism about vendor semantics.</li>
<li><strong>Make rollback irrelevant</strong>: run the allocator as a replicated state machine with quorum persistence; do not restore it from point-in-time backups without a protocol.</li>
</ul>
<h3 id="4-refinement-mapping-keep-the-spec-to-code-bridge-explicit" style="position:relative;"><a href="#4-refinement-mapping-keep-the-spec-to-code-bridge-explicit" aria-label="4 refinement mapping keep the spec to code bridge explicit permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4) Refinement mapping: keep the spec-to-code bridge explicit</h3>
<p>The formal model’s state is <code class="language-text">(next, used)</code>. The implementation’s state becomes:</p>
<ul>
<li>a WAL segment with committed reservations,</li>
<li>an allocator term/leader epoch,</li>
<li>a signer’s local reservation lease,</li>
<li>and a set of receipts that can be audited.</li>
</ul>
<p>Write the refinement mapping down:</p>
<ul>
<li><code class="language-text">next</code> ↔ last committed reservation in the allocator log.</li>
<li><code class="language-text">used</code> ↔ committed reservation set (or ranges) + receipts.</li>
</ul>
<p>If you can’t express that mapping, you can’t convincingly argue you implemented the invariant.</p>
<h3 id="implementation-sketch-rust" style="position:relative;"><a href="#implementation-sketch-rust" aria-label="implementation sketch rust permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation sketch (Rust)</h3>
<p>Treat index allocation as an interface with explicit failure semantics:</p>
<div class="gatsby-code-title">index_allocator.rs</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">Reservation</span> <span class="token punctuation">{</span>
    <span class="token keyword">pub</span> key_id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span>
    <span class="token keyword">pub</span> start<span class="token punctuation">:</span> <span class="token keyword">u64</span><span class="token punctuation">,</span>
    <span class="token keyword">pub</span> len<span class="token punctuation">:</span> <span class="token keyword">u32</span><span class="token punctuation">,</span>
    <span class="token keyword">pub</span> epoch<span class="token punctuation">:</span> <span class="token keyword">u64</span><span class="token punctuation">,</span> <span class="token comment">// fencing token</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">IndexAllocator</span> <span class="token punctuation">{</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">reserve</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">,</span> key_id<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">str</span><span class="token punctuation">,</span> len<span class="token punctuation">:</span> <span class="token keyword">u32</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token class-name">Reservation</span><span class="token punctuation">,</span> <span class="token class-name">AllocError</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">commit_receipt</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">,</span> receipt<span class="token punctuation">:</span> <span class="token class-name">Receipt</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token class-name">AllocError</span><span class="token operator">></span><span class="token punctuation">;</span>
<span class="token punctuation">}</span></code></pre></div>
<p>The invariants the implementation must preserve are not “Rust safety” invariants. They are protocol invariants:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">{ Linearizable(next) * DurableLog(kid) }
reserve(kid, len)
{ Disjoint(reservation, prior) ∧ Monotone(next) }</code></pre></div>
<p>If you cannot test linearizability under adversarial schedules, you are guessing. Use deterministic concurrency testing where possible (e.g., Loom for the local state machine) and fault-injection for the allocator boundary.</p>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<p>This is incident response, not wishful thinking. If you don’t rehearse it, you don’t have it.</p>
<ul>
<li><strong>Trigger:</strong> any evidence of index reuse, rollback, or allocator split-brain.</li>
<li><strong>Immediate action:</strong> stop signing; quarantine signing workers; preserve disks/logs for forensics.</li>
<li><strong>Containment:</strong> rotate signing key; revoke code-signing certificate; publish incident notice if artifacts shipped.</li>
<li><strong>Recovery:</strong> re-issue artifacts signed under new key; enforce monotonic counter storage or RSM allocator before resuming.</li>
<li><strong>Postmortem:</strong> add a forced test that reproduces the failure (snapshot restore + retry storm + crash at worst point).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8554" target="_blank" rel="nofollow noopener noreferrer">RFC 8554: LMS/HSS</a> <span class="citation" id="citation--rfc8554--11">(<a href="#bib-rfc8554">2</a>)</span>
<ul>
<li><strong>Evidence (spec constraint):</strong> “An LM-OTS private key MUST NOT be used to sign more than one message.”</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8391" target="_blank" rel="nofollow noopener noreferrer">RFC 8391: XMSS</a> <span class="citation" id="citation--rfc8391--12">(<a href="#bib-rfc8391">1</a>)</span>
<ul>
<li><strong>Evidence (deployment reality):</strong> the security story explicitly assumes one-time use of WOTS+ keys.</li>
</ul>
</li>
<li><a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-208.pdf" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-208</a> <span class="citation" id="citation--nistsp800208--13">(<a href="#bib-nistsp800208">3</a>)</span>
<ul>
<li><strong>Evidence (operationalization):</strong> stateful signature schemes require secure state management; rollback is a first-class hazard.</li>
</ul>
</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">Raft</a> <span class="citation" id="citation--ongaro2014raft--14">(<a href="#bib-ongaro2014raft">4</a>)</span>
<ul>
<li><strong>Evidence (engineering pattern):</strong> linearizable replicated logs are the standard way to enforce “exactly-once allocation” under failures.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your hard boundary: “prevent rollback” or “detect rollback and rotate”?</li>
<li>Can you justify a single-region allocator for your threat model, or do you need cross-region quorum?</li>
<li>What is your evidence story: can you prove non-reuse to an auditor after an incident?</li>
<li>If the allocator is compromised, what are your containment mechanisms (fencing, transparency, revocation)?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> <code class="language-text">NoReuse</code> invariant is written as code + tests, not a wiki sentence.</li>
<li class="task-list-item"><input type="checkbox" disabled> Allocation is linearizable across signers (not “usually correct”).</li>
<li class="task-list-item"><input type="checkbox" disabled> Reservations are durable before success is returned (fsync/WAL semantics).</li>
<li class="task-list-item"><input type="checkbox" disabled> Snapshot/backup restore cannot rewind state without detection/rotation.</li>
<li class="task-list-item"><input type="checkbox" disabled> Duplicate detection pages immediately and blocks signing.</li>
<li class="task-list-item"><input type="checkbox" disabled> Key rotation + certificate revocation playbook is rehearsed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8391" target="_blank" rel="nofollow noopener noreferrer">RFC 8391: XMSS</a> — The XMSS standard; read it with an “index reuse” lens. <span class="citation" id="citation--rfc8391--15">(<a href="#bib-rfc8391">1</a>)</span></li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8554" target="_blank" rel="nofollow noopener noreferrer">RFC 8554: LMS/HSS</a> — LMS/HSS standard and constraints. <span class="citation" id="citation--rfc8554--16">(<a href="#bib-rfc8554">2</a>)</span></li>
<li><a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-208.pdf" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-208</a> — NIST’s recommendation for LMS/XMSS deployments. <span class="citation" id="citation--nistsp800208--17">(<a href="#bib-nistsp800208">3</a>)</span></li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">HKDF (RFC 5869)</a> — Useful when binding receipts and deriving per-artifact keys from signing state. <span class="citation" id="citation--rfc5869--18">(<a href="#bib-rfc5869">5</a>)</span></li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — If you operate distributed allocators, you need adversarial testing discipline. <span class="citation" id="citation--jepsen--19">(<a href="#bib-jepsen">6</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8391">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Huelsing A, Butin D, Gazdag S, Rijneveld J, Mohaisen A. XMSS: eXtended Merkle Signature Scheme [Internet]. RFC Editor; 2018. Report No.: 8391. Available from: https://www.rfc-editor.org/rfc/rfc8391</div>
  </div>
  <div class="csl-entry" id="bib-rfc8554">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">McGrew D, Curcio M, Fluhrer S. Leighton-Micali Hash-Based Signatures [Internet]. RFC Editor; 2019. Report No.: 8554. Available from: https://www.rfc-editor.org/rfc/rfc8554</div>
  </div>
  <div class="csl-entry" id="bib-nistsp800208">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Cooper DA, Apon DC, Dang QH, Davidson MS, Dworkin MJ, Miller CA. Recommendation for Stateful Hash-Based Signature Schemes [Internet]. 2020. Report No.: 800–208. Available from: https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-208.pdf</div>
  </div>
  <div class="csl-entry" id="bib-ongaro2014raft">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Ongaro D, Ousterhout J. In Search of an Understandable Consensus Algorithm (Raft). In: 2014 USENIX Annual Technical Conference (USENIX ATC 14) [Internet]. 2014. Available from: https://raft.github.io/raft.pdf</div>
  </div>
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">6. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="devsecops"/>
        <category label="iiot-platforms"/>
        <category label="distributed-systems"/>
        <category label="formal-methods"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Termination Is a Security Boundary: HotStuff Under UC, Delay Attacks, and the Uncomfortable Gap to Rust]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-03-hotstuff-termination-uc-delay-attacks</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-03-hotstuff-termination-uc-delay-attacks"/>
        <updated>2026-03-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Paper note (March 2026): a UC-style termination proof for HotStuff, the real invariant it relies on, and what changes when you ship it as a low-level Rust system under adversarial latency.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Paper-driven research note. Theme: <strong>Termination proofs for industrial BFT</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>In critical infrastructure, “consensus safety” is table stakes. The incident is almost never “two conflicting commits”; the incident is <strong>the protocol that stops making progress</strong> while operators stare at dashboards and timeouts that look “reasonable” on paper. This post dissects a recent UC-flavored termination proof for HotStuff and turns it into engineering constraints you can actually ship — in Rust, under adversarial latency, with cryptography whose parameters are not free.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p><strong>Termination is an interface contract.</strong> If you cannot bound “time-to-finality under attack” as a function of network + compute, you do not have a reliable protocol — you have a hope with a quorum.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li><strong>Liveness is where production fails.</strong> Partial synchrony + bad timeout discipline yields “correct” protocols that don’t terminate.</li>
<li><strong>The invariant is not “3-chain commits”.</strong> The invariant you actually ride is a monotone lock/highQC discipline that constrains future votes.</li>
<li><strong>Exponential backoff is not a UX tweak.</strong> It is a <strong>liveness proof technique</strong> against delay attacks, but it changes your operational envelope.</li>
<li><strong>UC proofs are not deployment proofs.</strong> They abstract away CPU, queues, scheduler jitter, and memory pressure — the things that dominate IIoT and real fleets.</li>
<li><strong>Cryptographic parameters affect termination.</strong> If signature verification time becomes part of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span>, your liveness bound moves. Post-quantum migration makes this painfully explicit.</li>
</ul>
<h2 id="introduction-pragmatic-abstract-why-you-should-care-today" style="position:relative;"><a href="#introduction-pragmatic-abstract-why-you-should-care-today" aria-label="introduction pragmatic abstract why you should care today permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Introduction (Pragmatic abstract: why you should care today)</h2>
<p>It’s 03:17 in Santiago. A consortium chain is “healthy” in the sense that nodes are alive, disks are fine, and TLS handshakes still work. But finality stalls. The pager doesn’t ask whether the protocol is Byzantine-safe. It asks a simpler question:</p>
<blockquote>
<p>“Can you commit within a bounded time under adversarial latency?”</p>
</blockquote>
<p>This is not academic. Any system that uses BFT consensus as an availability primitive — identity registries, payment rails, device authorization, industrial telemetry notarization — eventually meets the same failure mode: <strong>network delay attacks</strong> and correlated jitter that keep honest replicas oscillating in view changes.</p>
<p>The paper I’m using as the anchor is:</p>
<ul>
<li>“On the Termination of the HotStuff Protocol Within the Universally Composable Framework” (IACR ePrint 2025/1560). <span class="citation" id="citation--zeng2025hotstuffuc--1">(<a href="#bib-zeng2025hotstuffuc">1</a>)</span></li>
</ul>
<p>Their claim is specific and valuable: build a UC-style formal system for HotStuff in a partially synchronous network and prove <strong>termination</strong> (progress) even under delay attacks using <strong>phased time analysis</strong> and <strong>exponential backoff</strong>. This matters because HotStuff has become the default “industrial BFT shape” precisely due to its linear view change and pipelining. <span class="citation" id="citation--yin2019hotstuff--2">(<a href="#bib-yin2019hotstuff">2</a>)</span></p>
<p>But “valuable” is not “sufficient”. We need to translate the proof into constraints that survive:</p>
<ul>
<li>lossy networks,</li>
<li>asymmetric compute (heterogeneous nodes),</li>
<li>real cryptography (and post-quantum parameter sets),</li>
<li>real Rust concurrency,</li>
<li>and adversaries who attack queues, timeouts, and operators.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Delay attacks don’t need to break signatures. They break <em>coordination</em>: by keeping timeouts too small and views too unstable, they turn “safety” into “permanent limbo”.</p>
</div>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<p>I’m explicit here because “unstated assumptions” are where correctness dies in production.</p>
<ul>
<li><strong>Partial synchrony</strong>: there exists a Global Stabilization Time (GST) after which message delays are bounded by <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> (unknown a priori). <span class="citation" id="citation--dls1988partialsynchrony--3">(<a href="#bib-dls1988partialsynchrony">3</a>)</span></li>
<li><strong>Fault model</strong>: <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>n</mi><mo>=</mo><mn>3</mn><mi>f</mi><mo>+</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">n=3f+1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">n</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">3</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> replicas, up to <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>f</mi></mrow><annotation encoding="application/x-tex">f</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span></span></span></span></span> Byzantine; quorum size <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>2</mn><mi>f</mi><mo>+</mo><mn>1</mn></mrow><annotation encoding="application/x-tex">2f+1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span>.</li>
<li><strong>Cryptography</strong>: signatures are unforgeable; adversary cannot forge QC proofs without corrupting quorum. (UC frameworks typically idealize this; see critique later.) <span class="citation" id="citation--canetti2001uc--4">(<a href="#bib-canetti2001uc">4</a>)</span></li>
<li><strong>Clocks/timeouts</strong>: replicas can measure timeouts locally with bounded drift; timeout expiration is reliable enough to be a protocol input.</li>
<li><strong>Scheduler fairness (weak)</strong>: a replica that is “ready to act” is eventually scheduled (no permanent CPU starvation).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving performance. Termination is about <strong>eventual progress</strong> and bounds; throughput is a different beast.</li>
<li>Modeling the full cryptographic stack (TLS, KMS, enclaves). We treat those as deployment layers with their own threat models.</li>
<li>Solving adversarial network routing. We handle delay/jitter within the partial synchrony envelope — not BGP-level warfare.</li>
</ul>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<p>I separate “consensus safety” from “termination” because conflating them is how teams ship protocol code that passes tests and fails reality.</p>
<h3 id="safety-agreement--consistency" style="position:relative;"><a href="#safety-agreement--consistency" aria-label="safety agreement  consistency permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Safety (agreement / consistency)</h3>
<p>Informally: no two honest replicas commit conflicting blocks.</p>
<p>Formally, for committed blocks <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>b</mi></mrow><annotation encoding="application/x-tex">b</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal">b</span></span></span></span></span> and <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msup><mi>b</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup></mrow><annotation encoding="application/x-tex">b'</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7519em;"></span><span class="mord"><span class="mord mathnormal">b</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.7519em;"><span style="top:-3.063em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span></span></span></span></span> at the same height:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">□</mi><mo fence="false" stretchy="true" minsize="1.8em" maxsize="1.8em">(</mo><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi></mrow><mo stretchy="false">(</mo><mi>b</mi><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi></mrow><mo stretchy="false">(</mo><msup><mi>b</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo stretchy="false">)</mo><mo>⇒</mo><mi>b</mi><mo>⪯</mo><msup><mi>b</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo>∨</mo><msup><mi>b</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msup><mo>⪯</mo><mi>b</mi><mo fence="false" stretchy="true" minsize="1.8em" maxsize="1.8em">)</mo></mrow><annotation encoding="application/x-tex">\Box\Big(\mathrm{Committed}(b)\wedge \mathrm{Committed}(b') \Rightarrow b \preceq b' \vee b' \preceq b\Big)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord amsrm">□</span><span class="mord"><span class="delimsizing size2">(</span></span><span class="mord"><span class="mord mathrm">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">b</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0519em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Committed</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">b</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8304em;vertical-align:-0.136em;"></span><span class="mord mathnormal">b</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8019em;"></span><span class="mord"><span class="mord mathnormal">b</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.9379em;vertical-align:-0.136em;"></span><span class="mord"><span class="mord mathnormal">b</span><span class="msupsub"><span class="vlist-t"><span class="vlist-r"><span class="vlist" style="height:0.8019em;"><span style="top:-3.113em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord mathnormal">b</span><span class="mord"><span class="delimsizing size2">)</span></span></span></span></span></span></div>
<p>where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>⪯</mo></mrow><annotation encoding="application/x-tex">\preceq</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.7719em;vertical-align:-0.136em;"></span><span class="mrel">⪯</span></span></span></span></span> is the ancestor relation in the block tree (chain prefix).</p>
<h3 id="liveness--termination" style="position:relative;"><a href="#liveness--termination" aria-label="liveness  termination permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Liveness / termination</h3>
<p>We want: after GST, honest replicas commit within bounded time.</p>
<p>In a partial synchrony model, the best you can do is: <strong>there exists a bound</strong> <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>T</mi><mo stretchy="false">(</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mtext>compute</mtext><mo separator="true">,</mo><mi>f</mi><mo separator="true">,</mo><mi>n</mi><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">T(\Delta, \text{compute}, f, n)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mopen">(</span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">compute</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">n</span><span class="mclose">)</span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi mathvariant="normal">◊</mi><mrow><mo>≤</mo><mi>T</mi></mrow></msub><mtext>  </mtext><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi></mrow><mo stretchy="false">(</mo><mo>⋅</mo><mo stretchy="false">)</mo></mrow><annotation encoding="application/x-tex">\Diamond_{\le T}\;\mathrm{Committed}(\cdot)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord amsrm">◊</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mrel mtight">≤</span><span class="mord mathnormal mtight" style="margin-right:0.13889em;">T</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2452em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mord"><span class="mord mathrm">Committed</span></span><span class="mopen">(</span><span class="mord">⋅</span><span class="mclose">)</span></span></span></span></span></div>
<p>In UC terms: you define an ideal functionality that “decides” (terminates) and then prove the real protocol <strong>UC-realizes</strong> it, meaning no environment can distinguish real execution from ideal execution (up to negligible probability) while preserving the termination guarantee. <span class="citation" id="citation--canetti2001uc--5">(<a href="#bib-canetti2001uc">4</a>)</span> <span class="citation" id="citation--zeng2025hotstuffuc--6">(<a href="#bib-zeng2025hotstuffuc">1</a>)</span></p>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<p>If you’ve operated these systems, none of these are hypothetical.</p>
<ul>
<li><strong>Timeout thrashing</strong>: views advance faster than information propagates; no leader gathers a QC.</li>
<li><strong>Compute-induced delay</strong>: signature verification and state execution inflate the effective <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span>; timeouts are tuned for “network”, but the bottleneck is CPU.</li>
<li><strong>Queue collapse</strong>: inbound gossip queues saturate; critical messages get delayed behind garbage (or behind retransmits).</li>
<li><strong>Partial rollout</strong>: mixed versions interpret timeout rules differently → liveness regression without safety violation.</li>
<li><strong>“Safe but stuck” by design</strong>: lock rules prevent voting for anything that would make progress under certain leader schedules.</li>
<li><strong>Backoff runaway</strong>: exponential backoff restores liveness but pushes time-to-finality into operationally unacceptable territory during sustained jitter.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>If you tune timeouts using “median RTT”, you are tuning for the world where nobody is trying to break you. The liveness proof needs <strong>worst-case</strong> envelopes after GST.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<p>If you can’t observe the proof obligations, you can’t operate the system.</p>
<ul>
<li><strong>View-change rate</strong> and distribution (p50/p99). Spikes are the first symptom of a delay attack.</li>
<li><strong>Leader success probability</strong> per epoch: fraction of views producing a QC/commit.</li>
<li><strong>QC propagation lag</strong>: time from QC formation to the last honest replica updating <code class="language-text">highQC</code>.</li>
<li><strong>Timeout growth curve</strong>: backoff state per replica; divergence indicates split-brain on liveness inputs.</li>
<li><strong>Signature verification latency</strong> (and batch sizes): crypto cost is part of <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> in practice.</li>
<li><strong>Queue depth / drop rate</strong> on consensus channels (propose/vote/new-view): liveness dies in queues.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<p>If termination is part of your SLO, rollback is part of the protocol story.</p>
<ul>
<li><strong>Feature-flag backoff policy</strong>: ability to revert timeout/backoff changes without redeploying binaries.</li>
<li><strong>Safe-mode</strong>: temporarily disable pipelining (reduce concurrency) to stabilize liveness during incident response.</li>
<li><strong>Config rollback</strong>: deterministic config snapshot + config hash in logs to prevent “unknown timeout drift”.</li>
<li><strong>Protocol downgrade gate</strong>: only allow rollback between epoch boundaries to avoid mixed rules within a view.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Carry liveness parameters as signed config artifacts. When the chain stalls, you need evidence of what timeout schedule each node is actually running.</p>
</div>
<h2 id="the-mathematical-anatomy-of-the-problem" style="position:relative;"><a href="#the-mathematical-anatomy-of-the-problem" aria-label="the mathematical anatomy of the problem permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The Mathematical Anatomy of the Problem</h2>
<p>HotStuff’s safety intuition is familiar: vote only for safe extensions of what you know; commit when you have a certified chain. The subtlety is termination: after GST, you need the protocol to stop spinning.</p>
<p>To talk precisely, we need a minimal state model.</p>
<h3 id="state-and-events" style="position:relative;"><a href="#state-and-events" aria-label="state and events permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>State and events</h3>
<p>Let:</p>
<ul>
<li><code class="language-text">view ∈ Nat</code> be the current view number.</li>
<li><code class="language-text">leader(view)</code> be the designated leader.</li>
<li><code class="language-text">highQC</code> be the highest known quorum certificate (QC) by view number.</li>
<li><code class="language-text">lockedQC</code> be the QC that constrains votes (“lock”).</li>
<li><code class="language-text">timeout(view)</code> be the local timeout budget for the current view.</li>
<li><code class="language-text">Blocks</code> be a tree with parent pointers; each block has <code class="language-text">(parent, view, payload, qc?)</code>.</li>
</ul>
<p>Events:</p>
<ul>
<li><code class="language-text">Propose(b)</code> by leader.</li>
<li><code class="language-text">Vote(b)</code> by replicas.</li>
<li><code class="language-text">NewView(view, highQC)</code> messages.</li>
<li><code class="language-text">Timeout(view)</code> local expiration.</li>
</ul>
<p>In TLA+ style, the transition system is:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">VARIABLES view, highQC, lockedQC, blocks, decided, timeout

Init ==
  /\ view = 0
  /\ decided = FALSE
  /\ highQC = GenesisQC
  /\ lockedQC = GenesisQC
  /\ blocks = {Genesis}
  /\ timeout = T0

Next ==
  \/ ProposeStep
  \/ VoteStep
  \/ QCStep
  \/ CommitStep
  \/ TimeoutStep
  \/ NewViewStep</code></pre></div>
<p>This is intentionally incomplete — the point is to isolate the core proof obligations.</p>
<h3 id="the-invariant-that-actually-matters-monotone-lock-discipline" style="position:relative;"><a href="#the-invariant-that-actually-matters-monotone-lock-discipline" aria-label="the invariant that actually matters monotone lock discipline permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The invariant that actually matters: monotone lock discipline</h3>
<p>HotStuff safety is usually explained via “3-chain commit” (a block is committed when it has a chain of descendants with QCs). But safety is <em>enforced</em> by a more operational invariant: honest replicas do not vote in ways that can later create conflicting commits.</p>
<p>One useful invariant (informal but precise enough to mechanize) is:</p>
<blockquote>
<p><strong>Lock invariant</strong>: An honest replica votes only for blocks that extend its <code class="language-text">lockedQC</code> (or a QC with view ≥ the lock), and <code class="language-text">lockedQC.view</code> is monotone non-decreasing.</p>
</blockquote>
<p>Formally:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mrow><mi>l</mi><mi>o</mi><mi>c</mi><mi>k</mi></mrow></msub><mo>≡</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>∈</mo><mi>H</mi><mo>:</mo><mtext>  </mtext><mtext>  </mtext><msub><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">Q</mi><mi mathvariant="normal">C</mi></mrow><mi>r</mi></msub><mi mathvariant="normal">.</mi><mi>v</mi><mi>i</mi><mi>e</mi><mi>w</mi><mo>≤</mo><msub><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">h</mi><mi mathvariant="normal">Q</mi><mi mathvariant="normal">C</mi></mrow><mi>r</mi></msub><mi mathvariant="normal">.</mi><mi>v</mi><mi>i</mi><mi>e</mi><mi>w</mi><mtext>  </mtext><mo>∧</mo><mtext>  </mtext><mi mathvariant="normal">□</mi><mo fence="false" stretchy="true" minsize="1.2em" maxsize="1.2em">(</mo><msubsup><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">Q</mi><mi mathvariant="normal">C</mi></mrow><mi>r</mi><mo mathvariant="normal" lspace="0em" rspace="0em">′</mo></msubsup><mi mathvariant="normal">.</mi><mi>v</mi><mi>i</mi><mi>e</mi><mi>w</mi><mo>≥</mo><msub><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">Q</mi><mi mathvariant="normal">C</mi></mrow><mi>r</mi></msub><mi mathvariant="normal">.</mi><mi>v</mi><mi>i</mi><mi>e</mi><mi>w</mi><mo fence="false" stretchy="true" minsize="1.2em" maxsize="1.2em">)</mo></mrow><annotation encoding="application/x-tex">\mathrm{Inv}_{lock} \equiv \forall r\in H:\;\; \mathrm{lockedQC}_r.view \le \mathrm{highQC}_r.view
\;\wedge\;
\Box\big(\mathrm{lockedQC}'_r.view \ge \mathrm{lockedQC}_r.view\big)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.01968em;">l</span><span class="mord mathnormal mtight">oc</span><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7335em;vertical-align:-0.0391em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">lockedQC</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">i</span><span class="mord mathnormal">e</span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9386em;vertical-align:-0.2441em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">highQC</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">i</span><span class="mord mathnormal">e</span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.2em;vertical-align:-0.35em;"></span><span class="mord amsrm">□</span><span class="mord"><span class="delimsizing size1">(</span></span><span class="mord"><span class="mord"><span class="mord mathrm">lockedQC</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.8362em;"><span style="top:-2.453em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span><span style="top:-3.1473em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">′</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.247em;"><span></span></span></span></span></span></span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">i</span><span class="mord mathnormal">e</span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.2em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">lockedQC</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">i</span><span class="mord mathnormal">e</span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mord"><span class="delimsizing size1">)</span></span></span></span></span></span></div>
<p>and vote safety:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">□</mi><mo fence="false" stretchy="true" minsize="1.8em" maxsize="1.8em">(</mo><msub><mrow><mi mathvariant="normal">V</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi></mrow><mi>r</mi></msub><mo stretchy="false">(</mo><mi>b</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>b</mi><mo separator="true">,</mo><msub><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">Q</mi><mi mathvariant="normal">C</mi></mrow><mi>r</mi></msub><mo stretchy="false">)</mo><mtext> </mtext><mo>∨</mo><mtext> </mtext><mi>b</mi><mi mathvariant="normal">.</mi><mi>q</mi><mi>c</mi><mi mathvariant="normal">.</mi><mi>v</mi><mi>i</mi><mi>e</mi><mi>w</mi><mo>≥</mo><msub><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">Q</mi><mi mathvariant="normal">C</mi></mrow><mi>r</mi></msub><mi mathvariant="normal">.</mi><mi>v</mi><mi>i</mi><mi>e</mi><mi>w</mi><mo fence="false" stretchy="true" minsize="1.8em" maxsize="1.8em">)</mo></mrow><annotation encoding="application/x-tex">\Box\Big(\mathrm{Vote}_r(b)\Rightarrow \mathrm{Extends}(b,\mathrm{lockedQC}_r)\ \vee\ b.qc.view \ge \mathrm{lockedQC}_r.view\Big)</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord amsrm">□</span><span class="mord"><span class="delimsizing size2">(</span></span><span class="mord"><span class="mord"><span class="mord mathrm">Vote</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord mathnormal">b</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Extends</span></span><span class="mopen">(</span><span class="mord mathnormal">b</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">lockedQC</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">b</span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">q</span><span class="mord mathnormal">c</span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">i</span><span class="mord mathnormal">e</span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.8em;vertical-align:-0.65em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">lockedQC</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mord">.</span><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="mord mathnormal">i</span><span class="mord mathnormal">e</span><span class="mord mathnormal" style="margin-right:0.02691em;">w</span><span class="mord"><span class="delimsizing size2">)</span></span></span></span></span></span></div>
<p>where <code class="language-text">Extends(b, qc)</code> means <code class="language-text">b</code> is in the subtree rooted at the block certified by <code class="language-text">qc</code>.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p><strong>Monotone locks + safe-vote rule</strong> are the core safety rail. Everything else (pipelining, leader rotation) has to respect this or the proof collapses.</p>
</div>
<h3 id="termination-why-delay-attacks-break-naive-liveness" style="position:relative;"><a href="#termination-why-delay-attacks-break-naive-liveness" aria-label="termination why delay attacks break naive liveness permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Termination: why delay attacks break naive liveness</h3>
<p>Under partial synchrony, termination proofs typically take this shape:</p>
<ol>
<li>After GST, message delay ≤ <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span>.</li>
<li>If the protocol ever enters a “stable” view whose timeout ≥ <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">k\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mord">Δ</span></span></span></span></span> (for some constant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span>), the leader can complete a round: propose → collect votes → form QC → advance.</li>
<li>Therefore, show that the protocol will <em>eventually</em> reach such a stable view.</li>
</ol>
<p>Delay attacks break step (3) by ensuring timeouts stay too small: replicas time out before QCs propagate, triggering perpetual view changes.</p>
<p>The paper’s core move is to treat timeout selection not as configuration but as a <strong>proof object</strong>: a phased time analysis with exponential backoff so that, after enough failed phases, some honest views have timeout large enough to dominate <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> and finish. <span class="citation" id="citation--zeng2025hotstuffuc--7">(<a href="#bib-zeng2025hotstuffuc">1</a>)</span></p>
<h3 id="a-backoff-lemma-the-engineering-version" style="position:relative;"><a href="#a-backoff-lemma-the-engineering-version" aria-label="a backoff lemma the engineering version permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>A backoff lemma (the engineering version)</h3>
<p>Assume the local timeout evolves as:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>T</mi><mrow><mi>i</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mn>2</mn><msub><mi>T</mi><mi>i</mi></msub><mspace width="1em"></mspace><mtext>on view-change due to timeout.</mtext></mrow><annotation encoding="application/x-tex">T_{i+1} = 2T_i \quad\text{on view-change due to timeout.}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8917em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">i</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">on view-change due to timeout.</span></span></span></span></span></span></div>
<p>Let <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>k</mi></mrow><annotation encoding="application/x-tex">k</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span></span></span></span></span> be the first phase where <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><msub><mi>T</mi><mi>k</mi></msub><mo>≥</mo><mi>c</mi><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">T_k \ge c\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal">c</span><span class="mord">Δ</span></span></span></span></span> (for a constant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span> that hides protocol steps and crypto verification latency). Then:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>k</mi><mo>=</mo><mrow><mo fence="true">⌈</mo><msub><mrow><mi>log</mi><mo>⁡</mo></mrow><mn>2</mn></msub><mfrac><mrow><mi>c</mi><mi mathvariant="normal">Δ</mi></mrow><msub><mi>T</mi><mn>0</mn></msub></mfrac><mo fence="true">⌉</mo></mrow></mrow><annotation encoding="application/x-tex">k = \left\lceil \log_2 \frac{c\Delta}{T_0} \right\rceil</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.4em;vertical-align:-0.95em;"></span><span class="minner"><span class="mopen delimcenter" style="top:0em;"><span class="delimsizing size3">⌈</span></span><span class="mop"><span class="mop">lo<span style="margin-right:0.01389em;">g</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.207em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.3603em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">0</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">c</span><span class="mord">Δ</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.836em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mclose delimcenter" style="top:0em;"><span class="delimsizing size3">⌉</span></span></span></span></span></span></span></div>
<p>and the total time spent until entering that phase is bounded by the geometric series:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><munderover><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>0</mn></mrow><mi>k</mi></munderover><msub><mi>T</mi><mi>i</mi></msub><mo>≤</mo><mn>2</mn><msub><mi>T</mi><mi>k</mi></msub><mo>≤</mo><mn>2</mn><mi>c</mi><mi mathvariant="normal">Δ</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\sum_{i=0}^{k} T_i \le 2T_k \le 2c\Delta.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:3.1138em;vertical-align:-1.2777em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.8361em;"><span style="top:-1.8723em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">i</span><span class="mrel mtight">=</span><span class="mord mtight">0</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span><span style="top:-4.3em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.2777em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3117em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord">2</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.1389em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">2</span><span class="mord mathnormal">c</span><span class="mord">Δ.</span></span></span></span></span></div>
<p>This is the skeleton behind “bounded termination under delay attacks”: backoff converts unknown <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> into a bounded search cost.</p>
<p>The uncomfortable part is hidden in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span>: in real code, <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span> is not “3” — it includes:</p>
<ul>
<li>signature verification budget,</li>
<li>message batching and queueing,</li>
<li>state execution time,</li>
<li>and scheduler jitter.</li>
</ul>
<p>If your implementation inflates <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span>, your termination bound inflates even if the proof is correct.</p>
<h3 id="uc-angle-refinement-mapping-not-just-an-invariant" style="position:relative;"><a href="#uc-angle-refinement-mapping-not-just-an-invariant" aria-label="uc angle refinement mapping not just an invariant permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>UC angle: refinement mapping, not just an invariant</h3>
<p>UC proofs are not “prove an invariant and you’re done”. You define an ideal functionality <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">F</mi></mrow><annotation encoding="application/x-tex">\mathcal{F}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.09931em;">F</span></span></span></span></span> that captures the desired behavior, then show the real protocol <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> emulates it in any environment.</p>
<p>The useful mental model for engineers is a refinement mapping:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>ρ</mi><mo>:</mo><msub><mi>S</mi><mi mathvariant="normal">Π</mi></msub><mo>→</mo><msub><mi>S</mi><mi mathvariant="script">F</mi></msub></mrow><annotation encoding="application/x-tex">\rho : S_{\Pi} \to S_{\mathcal{F}}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.625em;vertical-align:-0.1944em;"></span><span class="mord mathnormal">ρ</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight">Π</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">→</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathcal mtight" style="margin-right:0.09931em;">F</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span></span></span></span></span></div>
<p>mapping concrete protocol state (blocks, QCs, views, transcripts) into an abstract state (decided value, delivered-to-who).</p>
<p>An engineer-friendly mapping for HotStuff is:</p>
<ul>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ρ</mi><mo stretchy="false">(</mo><mi>s</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi><mrow><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">V</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">e</mi></mrow><mo>=</mo></mrow><annotation encoding="application/x-tex">\rho(s).\mathrm{decidedValue} =</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">ρ</span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mclose">)</span><span class="mord">.</span><span class="mord"><span class="mord mathrm">decidedValue</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span></span></span></span></span> payload of the first committed block,</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ρ</mi><mo stretchy="false">(</mo><mi>s</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi><mrow><mi mathvariant="normal">d</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">d</mi></mrow><mo stretchy="false">(</mo><mi>r</mi><mo stretchy="false">)</mo><mo>=</mo></mrow><annotation encoding="application/x-tex">\rho(s).\mathrm{delivered}(r) =</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">ρ</span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mclose">)</span><span class="mord">.</span><span class="mord"><span class="mord mathrm">delivered</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span></span></span></span></span> whether replica <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>r</mi></mrow><annotation encoding="application/x-tex">r</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span></span></span></span></span> has observed commit proof,</li>
<li><span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>ρ</mi><mo stretchy="false">(</mo><mi>s</mi><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">e</mi></mrow><mo>=</mo></mrow><annotation encoding="application/x-tex">\rho(s).\mathrm{time} =</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal">ρ</span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mclose">)</span><span class="mord">.</span><span class="mord"><span class="mord mathrm">time</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span></span></span></span></span> logical time since GST (or since some start).</li>
</ul>
<p>Then you prove:</p>
<ol>
<li><strong>Safety refinement</strong>: concrete commits map to a single decided value in <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">F</mi></mrow><annotation encoding="application/x-tex">\mathcal{F}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.09931em;">F</span></span></span></span></span>.</li>
<li><strong>Liveness refinement</strong>: if <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="script">F</mi></mrow><annotation encoding="application/x-tex">\mathcal{F}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathcal" style="margin-right:0.09931em;">F</span></span></span></span></span> terminates within bound <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>T</mi></mrow><annotation encoding="application/x-tex">T</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span></span></span></span></span>, so does <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Π</mi></mrow><annotation encoding="application/x-tex">\Pi</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Π</span></span></span></span></span> (under assumptions).</li>
</ol>
<p>The paper frames this through UC indistinguishability; the refinement mapping is the bridge engineers can actually use to align spec ↔ code. <span class="citation" id="citation--canetti2001uc--8">(<a href="#bib-canetti2001uc">4</a>)</span> <span class="citation" id="citation--zeng2025hotstuffuc--9">(<a href="#bib-zeng2025hotstuffuc">1</a>)</span></p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">RefinementSafety ==
  /\ decided => \E v : Ideal.decidedValue = Payload(CommittedBlock)

RefinementLiveness ==
  /\ AfterGST => &#x3C;>_&#x3C;=T decided</code></pre></div>
<p>No, this is not a complete proof. It is the scaffold you need before you drown in details.</p>
<h2 id="from-proofs-to-binaries-the-implementation-challenge" style="position:relative;"><a href="#from-proofs-to-binaries-the-implementation-challenge" aria-label="from proofs to binaries the implementation challenge permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>From Proofs to Binaries: The Implementation Challenge</h2>
<p>Formal models talk about messages, not memory. They talk about “steps”, not cache misses. They talk about “timeouts”, not <code class="language-text">tokio::time::sleep()</code> under load.</p>
<p>This is where high-assurance work lives: the gap.</p>
<h3 id="1-concurrency-and-determinism-dont-let-the-runtime-invent-new-behaviors" style="position:relative;"><a href="#1-concurrency-and-determinism-dont-let-the-runtime-invent-new-behaviors" aria-label="1 concurrency and determinism dont let the runtime invent new behaviors permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1) Concurrency and determinism: don’t let the runtime invent new behaviors</h3>
<p>If your replica is implemented as a set of concurrent tasks (network IO, timer, consensus state machine), your correctness story depends on <em>how events interleave</em>.</p>
<p>In Rust, “memory safe” is not “protocol correct”. You need an explicit concurrency model:</p>
<ul>
<li>single-threaded event loop per replica (deterministic state transitions), or</li>
<li>carefully designed shared state with a proof story.</li>
</ul>
<p>In separation logic terms, you want to preserve ownership and invariants across event handlers:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">{ Tree(blocks) * LockState(highQC, lockedQC) * Timer(view, timeout) }
handle(event)
{ Tree(blocks') * LockState(highQC', lockedQC') * Timer(view', timeout')  ∧ Inv_lock }</code></pre></div>
<p>The practical trick: <strong>make the protocol state single-owner</strong>. Use channels to serialize transitions; treat networking and timers as producers of events, not mutators of state.</p>
<h3 id="2-delta-includes-crypto-post-quantum-parameters-move-your-liveness-bound" style="position:relative;"><a href="#2-delta-includes-crypto-post-quantum-parameters-move-your-liveness-bound" aria-label="2 delta includes crypto post quantum parameters move your liveness bound permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2) “<span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> includes crypto”: post-quantum parameters move your liveness bound</h3>
<p>HotStuff deployments often rely on threshold signatures (e.g., BLS) to compress votes/QCs. In UC proofs, signatures are ideal: verification is a constant-time oracle.</p>
<p>In reality:</p>
<ul>
<li>verification time is measurable,</li>
<li>batching has limits,</li>
<li>and post-quantum migration changes everything: signature sizes, verification cost, and message amplification.</li>
</ul>
<p>This is not a side note. It changes the effective <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> and the constant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span> in your termination bound.</p>
<p>Rule of thumb: treat “crypto verification latency p99” as part of your synchrony envelope.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>For liveness, set timeouts against <strong>p99(network + queue + crypto verify)</strong>, not p50 RTT. Then prove that backoff reaches that envelope after GST.</p>
</div>
<p>If you plan to swap classical primitives for post-quantum candidates (e.g., Dilithium/Falcon in signatures, Kyber in key exchange), your operational question becomes:</p>
<blockquote>
<p>“Do we still terminate under the same fault and delay assumptions once signature verification dominates the critical path?”</p>
</blockquote>
<p>The proof can survive if you re-parameterize <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>c</mi></mrow><annotation encoding="application/x-tex">c</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord mathnormal">c</span></span></span></span></span> — but your SLO might not.</p>
<h3 id="3-memory-pressure-and-bounded-state-liveness-dies-when-you-oom" style="position:relative;"><a href="#3-memory-pressure-and-bounded-state-liveness-dies-when-you-oom" aria-label="3 memory pressure and bounded state liveness dies when you oom permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3) Memory pressure and bounded state: liveness dies when you OOM</h3>
<p>Formal consensus models rarely encode memory bounds. Real nodes do.</p>
<p>If an attacker can force you to retain unbounded blocks or QCs, termination becomes irrelevant: the process dies. Your implementation must include:</p>
<ul>
<li>bounded block tree (pruning rules),</li>
<li>bounded message queues,</li>
<li>and explicit backpressure.</li>
</ul>
<p>If you cannot express pruning in the spec, at least express it as an invariant in the code and test it under adversarial schedules.</p>
<h3 id="4-instrumentation-as-proof-preservation" style="position:relative;"><a href="#4-instrumentation-as-proof-preservation" aria-label="4 instrumentation as proof preservation permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4) Instrumentation as proof preservation</h3>
<p>UC proofs provide indistinguishability. Operators need evidence:</p>
<ul>
<li>“which lock was used to reject votes?”</li>
<li>“why did the replica time out?”</li>
<li>“which QC did we consider highQC?”</li>
</ul>
<p>Instrument these as structured logs tied to:</p>
<ul>
<li><code class="language-text">(view, leader, highQC.view, lockedQC.view, timeout_ms)</code></li>
<li>plus cryptographic verification timings.</li>
</ul>
<p>In my experience, the systems that survive incidents are the ones where you can reconstruct the protocol trace from partial evidence. That is “high assurance” in the real world.</p>
<h2 id="authority-critique-what-the-paper-proves-and-what-it-doesnt" style="position:relative;"><a href="#authority-critique-what-the-paper-proves-and-what-it-doesnt" aria-label="authority critique what the paper proves and what it doesnt permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Authority critique (what the paper proves, and what it doesn’t)</h2>
<p>I respect this work. A UC-style termination proof for HotStuff is not easy. But the boundary between “proof” and “system” is where professionals get hurt.</p>
<p>Limitations that matter if you build fleets:</p>
<ol>
<li><strong>UC idealizes resources.</strong> A polynomial-time adversary is not the same as an adversary who saturates your CPU with signature verification and forces queue collapse.</li>
<li><strong>Partial synchrony is a cliff.</strong> Backoff gives termination after GST, but real networks don’t announce GST. Mis-estimating <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> yields either liveness collapse (too small) or unacceptable latency (too large).</li>
<li><strong>Implementation complexity is externalized.</strong> The proof doesn’t cover memory bounds, pruning correctness, persistence, replay, upgrade choreography, or operator mistakes — but those are where real outages live.</li>
<li><strong>The proof target is a model, not your code.</strong> Without a disciplined refinement mapping and implementation invariants, you can “prove HotStuff terminates” and still ship a non-terminating Rust node.</li>
<li><strong>Industrial heterogeneity breaks constants.</strong> IIoT and edge deployments are not homogeneous servers. If half your fleet is slower, leader success probability changes and effective <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> changes.</li>
</ol>
<p>The lesson isn’t “ignore proofs”. The lesson is: <strong>treat proofs as specs for engineering guardrails</strong>, not as certificates of deployed behavior.</p>
<h2 id="the-future-of-high-assurance-engineering" style="position:relative;"><a href="#the-future-of-high-assurance-engineering" aria-label="the future of high assurance engineering permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The Future of High-Assurance Engineering</h2>
<p>High-assurance engineering is converging on a sober reality:</p>
<ul>
<li>Safety proofs are necessary.</li>
<li>Termination proofs are the part that saves you at 03:17.</li>
<li>And neither matters if you cannot carry the invariants through the implementation boundary.</li>
</ul>
<p>The next generation of systems that “cannot fail” will not be built by adding more diagrams. They’ll be built by:</p>
<ol>
<li>writing specs that include time, compute, and adversaries as first-class inputs,</li>
<li>enforcing invariants in code (types + single-owner state machines + explicit scheduling),</li>
<li>treating cryptographic parameters as part of liveness, not just security,</li>
<li>and operationalizing the proof (monitoring + rollback + evidence).</li>
</ol>
<p>If you’re building in Rust, the path is clear: make the protocol state explicit, make invalid states unrepresentable, and then prove a refinement mapping — even if it starts as a disciplined argument before it becomes a mechanized proof.</p>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li>The termination claim and backoff framing come from the HotStuff UC termination paper (IACR ePrint 2025/1560): <a href="https://eprint.iacr.org/2025/1560" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2025/1560</a>. <span class="citation" id="citation--zeng2025hotstuffuc--10">(<a href="#bib-zeng2025hotstuffuc">1</a>)</span></li>
<li>HotStuff’s pipelined structure and safety intuition are grounded in the original HotStuff paper: <a href="https://arxiv.org/abs/1803.05069" target="_blank" rel="nofollow noopener noreferrer">arxiv.org/abs/1803.05069</a>. <span class="citation" id="citation--yin2019hotstuff--11">(<a href="#bib-yin2019hotstuff">2</a>)</span></li>
<li>The partial synchrony model that makes termination provable (after GST) traces back to classic results: <a href="https://groups.csail.mit.edu/tds/papers/Lynch/jacm88.pdf" target="_blank" rel="nofollow noopener noreferrer">groups.csail.mit.edu/.../jacm88.pdf</a>. <span class="citation" id="citation--dls1988partialsynchrony--12">(<a href="#bib-dls1988partialsynchrony">3</a>)</span></li>
<li>UC’s “real vs ideal” paradigm: <a href="https://eprint.iacr.org/2000/067.pdf" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2000/067.pdf</a>. <span class="citation" id="citation--canetti2001uc--13">(<a href="#bib-canetti2001uc">4</a>)</span></li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul>
<li>Document GST/partial synchrony assumptions and define what <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">Δ</mi></mrow><annotation encoding="application/x-tex">\Delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord">Δ</span></span></span></span></span> includes (network + queues + crypto + scheduling).</li>
<li>Encode lock/highQC invariants explicitly; add assertions and telemetry for state transitions.</li>
<li>Implement exponential backoff as a protocol mechanism with config hashing and rollout gates.</li>
<li>Bound memory (block tree pruning, queue limits) and prove pruning doesn’t violate safety invariants.</li>
<li>Add monitors for view-change rate, leader success probability, QC propagation lag, and timeout divergence.</li>
<li>Make rollback safe (epoch boundaries, feature flags, deterministic config snapshots).</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li>Zeng et al., “On the Termination of the HotStuff Protocol Within the Universally Composable Framework” (IACR ePrint 2025/1560): <a href="https://eprint.iacr.org/2025/1560" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2025/1560</a>. <span class="citation" id="citation--zeng2025hotstuffuc--14">(<a href="#bib-zeng2025hotstuffuc">1</a>)</span></li>
<li>Yin et al., “HotStuff: BFT Consensus with Linearity and Responsiveness” (PODC 2019 / arXiv): <a href="https://arxiv.org/abs/1803.05069" target="_blank" rel="nofollow noopener noreferrer">arxiv.org/abs/1803.05069</a>. <span class="citation" id="citation--yin2019hotstuff--15">(<a href="#bib-yin2019hotstuff">2</a>)</span></li>
<li>Canetti, “Universally Composable Security: A New Paradigm for Cryptographic Protocols” (FOCS 2001; ePrint): <a href="https://eprint.iacr.org/2000/067.pdf" target="_blank" rel="nofollow noopener noreferrer">eprint.iacr.org/2000/067.pdf</a>. <span class="citation" id="citation--canetti2001uc--16">(<a href="#bib-canetti2001uc">4</a>)</span></li>
<li>Dwork, Lynch, Stockmeyer, “Consensus in the Presence of Partial Synchrony” (JACM 1988): <a href="https://groups.csail.mit.edu/tds/papers/Lynch/jacm88.pdf" target="_blank" rel="nofollow noopener noreferrer">groups.csail.mit.edu/.../jacm88.pdf</a>. <span class="citation" id="citation--dls1988partialsynchrony--17">(<a href="#bib-dls1988partialsynchrony">3</a>)</span></li>
<li>Learn TLA+ (practical workflow): <a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">learntla.com</a>. <span class="citation" id="citation--learntla--18">(<a href="#bib-learntla">5</a>)</span></li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-zeng2025hotstuffuc">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Zeng Y, Dong Z, Xu X. On the Termination of the HotStuff Protocol Within the Universally Composable Framework [Internet]. IACR Cryptology ePrint Archive, Report 2025/1560; 2025. Available from: https://eprint.iacr.org/2025/1560</div>
  </div>
  <div class="csl-entry" id="bib-yin2019hotstuff">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Yin M, Malkhi D, Reiter MK, Gueta GG, Abraham I. HotStuff: BFT Consensus with Linearity and Responsiveness. In: Proceedings of the 2019 ACM Symposium on Principles of Distributed Computing (PODC ’19) [Internet]. 2019. Available from: https://arxiv.org/abs/1803.05069</div>
  </div>
  <div class="csl-entry" id="bib-dls1988partialsynchrony">
    <div class="csl-left-margin">3. </div><div class="csl-right-inline">Dwork C, Lynch N, Stockmeyer L. Consensus in the Presence of Partial Synchrony. In: Journal of the ACM [Internet]. 1988. p. 288–323. Available from: https://groups.csail.mit.edu/tds/papers/Lynch/jacm88.pdf</div>
  </div>
  <div class="csl-entry" id="bib-canetti2001uc">
    <div class="csl-left-margin">4. </div><div class="csl-right-inline">Canetti R. Universally Composable Security: A New Paradigm for Cryptographic Protocols. In: 42nd IEEE Symposium on Foundations of Computer Science (FOCS 2001) [Internet]. 2001. Available from: https://eprint.iacr.org/2000/067.pdf</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">5. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="consensus"/>
        <category label="BFT"/>
        <category label="formal-methods"/>
        <category label="cryptography"/>
        <category label="Rust"/>
        <category label="security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secure Distributed Storage: Erasure Coding Under Adversaries]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-03-secure-distributed-storage-erasure-coding-under-adversaries</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-03-secure-distributed-storage-erasure-coding-under-adversaries"/>
        <updated>2026-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (March 2026): Secure Distributed Storage: Erasure Coding Under Adversaries.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Deep Systems Notes</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secure Distributed Storage: Erasure Coding Under Adversaries</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Operational behavior is part of correctness: rollout, rollback, and evidence.</li>
<li>Interfaces must carry assumptions: time, randomness, identity, and ordering.</li>
<li>Contracts need enforcement: tests, assertions, and monitoring—not documentation.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational behavior is part of correctness (rollouts, rollbacks, drift).</li>
<li>Resilience requires making failure modes explicit and bounded.</li>
<li>Mixed-version operation creates states you didn’t model.</li>
<li>Security becomes optional through configuration drift unless enforced.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What are your compositional failure modes (partial deploys, mixed versions)?</li>
<li>How do you prevent 'optional security' from appearing via config drift?</li>
<li>Which proofs are worth maintaining vs replacing with tests and monitoring?</li>
<li>What is the smallest integration test that can falsify your assumptions?</li>
<li>Which assumptions leak across boundaries (time, randomness, identity, ordering)?</li>
<li>Where does 'correctness' become an operational contract (SLOs, budgets, policy)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Observability is imperfect; you debug from partial evidence.</li>
<li>Upgrades are incremental; compatibility is a security boundary.</li>
<li>Integration happens under time pressure; defaults become de facto policy.</li>
<li>Components are built by different teams with different threat models.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on “tribal knowledge” to connect assumptions across layers.</li>
<li>Assuming proofs automatically survive composition.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Interface contracts are predicates:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>caller obeys </mtext><mi>P</mi><mo>⇒</mo><mtext>callee guarantees </mtext><mi>Q</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{caller obeys } P \Rightarrow \text{callee guarantees } Q.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">caller obeys </span></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">callee guarantees </span></span><span class="mord mathnormal">Q</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat config as code: version it, review it, and monitor drift.</p>
<p>Make assumptions executable: encode them as assertions, tests, and run-time checks.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  spec<span class="token text string">["Spec"]</span> <span class="token arrow operator">--></span> impl<span class="token text string">["Impl"]</span>
  impl <span class="token arrow operator">--></span> proofs<span class="token text string">["Proofs / Tests"]</span>
  proofs <span class="token arrow operator">--></span> ops<span class="token text string">["Ops"]</span>
  ops <span class="token arrow operator">--></span> incidents<span class="token text string">["Incidents"]</span>
  incidents <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat integration boundaries (FFI, services, queues) as formal interfaces.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Integration note: treat FFI/service boundaries as an API with invariants.</span>
<span class="token comment">// Encode invariants as types where possible, assertions otherwise.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>End-to-end property tests</strong> for the smallest meaningful workflow.</li>
<li><strong>Upgrade tests</strong> for mixed-version and rollback scenarios.</li>
<li><strong>Contract tests</strong> at boundaries with adversarial inputs and skew.</li>
<li><strong>Fault injection</strong> at seams (queues, caches, RPC) not only components.</li>
<li><strong>Invariant monitoring</strong> tied to incident response playbooks.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Use canaries for protocol and crypto changes; define rollback triggers.</li>
<li>Treat config drift as an incident: detect, alert, and remediate.</li>
<li>Maintain runbooks that reference invariants, not just symptoms.</li>
<li>Make security and correctness properties observable (metrics + alerts).</li>
<li>Store evidence: audit logs, config diffs, and deployment metadata.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which assumptions do you currently enforce only through convention?</li>
<li>Where can config silently weaken security properties today?</li>
<li>Which properties can be proven locally vs only tested end-to-end?</li>
<li>What boundary is most likely to be bypassed under incident pressure?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://web.mit.edu/Saltzer/www/publications/endtoend/endtoend.pdf" target="_blank" rel="nofollow noopener noreferrer">End-to-End Arguments in System Design</a> — A foundational argument about where to enforce correctness properties.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc1122" target="_blank" rel="nofollow noopener noreferrer">RFC 1122: Requirements for Internet Hosts</a> — A classic example of operational constraints becoming protocol reality.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Integration-focused fault testing and correctness thinking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="formal-methods"/>
        <category label="security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Verifiable Computation as Infrastructure: Proof Systems at Scale]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-02-verifiable-computation-as-infrastructure-proof-systems-at-sc</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-02-verifiable-computation-as-infrastructure-proof-systems-at-sc"/>
        <updated>2026-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (February 2026): Verifiable Computation as Infrastructure: Proof Systems at Scale.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Deep Systems Notes</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Verifiable Computation as Infrastructure: Proof Systems at Scale</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Interfaces must carry assumptions: time, randomness, identity, and ordering.</li>
<li>Operational behavior is part of correctness: rollout, rollback, and evidence.</li>
<li>Integration boundaries are where proofs evaporate; treat them as first-class.</li>
<li>Define safety properties before performance goals.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most real failures happen at integration boundaries, not inside components.</li>
<li>Operational behavior is part of correctness (rollouts, rollbacks, drift).</li>
<li>Mixed-version operation creates states you didn’t model.</li>
<li>Resilience requires making failure modes explicit and bounded.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you keep ‘security properties’ visible to operators and SREs?</li>
<li>Where does 'correctness' become an operational contract (SLOs, budgets, policy)?</li>
<li>What are your compositional failure modes (partial deploys, mixed versions)?</li>
<li>What is the smallest integration test that can falsify your assumptions?</li>
<li>Which proofs are worth maintaining vs replacing with tests and monitoring?</li>
<li>How do you prevent 'optional security' from appearing via config drift?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Components are built by different teams with different threat models.</li>
<li>Upgrades are incremental; compatibility is a security boundary.</li>
<li>Integration happens under time pressure; defaults become de facto policy.</li>
<li>Observability is imperfect; you debug from partial evidence.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Allowing config to silently weaken security properties.</li>
<li>Relying on “tribal knowledge” to connect assumptions across layers.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Composability is the promise that proofs survive integration:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><mrow><msub><mi mathvariant="normal">Π</mi><mn>1</mn></msub><mo>∘</mo><msub><mi mathvariant="normal">Π</mi><mn>2</mn></msub></mrow></msub><mo>≤</mo><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><msub><mi mathvariant="normal">Π</mi><mn>1</mn></msub></msub><mo>+</mo><msub><mrow><mi mathvariant="normal">A</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi></mrow><msub><mi mathvariant="normal">Π</mi><mn>2</mn></msub></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Adv}_{\Pi_1\circ \Pi_2} \le \mathrm{Adv}_{\Pi_1} + \mathrm{Adv}_{\Pi_2}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.9445em;vertical-align:-0.2501em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mtight">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span><span class="mbin mtight">∘</span><span class="mord mtight"><span class="mord mtight">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2501em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.9445em;vertical-align:-0.2501em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mtight">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2501em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.9445em;vertical-align:-0.2501em;"></span><span class="mord"><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Adv</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3283em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mtight">Π</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3173em;"><span style="top:-2.357em;margin-left:0em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.143em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2501em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Make assumptions executable: encode them as assertions, tests, and run-time checks.</p>
<p>Choose what to prove and what to monitor. Both are necessary in practice.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  boundary<span class="token text string">["Boundary"]</span> <span class="token arrow operator">--></span> contract[<span class="token string">"Contract (P -> Q)"</span>]
  contract <span class="token arrow operator">--></span> test<span class="token text string">["Tests"]</span>
  test <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitoring"]</span>
  monitor <span class="token arrow operator">--></span> incident<span class="token text string">["Incident"]</span>
  incident <span class="token arrow operator">--></span> contract</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>If it’s not enforced, it’s not a contract.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Boundary contract template:
Preconditions (P):
- input validation, size limits, auth context
- monotonic versions / idempotency keys
Postconditions (Q):
- durable state transitions
- evidence emitted (audit/metrics)
Failure modes:
- explicit, typed, and observable</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>End-to-end property tests</strong> for the smallest meaningful workflow.</li>
<li><strong>Upgrade tests</strong> for mixed-version and rollback scenarios.</li>
<li><strong>Fault injection</strong> at seams (queues, caches, RPC) not only components.</li>
<li><strong>Invariant monitoring</strong> tied to incident response playbooks.</li>
<li><strong>Contract tests</strong> at boundaries with adversarial inputs and skew.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat config drift as an incident: detect, alert, and remediate.</li>
<li>Maintain runbooks that reference invariants, not just symptoms.</li>
<li>Store evidence: audit logs, config diffs, and deployment metadata.</li>
<li>Make security and correctness properties observable (metrics + alerts).</li>
<li>Use canaries for protocol and crypto changes; define rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What boundary is most likely to be bypassed under incident pressure?</li>
<li>Which assumptions do you currently enforce only through convention?</li>
<li>Which properties can be proven locally vs only tested end-to-end?</li>
<li>Where can config silently weaken security properties today?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://web.mit.edu/Saltzer/www/publications/endtoend/endtoend.pdf" target="_blank" rel="nofollow noopener noreferrer">End-to-End Arguments in System Design</a> — A foundational argument about where to enforce correctness properties.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Integration-focused fault testing and correctness thinking.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc1122" target="_blank" rel="nofollow noopener noreferrer">RFC 1122: Requirements for Internet Hosts</a> — A classic example of operational constraints becoming protocol reality.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="formal-methods"/>
        <category label="security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Composable Security: Where Proofs Break in Real Systems]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2026-01-composable-security-where-proofs-break-in-real-systems</id>
        <link href="https://mayckongiovani.xyz/pensieve/2026-01-composable-security-where-proofs-break-in-real-systems"/>
        <updated>2026-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (January 2026): Composable Security: Where Proofs Break in Real Systems.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Deep Systems Notes</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Composable Security: Where Proofs Break in Real Systems</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Operational behavior is part of correctness: rollout, rollback, and evidence.</li>
<li>Contracts need enforcement: tests, assertions, and monitoring—not documentation.</li>
<li>Integration boundaries are where proofs evaporate; treat them as first-class.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Security becomes optional through configuration drift unless enforced.</li>
<li>Most real failures happen at integration boundaries, not inside components.</li>
<li>Resilience requires making failure modes explicit and bounded.</li>
<li>Operational behavior is part of correctness (rollouts, rollbacks, drift).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which assumptions leak across boundaries (time, randomness, identity, ordering)?</li>
<li>Which proofs are worth maintaining vs replacing with tests and monitoring?</li>
<li>What are your compositional failure modes (partial deploys, mixed versions)?</li>
<li>How do you keep ‘security properties’ visible to operators and SREs?</li>
<li>How do you prevent 'optional security' from appearing via config drift?</li>
<li>Where does 'correctness' become an operational contract (SLOs, budgets, policy)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Components are built by different teams with different threat models.</li>
<li>Integration happens under time pressure; defaults become de facto policy.</li>
<li>Adversaries exploit ambiguity between systems, not within them.</li>
<li>Observability is imperfect; you debug from partial evidence.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on “tribal knowledge” to connect assumptions across layers.</li>
<li>Allowing config to silently weaken security properties.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Interface contracts are predicates:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>caller obeys </mtext><mi>P</mi><mo>⇒</mo><mtext>callee guarantees </mtext><mi>Q</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{caller obeys } P \Rightarrow \text{callee guarantees } Q.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">caller obeys </span></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">callee guarantees </span></span><span class="mord mathnormal">Q</span><span class="mord">.</span></span></span></span></span></div>
<p>Make assumptions executable: encode them as assertions, tests, and run-time checks.</p>
<p>Treat config as code: version it, review it, and monitor drift.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  boundary<span class="token text string">["Boundary"]</span> <span class="token arrow operator">--></span> contract[<span class="token string">"Contract (P -> Q)"</span>]
  contract <span class="token arrow operator">--></span> test<span class="token text string">["Tests"]</span>
  test <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitoring"]</span>
  monitor <span class="token arrow operator">--></span> incident<span class="token text string">["Incident"]</span>
  incident <span class="token arrow operator">--></span> contract</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Operational constraints are part of the design: deploy, rollback, and drift.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Integration note: treat FFI/service boundaries as an API with invariants.</span>
<span class="token comment">// Encode invariants as types where possible, assertions otherwise.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>End-to-end property tests</strong> for the smallest meaningful workflow.</li>
<li><strong>Invariant monitoring</strong> tied to incident response playbooks.</li>
<li><strong>Upgrade tests</strong> for mixed-version and rollback scenarios.</li>
<li><strong>Contract tests</strong> at boundaries with adversarial inputs and skew.</li>
<li><strong>Fault injection</strong> at seams (queues, caches, RPC) not only components.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Use canaries for protocol and crypto changes; define rollback triggers.</li>
<li>Maintain runbooks that reference invariants, not just symptoms.</li>
<li>Store evidence: audit logs, config diffs, and deployment metadata.</li>
<li>Treat config drift as an incident: detect, alert, and remediate.</li>
<li>Make security and correctness properties observable (metrics + alerts).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Integration-focused fault testing and correctness thinking.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where can config silently weaken security properties today?</li>
<li>Which assumptions do you currently enforce only through convention?</li>
<li>What boundary is most likely to be bypassed under incident pressure?</li>
<li>Which properties can be proven locally vs only tested end-to-end?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc1122" target="_blank" rel="nofollow noopener noreferrer">RFC 1122: Requirements for Internet Hosts</a> — A classic example of operational constraints becoming protocol reality.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Integration-focused fault testing and correctness thinking.</li>
<li><a href="https://web.mit.edu/Saltzer/www/publications/endtoend/endtoend.pdf" target="_blank" rel="nofollow noopener noreferrer">End-to-End Arguments in System Design</a> — A foundational argument about where to enforce correctness properties.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="formal-methods"/>
        <category label="security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Research Frontiers: Composability, Proofs, and Future Primitives]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-12-research-frontiers-composability-proofs-and-future-primitive</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-12-research-frontiers-composability-proofs-and-future-primitive"/>
        <updated>2025-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (December 2025): Research Frontiers: Composability, Proofs, and Future Primitives.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Research Frontiers: Composability, Proofs, and Future Primitives</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Make failure modes explicit and observable.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>How do you stop downgrade under active adversaries?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming performance impacts will be negligible.</li>
<li>Treating PQ migration as a single deployment event.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<p>Treat ops as part of the protocol: monitoring, rollback, and incident response.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  threat<span class="token text string">["Threat Model (quantum + classical)"]</span> <span class="token arrow operator">--></span> design<span class="token text string">["Protocol Design"]</span>
  design <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (no_std where needed)"]</span>
  impl <span class="token arrow operator">--></span> verify<span class="token text string">["Verification (tests + formal)"]</span>
  verify <span class="token arrow operator">--></span> ops<span class="token text string">["Operationalization (rotation + monitoring)"]</span>
  ops <span class="token arrow operator">--></span> threat</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>PQ readiness is a systems program: crypto, networking, ops, and UX must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Long-Lived Secrets: Forward Secrecy, KEMs, and Key Erasure]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-11-long-lived-secrets-forward-secrecy-kems-and-key-erasure</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-11-long-lived-secrets-forward-secrecy-kems-and-key-erasure"/>
        <updated>2025-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (November 2025): Long-Lived Secrets: Forward Secrecy, KEMs, and Key Erasure.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Long-Lived Secrets: Forward Secrecy, KEMs, and Key Erasure</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Hybrid is an operational mode: deploy, monitor, rollback—not a paper design.</li>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Switching algorithms without inventorying where secrets are used.</li>
<li>Treating PQ migration as a single deployment event.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Risk is a function of exposure and lifetime:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo>≈</mo><mrow><mi mathvariant="normal">e</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">b</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{risk} \approx \mathrm{exposure} \times \mathrm{lifetime} \times \mathrm{adversary\_capability}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm">risk</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">exposure</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.0833em;"></span><span class="mord"><span class="mord mathrm">lifetime</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">adversary_capability</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<p>Treat ops as part of the protocol: monitoring, rollback, and incident response.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Operationalize early: rollback and monitoring are part of the design.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--1">(<a href="#bib-rfc8446">1</a>)</span> — A useful reference for handshake structure and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Post-Quantum DoS Surfaces: Handshakes, Amplification, and Mitigations]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-10-post-quantum-dos-surfaces-handshakes-amplification-and-mitig</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-10-post-quantum-dos-surfaces-handshakes-amplification-and-mitig"/>
        <updated>2025-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (October 2025): Post-Quantum DoS Surfaces: Handshakes, Amplification, and Mitigations.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Post-Quantum DoS Surfaces: Handshakes, Amplification, and Mitigations</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Hybrid is an operational mode: deploy, monitor, rollback—not a paper design.</li>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Define safety properties before performance goals.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming performance impacts will be negligible.</li>
<li>Switching algorithms without inventorying where secrets are used.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Risk is a function of exposure and lifetime:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo>≈</mo><mrow><mi mathvariant="normal">e</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">b</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{risk} \approx \mathrm{exposure} \times \mathrm{lifetime} \times \mathrm{adversary\_capability}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm">risk</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">exposure</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.0833em;"></span><span class="mord"><span class="mord mathrm">lifetime</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">adversary_capability</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat ops as part of the protocol: monitoring, rollback, and incident response.</p>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Design hybrid modes with explicit binding and observable outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Operationalizing PQC: Monitoring, Rollback, and Incident Response]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-09-operationalizing-pqc-monitoring-rollback-and-incident-respon</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-09-operationalizing-pqc-monitoring-rollback-and-incident-respon"/>
        <updated>2025-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (September 2025): Operationalizing PQC: Monitoring, Rollback, and Incident Response.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Operationalizing PQC: Monitoring, Rollback, and Incident Response</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Hybrid is an operational mode: deploy, monitor, rollback—not a paper design.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming performance impacts will be negligible.</li>
<li>Treating PQ migration as a single deployment event.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  threat<span class="token text string">["Threat Model (quantum + classical)"]</span> <span class="token arrow operator">--></span> design<span class="token text string">["Protocol Design"]</span>
  design <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (no_std where needed)"]</span>
  impl <span class="token arrow operator">--></span> verify<span class="token text string">["Verification (tests + formal)"]</span>
  verify <span class="token arrow operator">--></span> ops<span class="token text string">["Operationalization (rotation + monitoring)"]</span>
  ops <span class="token arrow operator">--></span> threat</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>PQ readiness is a systems program: crypto, networking, ops, and UX must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Migration scoreboard:
- Inventory coverage (% of services/devices)
- Hybrid enabled (% of traffic)
- Negotiation failures (by client cohort)
- Handshake cost (CPU/bandwidth p95/p99)
- Downgrade attempts detected</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--2">(<a href="#bib-nistpqc">2</a>)</span> — The standardization baseline for PQC readiness programs.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Quantum Tunneler: A Quantum-Safe IPSec Stack in Rust]]></title>
        <id>https://mayckongiovani.xyz/blog/quantum-tunneler</id>
        <link href="https://mayckongiovani.xyz/blog/quantum-tunneler"/>
        <updated>2025-08-03T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[An in-depth technical deep-dive into Quantum Tunneler—an end-to-end, Rust-based implementation of a post-quantum IPSec stack leveraging Kyber and Falcon.]]></summary>
        <content type="html"><![CDATA[<h2 id="introduction" style="position:relative;"><a href="#introduction" aria-label="introduction permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Introduction</h2>
<p>As quantum computing capabilities advance, classical public-key schemes such as RSA and ECC face existential threats. <strong>Quantum Tunneler</strong> is a ground-up Rust implementation of a fully <strong>quantum-safe IPSec stack</strong>, demonstrating how to build secure network tunnels that resist adversaries equipped with quantum hardware. This article walks through the motivations, the core architecture, and the deep technical details that make Quantum Tunneler both performant and future-proof.</p>
<h2 id="the-quantum-threat--motivation" style="position:relative;"><a href="#the-quantum-threat--motivation" aria-label="the quantum threat  motivation permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>The Quantum Threat &#x26; Motivation</h2>
<ol>
<li><strong>Shor’s Algorithm</strong> breaks RSA/ECDSA/ECDH in polynomial time.</li>
<li><strong>Harvest-now, decrypt-later</strong> attacks put any recorded IPSec sessions at risk.</li>
<li><strong>Regulatory &#x26; compliance</strong> demands are shifting toward post-quantum readiness.</li>
</ol>
<p>Quantum Tunneler addresses these challenges by replacing the classical Diffie-Hellman and signature primitives at every layer of the IPSec stack with <strong>NIST-recommended post-quantum algorithms</strong>:</p>
<ul>
<li><strong>CRYSTALS-Kyber</strong> for Key Encapsulation Mechanism (KEM)</li>
<li><strong>Falcon</strong> for digital signatures</li>
</ul>
<h2 id="post-quantum-cryptography-primer" style="position:relative;"><a href="#post-quantum-cryptography-primer" aria-label="post quantum cryptography primer permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Post-Quantum Cryptography Primer</h2>
<p>Before diving into the implementation, a quick recap of the two core algorithms:</p>
<ul>
<li><strong>Kyber (KEM)</strong>
<ul>
<li><strong>KeyGen</strong>: outputs <code class="language-text">(pk, sk)</code></li>
<li><strong>Encapsulate</strong>: using <code class="language-text">pk</code> produces <code class="language-text">(ct, ss)</code></li>
<li><strong>Decapsulate</strong>: using <code class="language-text">sk</code> and <code class="language-text">ct</code> recovers the same <code class="language-text">ss</code></li>
</ul>
</li>
<li><strong>Falcon (Signature)</strong>
<ul>
<li><strong>KeyGen</strong>: outputs <code class="language-text">(pk, sk)</code></li>
<li><strong>Sign</strong>: using <code class="language-text">sk</code> signs arbitrary message bytes → <code class="language-text">sig</code></li>
<li><strong>Verify</strong>: using <code class="language-text">pk</code>, <code class="language-text">msg</code>, <code class="language-text">sig</code> → boolean</li>
</ul>
</li>
</ul>
<p>Both are implemented in pure Rust (with optional <code class="language-text">no_std</code>) and integrated via generic traits:</p>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">KeyEncapsulation</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">PublicKey</span><span class="token punctuation">;</span> <span class="token keyword">type</span> <span class="token type-definition class-name">SecretKey</span><span class="token punctuation">;</span> <span class="token keyword">type</span> <span class="token type-definition class-name">Ciphertext</span><span class="token punctuation">;</span> <span class="token keyword">type</span> <span class="token type-definition class-name">SharedSecret</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">keygen</span><span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">(</span><span class="token class-name">PublicKey</span><span class="token punctuation">,</span> <span class="token class-name">SecretKey</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">encapsulate</span><span class="token punctuation">(</span>pk<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">PublicKey</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">(</span><span class="token class-name">Ciphertext</span><span class="token punctuation">,</span> <span class="token class-name">SharedSecret</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">decapsulate</span><span class="token punctuation">(</span>sk<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">SecretKey</span><span class="token punctuation">,</span> ct<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">Ciphertext</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">SharedSecret</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">DigitalSignature</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">PublicKey</span><span class="token punctuation">;</span> <span class="token keyword">type</span> <span class="token type-definition class-name">SecretKey</span><span class="token punctuation">;</span> <span class="token keyword">type</span> <span class="token type-definition class-name">Signature</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">keygen</span><span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">(</span><span class="token class-name">PublicKey</span><span class="token punctuation">,</span> <span class="token class-name">SecretKey</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">sign</span><span class="token punctuation">(</span>sk<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">SecretKey</span><span class="token punctuation">,</span> message<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Signature</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">verify</span><span class="token punctuation">(</span>pk<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">PublicKey</span><span class="token punctuation">,</span> message<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">,</span> sig<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">Signature</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="ipsec--ikev2-overview" style="position:relative;"><a href="#ipsec--ikev2-overview" aria-label="ipsec  ikev2 overview permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>IPSec &#x26; IKEv2 Overview</h2>
<p>IPSec provides <strong>confidentiality</strong>, <strong>integrity</strong>, and <strong>anti-replay</strong> for IP packets via two main components:</p>
<ul>
<li><strong>IKEv2</strong>: mutual authentication &#x26; key exchange</li>
<li><strong>ESP/AH</strong>: packet encapsulation &#x26; integrity tags</li>
</ul>
<p>Quantum Tunneler replaces:</p>
<ul>
<li>The classical Diffie-Hellman in <strong>IKE_SA_INIT</strong> with a Kyber KEM exchange.</li>
<li>The RSA/ECDSA signature in <strong>IKE_AUTH</strong> with Falcon.</li>
<li>The symmetric ciphers / MACs in ESP/AH with hybrid or pure-PQC constructs derived from shared secrets.</li>
</ul>
<h2 id="architecture--workspace-layout" style="position:relative;"><a href="#architecture--workspace-layout" aria-label="architecture  workspace layout permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Architecture &#x26; Workspace Layout</h2>
<p>Quantum Tunneler is organized as a Rust <em>workspace</em>:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">quantum-tunneler/
├── Cargo.toml            # workspace
├── quantum_ipsec/        # core library
│   ├── Cargo.toml
│   └── src/
│       ├── crypto/       # kyber.rs, falcon.rs, traits.rs
│       ├── ikev2/        # initiator.rs, responder.rs, parser.rs
│       ├── ipsec/        # esp.rs, ah.rs, sa.rs, policy.rs
│       └── utils.rs      # common types &amp; helpers
└── cli/                  # command-line interface
    ├── Cargo.toml
    └── src/
        ├── main.rs
        └── commands/     # init.rs, connect.rs, status.rs, benchmark.rs</code></pre></div>
<h3 id="core-crate-quantum_ipsec" style="position:relative;"><a href="#core-crate-quantum_ipsec" aria-label="core crate quantum_ipsec permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Core Crate (<code class="language-text">quantum_ipsec</code>)</h3>
<ul>
<li>
<p><strong><code class="language-text">crypto/</code></strong></p>
<ul>
<li><code class="language-text">kyber.rs</code>: native Rust KEM implementation, optional use of <a href="https://docs.rs/pqcrypto" target="_blank" rel="nofollow noopener noreferrer"><code class="language-text">pqcrypto</code></a>.</li>
<li><code class="language-text">falcon.rs</code>: signature scheme, vendored C bindings via <code class="language-text">unsafe</code> FFI or pure-Rust port.</li>
<li><code class="language-text">traits.rs</code>: defines <code class="language-text">KeyEncapsulation</code> &#x26; <code class="language-text">DigitalSignature</code>.</li>
</ul>
</li>
<li>
<p><strong><code class="language-text">ikev2/</code></strong></p>
<ul>
<li><code class="language-text">parser.rs</code>: BER-style message parsing / serialization per RFC 7296.</li>
<li><code class="language-text">initiator.rs</code> / <code class="language-text">responder.rs</code>: orchestrate IKE_SA_INIT and IKE_AUTH flows.</li>
<li><code class="language-text">crypto_adapter.rs</code>: bridges IKE messages to <code class="language-text">crypto</code> module.</li>
</ul>
</li>
<li>
<p><strong><code class="language-text">ipsec/</code></strong></p>
<ul>
<li><code class="language-text">esp.rs</code>: encapsulates and decapsulates IP packets using shared secrets.</li>
<li><code class="language-text">ah.rs</code>: computes/validates Falcon-based authentication tags.</li>
<li><code class="language-text">sa.rs</code>: in-memory store of SPIs, nonces, sequence counters.</li>
<li><code class="language-text">policy.rs</code>: Security Policy Database (SPD) and SAD management.</li>
</ul>
</li>
</ul>
<h3 id="cli-quantum-ipsec" style="position:relative;"><a href="#cli-quantum-ipsec" aria-label="cli quantum ipsec permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>CLI (<code class="language-text">quantum-ipsec</code>)</h3>
<p>All commands are thin wrappers around core APIs via <a href="https://docs.rs/clap" target="_blank" rel="nofollow noopener noreferrer"><code class="language-text">clap</code></a>. Sample usage:</p>
<div class="gatsby-highlight" data-language="bash"><pre class="language-bash"><code class="language-bash"><span class="token comment"># Initialize local peer, generate PQC keypairs</span>
quantum-ipsec init <span class="token parameter variable">--config</span> default.toml

<span class="token comment"># Negotiate IKEv2 with remote peer</span>
quantum-ipsec connect <span class="token parameter variable">--peer</span> <span class="token number">10.0</span>.0.2 <span class="token parameter variable">--mode</span> tunnel

<span class="token comment"># Inspect active SAs</span>
quantum-ipsec status <span class="token parameter variable">--json</span>

<span class="token comment"># Benchmark handshake &amp; packet throughput</span>
quantum-ipsec benchmark <span class="token parameter variable">--duration</span> 30s --payload-size <span class="token number">512</span></code></pre></div>
<h2 id="deep-dive-esp-packet-flow" style="position:relative;"><a href="#deep-dive-esp-packet-flow" aria-label="deep dive esp packet flow permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Deep Dive: ESP Packet Flow</h2>
<ol>
<li><strong>SA Lookup</strong>: find SA by SPI</li>
<li><strong>Key Derivation</strong>: derive symmetric key via HKDF from Kyber <code class="language-text">SharedSecret</code></li>
<li><strong>Encryption</strong>: encrypt payload with XChaCha20-Poly1305 (or pure-PQC hybrid)</li>
<li><strong>MAC</strong>: compute Falcon signature over header + ciphertext</li>
<li><strong>Output</strong>: <code class="language-text">[ SPI | Sequence Number | Ciphertext | Signature ]</code></li>
</ol>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">pub</span> <span class="token keyword">fn</span> <span class="token function-definition function">encrypt_packet</span><span class="token punctuation">(</span>sa<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token class-name">SecurityAssociation</span><span class="token punctuation">,</span> plaintext<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">IpPacket</span> <span class="token punctuation">{</span>
    <span class="token keyword">let</span> sym_key <span class="token operator">=</span> <span class="token function">hkdf_expand</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>sa<span class="token punctuation">.</span>shared_secret<span class="token punctuation">,</span> <span class="token string">b"esp-key"</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token keyword">let</span> ciphertext <span class="token operator">=</span> <span class="token class-name">XChaCha20Poly1305</span><span class="token punctuation">::</span><span class="token function">new</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>sym_key<span class="token punctuation">)</span><span class="token punctuation">.</span><span class="token function">encrypt</span><span class="token punctuation">(</span>nonce<span class="token punctuation">,</span> plaintext<span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token keyword">let</span> signature <span class="token operator">=</span> <span class="token class-name">Falcon</span><span class="token punctuation">::</span><span class="token function">sign</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>sa<span class="token punctuation">.</span>sk_sig<span class="token punctuation">,</span> <span class="token operator">&amp;</span>ciphertext<span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token class-name">IpPacket</span> <span class="token punctuation">{</span> spi<span class="token punctuation">:</span> sa<span class="token punctuation">.</span>spi<span class="token punctuation">,</span> seq<span class="token punctuation">:</span> sa<span class="token punctuation">.</span><span class="token function">seq_next</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> data<span class="token punctuation">:</span> ciphertext<span class="token punctuation">,</span> auth<span class="token punctuation">:</span> signature <span class="token punctuation">}</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="performance-considerations--benchmarking" style="position:relative;"><a href="#performance-considerations--benchmarking" aria-label="performance considerations  benchmarking permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Performance Considerations &#x26; Benchmarking</h2>
<ul>
<li><strong>Handshake Latency</strong>: measured via <code class="language-text">criterion</code> for 1 000 Kyber encapsulations + Falcon signatures.</li>
<li><strong>Throughput</strong>: payload encryption/decryption at various sizes (64 B–1500 B).</li>
<li><strong>Memory Footprint</strong>: <code class="language-text">no_std</code> build size (~80 KB on Cortex-M4).</li>
<li><strong>Concurrency</strong>: multi-peer stress tests using asynchronous Tokio drivers.</li>
</ul>
<h2 id="testing--validation" style="position:relative;"><a href="#testing--validation" aria-label="testing  validation permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Testing &#x26; Validation</h2>
<ul>
<li><strong>Official Test Vectors</strong> from NIST for Kyber and Falcon.</li>
<li><strong>Fuzzing</strong> with <code class="language-text">proptest</code> on parsers (<code class="language-text">parser.rs</code>).</li>
<li><strong>Integration</strong>: two-node TUN/TAP simulation, packet dumps inspected in Wireshark.</li>
<li><strong>Fault Injection</strong>: truncated messages, invalid SPIs, replayed packets.</li>
</ul>
<h2 id="future-extensions" style="position:relative;"><a href="#future-extensions" aria-label="future extensions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Future Extensions</h2>
<ul>
<li><strong>Hybrid Mode</strong>: combine AES-GCM with Kyber fallback for incremental migration.</li>
<li><strong>WebAssembly Front-End</strong>: interactive demos in the browser with WASM.</li>
<li><strong>TUI Dashboard</strong>: live session metrics via <code class="language-text">ratatui</code>.</li>
<li><strong>QUIC Integration</strong>: embed quantum-safe IKEv2 into QUIC handshake.</li>
</ul>
<h2 id="conclusion" style="position:relative;"><a href="#conclusion" aria-label="conclusion permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Conclusion</h2>
<p>Quantum Tunneler demonstrates that it is entirely feasible to implement a production-grade IPSec stack with <strong>post-quantum security</strong> in Rust. By modularizing the core cryptographic primitives, protocol logic, and user interface, the project provides a blueprint for next-generation secure networking—ready for the era of quantum adversaries. Contributions, feedback, and forks are highly encouraged!</p>]]></content>
        <category label="post-quantum-cryptography"/>
        <category label="Rust"/>
        <category label="IPSec"/>
        <category label="cryptography"/>
        <category label="no-std"/>
        <category label="network-security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Quantum-Safe VPN Design: Lessons from Implementing a PQ IPSec Stack]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-08-quantum-safe-vpn-design-lessons-from-implementing-a-pq-ipsec</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-08-quantum-safe-vpn-design-lessons-from-implementing-a-pq-ipsec"/>
        <updated>2025-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (August 2025): Quantum-Safe VPN Design: Lessons from Implementing a PQ IPSec Stack.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Quantum-Safe VPN Design: Lessons from Implementing a PQ IPSec Stack</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>How do you stop downgrade under active adversaries?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Switching algorithms without inventorying where secrets are used.</li>
<li>Assuming performance impacts will be negligible.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<p>Treat ops as part of the protocol: monitoring, rollback, and incident response.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Design hybrid modes with explicit binding and observable outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational lessons relevant to rotation and recovery at scale.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--2">(<a href="#bib-nistpqc">2</a>)</span> — The standardization baseline for PQC readiness programs.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[QuantumSafe Finance – Deep Technical Overview (Phase 2)]]></title>
        <id>https://mayckongiovani.xyz/pensieve/quantumsafe-finance-phase-2</id>
        <link href="https://mayckongiovani.xyz/pensieve/quantumsafe-finance-phase-2"/>
        <updated>2025-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Comprehensive article on the motivations, architecture, and current Phase 2 development of the QuantumSafe Finance Open-Core PQC platform.]]></summary>
        <content type="html"><![CDATA[<p><span
      class="gatsby-resp-image-wrapper"
      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 700px; "
    >
      <a
    class="gatsby-resp-image-link"
    href="/static/ea70d91179af4ca364008fd19d35e4e1/f1720/architecture.png"
    style="display: block"
    target="_blank"
    rel="noopener"
  >
    <span
    class="gatsby-resp-image-background-image"
    style="padding-bottom: 100%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAIAAAAC64paAAAACXBIWXMAAAsTAAALEwEAmpwYAAAC3UlEQVR42lWTCXOiQBCF/f//Zo1JNlvGxBzeay4jHkEUQRQvQE7B7H4DuuVWdWHPOK+P169zgesEnjBfOLtDso/3YRIFcRSG/i6JwyjweJPE+ySOvg/7MNgFrp1BcinMjgLXnOuXFxcP93fY00P57rZYuMgX8vny/V3x181jmd/b8l1pZRr70PNTfC6LQWx/Zw/70ufH23j0Neh1+Qz6EhfqeDSfaX2pO+xJ3c77ZrnwHSurN+c6lqaOF4YuD/vaRLE2S0OfUmGyjw5xeEjEF/Bcn3K/XBi8NDR1OlG8nZWzt6uZpk4UuZD/cXN9xS2ZOXKpyEMcgg56kjzotVuNZqPWqFV1dbKcG6Qh85ZXrUa9Xn1u1qutZl2RB7QQ+e5yPjPnM2gjYmq0IhFRHcv4AFPC0qf70IcJzLW3axpzbV0d0xHcrs0Fl17aII+FHQlzsznZmZHH0FUSQpX02Xl7acMhrUIHf9EL70Nvh53A7pFw8QdgTf2Ow+l49PP6slQsku1PHL2/tikVsICdpJE7R2ZRFzOd5MwTkob97nIxg2dIPocF/2U+A/NlmNZmBdWqMrLWy+3aBH+iTWHyHOn8DOw5UIIxUjqk+H630+t2OBKFUb+/viC10m0RIpCjvVnl/iWEY8ZAyIHURduQdHVZqD4/4qOt3ucHEWuVp2a9RjBE4GzXGdjeBx6RIBnl017KrlyrPMPTbDqBp6z4TIs425UJ8DhnbL0UBcIENdCz52yFSAxtZ224Ifp3EkEeCZlFHPoCnI3e0KbpOnQy3SIJZysIQ6pUxHG1MIjIG9jCoSkBhlXIoNrO2ytLQ4cpsSOQBFO+BugMJzvCGZoZDcWlY62Pi7FZLSpPjw/3pWnKM7Wwg+1W8+V386svARjLQ57VqxUIM9PFAigIE4d03WCMvjlSGF90sjbnMGQh7plGw9li0gJfsZKA2QosVezJ93fCUg1nfnYPbZjwAzfwnL+GRTsx+ph8lQAAAABJRU5ErkJggg=='); background-size: cover; display: block;"
  ></span>
  <img
        class="gatsby-resp-image-image"
        alt="QuantumSafe Finance Architecture"
        title=""
        src="/static/ea70d91179af4ca364008fd19d35e4e1/39600/architecture.png"
        srcset="/static/ea70d91179af4ca364008fd19d35e4e1/1aaec/architecture.png 175w,
/static/ea70d91179af4ca364008fd19d35e4e1/98287/architecture.png 350w,
/static/ea70d91179af4ca364008fd19d35e4e1/39600/architecture.png 700w,
/static/ea70d91179af4ca364008fd19d35e4e1/f1720/architecture.png 1024w"
        sizes="(max-width: 700px) 100vw, 700px"
        style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"
        loading="lazy"
        decoding="async"
      />
  </a>
    </span></p>
<h2 id="introduction" style="position:relative;"><a href="#introduction" aria-label="introduction permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Introduction</h2>
<p>In 2025, we stand on the brink of a seismic shift in information security. <strong>Quantum computers</strong>, harnessing phenomena such as superposition and entanglement, threaten to undermine nearly all public-key cryptosystems in use today. At QuantumSafe Finance, we’re building an <strong>Open-Core</strong> framework that blends high-performance post-quantum primitives with an intelligent audit pipeline—allowing financial institutions to <em>prepare now</em> for a quantum future while maintaining compliance and performance.</p>
<p>This article explores:</p>
<ol>
<li><strong>Why</strong> post-quantum cryptography (PQC) is essential for fintech and banking</li>
<li>The <strong>threat models</strong> introduced by large-scale quantum hardware</li>
<li>Our <strong>Phase 2 “Audit Lite”</strong> architecture and progress</li>
<li>A <strong>deep technical dive</strong> into audit pipelines, ML anomaly detection, and rule engines</li>
<li><strong>Integration examples</strong>, performance numbers, and next steps</li>
</ol>
<blockquote>
<p>“The only secure computer is one that’s powered off, locked in a safe, and buried forty feet underground.”
― Gene Spafford, paraphrased</p>
<p><em>We’re not burying servers underground, but we are building tomorrow’s cryptographic defenses today.</em></p>
</blockquote>
<hr>
<h2 id="1-why-post-quantum-cryptography-matters" style="position:relative;"><a href="#1-why-post-quantum-cryptography-matters" aria-label="1 why post quantum cryptography matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1. Why Post-Quantum Cryptography Matters</h2>
<h3 id="11-the-quantum-threat-model" style="position:relative;"><a href="#11-the-quantum-threat-model" aria-label="11 the quantum threat model permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1.1 The Quantum Threat Model</h3>
<ul>
<li><strong>Shor’s algorithm</strong> (1994) runs in polynomial time on a sufficiently large quantum computer, breaking RSA, ECC, and discrete-log-based schemes in <em>seconds</em>.</li>
<li><strong>Grover’s algorithm</strong> yields a quadratic speed-up for brute-force search, effectively halving symmetric key strength (e.g., AES-256 → AES-128 level).</li>
</ul>
<p>Financial systems rely on RSA/ECC for TLS handshakes, digital signatures, code signing, and blockchain consensus. A single fault in key management can cascade into massive breaches:</p>
<ul>
<li><strong>Transactional integrity</strong> is compromised when digital signatures become forgeable.</li>
<li><strong>Data confidentiality</strong> fails when encrypted archives can be retroactively decrypted.</li>
<li><strong>Regulatory penalties</strong> (GDPR, PCI DSS, GLBA) mount quickly once compromise is demonstrated.</li>
</ul>
<h3 id="12-industry-context" style="position:relative;"><a href="#12-industry-context" aria-label="12 industry context permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>1.2 Industry Context</h3>
<table>
<thead>
<tr>
<th>Algorithm</th>
<th>Classical Security</th>
<th>Quantum-Resilient Alternative</th>
</tr>
</thead>
<tbody>
<tr>
<td>RSA-2048</td>
<td>~112-bit</td>
<td>Kyber-512 (CSPR > 128-bit)</td>
</tr>
<tr>
<td>ECC-P256</td>
<td>~128-bit</td>
<td>Dilithium-II (≥128-bit)</td>
</tr>
<tr>
<td>HMAC-SHA2</td>
<td>256-bit</td>
<td>SHA2-256 w/ doubled key length</td>
</tr>
</tbody>
</table>
<p><em>PQC standards are finalized; NIST approved CRYSTALS-Kyber, Dilithium, Falcon, and SPHINCS+ in late 2024. Integration at scale remains the challenge.</em></p>
<hr>
<h2 id="2-phase-2--audit-lite-module" style="position:relative;"><a href="#2-phase-2--audit-lite-module" aria-label="2 phase 2  audit lite module permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2. Phase 2 – “Audit Lite” Module</h2>
<p>We’ve completed <strong>Phase 1</strong> (core PQC Rust engine, multi-language bindings, TLS sidecar PoC). Now in <strong>Phase 2</strong>, we’re delivering:</p>
<ul>
<li><strong>Real-time log ingestion</strong> (Kafka → Elasticsearch)</li>
<li><strong>Lightweight rule engine</strong> (YARA-like syntax) for compliance checks</li>
<li><strong>ML anomaly detection</strong> for cryptographic API misuse</li>
<li><strong>Minimal dashboard</strong> with alert visualization and PDF reporting</li>
</ul>
<h3 id="21-goals--scope" style="position:relative;"><a href="#21-goals--scope" aria-label="21 goals  scope permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>2.1 Goals &#x26; Scope</h3>
<ol>
<li><strong>Detect misuse patterns</strong> such as
<ul>
<li>Unusually large payloads</li>
<li>Signing requests outside business hours</li>
<li>Repeated key-encapsulation failures</li>
</ul>
</li>
<li><strong>Automate regulatory compliance</strong> checks (PCI DSS, ISO 27001, LGPD)</li>
<li><strong>Minimize operational overhead</strong>: add &#x3C; 1 ms per transaction, scale to 5 K TPS per node</li>
</ol>
<hr>
<h2 id="3-technical-deep-dive" style="position:relative;"><a href="#3-technical-deep-dive" aria-label="3 technical deep dive permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3. Technical Deep Dive</h2>
<h3 id="31-log-ingestion-pipeline" style="position:relative;"><a href="#31-log-ingestion-pipeline" aria-label="31 log ingestion pipeline permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.1 Log Ingestion Pipeline</h3>
<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token comment"># Helm values for Audit Lite deployment</span>
<span class="token key atrule">audit</span><span class="token punctuation">:</span>
  <span class="token key atrule">enabled</span><span class="token punctuation">:</span> <span class="token boolean important">true</span>
  <span class="token key atrule">kafka</span><span class="token punctuation">:</span>
    <span class="token key atrule">brokers</span><span class="token punctuation">:</span>
      <span class="token punctuation">-</span> kafka1<span class="token punctuation">:</span><span class="token number">9092</span>
      <span class="token punctuation">-</span> kafka2<span class="token punctuation">:</span><span class="token number">9092</span>
    <span class="token key atrule">topic</span><span class="token punctuation">:</span> pqc<span class="token punctuation">-</span>logs
  <span class="token key atrule">elasticsearch</span><span class="token punctuation">:</span>
    <span class="token key atrule">hosts</span><span class="token punctuation">:</span>
      <span class="token punctuation">-</span> es1<span class="token punctuation">:</span><span class="token number">9200</span>
      <span class="token punctuation">-</span> es2<span class="token punctuation">:</span><span class="token number">9200</span></code></pre></div>
<ol>
<li>
<p><strong>Producers</strong> (sidecar + core engine) emit structured JSON logs:</p>
<div class="gatsby-highlight" data-language="json"><pre class="language-json"><code class="language-json"><span class="token punctuation">{</span>
  <span class="token property">"timestamp"</span><span class="token operator">:</span> <span class="token string">"2025-08-03T12:45:23Z"</span><span class="token punctuation">,</span>
  <span class="token property">"component"</span><span class="token operator">:</span> <span class="token string">"pqc-engine"</span><span class="token punctuation">,</span>
  <span class="token property">"operation"</span><span class="token operator">:</span> <span class="token string">"sign"</span><span class="token punctuation">,</span>
  <span class="token property">"algorithm"</span><span class="token operator">:</span> <span class="token string">"Dilithium-II"</span><span class="token punctuation">,</span>
  <span class="token property">"duration_ms"</span><span class="token operator">:</span> <span class="token number">0.45</span><span class="token punctuation">,</span>
  <span class="token property">"status"</span><span class="token operator">:</span> <span class="token string">"OK"</span><span class="token punctuation">,</span>
  <span class="token property">"client_id"</span><span class="token operator">:</span> <span class="token string">"accounting-service"</span>
<span class="token punctuation">}</span></code></pre></div>
</li>
<li>
<p><strong>Kafka</strong> provides durable buffering and partitioned scale.</p>
</li>
<li>
<p><strong>Logstash</strong> (or custom Python consumer) transforms and pushes to <strong>Elasticsearch</strong> indices with time-based sharding.</p>
</li>
</ol>
<h3 id="32-rule-engine-yara-like" style="position:relative;"><a href="#32-rule-engine-yara-like" aria-label="32 rule engine yara like permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.2 Rule Engine (YARA-like)</h3>
<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token comment"># Example rule</span>
<span class="token key atrule">rules</span><span class="token punctuation">:</span>
  <span class="token punctuation">-</span> <span class="token key atrule">id</span><span class="token punctuation">:</span> late<span class="token punctuation">-</span>night<span class="token punctuation">-</span>signs
    <span class="token key atrule">description</span><span class="token punctuation">:</span> <span class="token string">"Signing operations between 02:00–04:00 UTC"</span>
    <span class="token key atrule">condition</span><span class="token punctuation">:</span> <span class="token punctuation">|</span><span class="token scalar string">
      operation == "sign" &amp;&amp;
      (hour(timestamp) >= 2 &amp;&amp; hour(timestamp) &lt; 4)</span></code></pre></div>
<ul>
<li>Written in simple declarative YAML.</li>
<li>Engine runs as part of ingestion, tagging documents with rule hits.</li>
<li>Alerts emitted to message bus (Slack webhook, email, or webhook endpoint).</li>
</ul>
<h3 id="33-ml-driven-anomaly-detection" style="position:relative;"><a href="#33-ml-driven-anomaly-detection" aria-label="33 ml driven anomaly detection permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.3 ML-Driven Anomaly Detection</h3>
<div class="gatsby-highlight" data-language="python"><pre class="language-python"><code class="language-python"><span class="token comment"># Simplified example: Isolation Forest on duration_ms</span>
<span class="token keyword">from</span> sklearn<span class="token punctuation">.</span>ensemble <span class="token keyword">import</span> IsolationForest
model <span class="token operator">=</span> IsolationForest<span class="token punctuation">(</span>contamination<span class="token operator">=</span><span class="token number">0.01</span><span class="token punctuation">)</span>
X <span class="token operator">=</span> load_feature_matrix<span class="token punctuation">(</span>index<span class="token operator">=</span><span class="token string">"pqc-logs-*"</span><span class="token punctuation">,</span> features<span class="token operator">=</span><span class="token punctuation">[</span><span class="token string">"duration_ms"</span><span class="token punctuation">,</span> <span class="token string">"payload_size"</span><span class="token punctuation">]</span><span class="token punctuation">)</span>
model<span class="token punctuation">.</span>fit<span class="token punctuation">(</span>X<span class="token punctuation">)</span>
anomalies <span class="token operator">=</span> model<span class="token punctuation">.</span>predict<span class="token punctuation">(</span>X<span class="token punctuation">)</span>  <span class="token comment"># -1 indicates anomaly</span></code></pre></div>
<ul>
<li>
<p><strong>Features</strong>:</p>
<ul>
<li><code class="language-text">duration_ms</code></li>
<li><code class="language-text">payload_size_bytes</code></li>
<li><code class="language-text">failure_rate</code> per client</li>
</ul>
</li>
<li>
<p><strong>Pipeline</strong>:</p>
<ol>
<li>Batch-train nightly on rolling window (7 days)</li>
<li>Serve model via lightweight REST (FastAPI)</li>
<li>Score live log events; anomalies → alert stream</li>
</ol>
</li>
</ul>
<h3 id="34-dashboard--reports" style="position:relative;"><a href="#34-dashboard--reports" aria-label="34 dashboard  reports permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>3.4 Dashboard &#x26; Reports</h3>
<div class="gatsby-highlight" data-language="html"><pre class="language-html"><code class="language-html"><span class="token comment">&lt;!-- React snippet: rendering alert counts --></span>
&lt;AlertChart
  data={fetch("/api/audit/alerts?range=24h")}
  xKey="rule_id"
  yKey="count"
/></code></pre></div>
<ul>
<li><strong>React + D3.js</strong> for interactive visualization.</li>
<li><strong>Node.js</strong> backend generates scheduled PDF/CSV reports via Puppeteer.</li>
</ul>
<hr>
<h2 id="4-integration-example" style="position:relative;"><a href="#4-integration-example" aria-label="4 integration example permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>4. Integration Example</h2>
<p>Developers can integrate Audit Lite with a few YAML lines:</p>
<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token key atrule">quantumsafe</span><span class="token punctuation">:</span>
  <span class="token key atrule">pqcSidecar</span><span class="token punctuation">:</span>
    <span class="token key atrule">image</span><span class="token punctuation">:</span> quantumsafe/pqc<span class="token punctuation">-</span>sidecar<span class="token punctuation">:</span>2.0.0
    <span class="token key atrule">args</span><span class="token punctuation">:</span>
      <span class="token punctuation">-</span> <span class="token punctuation">-</span><span class="token punctuation">-</span>audit<span class="token punctuation">-</span>topic=pqc<span class="token punctuation">-</span>logs
  <span class="token key atrule">auditLite</span><span class="token punctuation">:</span>
    <span class="token key atrule">enabled</span><span class="token punctuation">:</span> <span class="token boolean important">true</span>
    <span class="token key atrule">rulesFile</span><span class="token punctuation">:</span> /etc/quantumsafe/rules.yaml</code></pre></div>
<p><em>In Kubernetes:</em> deploy as two containers in the same Pod (sidecar + audit service). No code changes required in the application.</p>
<hr>
<h2 id="5-performance--scaling" style="position:relative;"><a href="#5-performance--scaling" aria-label="5 performance  scaling permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>5. Performance &#x26; Scaling</h2>
<table>
<thead>
<tr>
<th>Metric</th>
<th>Measured Result</th>
</tr>
</thead>
<tbody>
<tr>
<td>Sidecar handshake overhead</td>
<td>0.5 ms ± 0.1 ms</td>
</tr>
<tr>
<td>Audit pipeline end-to-end latency</td>
<td>8 ms (median)</td>
</tr>
<tr>
<td>ML model inference time</td>
<td>1.2 ms per event</td>
</tr>
<tr>
<td>Horizontal scaling</td>
<td>10K events/s per instance</td>
</tr>
</tbody>
</table>
<p><em>Linear scaling demonstrated up to 100K events/s across a 10-node cluster.</em></p>
<hr>
<h2 id="6-next-steps--roadmap" style="position:relative;"><a href="#6-next-steps--roadmap" aria-label="6 next steps  roadmap permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>6. Next Steps &#x26; Roadmap</h2>
<ol>
<li>
<p><strong>Phase 3</strong> – Full Enterprise Modules</p>
<ul>
<li>Pre-trained ML packs, advanced rule templating, HSM adapters.</li>
</ul>
</li>
<li>
<p><strong>Phase 4</strong> – Certification &#x26; Compliance Tooling</p>
<ul>
<li>Automated PCI DSS audit reports, LGPD data-privacy workflows.</li>
</ul>
</li>
<li>
<p><strong>Phase 5</strong> – Ecosystem &#x26; Marketplace</p>
<ul>
<li>Plugin marketplace for third-party compliance packs and connectors.</li>
</ul>
</li>
</ol>
<hr>
<h2 id="conclusion" style="position:relative;"><a href="#conclusion" aria-label="conclusion permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Conclusion</h2>
<p>Phase 2 represents a crucial milestone: <strong>enabling intelligent, automated auditing</strong> alongside quantum-safe cryptography. By addressing both the cryptographic threat and operational compliance, we position QuantumSafe Finance as a research-driven, production-ready framework—poised to become the standard for financial institutions navigating the quantum era.</p>
<div class="gatsby-highlight" data-language="yaml"><pre class="language-yaml"><code class="language-yaml"><span class="token comment"># Quick reference: Phase status</span>
<span class="token key atrule">phase</span><span class="token punctuation">:</span> <span class="token number">2</span>
<span class="token key atrule">core</span><span class="token punctuation">:</span> complete
<span class="token key atrule">auditLite</span><span class="token punctuation">:</span> in<span class="token punctuation">-</span>development
<span class="token key atrule">enterpriseModules</span><span class="token punctuation">:</span> pending</code></pre></div>
<hr>]]></content>
        <category label="post-quantum"/>
        <category label="cryptography"/>
        <category label="fintech"/>
        <category label="audit"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[no_std Crypto in Rust: Determinism, Side Channels, and Constraints]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-07-no-std-crypto-in-rust-determinism-side-channels-and-constrai</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-07-no-std-crypto-in-rust-determinism-side-channels-and-constrai"/>
        <updated>2025-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (July 2025): no_std Crypto in Rust: Determinism, Side Channels, and Constraints.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>no_std Crypto in Rust: Determinism, Side Channels, and Constraints</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Define success metrics beyond “enabled”: cohorts, failures, and evidence.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on ‘automatic’ negotiation without downgrade resistance.</li>
<li>Switching algorithms without inventorying where secrets are used.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Risk is a function of exposure and lifetime:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo>≈</mo><mrow><mi mathvariant="normal">e</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">b</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{risk} \approx \mathrm{exposure} \times \mathrm{lifetime} \times \mathrm{adversary\_capability}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm">risk</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">exposure</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.0833em;"></span><span class="mord"><span class="mord mathrm">lifetime</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">adversary_capability</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  threat<span class="token text string">["Threat Model (quantum + classical)"]</span> <span class="token arrow operator">--></span> design<span class="token text string">["Protocol Design"]</span>
  design <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (no_std where needed)"]</span>
  impl <span class="token arrow operator">--></span> verify<span class="token text string">["Verification (tests + formal)"]</span>
  verify <span class="token arrow operator">--></span> ops<span class="token text string">["Operationalization (rotation + monitoring)"]</span>
  ops <span class="token arrow operator">--></span> threat</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Operationalize early: rollback and monitoring are part of the design.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--1">(<a href="#bib-rfc8446">1</a>)</span> — A useful reference for handshake structure and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Building NeuroTradeX — Architecting an AI-Driven Trading System]]></title>
        <id>https://mayckongiovani.xyz/pensieve/neurotradex-architecture</id>
        <link href="https://mayckongiovani.xyz/pensieve/neurotradex-architecture"/>
        <updated>2025-06-18T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[A deep-dive into the modular design, architecture, and implementation of the NeuroTradeX open-source platform for financial and crypto trading.]]></summary>
        <content type="html"><![CDATA[<p><span
      class="gatsby-resp-image-wrapper"
      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 700px; "
    >
      <a
    class="gatsby-resp-image-link"
    href="/static/de26140bfe60ea1da24683aa7843508f/437a1/neurotradex-diagram.png"
    style="display: block"
    target="_blank"
    rel="noopener"
  >
    <span
    class="gatsby-resp-image-background-image"
    style="padding-bottom: 66.85714285714286%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAANCAIAAAAmMtkJAAAACXBIWXMAAAsTAAALEwEAmpwYAAABqklEQVR42p2S226bQBRF+f9falLJdZIHy0qLYlm+UWAwNwsQDAy2xzZ0McSOKvWp+2E49zl7M1Zn0Pd90zRSyrZty7JqmrqqOAeUZUl8tLXWVHZ3WI9mz/Ofn7/P5/P395/T6cu3pyfbtrF/TKeTyWQ2m72+vcVx/Ffz9Xo9a30xYDAuafyrwcUYRG6320UPtjbAGJplXYdh6Pt+GEX7MCyKQinlCxEaBEFA6nQ6HQ6HKI5FEHC553lQYKJV1zULf3wstrud63kUZVm+2Wwc57fjOMvlcrvdykoKETBxtVp5vk+2UWpoPp/Pqm0rKZMkQS1cokRAmqZsgTEQ0Xooq6o8z9W9zBrVIkdi5EaEk/WE8Fkb2qNInMfjkU0fmlnUwZ4obG8G4yzESpKYm/VFj0MBC+ZFQdunYEyKogg+MN/v92zFnkQ810UFtHFdl7+RpgcMXISAszT3WzwA/F+2vVgs1us1/VmWwR+dcHeo6Lq8k1F2IQQuwU+1oc7laNC0Ssp6VKJpFGl2rs1JBOaUje8MQxshrK4fpOjMp/t6PIM8D/w70t+f5//hD3tR3zj4HJltAAAAAElFTkSuQmCC'); background-size: cover; display: block;"
  ></span>
  <img
        class="gatsby-resp-image-image"
        alt="NeuroTradeX Architecture"
        title=""
        src="/static/de26140bfe60ea1da24683aa7843508f/39600/neurotradex-diagram.png"
        srcset="/static/de26140bfe60ea1da24683aa7843508f/1aaec/neurotradex-diagram.png 175w,
/static/de26140bfe60ea1da24683aa7843508f/98287/neurotradex-diagram.png 350w,
/static/de26140bfe60ea1da24683aa7843508f/39600/neurotradex-diagram.png 700w,
/static/de26140bfe60ea1da24683aa7843508f/57cd1/neurotradex-diagram.png 1050w,
/static/de26140bfe60ea1da24683aa7843508f/4af54/neurotradex-diagram.png 1400w,
/static/de26140bfe60ea1da24683aa7843508f/437a1/neurotradex-diagram.png 1536w"
        sizes="(max-width: 700px) 100vw, 700px"
        style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"
        loading="lazy"
        decoding="async"
      />
  </a>
    </span></p>
<blockquote>
<p>NeuroTradeX is an advanced, modular trading platform designed for real-time, explainable AI in financial and crypto markets.
It was built with a focus on transparency, security, extensibility, and performance — combining technologies like LSTM, Transformers, SHAP, WebSocket streaming, Dockerized services, and real exchange integrations.</p>
</blockquote>
<hr>
<h2 id="️-system-overview" style="position:relative;"><a href="#%EF%B8%8F-system-overview" aria-label="️ system overview permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>⚙️ System Overview</h2>
<p>At its core, <strong>NeuroTradeX</strong> is composed of 5 decoupled services:</p>
<ol>
<li><code class="language-text">data-core</code>: feature pipelines, OHLCV ingestion, sentiment processing via LLMs</li>
<li><code class="language-text">model-engine</code>: deep learning prediction using LSTM, Transformer, and SHAP explanations</li>
<li><code class="language-text">exec-core</code>: real or simulated execution (Binance, paper trading), with risk controls</li>
<li><code class="language-text">dashboard-ui</code>: live Next.js UI to monitor model confidence, signal history, logs</li>
<li><code class="language-text">alert-system</code>: async, multi-channel alerts via Telegram, Discord, and Webhooks</li>
</ol>
<p>The entire system is open-source and hosted at:
🔗 <a href="https://gitlab.com/neurotradex" target="_blank" rel="nofollow noopener noreferrer"><code class="language-text">gitlab.com/neurotradex</code></a></p>
<hr>
<h2 id="-modular-architecture" style="position:relative;"><a href="#-modular-architecture" aria-label=" modular architecture permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>🧱 Modular Architecture</h2>
<p>Each module runs independently, communicates through structured JSON files or WebSocket streams, and is deployable via Docker Compose or Kubernetes.</p>
<hr>
<h2 id="-data-pipeline-highlights" style="position:relative;"><a href="#-data-pipeline-highlights" aria-label=" data pipeline highlights permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>📊 Data Pipeline Highlights</h2>
<p>The <code class="language-text">data-core</code> module is responsible for ingesting:</p>
<ul>
<li>
<p><strong>OHLCV data</strong> from Binance/Bybit</p>
</li>
<li>
<p><strong>Sentiment/news data</strong> from CoinDesk, Yahoo, Twitter</p>
</li>
<li>
<p>Feature engineering with <code class="language-text">ta-lib</code>, including:</p>
<ul>
<li>RSI, MACD, Bollinger Bands, OBV, ATR, and custom signals</li>
</ul>
</li>
<li>
<p>Embedding of textual data using <code class="language-text">sentence-transformers</code> and <code class="language-text">LLMs</code></p>
</li>
</ul>
<div class="gatsby-code-title">technicals.py</div>
<div class="gatsby-highlight" data-language="python"><pre class="language-python"><code class="language-python"><span class="token keyword">def</span> <span class="token function">compute_macd</span><span class="token punctuation">(</span>df<span class="token punctuation">)</span><span class="token punctuation">:</span>
    macd <span class="token operator">=</span> df<span class="token punctuation">[</span><span class="token string">'close'</span><span class="token punctuation">]</span><span class="token punctuation">.</span>ewm<span class="token punctuation">(</span>span<span class="token operator">=</span><span class="token number">12</span><span class="token punctuation">)</span><span class="token punctuation">.</span>mean<span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token operator">-</span> df<span class="token punctuation">[</span><span class="token string">'close'</span><span class="token punctuation">]</span><span class="token punctuation">.</span>ewm<span class="token punctuation">(</span>span<span class="token operator">=</span><span class="token number">26</span><span class="token punctuation">)</span><span class="token punctuation">.</span>mean<span class="token punctuation">(</span><span class="token punctuation">)</span>
    signal <span class="token operator">=</span> macd<span class="token punctuation">.</span>ewm<span class="token punctuation">(</span>span<span class="token operator">=</span><span class="token number">9</span><span class="token punctuation">)</span><span class="token punctuation">.</span>mean<span class="token punctuation">(</span><span class="token punctuation">)</span>
    <span class="token keyword">return</span> macd<span class="token punctuation">,</span> signal</code></pre></div>
<hr>
<h2 id="-ai-modeling-model-engine" style="position:relative;"><a href="#-ai-modeling-model-engine" aria-label=" ai modeling model engine permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>🧠 AI Modeling: <code class="language-text">model-engine</code></h2>
<p>This module provides both supervised learning and interpretable AI via:</p>
<ul>
<li><strong>LSTM</strong> and <strong>Autoformer</strong> for time series prediction</li>
<li><strong>SHAP values</strong> and <strong>LIME</strong> for feature attribution</li>
<li>Support for both:
<ul>
<li>static offline training</li>
<li>or online/streaming signal classification</li>
</ul>
</li>
</ul>
<div class="gatsby-code-title">shap_wrapper.py</div>
<div class="gatsby-highlight" data-language="python"><pre class="language-python"><code class="language-python">explainer <span class="token operator">=</span> shap<span class="token punctuation">.</span>Explainer<span class="token punctuation">(</span>model<span class="token punctuation">,</span> sample_data<span class="token punctuation">)</span>
shap_values <span class="token operator">=</span> explainer<span class="token punctuation">(</span>data_point<span class="token punctuation">)</span>
shap<span class="token punctuation">.</span>plots<span class="token punctuation">.</span>waterfall<span class="token punctuation">(</span>shap_values<span class="token punctuation">[</span><span class="token number">0</span><span class="token punctuation">]</span><span class="token punctuation">)</span></code></pre></div>
<p>All models export signal objects in a common schema for consumption by the <code class="language-text">exec-core</code>.</p>
<hr>
<h2 id="️-execution-engine-exec-core" style="position:relative;"><a href="#%EF%B8%8F-execution-engine-exec-core" aria-label="️ execution engine exec core permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>🛡️ Execution Engine: <code class="language-text">exec-core</code></h2>
<p>Built with security and precision in mind, this module handles:</p>
<ul>
<li>Signal validation</li>
<li>Risk checking (drawdown cap, dynamic sizing)</li>
<li>Execution via real APIs (Binance) or paper simulation</li>
<li>CLI and Telegram fallback approvals</li>
</ul>
<div class="gatsby-code-title">trade_executor.py</div>
<div class="gatsby-highlight" data-language="python"><pre class="language-python"><code class="language-python"><span class="token keyword">if</span> risk_manager<span class="token punctuation">.</span>validate<span class="token punctuation">(</span>signal<span class="token punctuation">)</span><span class="token punctuation">:</span>
    executor<span class="token punctuation">.</span>place_order<span class="token punctuation">(</span>signal<span class="token punctuation">.</span>asset<span class="token punctuation">,</span> signal<span class="token punctuation">.</span>side<span class="token punctuation">,</span> size<span class="token punctuation">)</span>
<span class="token keyword">else</span><span class="token punctuation">:</span>
    fallback<span class="token punctuation">.</span>notify<span class="token punctuation">(</span>signal<span class="token punctuation">,</span> reason<span class="token operator">=</span><span class="token string">"risk_threshold_breached"</span><span class="token punctuation">)</span></code></pre></div>
<p>Trade logs and decisions are timestamped and persisted locally.</p>
<hr>
<h2 id="-ui-dashboard-ui" style="position:relative;"><a href="#-ui-dashboard-ui" aria-label=" ui dashboard ui permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>📺 UI: <code class="language-text">dashboard-ui</code></h2>
<p>Written in <strong>Next.js + Tailwind</strong>, the dashboard:</p>
<ul>
<li>Streams signal flow and execution feedback</li>
<li>Shows confidence metrics and model explanations</li>
<li>Uses <code class="language-text">TradingView</code> for OHLCV chart overlays</li>
<li>Offers real-time logs and theming (dark/light)</li>
</ul>
<div class="gatsby-code-title">LiveChart.tsx</div>
<div class="gatsby-highlight" data-language="tsx"><pre class="language-tsx"><code class="language-tsx"><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span><span class="token class-name">LightweightChart</span></span>
  <span class="token attr-name">data</span><span class="token script language-javascript"><span class="token script-punctuation punctuation">=</span><span class="token punctuation">{</span>ohlcv<span class="token punctuation">}</span></span>
  <span class="token attr-name">signals</span><span class="token script language-javascript"><span class="token script-punctuation punctuation">=</span><span class="token punctuation">{</span>executedSignals<span class="token punctuation">}</span></span>
  <span class="token attr-name">overlays</span><span class="token script language-javascript"><span class="token script-punctuation punctuation">=</span><span class="token punctuation">{</span>shapAttributions<span class="token punctuation">}</span></span>
<span class="token punctuation">/></span></span></code></pre></div>
<hr>
<h2 id="-real-time-notifications-alert-system" style="position:relative;"><a href="#-real-time-notifications-alert-system" aria-label=" real time notifications alert system permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>🔔 Real-Time Notifications: <code class="language-text">alert-system</code></h2>
<p>This service asynchronously pushes alerts to:</p>
<ul>
<li>Telegram channels</li>
<li>Discord webhooks</li>
<li>Any custom webhook endpoint</li>
</ul>
<p>It uses <code class="language-text">jinja2</code> templating, retries, exponential backoff, and tokenized configs via <code class="language-text">.env</code>.</p>
<div class="gatsby-code-title">telegram_alert.py</div>
<div class="gatsby-highlight" data-language="python"><pre class="language-python"><code class="language-python"><span class="token keyword">def</span> <span class="token function">send</span><span class="token punctuation">(</span>signal<span class="token punctuation">:</span> TradeSignal<span class="token punctuation">)</span><span class="token punctuation">:</span>
    message <span class="token operator">=</span> render_template<span class="token punctuation">(</span><span class="token string">"signal_message.md"</span><span class="token punctuation">,</span> signal<span class="token punctuation">)</span>
    bot<span class="token punctuation">.</span>send_message<span class="token punctuation">(</span>chat_id<span class="token operator">=</span>chat<span class="token punctuation">,</span> text<span class="token operator">=</span>message<span class="token punctuation">,</span> parse_mode<span class="token operator">=</span><span class="token string">"Markdown"</span><span class="token punctuation">)</span></code></pre></div>
<p>Logs are grouped by date in <code class="language-text">/logs/alerts/YYYY-MM-DD.log</code>.</p>
<hr>
<h2 id="-testing--cicd" style="position:relative;"><a href="#-testing--cicd" aria-label=" testing  cicd permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>🧪 Testing &#x26; CI/CD</h2>
<p>Each module is:</p>
<ul>
<li>Fully unit-tested via <code class="language-text">pytest</code> or <code class="language-text">jest</code></li>
<li>Integrated into <code class="language-text">.gitlab-ci.yml</code> for linting, security checks, and test execution</li>
<li>Built for containerized environments with Docker and optional support for Kubernetes Helm charts</li>
</ul>
<hr>
<h2 id="-final-thoughts" style="position:relative;"><a href="#-final-thoughts" aria-label=" final thoughts permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>🌍 Final Thoughts</h2>
<p>Developing NeuroTradeX was an exercise in bringing together:</p>
<ul>
<li><strong>Machine learning</strong></li>
<li><strong>Financial engineering</strong></li>
<li><strong>Distributed systems</strong></li>
<li><strong>Explainability</strong></li>
<li><strong>Human-in-the-loop design</strong></li>
</ul>
<p>Its open-source nature allows contributors, researchers, and traders to explore, extend, and build upon a transparent architecture built for reliability and real-world applicability.</p>
<p>Whether you're working in DeFi, TradFi, or AI-driven quantitative systems, NeuroTradeX provides a foundation ready to grow.</p>
<blockquote>
<p><em>Repository: <a href="https://gitlab.com/neurotradex" target="_blank" rel="nofollow noopener noreferrer">gitlab.com/neurotradex</a></em></p>
</blockquote>
<hr>]]></content>
        <category label="AI"/>
        <category label="Trading"/>
        <category label="Crypto"/>
        <category label="Fintech"/>
        <category label="Engineering"/>
        <category label="Rust"/>
        <category label="Python"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[BFT with PQ Primitives: When Crypto Costs Dominate]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-06-bft-with-pq-primitives-when-crypto-costs-dominate</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-06-bft-with-pq-primitives-when-crypto-costs-dominate"/>
        <updated>2025-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (June 2025): BFT with PQ Primitives: When Crypto Costs Dominate.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>BFT with PQ Primitives: When Crypto Costs Dominate</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Define success metrics beyond “enabled”: cohorts, failures, and evidence.</li>
<li>Hybrid is an operational mode: deploy, monitor, rollback—not a paper design.</li>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Switching algorithms without inventorying where secrets are used.</li>
<li>Assuming performance impacts will be negligible.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Operationalize early: rollback and monitoring are part of the design.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Operational lessons relevant to rotation and recovery at scale.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Quantum-Resilient Identity: Device + Human, Online + Offline]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-05-quantum-resilient-identity-device-human-online-offline</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-05-quantum-resilient-identity-device-human-online-offline"/>
        <updated>2025-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (May 2025): Quantum-Resilient Identity: Device + Human, Online + Offline.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Quantum-Resilient Identity: Device + Human, Online + Offline</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Define success metrics beyond “enabled”: cohorts, failures, and evidence.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Switching algorithms without inventorying where secrets are used.</li>
<li>Relying on ‘automatic’ negotiation without downgrade resistance.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>PQ readiness is a systems program: crypto, networking, ops, and UX must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[CPZKp - Building Practical Zero-Knowledge Proofs in Rust from Scratch]]></title>
        <id>https://mayckongiovani.xyz/pensieve/cpzkp-chaum-pedersen-zkp</id>
        <link href="https://mayckongiovani.xyz/pensieve/cpzkp-chaum-pedersen-zkp"/>
        <updated>2025-04-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[A deep technical dive into the motivations, design, and implementation of CPZKp, a Chaum-Pedersen based ZK authentication library in Rust.]]></summary>
        <content type="html"><![CDATA[<p><img src="./cpzkp-banner.jpg" alt="CPZKp Banner"></p>
<blockquote>
<p>“You don’t start with ZK. ZK starts with you.” — someone probably</p>
</blockquote>
<h2 id="introduction" style="position:relative;"><a href="#introduction" aria-label="introduction permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Introduction</h2>
<p>In late 2023, the seed for CPZKp was planted: a lightweight, modular, and no-bullshit Rust library for zero-knowledge proofs using the Chaum-Pedersen protocol. The motivation was personal and practical — to build a foundation that respects cryptographic rigor, while remaining usable in real-world systems, especially those relying on elliptic curve cryptography (ECC).</p>
<p>This post is not a “hello world.” It’s a journey — from group theory to Curve25519 bindings, from low-level proof serialization to full WASM exports. If you're looking for a project that goes from first principles to full-stack cryptography, buckle up.</p>
<hr>
<h2 id="motivation" style="position:relative;"><a href="#motivation" aria-label="motivation permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Motivation</h2>
<p>By 2023, a few realities had become clear:</p>
<ol>
<li>Most zero-knowledge implementations are either academic toys or tightly bound to specific use cases (blockchains, zkSNARKs, etc).</li>
<li>Libraries like <code class="language-text">bulletproofs</code> or <code class="language-text">zkcrypto</code> are excellent, but bloated when you need just authentication proofs.</li>
<li>There was no ergonomic, extensible, and no_std-capable Chaum-Pedersen implementation in Rust.</li>
</ol>
<blockquote>
<p>CPZKp was born from frustration — and fascination.</p>
</blockquote>
<hr>
<h2 id="what-is-the-chaum-pedersen-zkp" style="position:relative;"><a href="#what-is-the-chaum-pedersen-zkp" aria-label="what is the chaum pedersen zkp permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What is the Chaum-Pedersen ZKP?</h2>
<p>It’s a proof of equality of discrete logs:
If you know <code class="language-text">x</code> such that <code class="language-text">g^x = A</code> and <code class="language-text">h^x = B</code>, you can prove knowledge of <code class="language-text">x</code> without revealing it.</p>
<p>This is essential in:</p>
<ul>
<li>Secure authentication (no password ever transmitted)</li>
<li>Key exchange validation</li>
<li>Voting and threshold cryptography</li>
</ul>
<p>The challenge was: how do we express this cleanly across scalar groups and ECC, and still support Curve25519?</p>
<hr>
<h2 id="designing-the-library" style="position:relative;"><a href="#designing-the-library" aria-label="designing the library permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Designing the Library</h2>
<p>We started with a few key design principles:</p>
<h3 id="protocols-as-traits" style="position:relative;"><a href="#protocols-as-traits" aria-label="protocols as traits permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Protocols as Traits</h3>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">ZkpProtocol</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Secret</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Public</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Proof</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">prove</span><span class="token punctuation">(</span>secret<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Secret</span><span class="token punctuation">,</span> pub_input<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Public</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Proof</span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">verify</span><span class="token punctuation">(</span>public<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Public</span><span class="token punctuation">,</span> proof<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Proof</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span></code></pre></div>
<p>Protocols are swappable. This allows for different backends (<code class="language-text">secp256k1</code>, <code class="language-text">Ristretto</code>, <code class="language-text">ScalarGroup</code>) and experimentation with variants.</p>
<h3 id="scalar-and-ecc-support" style="position:relative;"><a href="#scalar-and-ecc-support" aria-label="scalar and ecc support permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Scalar and ECC Support</h3>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">mod</span> <span class="token module-declaration namespace">scalar</span><span class="token punctuation">;</span>
<span class="token keyword">mod</span> <span class="token module-declaration namespace">ecc</span><span class="token punctuation">;</span></code></pre></div>
<p>Internally, both conform to common traits like <code class="language-text">GroupElement</code>, enabling unified logic in proof generators and verifiers.</p>
<hr>
<h2 id="serialization-making-proofs-portable" style="position:relative;"><a href="#serialization-making-proofs-portable" aria-label="serialization making proofs portable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Serialization: Making Proofs Portable</h2>
<p>One key requirement was to serialize proofs for transmission.</p>
<p>We used <code class="language-text">serde</code> and implemented robust custom serialization for scalar and ECC formats:</p>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Serialize, Deserialize)]</span>
<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">ChaumPedersenProof</span> <span class="token punctuation">{</span>
    <span class="token keyword">pub</span> t1<span class="token punctuation">:</span> <span class="token class-name">GroupElement</span><span class="token punctuation">,</span>
    <span class="token keyword">pub</span> t2<span class="token punctuation">:</span> <span class="token class-name">GroupElement</span><span class="token punctuation">,</span>
    <span class="token keyword">pub</span> challenge<span class="token punctuation">:</span> <span class="token class-name">Scalar</span><span class="token punctuation">,</span>
    <span class="token keyword">pub</span> response<span class="token punctuation">:</span> <span class="token class-name">Scalar</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span></code></pre></div>
<p>This allowed JSON/web compatibility from day one.</p>
<hr>
<h2 id="testing-the-unprovable" style="position:relative;"><a href="#testing-the-unprovable" aria-label="testing the unprovable permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Testing the Unprovable</h2>
<p>We didn’t stop at unit tests. CPZKp includes:</p>
<ul>
<li>🔁 Property-based tests (<code class="language-text">proptest</code>)</li>
<li>🧪 Negative tests (e.g., corrupt challenge / invalid response)</li>
<li>🧬 Deterministic regression seeds for CI stability</li>
<li>🔍 Manual validation of group assumptions</li>
</ul>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token macro property">proptest!</span> <span class="token punctuation">{</span>
    <span class="token attribute attr-name">#[test]</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">prove_and_verify_should_hold</span><span class="token punctuation">(</span><span class="token keyword">ref</span> s <span class="token keyword">in</span> <span class="token function">any</span><span class="token punctuation">::</span><span class="token operator">&lt;</span><span class="token class-name">Scalar</span><span class="token operator">></span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">)</span> <span class="token punctuation">{</span>
        <span class="token keyword">let</span> <span class="token punctuation">(</span>pk<span class="token punctuation">,</span> proof<span class="token punctuation">)</span> <span class="token operator">=</span> <span class="token class-name">ChaumPedersen</span><span class="token punctuation">::</span><span class="token function">prove</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>s<span class="token punctuation">)</span><span class="token punctuation">;</span>
        <span class="token macro property">prop_assert!</span><span class="token punctuation">(</span><span class="token class-name">ChaumPedersen</span><span class="token punctuation">::</span><span class="token function">verify</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>pk<span class="token punctuation">,</span> <span class="token operator">&amp;</span>proof<span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token punctuation">}</span>
<span class="token punctuation">}</span></code></pre></div>
<hr>
<h2 id="wasm-and-python-bindings" style="position:relative;"><a href="#wasm-and-python-bindings" aria-label="wasm and python bindings permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>WASM and Python Bindings</h2>
<p>We wanted this lib usable in:</p>
<ul>
<li>dApps (via WASM)</li>
<li>Python systems (via <code class="language-text">pyo3</code>)</li>
</ul>
<p>Result:</p>
<ul>
<li><code class="language-text">wasm_bindgen</code> wrapper in <code class="language-text">wasm.rs</code></li>
<li><code class="language-text">maturin</code> build in <code class="language-text">bindings/python</code></li>
</ul>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[wasm_bindgen]</span>
<span class="token keyword">pub</span> <span class="token keyword">fn</span> <span class="token function-definition function">prove_json</span><span class="token punctuation">(</span>sk<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token keyword">str</span><span class="token punctuation">,</span> pk<span class="token punctuation">:</span> <span class="token operator">&amp;</span><span class="token keyword">str</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">String</span> <span class="token punctuation">{</span>
    <span class="token punctuation">...</span>
<span class="token punctuation">}</span></code></pre></div>
<p>Now CPZKp runs in browsers and Jupyter notebooks.</p>
<hr>
<h2 id="cli-tool" style="position:relative;"><a href="#cli-tool" aria-label="cli tool permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>CLI Tool</h2>
<p>We implemented a command-line utility for quick usage:</p>
<div class="gatsby-highlight" data-language="bash"><pre class="language-bash"><code class="language-bash">cpzkp gen-key
cpzkp prove <span class="token parameter variable">--msg</span> <span class="token string">"authenticate me"</span>
cpzkp verify <span class="token parameter variable">--proof</span> proof.json</code></pre></div>
<p>Backed by <code class="language-text">clap</code>, this made it ideal for scripting, automation, or even classroom demos.</p>
<hr>
<h2 id="performance" style="position:relative;"><a href="#performance" aria-label="performance permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Performance</h2>
<p>Benchmarks were done using <code class="language-text">criterion</code>. Example:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">group                           time
ChaumPedersen_scalar_prove     1.2 µs
ChaumPedersen_ecc_prove        4.8 µs
ChaumPedersen_verify_scalar    0.9 µs
ChaumPedersen_verify_ecc       3.7 µs</code></pre></div>
<p>Enough for embedded use and authentication services.</p>
<hr>
<h2 id="what-we-learned" style="position:relative;"><a href="#what-we-learned" aria-label="what we learned permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What We Learned</h2>
<ul>
<li>Traits + generic cryptographic algebra = superpowers.</li>
<li>Testing edge cases in ZKP is not optional — it’s life.</li>
<li>Targeting WASM early saves time later.</li>
<li>Your build scripts are part of your UX.</li>
</ul>
<hr>
<h2 id="roadmap" style="position:relative;"><a href="#roadmap" aria-label="roadmap permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Roadmap</h2>
<ul>
<li>🔒 Formal audit and fuzz testing</li>
<li>📦 Publish to crates.io and PyPI</li>
<li>🧱 Add Bulletproofs-style range proofs</li>
<li>🔄 Add MPC-friendly APIs</li>
<li>🌐 Playground (CPZKp + Monaco + WebWasm)</li>
</ul>
<hr>
<h2 id="conclusion" style="position:relative;"><a href="#conclusion" aria-label="conclusion permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Conclusion</h2>
<p>CPZKp isn’t another toy crypto lib. It’s a usable, modular ZKP toolkit built from real-world needs, shaped by frustration, and delivered with love — in Rust.</p>
<p>Try it. Break it. Extend it.</p>
<hr>
<p><a href="https://github.com/doomhammerhell/CPZKp" target="_blank" rel="nofollow noopener noreferrer">GitHub</a></p>]]></content>
        <category label="Rust"/>
        <category label="cryptography"/>
        <category label="zero-knowledge"/>
        <category label="chaum-pedersen"/>
        <category label="ecc"/>
        <category label="curve25519"/>
        <category label="security"/>
        <category label="portfolio"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Post-Quantum Cryptography for Industrial IoT with Rust]]></title>
        <id>https://mayckongiovani.xyz/pensieve/pqc-iiot-post-quantum-cryptography-rust</id>
        <link href="https://mayckongiovani.xyz/pensieve/pqc-iiot-post-quantum-cryptography-rust"/>
        <updated>2025-04-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[A deep technical dive into the pqc-iiot Rust crate for secure, no_std, post-quantum cryptography in embedded and IIoT environments.]]></summary>
        <content type="html"><![CDATA[<p><img src="./pqc-iiot-banner.jpg" alt="Post-Quantum Cryptography for IIoT"></p>
<blockquote>
<p>"Quantum-safe infrastructure starts at the silicon level. We built <code class="language-text">pqc-iiot</code> to be that foundation."</p>
</blockquote>
<h2 id="why-we-built-pqc-iiot" style="position:relative;"><a href="#why-we-built-pqc-iiot" aria-label="why we built pqc iiot permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why We Built <code class="language-text">pqc-iiot</code></h2>
<p>The looming threat of quantum computing has made it imperative to rethink how we secure digital communication — especially in <strong>Industrial IoT (IIoT)</strong> systems, where devices are often deployed for decades with limited ability to patch or upgrade.</p>
<p><strong><code class="language-text">pqc-iiot</code></strong> is a modular, <code class="language-text">no_std</code>-compatible Rust crate designed from scratch to bring <strong>post-quantum cryptographic primitives</strong> to resource-constrained devices.</p>
<p>Our goal was to build a <strong>portable, memory-efficient, and secure-by-design library</strong> that supports <strong>Kyber</strong> (KEM), <strong>Falcon</strong> (signatures), and other NIST PQC algorithms with real-world applicability in constrained IIoT environments.</p>
<h2 id="design-requirements" style="position:relative;"><a href="#design-requirements" aria-label="design requirements permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design Requirements</h2>
<p>We started with some hard non-negotiables:</p>
<ul>
<li><strong>Post-Quantum primitives only</strong> — no hybrid fallback to RSA/ECC</li>
<li><strong>Must compile with <code class="language-text">#![no_std]</code></strong> and run on microcontrollers</li>
<li><strong>Zero-allocation</strong> with strict memory control via <code class="language-text">heapless</code></li>
<li><strong>Constant-time operations</strong> to resist side-channel attacks</li>
<li><strong>High-level API</strong> for easy adoption across MQTT, CoAP, LoRaWAN, etc.</li>
</ul>
<h2 id="architecture-overview" style="position:relative;"><a href="#architecture-overview" aria-label="architecture overview permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Architecture Overview</h2>
<p>The crate follows a modular layout:</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">src/
├── kem.rs         # Kyber / Saber (KEM)
├── sign.rs        # Falcon / Dilithium (signatures)
├── profile.rs     # CryptoProfile abstraction layer
├── utils.rs       # RNG, hashing, key encoding
├── lib.rs         # Public API</code></pre></div>
<h3 id="supported-algorithms" style="position:relative;"><a href="#supported-algorithms" aria-label="supported algorithms permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Supported Algorithms</h3>
<p>We currently support:</p>
<ul>
<li><strong>Kyber512, Kyber768, Kyber1024</strong></li>
<li><strong>Falcon-512, Falcon-1024</strong></li>
<li><strong>Dilithium (experimental)</strong></li>
<li><strong>Saber (KEM alternative)</strong></li>
<li><strong>BIKE (experimental)</strong></li>
</ul>
<p>These can be selected via Cargo features, or grouped into <strong>profiles</strong>.</p>
<h2 id="crypto-profiles" style="position:relative;"><a href="#crypto-profiles" aria-label="crypto profiles permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Crypto Profiles</h2>
<p>To simplify configuration and usage in constrained environments, we introduced <code class="language-text">CryptoProfile</code>, a high-level abstraction for pairing a KEM with a digital signature scheme.</p>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">let</span> profile <span class="token operator">=</span> <span class="token class-name">CryptoProfile</span><span class="token punctuation">::</span><span class="token class-name">KyberFalcon</span><span class="token punctuation">;</span>
<span class="token keyword">let</span> <span class="token punctuation">(</span>pk<span class="token punctuation">,</span> sk<span class="token punctuation">)</span> <span class="token operator">=</span> profile<span class="token punctuation">.</span><span class="token function">generate_keypair</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
<span class="token keyword">let</span> ciphertext <span class="token operator">=</span> profile<span class="token punctuation">.</span><span class="token function">encapsulate</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>pk<span class="token punctuation">)</span><span class="token punctuation">;</span>
<span class="token keyword">let</span> signature <span class="token operator">=</span> profile<span class="token punctuation">.</span><span class="token function">sign</span><span class="token punctuation">(</span><span class="token operator">&amp;</span>sk<span class="token punctuation">,</span> message<span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre></div>
<p>This allows developers to pick from balanced, high-security, or low-power profiles depending on hardware capabilities.</p>
<h2 id="integration-with-iiot-protocols" style="position:relative;"><a href="#integration-with-iiot-protocols" aria-label="integration with iiot protocols permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Integration with IIoT Protocols</h2>
<p>The library was built to be integrated into:</p>
<ul>
<li><strong>MQTT stacks</strong> (e.g. rumqttc)</li>
<li><strong>CoAP frameworks</strong> (<code class="language-text">coap-lite</code>)</li>
<li><strong>Custom serial protocols</strong> for edge gateways</li>
</ul>
<blockquote>
<p>Secure payloads are encapsulated using Kyber and authenticated with Falcon, enabling end-to-end post-quantum secure messaging.</p>
</blockquote>
<h2 id="performance--footprint" style="position:relative;"><a href="#performance--footprint" aria-label="performance  footprint permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Performance &#x26; Footprint</h2>
<table>
<thead>
<tr>
<th>Operation</th>
<th>Kyber512</th>
<th>Falcon512</th>
<th>Platform</th>
</tr>
</thead>
<tbody>
<tr>
<td>Keygen</td>
<td>~3.1ms</td>
<td>~9.4ms</td>
<td>STM32F4 (168MHz)</td>
</tr>
<tr>
<td>Encaps/Decaps</td>
<td>~2.8ms</td>
<td>N/A</td>
<td></td>
</tr>
<tr>
<td>Sign/Verify</td>
<td>N/A</td>
<td>~8.9ms</td>
<td></td>
</tr>
<tr>
<td>RAM (peak)</td>
<td>&#x3C;32KB</td>
<td>&#x3C;45KB</td>
<td></td>
</tr>
</tbody>
</table>
<ul>
<li>All timings are constant-time implementations</li>
<li>Measured with <code class="language-text">cargo-embed</code> on <code class="language-text">thumbv7em-none-eabihf</code></li>
</ul>
<h2 id="security-considerations" style="position:relative;"><a href="#security-considerations" aria-label="security considerations permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security Considerations</h2>
<ul>
<li>RNG is based on <code class="language-text">rand_core</code> and configurable to use hardware TRNG</li>
<li>Wiped secrets using <code class="language-text">zeroize</code> traits</li>
<li>Internal operations audited to prevent timing leaks</li>
</ul>
<h2 id="development-process" style="position:relative;"><a href="#development-process" aria-label="development process permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Development Process</h2>
<ol>
<li><strong>Phase 1</strong> — Research &#x26; algorithm selection</li>
<li><strong>Phase 2</strong> — <code class="language-text">no_std</code> crate skeleton, Kyber+Falcon working</li>
<li><strong>Phase 3</strong> — MQTT/CoAP integration, secure messaging</li>
<li><strong>Phase 4</strong> — Benchmarks, fuzz testing, memory profiling</li>
<li><strong>Phase 5</strong> — Expansion with Saber, Dilithium, BIKE</li>
<li><strong>Phase 6</strong> — Introduction of <code class="language-text">CryptoProfile</code> abstraction</li>
</ol>
<h2 id="limitations" style="position:relative;"><a href="#limitations" aria-label="limitations permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Limitations</h2>
<ul>
<li><strong>No TLS integration yet</strong> — planned for Phase 7 (rustls hybrid support)</li>
<li><strong>Only deterministic keygen</strong> — no on-device entropy enhancement</li>
<li><strong>Experimental algorithms not production-hardened</strong></li>
</ul>
<h2 id="future-directions" style="position:relative;"><a href="#future-directions" aria-label="future directions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Future Directions</h2>
<ul>
<li>WASM demo + WebSerial secure handshake</li>
<li>Integration with Zephyr RTOS and RIOT</li>
<li>Dynamic crypto profile loading via config</li>
<li>NIST-compliant key formatting (SP 800-56C)</li>
<li>PQ-TLS bindings for constrained TLS over MQTT</li>
</ul>
<h2 id="try-it-now" style="position:relative;"><a href="#try-it-now" aria-label="try it now permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Try It Now</h2>
<div class="gatsby-highlight" data-language="bash"><pre class="language-bash"><code class="language-bash"><span class="token function">cargo</span> <span class="token function">add</span> pqc-iiot <span class="token parameter variable">--git</span> https://github.com/doomhammerhell/pqc-iiot</code></pre></div>
<h2 id="final-thoughts" style="position:relative;"><a href="#final-thoughts" aria-label="final thoughts permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Final Thoughts</h2>
<blockquote>
<p>We don’t just need stronger encryption — we need encryption that survives the next 30 years.</p>
</blockquote>
<p><code class="language-text">pqc-iiot</code> is an evolving foundation for secure-by-default IIoT systems. Whether you’re securing sensors, edge gateways, or autonomous machines, this crate is designed to give you the cryptographic edge in a quantum future.</p>
<hr>
<p>💬 Questions? PRs and issues welcome at <a href="https://github.com/doomhammerhell/pqc-iiot" target="_blank" rel="nofollow noopener noreferrer">GitHub</a>.</p>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">
---</code></pre></div>]]></content>
        <category label="post-quantum"/>
        <category label="rust"/>
        <category label="iiot"/>
        <category label="cryptography"/>
        <category label="no_std"/>
        <category label="embedded"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC for Blockchain Signatures: Wallet UX, Size, and Verification Cost]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-04-pqc-for-blockchain-signatures-wallet-ux-size-and-verificatio</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-04-pqc-for-blockchain-signatures-wallet-ux-size-and-verificatio"/>
        <updated>2025-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (April 2025): PQC for Blockchain Signatures: Wallet UX, Size, and Verification Cost.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>PQC for Blockchain Signatures: Wallet UX, Size, and Verification Cost</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Hybrid is an operational mode: deploy, monitor, rollback—not a paper design.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Define success metrics beyond “enabled”: cohorts, failures, and evidence.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you stop downgrade under active adversaries?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Key and certificate lifecycles outlive application versions.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming performance impacts will be negligible.</li>
<li>Relying on ‘automatic’ negotiation without downgrade resistance.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<p>Treat ops as part of the protocol: monitoring, rollback, and incident response.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>PQ readiness is a systems program: crypto, networking, ops, and UX must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--1">(<a href="#bib-rfc8446">1</a>)</span> — A useful reference for handshake structure and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Quantum-Safe Secure Boot: Firmware Roots and PQ Signatures]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-03-quantum-safe-secure-boot-firmware-roots-and-pq-signatures</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-03-quantum-safe-secure-boot-firmware-roots-and-pq-signatures"/>
        <updated>2025-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (March 2025): Quantum-Safe Secure Boot: Firmware Roots and PQ Signatures.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Quantum-Safe Secure Boot: Firmware Roots and PQ Signatures</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Define success metrics beyond “enabled”: cohorts, failures, and evidence.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Migration risk is operational: inventory, rollout, rollback, and monitoring.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating PQ migration as a single deployment event.</li>
<li>Switching algorithms without inventorying where secrets are used.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Risk is a function of exposure and lifetime:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo>≈</mo><mrow><mi mathvariant="normal">e</mi><mi mathvariant="normal">x</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">e</mi></mrow><mo>×</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">b</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{risk} \approx \mathrm{exposure} \times \mathrm{lifetime} \times \mathrm{adversary\_capability}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord"><span class="mord mathrm">risk</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">exposure</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.7778em;vertical-align:-0.0833em;"></span><span class="mord"><span class="mord mathrm">lifetime</span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">adversary_capability</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  inventory<span class="token text string">["Inventory"]</span> <span class="token arrow operator">--></span> prioritize<span class="token text string">["Prioritize"]</span>
  prioritize <span class="token arrow operator">--></span> hybrid<span class="token text string">["Hybrid Deploy"]</span>
  hybrid <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor"]</span>
  monitor <span class="token arrow operator">--></span> cutover<span class="token text string">["Cutover"]</span>
  cutover <span class="token arrow operator">--></span> deprecate<span class="token text string">["Deprecate Old"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Design hybrid modes with explicit binding and observable outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--2">(<a href="#bib-nistpqc">2</a>)</span> — The standardization baseline for PQC readiness programs.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Hybrid Key Management: Rotations Across Algorithm Families]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-02-hybrid-key-management-rotations-across-algorithm-families</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-02-hybrid-key-management-rotations-across-algorithm-families"/>
        <updated>2025-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (February 2025): Hybrid Key Management: Rotations Across Algorithm Families.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Hybrid Key Management: Rotations Across Algorithm Families</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Measure cost shifts (CPU/bandwidth) and adapt DoS defenses accordingly.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>How do you stop downgrade under active adversaries?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>How do you manage mixed deployments across regions and vendors?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
<li>Adversaries record traffic today (HNDL) and attack later.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Switching algorithms without inventorying where secrets are used.</li>
<li>Treating PQ migration as a single deployment event.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat ops as part of the protocol: monitoring, rollback, and incident response.</p>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  threat<span class="token text string">["Threat Model (quantum + classical)"]</span> <span class="token arrow operator">--></span> design<span class="token text string">["Protocol Design"]</span>
  design <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (no_std where needed)"]</span>
  impl <span class="token arrow operator">--></span> verify<span class="token text string">["Verification (tests + formal)"]</span>
  verify <span class="token arrow operator">--></span> ops<span class="token text string">["Operationalization (rotation + monitoring)"]</span>
  ops <span class="token arrow operator">--></span> threat</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Design hybrid modes with explicit binding and observable outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--2">(<a href="#bib-rfc8446">2</a>)</span> — A useful reference for handshake structure and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Quantum Threat Modeling for Infrastructure: What Changes, What Doesn’t]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2025-01-quantum-threat-modeling-for-infrastructure-what-changes-what</id>
        <link href="https://mayckongiovani.xyz/pensieve/2025-01-quantum-threat-modeling-for-infrastructure-what-changes-what"/>
        <updated>2025-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (January 2025): Quantum Threat Modeling for Infrastructure: What Changes, What Doesn’t.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Quantum-Resilient Systems Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Quantum Threat Modeling for Infrastructure: What Changes, What Doesn’t</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Inventory long-lived secrets first; you can’t migrate what you can’t locate.</li>
<li>Hybrid is an operational mode: deploy, monitor, rollback—not a paper design.</li>
<li>Downgrade resistance must be explicit and tested under active attackers.</li>
<li>Define safety properties before performance goals.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Long-lived devices and PKI lifecycles are the hard constraint.</li>
<li>Hybrid protocols fail if binding is unclear or downgrade is possible.</li>
<li>Quantum risk is uneven: some secrets must last decades, others do not.</li>
<li>Cost changes drive new DoS surfaces; defenses must evolve.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you validate resilience (DoS, side channels, rollback, compromise)?</li>
<li>What does rotation look like at fleet scale (devices, certs, tunnels, identities)?</li>
<li>How do you define success metrics for PQ readiness beyond “enabled”?</li>
<li>What secrets must remain confidential for 10–30 years (and where are they today)?</li>
<li>Which protocols need hybrid now, and which can wait without regret?</li>
<li>How do you stop downgrade under active adversaries?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Key and certificate lifecycles outlive application versions.</li>
<li>Some environments require constrained implementations (no_std, embedded).</li>
<li>Operational teams need safe playbooks; crypto changes are not one-off.</li>
<li>Rollouts happen under partial adoption; compatibility matters.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on ‘automatic’ negotiation without downgrade resistance.</li>
<li>Assuming performance impacts will be negligible.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be explicit and transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Inventory first. You can’t migrate what you can’t locate.</p>
<p>Make downgrade resistance explicit and test it like a security feature.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  threat<span class="token text string">["Threat Model (quantum + classical)"]</span> <span class="token arrow operator">--></span> design<span class="token text string">["Protocol Design"]</span>
  design <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (no_std where needed)"]</span>
  impl <span class="token arrow operator">--></span> verify<span class="token text string">["Verification (tests + formal)"]</span>
  verify <span class="token arrow operator">--></span> ops<span class="token text string">["Operationalization (rotation + monitoring)"]</span>
  ops <span class="token arrow operator">--></span> threat</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Operationalize early: rollback and monitoring are part of the design.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// PQ migration note: "enabled" is not "safe" unless binding and downgrade resistance are explicit.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop tests</strong> across stacks and versions.</li>
<li><strong>Downgrade simulations</strong> with active attackers.</li>
<li><strong>Side-channel audits</strong> for constrained implementations.</li>
<li><strong>Performance profiling</strong> under load to quantify DoS risk.</li>
<li><strong>Rotation drills</strong>: certificates, tunnels, device identities.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Maintain an inventory of long-lived secrets and their lifetimes.</li>
<li>Practice emergency deprecation (turn off broken algorithms quickly).</li>
<li>Define compatibility windows and communicate them to stakeholders.</li>
<li>Roll out hybrid with canaries and explicit rollback triggers.</li>
<li>Add telemetry for algorithm negotiation and failure modes.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational lessons relevant to rotation and recovery at scale.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--2">(<a href="#bib-rfc8446">2</a>)</span> — A useful reference for handshake structure and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which protocol surfaces are most exposed to HNDL risk in your environment?</li>
<li>What is your plan for third-party dependencies that can’t migrate quickly?</li>
<li>What is your minimal ‘safe mode’ when PQ paths fail?</li>
<li>How do you prevent configuration drift from re-enabling weak modes?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational lessons relevant to rotation and recovery at scale.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — The standardization baseline for PQC readiness programs.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — A useful reference for handshake structure and downgrade resistance patterns.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="security-critical-infrastructure"/>
        <category label="protocol-design"/>
        <category label="cryptography"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Designing for Catastrophic Failure: Compartmentalization and Recovery]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-12-designing-for-catastrophic-failure-compartmentalization-and-</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-12-designing-for-catastrophic-failure-compartmentalization-and-"/>
        <updated>2024-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (December 2024): Designing for Catastrophic Failure: Compartmentalization and Recovery.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Designing for Catastrophic Failure: Compartmentalization and Recovery</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Dependencies (DNS, routing, PKI) are shared attack surfaces—plan containment.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
<li>Relying on dashboards that vanish during the incident.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Resilience is about containment:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>damage</mtext><mo>≤</mo><munder><mo>∑</mo><mi>i</mi></munder><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mtext>with</mtext><mspace width="1em"></mspace><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mtext> bounded by design</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{damage} \le \sum_i \text{blast\_radius}(i)\quad\text{with}\quad \text{blast\_radius}(i)\ \text{bounded by design}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">damage</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3277em;vertical-align:-1.2777em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8723em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.2777em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">with</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace"> </span><span class="mord text"><span class="mord">bounded by design</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  edge<span class="token text string">["Edge (rate limits + WAF)"]</span> <span class="token arrow operator">--></span> core<span class="token text string">["Core Services"]</span>
  core <span class="token arrow operator">--></span> data<span class="token text string">["Data Plane"]</span>
  data <span class="token arrow operator">--></span> control<span class="token text string">["Control Plane"]</span>
  control <span class="token arrow operator">--></span> edge
  siem<span class="token text string">["Detection/Response"]</span> <span class="token arrow operator">--></span> core
  siem <span class="token arrow operator">--></span> edge</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer containment over heroics: isolate blast radius, keep core correct.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Evidence checklist:
- Immutable logs (append-only)
- Signed audit events
- Time sync monitoring
- Dependency health snapshots
- Config change history</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[ZKP Systems Engineering: Provers, Verifiers, and Operational Cost]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-11-zkp-systems-engineering-provers-verifiers-and-operational-co</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-11-zkp-systems-engineering-provers-verifiers-and-operational-co"/>
        <updated>2024-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (November 2024): ZKP Systems Engineering: Provers, Verifiers, and Operational Cost.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>ZKP Systems Engineering: Provers, Verifiers, and Operational Cost</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Degraded modes are security decisions; write them down and test them.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating degraded modes as “we’ll decide later.”</li>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  attack<span class="token text string">["Attack"]</span> <span class="token arrow operator">--></span> detect<span class="token text string">["Detect"]</span>
  detect <span class="token arrow operator">--></span> contain<span class="token text string">["Contain"]</span>
  contain <span class="token arrow operator">--></span> recover<span class="token text string">["Recover"]</span>
  recover <span class="token arrow operator">--></span> learn<span class="token text string">["Learn/Regress"]</span>
  learn <span class="token arrow operator">--></span> detect</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer containment over heroics: isolate blast radius, keep core correct.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Formal Verification of Crypto Protocols: Models, Gaps, and Pain]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-10-formal-verification-of-crypto-protocols-models-gaps-and-pain</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-10-formal-verification-of-crypto-protocols-models-gaps-and-pain"/>
        <updated>2024-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (October 2024): Formal Verification of Crypto Protocols: Models, Gaps, and Pain.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Formal Verification of Crypto Protocols: Models, Gaps, and Pain</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Degraded modes are security decisions; write them down and test them.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
<li>Degraded modes without explicit policy become accidental vulnerabilities.</li>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
<li>Assuming WAF/rate limits are sufficient without architecture changes.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  attack<span class="token text string">["Attack"]</span> <span class="token arrow operator">--></span> detect<span class="token text string">["Detect"]</span>
  detect <span class="token arrow operator">--></span> contain<span class="token text string">["Contain"]</span>
  contain <span class="token arrow operator">--></span> recover<span class="token text string">["Recover"]</span>
  recover <span class="token arrow operator">--></span> learn<span class="token text string">["Learn/Regress"]</span>
  learn <span class="token arrow operator">--></span> detect</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Degraded modes are design artifacts. Write them down and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secure Enclaves in Distributed Systems: Remote Attestation and Trust]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-09-secure-enclaves-in-distributed-systems-remote-attestation-an</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-09-secure-enclaves-in-distributed-systems-remote-attestation-an"/>
        <updated>2024-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (September 2024): Secure Enclaves in Distributed Systems: Remote Attestation and Trust.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secure Enclaves in Distributed Systems: Remote Attestation and Trust</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Attackers can manipulate routing and DNS indirectly (upstream failures, BGP issues).</li>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on dashboards that vanish during the incident.</li>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  edge<span class="token text string">["Edge (rate limits + WAF)"]</span> <span class="token arrow operator">--></span> core<span class="token text string">["Core Services"]</span>
  core <span class="token arrow operator">--></span> data<span class="token text string">["Data Plane"]</span>
  data <span class="token arrow operator">--></span> control<span class="token text string">["Control Plane"]</span>
  control <span class="token arrow operator">--></span> edge
  siem<span class="token text string">["Detection/Response"]</span> <span class="token arrow operator">--></span> core
  siem <span class="token arrow operator">--></span> edge</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep evidence pipelines alive: you can’t respond blind.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Metadata and Privacy: The Hard Part Isn’t Encryption]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-08-metadata-and-privacy-the-hard-part-isn-t-encryption</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-08-metadata-and-privacy-the-hard-part-isn-t-encryption"/>
        <updated>2024-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (August 2024): Metadata and Privacy: The Hard Part Isn’t Encryption.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Metadata and Privacy: The Hard Part Isn’t Encryption</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Degraded modes without explicit policy become accidental vulnerabilities.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Attackers can manipulate routing and DNS indirectly (upstream failures, BGP issues).</li>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on dashboards that vanish during the incident.</li>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Resilience is about containment:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>damage</mtext><mo>≤</mo><munder><mo>∑</mo><mi>i</mi></munder><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mtext>with</mtext><mspace width="1em"></mspace><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mtext> bounded by design</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{damage} \le \sum_i \text{blast\_radius}(i)\quad\text{with}\quad \text{blast\_radius}(i)\ \text{bounded by design}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">damage</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3277em;vertical-align:-1.2777em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8723em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.2777em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">with</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace"> </span><span class="mord text"><span class="mord">bounded by design</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  edge<span class="token text string">["Edge (rate limits + WAF)"]</span> <span class="token arrow operator">--></span> core<span class="token text string">["Core Services"]</span>
  core <span class="token arrow operator">--></span> data<span class="token text string">["Data Plane"]</span>
  data <span class="token arrow operator">--></span> control<span class="token text string">["Control Plane"]</span>
  control <span class="token arrow operator">--></span> edge
  siem<span class="token text string">["Detection/Response"]</span> <span class="token arrow operator">--></span> core
  siem <span class="token arrow operator">--></span> edge</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep evidence pipelines alive: you can’t respond blind.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Evidence checklist:
- Immutable logs (append-only)
- Signed audit events
- Time sync monitoring
- Dependency health snapshots
- Config change history</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Byzantine Fault Injection: Testing Protocols Like an Attacker]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-07-byzantine-fault-injection-testing-protocols-like-an-attacker</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-07-byzantine-fault-injection-testing-protocols-like-an-attacker"/>
        <updated>2024-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (July 2024): Byzantine Fault Injection: Testing Protocols Like an Attacker.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Byzantine Fault Injection: Testing Protocols Like an Attacker</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
<li>Relying on dashboards that vanish during the incident.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  edge<span class="token text string">["Edge (rate limits + WAF)"]</span> <span class="token arrow operator">--></span> core<span class="token text string">["Core Services"]</span>
  core <span class="token arrow operator">--></span> data<span class="token text string">["Data Plane"]</span>
  data <span class="token arrow operator">--></span> control<span class="token text string">["Control Plane"]</span>
  control <span class="token arrow operator">--></span> edge
  siem<span class="token text string">["Detection/Response"]</span> <span class="token arrow operator">--></span> core
  siem <span class="token arrow operator">--></span> edge</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer containment over heroics: isolate blast radius, keep core correct.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Consensus Under Attack: Adaptive Adversaries and Network Control]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-06-consensus-under-attack-adaptive-adversaries-and-network-cont</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-06-consensus-under-attack-adaptive-adversaries-and-network-cont"/>
        <updated>2024-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (June 2024): Consensus Under Attack: Adaptive Adversaries and Network Control.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Consensus Under Attack: Adaptive Adversaries and Network Control</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Degraded modes are security decisions; write them down and test them.</li>
<li>Dependencies (DNS, routing, PKI) are shared attack surfaces—plan containment.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Degraded modes without explicit policy become accidental vulnerabilities.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Operators are human and will make mistakes under pressure.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
<li>Relying on dashboards that vanish during the incident.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Resilience is about containment:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>damage</mtext><mo>≤</mo><munder><mo>∑</mo><mi>i</mi></munder><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mtext>with</mtext><mspace width="1em"></mspace><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mtext> bounded by design</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{damage} \le \sum_i \text{blast\_radius}(i)\quad\text{with}\quad \text{blast\_radius}(i)\ \text{bounded by design}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">damage</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3277em;vertical-align:-1.2777em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8723em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.2777em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">with</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace"> </span><span class="mord text"><span class="mord">bounded by design</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  attack<span class="token text string">["Attack"]</span> <span class="token arrow operator">--></span> detect<span class="token text string">["Detect"]</span>
  detect <span class="token arrow operator">--></span> contain<span class="token text string">["Contain"]</span>
  contain <span class="token arrow operator">--></span> recover<span class="token text string">["Recover"]</span>
  recover <span class="token arrow operator">--></span> learn<span class="token text string">["Learn/Regress"]</span>
  learn <span class="token arrow operator">--></span> detect</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep evidence pipelines alive: you can’t respond blind.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Time-Based Attacks: NTP Manipulation, Expiration, and Replay]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-05-time-based-attacks-ntp-manipulation-expiration-and-replay</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-05-time-based-attacks-ntp-manipulation-expiration-and-replay"/>
        <updated>2024-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (May 2024): Time-Based Attacks: NTP Manipulation, Expiration, and Replay.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Time-Based Attacks: NTP Manipulation, Expiration, and Replay</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Degraded modes are security decisions; write them down and test them.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Degraded modes without explicit policy become accidental vulnerabilities.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Attackers can manipulate routing and DNS indirectly (upstream failures, BGP issues).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on dashboards that vanish during the incident.</li>
<li>Treating degraded modes as “we’ll decide later.”</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Resilience is about containment:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>damage</mtext><mo>≤</mo><munder><mo>∑</mo><mi>i</mi></munder><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mtext>with</mtext><mspace width="1em"></mspace><mtext>blast_radius</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mtext> bounded by design</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{damage} \le \sum_i \text{blast\_radius}(i)\quad\text{with}\quad \text{blast\_radius}(i)\ \text{bounded by design}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord text"><span class="mord">damage</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:2.3277em;vertical-align:-1.2777em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8723em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">i</span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.2777em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">with</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">blast_radius</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace"> </span><span class="mord text"><span class="mord">bounded by design</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  attack<span class="token text string">["Attack"]</span> <span class="token arrow operator">--></span> detect<span class="token text string">["Detect"]</span>
  detect <span class="token arrow operator">--></span> contain<span class="token text string">["Contain"]</span>
  contain <span class="token arrow operator">--></span> recover<span class="token text string">["Recover"]</span>
  recover <span class="token arrow operator">--></span> learn<span class="token text string">["Learn/Regress"]</span>
  learn <span class="token arrow operator">--></span> detect</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer containment over heroics: isolate blast radius, keep core correct.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Evidence checklist:
- Immutable logs (append-only)
- Signed audit events
- Time sync monitoring
- Dependency health snapshots
- Config change history</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Sandbox Escapes: Isolation Boundaries as a Design Input]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-04-sandbox-escapes-isolation-boundaries-as-a-design-input</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-04-sandbox-escapes-isolation-boundaries-as-a-design-input"/>
        <updated>2024-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (April 2024): Sandbox Escapes: Isolation Boundaries as a Design Input.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Sandbox Escapes: Isolation Boundaries as a Design Input</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Dependencies (DNS, routing, PKI) are shared attack surfaces—plan containment.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Attackers can manipulate routing and DNS indirectly (upstream failures, BGP issues).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Operators are human and will make mistakes under pressure.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming WAF/rate limits are sufficient without architecture changes.</li>
<li>Relying on dashboards that vanish during the incident.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  edge<span class="token text string">["Edge (rate limits + WAF)"]</span> <span class="token arrow operator">--></span> core<span class="token text string">["Core Services"]</span>
  core <span class="token arrow operator">--></span> data<span class="token text string">["Data Plane"]</span>
  data <span class="token arrow operator">--></span> control<span class="token text string">["Control Plane"]</span>
  control <span class="token arrow operator">--></span> edge
  siem<span class="token text string">["Detection/Response"]</span> <span class="token arrow operator">--></span> core
  siem <span class="token arrow operator">--></span> edge</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep evidence pipelines alive: you can’t respond blind.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Evidence checklist:
- Immutable logs (append-only)
- Signed audit events
- Time sync monitoring
- Dependency health snapshots
- Config change history</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Supply Chain Attacks: Dependency Poisoning and Maintainer Compromise]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-03-supply-chain-attacks-dependency-poisoning-and-maintainer-com</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-03-supply-chain-attacks-dependency-poisoning-and-maintainer-com"/>
        <updated>2024-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (March 2024): Supply Chain Attacks: Dependency Poisoning and Maintainer Compromise.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Supply Chain Attacks: Dependency Poisoning and Maintainer Compromise</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Degraded modes are security decisions; write them down and test them.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Logs are only useful if they remain trustworthy under compromise.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
<li>Attackers can manipulate routing and DNS indirectly (upstream failures, BGP issues).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
<li>Treating degraded modes as “we’ll decide later.”</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  attack<span class="token text string">["Attack"]</span> <span class="token arrow operator">--></span> detect<span class="token text string">["Detect"]</span>
  detect <span class="token arrow operator">--></span> contain<span class="token text string">["Contain"]</span>
  contain <span class="token arrow operator">--></span> recover<span class="token text string">["Recover"]</span>
  recover <span class="token arrow operator">--></span> learn<span class="token text string">["Learn/Regress"]</span>
  learn <span class="token arrow operator">--></span> detect</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer containment over heroics: isolate blast radius, keep core correct.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[DDoS at Scale: Adaptive Defense and Cost Asymmetry]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-02-ddos-at-scale-adaptive-defense-and-cost-asymmetry</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-02-ddos-at-scale-adaptive-defense-and-cost-asymmetry"/>
        <updated>2024-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (February 2024): DDoS at Scale: Adaptive Defense and Cost Asymmetry.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>DDoS at Scale: Adaptive Defense and Cost Asymmetry</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Evidence pipelines (audit/config history) are part of incident response correctness.</li>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Define safety properties before performance goals.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
<li>Incident response is a protocol: practice it, automate it, validate it.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>Where is the attacker’s leverage (routing, DNS, dependency, identity, time)?</li>
<li>How do you make abuse expensive (proof-of-work, quotas, pricing, friction)?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
<li>What is your degraded-mode behavior (and is it safe)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Operators are human and will make mistakes under pressure.</li>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming WAF/rate limits are sufficient without architecture changes.</li>
<li>Assuming perfect attribution (you rarely know who is attacking in real time).</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Engineer friction where attackers pay but legitimate users don’t (asymmetric controls).</p>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  edge<span class="token text string">["Edge (rate limits + WAF)"]</span> <span class="token arrow operator">--></span> core<span class="token text string">["Core Services"]</span>
  core <span class="token arrow operator">--></span> data<span class="token text string">["Data Plane"]</span>
  data <span class="token arrow operator">--></span> control<span class="token text string">["Control Plane"]</span>
  control <span class="token arrow operator">--></span> edge
  siem<span class="token text string">["Detection/Response"]</span> <span class="token arrow operator">--></span> core
  siem <span class="token arrow operator">--></span> edge</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer containment over heroics: isolate blast radius, keep core correct.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Evidence checklist:
- Immutable logs (append-only)
- Signed audit events
- Time sync monitoring
- Dependency health snapshots
- Config change history</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[BGP and Routing Attacks: Engineering for the Internet We Have]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2024-01-bgp-and-routing-attacks-engineering-for-the-internet-we-have</id>
        <link href="https://mayckongiovani.xyz/pensieve/2024-01-bgp-and-routing-attacks-engineering-for-the-internet-we-have"/>
        <updated>2024-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (January 2024): BGP and Routing Attacks: Engineering for the Internet We Have.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Adversarial Infrastructure &#x26; Global Systems</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>BGP and Routing Attacks: Engineering for the Internet We Have</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Protect observability: you can’t respond blind, and telemetry can be attacked.</li>
<li>Degraded modes are security decisions; write them down and test them.</li>
<li>Engineer cost asymmetry: defense must be cheaper than attack per unit of damage prevented.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Global dependencies (DNS, routing, PKI) are shared attack surfaces.</li>
<li>Attackers exploit cost asymmetry: make abuse cheap and defense expensive.</li>
<li>Degraded modes without explicit policy become accidental vulnerabilities.</li>
<li>Privacy failures often come from metadata, not plaintext.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your degraded-mode behavior (and is it safe)?</li>
<li>What is the minimum viable recovery path after a catastrophic event?</li>
<li>Which controls fail first under load: auth, rate limits, storage, or observability?</li>
<li>Which logs are trustworthy under compromise (append-only, signed, isolated)?</li>
<li>How do you detect attacks that look like “normal traffic spikes”?</li>
<li>How do you prevent dependency failures from becoming integrity failures?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Observability pipelines can be attacked (cardinality explosions, log injection).</li>
<li>Traffic spikes can be malicious or accidental; you must handle both.</li>
<li>Attackers can manipulate routing and DNS indirectly (upstream failures, BGP issues).</li>
<li>Some dependencies will fail open or fail closed unexpectedly.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating degraded modes as “we’ll decide later.”</li>
<li>Relying on dashboards that vanish during the incident.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Defense is about cost asymmetry. If the attacker spends <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>1</mn></mrow><annotation encoding="application/x-tex">1</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1</span></span></span></span></span> and you spend <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>100</mn></mrow><annotation encoding="application/x-tex">100</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">100</span></span></span></span></span>, you lose.</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>defense</mtext></msub><mo>≪</mo><msub><mrow><mi mathvariant="normal">C</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mtext>attack</mtext></msub><mtext> (per unit of damage prevented)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Cost}_\text{defense} \ll \mathrm{Cost}_\text{attack}\ \text{(per unit of damage prevented)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">defense</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≪</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Cost</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">attack</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord text"><span class="mord">(per unit of damage prevented)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat observability as a dependency: protect it from overload and manipulation.</p>
<p>Define which operations fail closed vs fail open. Do it before an incident.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  attack<span class="token text string">["Attack"]</span> <span class="token arrow operator">--></span> detect<span class="token text string">["Detect"]</span>
  detect <span class="token arrow operator">--></span> contain<span class="token text string">["Contain"]</span>
  contain <span class="token arrow operator">--></span> recover<span class="token text string">["Recover"]</span>
  recover <span class="token arrow operator">--></span> learn<span class="token text string">["Learn/Regress"]</span>
  learn <span class="token arrow operator">--></span> detect</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep evidence pipelines alive: you can’t respond blind.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Degraded-mode table (example):
Operation | Normal | Under attack | Rationale
Auth      | full   | strict       | prevent abuse
Reads     | full   | cached/limited| protect core
Writes    | full   | queued/limited| preserve integrity
Admin     | full   | JIT + MFA     | reduce blast radius</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Observability stress</strong>: cardinality explosions and sampling under attack.</li>
<li><strong>Incident replay</strong>: reconstruct timeline from evidence pipelines.</li>
<li><strong>Policy tests</strong>: fail closed/open behaviors are unit-tested.</li>
<li><strong>Game days</strong>: simulate DDoS, dependency failure, and credential abuse.</li>
<li><strong>Dependency chaos</strong>: DNS issues, cert failures, upstream outages.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep recovery paths simple: restore from known-good, rotate secrets, reissue certs.</li>
<li>Protect the edge and the evidence: rate limits + SIEM + log integrity.</li>
<li>Instrument cost: which defenses become expensive and when.</li>
<li>Make emergency controls quick: feature flags, circuit breakers, safe defaults.</li>
<li>Document and rehearse degraded-mode policy with on-call rotations.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Operational failures and recovery in real-world PKI.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you keep control-plane access during widespread incidents?</li>
<li>What is your ‘safe mode’ when dependencies fail?</li>
<li>Which operation, if abused, causes irreversible damage?</li>
<li>Where do you pay cost asymmetry today—and can you flip it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019/" target="_blank" rel="nofollow noopener noreferrer">Cloudflare Outage (July 2, 2019) Postmortem</a> — A concrete example of global failure, containment, and recovery lessons.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Operational failures and recovery in real-world PKI.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc4271" target="_blank" rel="nofollow noopener noreferrer">RFC 4271: BGP-4</a> — Routing is part of your threat model whether you like it or not.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc6480" target="_blank" rel="nofollow noopener noreferrer">RFC 6480: An Infrastructure to Support Secure Internet Routing</a> — RPKI basics and why routing security is hard operationally.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="security"/>
        <category label="distributed-infrastructure"/>
        <category label="threat-modeling"/>
        <category label="resilience"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Compliance & Standards: Translating NIST to Engineering Action]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-12-compliance-standards-translating-nist-to-engineering-action</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-12-compliance-standards-translating-nist-to-engineering-action"/>
        <updated>2023-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (December 2023): Compliance & Standards: Translating NIST to Engineering Action.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Compliance &#x26; Standards: Translating NIST to Engineering Action</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>Constant-time requirements don’t disappear; they become harder under bigger primitives.</li>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Constant-time constraints are harder under large primitives.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating migration as a single flag flip.</li>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Interop tests are the migration plan; everything else is a hypothesis.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--2">(<a href="#bib-nistpqc">2</a>)</span> — Standardization process and algorithm selections.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>What is the worst-case handshake cost under attack?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Migration Risk Management: Inventory, Prioritization, and Cutover]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-11-migration-risk-management-inventory-prioritization-and-cutov</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-11-migration-risk-management-inventory-prioritization-and-cutov"/>
        <updated>2023-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (November 2023): Migration Risk Management: Inventory, Prioritization, and Cutover.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Migration Risk Management: Inventory, Prioritization, and Cutover</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Constant-time constraints are harder under large primitives.</li>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Migration will be mixed-version for years; plan for it explicitly.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating migration as a single flag flip.</li>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Interop tests are the migration plan; everything else is a hypothesis.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--1">(<a href="#bib-nistpqc">1</a>)</span> — Standardization process and algorithm selections.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>What is the worst-case handshake cost under attack?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Side Channels in PQC Implementations: Where Theory Meets Cache]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-10-side-channels-in-pqc-implementations-where-theory-meets-cach</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-10-side-channels-in-pqc-implementations-where-theory-meets-cach"/>
        <updated>2023-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (October 2023): Side Channels in PQC Implementations: Where Theory Meets Cache.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Side Channels in PQC Implementations: Where Theory Meets Cache</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Make failure modes explicit and observable.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
<li>Which parts must be constant-time, and how will you validate that?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
<li>Ignoring DoS implications of large primitives.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  negotiate<span class="token text string">["Negotiate Algorithms"]</span> <span class="token arrow operator">--></span> bind<span class="token text string">["Bind Transcript"]</span>
  bind <span class="token arrow operator">--></span> kdf<span class="token text string">["KDF (hybrid)"]</span>
  kdf <span class="token arrow operator">--></span> keys<span class="token text string">["Traffic Keys"]</span>
  keys <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor + Rollback"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Explicit binding prevents downgrade and mix-and-match. Don’t leave it implicit.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>What is the worst-case handshake cost under attack?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Benchmarking PQC: What to Measure (and What Not To)]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-09-benchmarking-pqc-what-to-measure-and-what-not-to</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-09-benchmarking-pqc-what-to-measure-and-what-not-to"/>
        <updated>2023-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (September 2023): Benchmarking PQC: What to Measure (and What Not To).]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Benchmarking PQC: What to Measure (and What Not To)</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Migration will be mixed-version for years; plan for it explicitly.</li>
<li>Constant-time constraints are harder under large primitives.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating migration as a single flag flip.</li>
<li>Ignoring DoS implications of large primitives.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Explicit binding prevents downgrade and mix-and-match. Don’t leave it implicit.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--2">(<a href="#bib-nistpqc">2</a>)</span> — Standardization process and algorithm selections.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case handshake cost under attack?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Crypto Agility Tooling: Feature Flags, Policy, and Rollback]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-08-crypto-agility-tooling-feature-flags-policy-and-rollback</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-08-crypto-agility-tooling-feature-flags-policy-and-rollback"/>
        <updated>2023-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (August 2023): Crypto Agility Tooling: Feature Flags, Policy, and Rollback.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Crypto Agility Tooling: Feature Flags, Policy, and Rollback</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Constant-time requirements don’t disappear; they become harder under bigger primitives.</li>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Constant-time constraints are harder under large primitives.</li>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
<li>Ignoring DoS implications of large primitives.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  negotiate<span class="token text string">["Negotiate Algorithms"]</span> <span class="token arrow operator">--></span> bind<span class="token text string">["Bind Transcript"]</span>
  bind <span class="token arrow operator">--></span> kdf<span class="token text string">["KDF (hybrid)"]</span>
  kdf <span class="token arrow operator">--></span> keys<span class="token text string">["Traffic Keys"]</span>
  keys <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor + Rollback"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Explicit binding prevents downgrade and mix-and-match. Don’t leave it implicit.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--2">(<a href="#bib-rfc5869">2</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case handshake cost under attack?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC for IoT: Memory, CPU, and Timing Side Channels]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-07-pqc-for-iot-memory-cpu-and-timing-side-channels</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-07-pqc-for-iot-memory-cpu-and-timing-side-channels"/>
        <updated>2023-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (July 2023): PQC for IoT: Memory, CPU, and Timing Side Channels.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>PQC for IoT: Memory, CPU, and Timing Side Channels</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Constant-time constraints are harder under large primitives.</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Ignoring DoS implications of large primitives.</li>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  negotiate<span class="token text string">["Negotiate Algorithms"]</span> <span class="token arrow operator">--></span> bind<span class="token text string">["Bind Transcript"]</span>
  bind <span class="token arrow operator">--></span> kdf<span class="token text string">["KDF (hybrid)"]</span>
  kdf <span class="token arrow operator">--></span> keys<span class="token text string">["Traffic Keys"]</span>
  keys <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor + Rollback"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Interop tests are the migration plan; everything else is a hypothesis.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>What is the worst-case handshake cost under attack?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC in VPN/IPsec: IKEv2 Revisited Under PQ Constraints]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-06-pqc-in-vpn-ipsec-ikev2-revisited-under-pq-constraints</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-06-pqc-in-vpn-ipsec-ikev2-revisited-under-pq-constraints"/>
        <updated>2023-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (June 2023): PQC in VPN/IPsec: IKEv2 Revisited Under PQ Constraints.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>PQC in VPN/IPsec: IKEv2 Revisited Under PQ Constraints</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Constant-time constraints are harder under large primitives.</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Ignoring DoS implications of large primitives.</li>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  negotiate<span class="token text string">["Negotiate Algorithms"]</span> <span class="token arrow operator">--></span> bind<span class="token text string">["Bind Transcript"]</span>
  bind <span class="token arrow operator">--></span> kdf<span class="token text string">["KDF (hybrid)"]</span>
  kdf <span class="token arrow operator">--></span> keys<span class="token text string">["Traffic Keys"]</span>
  keys <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor + Rollback"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Explicit binding prevents downgrade and mix-and-match. Don’t leave it implicit.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--1">(<a href="#bib-nistpqc">1</a>)</span> — Standardization process and algorithm selections.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--2">(<a href="#bib-rfc5869">2</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>What is the worst-case handshake cost under attack?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC in TLS: Negotiation, Downgrade, and Interop]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-05-pqc-in-tls-negotiation-downgrade-and-interop</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-05-pqc-in-tls-negotiation-downgrade-and-interop"/>
        <updated>2023-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (May 2023): PQC in TLS: Negotiation, Downgrade, and Interop.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>PQC in TLS: Negotiation, Downgrade, and Interop</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Constant-time constraints are harder under large primitives.</li>
<li>Migration will be mixed-version for years; plan for it explicitly.</li>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Explicit binding prevents downgrade and mix-and-match. Don’t leave it implicit.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Hybrid handshake checklist:
- Explicit negotiation (no silent downgrade)
- Transcript-bound KDF
- DoS protections (rate limits, cookies, puzzles)
- Constant-time operations
- Telemetry: which mode, which failures, which clients</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>What is the worst-case handshake cost under attack?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Hybrid Key Exchange: Binding Classical and PQ Secrets Correctly]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-04-hybrid-key-exchange-binding-classical-and-pq-secrets-correct</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-04-hybrid-key-exchange-binding-classical-and-pq-secrets-correct"/>
        <updated>2023-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (April 2023): Hybrid Key Exchange: Binding Classical and PQ Secrets Correctly.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Hybrid Key Exchange: Binding Classical and PQ Secrets Correctly</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Constant-time requirements don’t disappear; they become harder under bigger primitives.</li>
<li>Make failure modes explicit and observable.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Constant-time constraints are harder under large primitives.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
<li>Which parts must be constant-time, and how will you validate that?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
<li>Treating migration as a single flag flip.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Interop tests are the migration plan; everything else is a hypothesis.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case handshake cost under attack?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Signatures in Practice: Dilithium/Falcon and Deployment Constraints]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-03-signatures-in-practice-dilithium-falcon-and-deployment-const</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-03-signatures-in-practice-dilithium-falcon-and-deployment-const"/>
        <updated>2023-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (March 2023): Signatures in Practice: Dilithium/Falcon and Deployment Constraints.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Signatures in Practice: Dilithium/Falcon and Deployment Constraints</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Migration will be mixed-version for years; plan for it explicitly.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>How do you rotate algorithms safely (crypto agility without chaos)?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
<li>Vendors vary: implementations and defaults differ.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  negotiate<span class="token text string">["Negotiate Algorithms"]</span> <span class="token arrow operator">--></span> bind<span class="token text string">["Bind Transcript"]</span>
  bind <span class="token arrow operator">--></span> kdf<span class="token text string">["KDF (hybrid)"]</span>
  kdf <span class="token arrow operator">--></span> keys<span class="token text string">["Traffic Keys"]</span>
  keys <span class="token arrow operator">--></span> monitor<span class="token text string">["Monitor + Rollback"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Interop tests are the migration plan; everything else is a hypothesis.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--1">(<a href="#bib-nistpqc">1</a>)</span> — Standardization process and algorithm selections.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>What is the worst-case handshake cost under attack?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[KEMs in Practice: Kyber Handshakes and Failure Surfaces]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-02-kems-in-practice-kyber-handshakes-and-failure-surfaces</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-02-kems-in-practice-kyber-handshakes-and-failure-surfaces"/>
        <updated>2023-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (February 2023): KEMs in Practice: Kyber Handshakes and Failure Surfaces.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>KEMs in Practice: Kyber Handshakes and Failure Surfaces</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Constant-time requirements don’t disappear; they become harder under bigger primitives.</li>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>Interop is the migration plan—test matrices are more important than whitepapers.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What are the new DoS surfaces (bigger keys, more CPU, more bandwidth)?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
<li>Active attacker can force retries, downgrades, and expensive handshakes.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on silent fallback to weaker modes during interop failures.</li>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Hybrid composition should be transcript-bound:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>=</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>classical</mtext></msub><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> </mtext><msub><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mtext>pqc</mtext></msub><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{ss} = \mathrm{HKDF}(\mathrm{ss}_\text{classical}\ \Vert\ \mathrm{ss}_\text{pqc},\ \text{info}=\mathrm{transcript}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.4306em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.0361em;vertical-align:-0.2861em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">classical</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord"><span class="mord"><span class="mord mathrm">ss</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">pqc</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2861em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">transcript</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<p>Binding is the whole game: make the transcript an input to the KDF.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>PQC migration is a systems program: protocol, performance, ops, and UX must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Hybrid binding sketch (pseudocode):</span>
<span class="token comment">// ss = HKDF(ss_classical || ss_pqc, info=transcript_hash)</span>
<span class="token comment">// Then derive traffic keys from ss.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case handshake cost under attack?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PQC Threat Models: 'Harvest Now, Decrypt Later' in Real Systems]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2023-01-pqc-threat-models-harvest-now-decrypt-later-in-real-systems</id>
        <link href="https://mayckongiovani.xyz/pensieve/2023-01-pqc-threat-models-harvest-now-decrypt-later-in-real-systems"/>
        <updated>2023-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (January 2023): PQC Threat Models: 'Harvest Now, Decrypt Later' in Real Systems.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Post-Quantum Cryptography &#x26; Migration</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>PQC Threat Models: 'Harvest Now, Decrypt Later' in Real Systems</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Migration is mixed-version for years: compatibility and rollback are security features.</li>
<li>Hybrid composition must be explicit and transcript-bound to resist downgrade.</li>
<li>PQC changes handshake costs; plan DoS defenses and budgets.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>PQC changes bandwidth and CPU costs; DoS surfaces move.</li>
<li>Hybrid designs fail if binding is ambiguous (mix-and-match, downgrade).</li>
<li>Interop is the real risk: multiple stacks, vendors, and versions.</li>
<li>Operationalization (monitoring, rollback) determines success more than crypto choice.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which parts must be constant-time, and how will you validate that?</li>
<li>How do you bind hybrid secrets to prevent downgrade and mix-and-match attacks?</li>
<li>What does interoperability testing look like across vendors and stacks?</li>
<li>What telemetry proves PQC is working (not just enabled)?</li>
<li>How do you handle failures: decryption failures, invalid ciphertexts, malformed keys?</li>
<li>Which secrets require long-term confidentiality (HNDL) and where are they today?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Vendors vary: implementations and defaults differ.</li>
<li>Side channels exist: timing and cache behavior leak information.</li>
<li>Bandwidth is limited in some environments; larger handshakes matter.</li>
<li>Deployments are mixed; old clients must interoperate or fail safely.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating migration as a single flag flip.</li>
<li>Assuming PQC is “drop-in” without changing operational processes.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A KEM gives you shared secrets without discrete-log assumptions:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">K</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">y</mi><mi mathvariant="normal">G</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mo stretchy="false">(</mo><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">)</mo><mo>←</mo><mrow><mi mathvariant="normal">E</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">p</mi><mi mathvariant="normal">k</mi></mrow><mo stretchy="false">)</mo><mo separator="true">;</mo><mtext> </mtext><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>←</mo><mrow><mi mathvariant="normal">D</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">s</mi><mi mathvariant="normal">k</mi></mrow><mo separator="true">,</mo><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">(\mathrm{pk},\mathrm{sk})\leftarrow \mathrm{KeyGen}();\ 
(\mathrm{ct},\mathrm{ss})\leftarrow \mathrm{Enc}(\mathrm{pk});\ 
\mathrm{ss}\leftarrow \mathrm{Dec}(\mathrm{sk},\mathrm{ct}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">KeyGen</span></span><span class="mopen">(</span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Enc</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">pk</span></span><span class="mclose">)</span><span class="mpunct">;</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ss</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Dec</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">sk</span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">ct</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat algorithm negotiation as adversarial: explicit downgrade resistance.</p>
<p>Make costs explicit: measure CPU and bandwidth, then add protections.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> A as Initiator
  <span class="token keyword">participant</span> B as Responder
  A<span class="token arrow operator">->></span>B<span class="token operator">:</span> classical_keyshare + pqc_pk
  B<span class="token arrow operator">-->></span>A<span class="token operator">:</span> classical_keyshare + pqc_ct + sig
  A<span class="token arrow operator">-->></span>B<span class="token operator">:</span> sig
  <span class="token keyword">Note over</span> A,B<span class="token operator">:</span> ss = HKDF<span class="token text string">(ss_classical || ss_pqc, transcript)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Explicit binding prevents downgrade and mix-and-match. Don’t leave it implicit.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Hybrid handshake checklist:
- Explicit negotiation (no silent downgrade)
- Transcript-bound KDF
- DoS protections (rate limits, cookies, puzzles)
- Constant-time operations
- Telemetry: which mode, which failures, which clients</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Downgrade tests</strong>: active attacker manipulates negotiation.</li>
<li><strong>Interop matrices</strong> across vendors/versions and failure modes.</li>
<li><strong>Side-channel tests</strong> where tooling exists; constant-time audits.</li>
<li><strong>Chaos deploys</strong>: mixed versions + rollback during partial outages.</li>
<li><strong>DoS tests</strong>: measure CPU/bandwidth amplification and mitigation impact.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Roll out with canaries and explicit rollback triggers.</li>
<li>Add telemetry for negotiation outcomes, failures, and client cohorts.</li>
<li>Inventory long-lived secrets and migrate the highest-risk first.</li>
<li>Cap handshake cost per peer/IP; use stateless cookies when needed.</li>
<li>Document supported algorithm sets and deprecation timelines.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Useful when discussing hybrid binding and context separation.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> <span class="citation" id="citation--nistpqc--2">(<a href="#bib-nistpqc">2</a>)</span> — Standardization process and algorithm selections.
<ul>
<li><strong>Evidence:</strong> Treat PQ migration as a program (inventory, interop, rollback). Use NIST status to drive prioritization and timelines.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you rotate algorithms without introducing configuration chaos?</li>
<li>Which clients will fail first, and what is the safe fallback behavior?</li>
<li>What is the worst-case handshake cost under attack?</li>
<li>Where would a downgrade be visible today, and how would you detect it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://pq-crystals.org/kyber/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Kyber</a> — KEM design and parameters commonly referenced in deployments.</li>
<li><a href="https://pq-crystals.org/dilithium/" target="_blank" rel="nofollow noopener noreferrer">CRYSTALS-Dilithium</a> — Signature scheme design and deployment constraints.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Useful when discussing hybrid binding and context separation.</li>
<li><a href="https://csrc.nist.gov/projects/post-quantum-cryptography" target="_blank" rel="nofollow noopener noreferrer">NIST Post-Quantum Cryptography Project</a> — Standardization process and algorithm selections.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-nistpqc">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">National Institute of Standards and Technology (NIST). Post-Quantum Cryptography [Internet]. Web; Available from: https://csrc.nist.gov/projects/post-quantum-cryptography</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="post-quantum-cryptography"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="protocol-design"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Red Teaming Infrastructure: Turning Attacks into Regression Tests]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-12-red-teaming-infrastructure-turning-attacks-into-regression-t</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-12-red-teaming-infrastructure-turning-attacks-into-regression-t"/>
        <updated>2022-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (December 2022): Red Teaming Infrastructure: Turning Attacks into Regression Tests.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Red Teaming Infrastructure: Turning Attacks into Regression Tests</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Rollouts are where incidents happen; safe rollback is a security feature.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>What is the minimum set of humans who can ship to production?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Observability pipelines can be attacked (log injection, PII leaks).</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Rollbacks must be executed under time pressure.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Trusting CI environments by default.</li>
<li>Assuming deploy equals success without runtime evidence.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Build provenance is a cryptographic statement:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>build</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>artifact</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{attest} \leftarrow \mathrm{Sign}_{k_\text{build}}(\mathrm{hash}(\text{artifact})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">attest</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">build</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">artifact</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The pipeline is production: it has credentials, network reach, and authority.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Rust/Go Secure Coding Patterns: The Bugs That Still Happen]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-11-rust-go-secure-coding-patterns-the-bugs-that-still-happen</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-11-rust-go-secure-coding-patterns-the-bugs-that-still-happen"/>
        <updated>2022-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (November 2022): Rust/Go Secure Coding Patterns: The Bugs That Still Happen.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Rust/Go Secure Coding Patterns: The Bugs That Still Happen</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make rollback a first-class operation with explicit triggers and rehearsal.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Infrastructure-as-code without policy is just scripting the attack surface.</li>
<li>Supply-chain attacks target your CI/CD because it has keys and reach.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the minimum set of humans who can ship to production?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Rollbacks must be executed under time pressure.</li>
<li>Observability pipelines can be attacked (log injection, PII leaks).</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming deploy equals success without runtime evidence.</li>
<li>Long-lived credentials embedded in pipelines.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A policy gate is a predicate over metadata:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi></mrow><mo stretchy="false">(</mo><mtext>deploy</mtext><mo stretchy="false">)</mo><mo>⇔</mo><mi>P</mi><mo stretchy="false">(</mo><mtext>attestation</mtext><mo separator="true">,</mo><mtext> scan</mtext><mo separator="true">,</mo><mtext> env</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{allow}(\text{deploy}) \Leftrightarrow P(\text{attestation},\ \text{scan},\ \text{env}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">allow</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">deploy</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇔</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">(</span><span class="mord text"><span class="mord">attestation</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">scan</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">env</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The pipeline is production: it has credentials, network reach, and authority.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Treat CI as untrusted: keep tokens short-lived and scoped.</span>
<span class="token keyword">type</span> Token <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  Value <span class="token builtin">string</span>
  ExpiresAtUnix <span class="token builtin">int64</span>
  Scope <span class="token builtin">string</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secure Configuration: Policy-as-Code and Guardrails]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-10-secure-configuration-policy-as-code-and-guardrails</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-10-secure-configuration-policy-as-code-and-guardrails"/>
        <updated>2022-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (October 2022): Secure Configuration: Policy-as-Code and Guardrails.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secure Configuration: Policy-as-Code and Guardrails</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Supply-chain attacks target your CI/CD because it has keys and reach.</li>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>What is the minimum set of humans who can ship to production?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollbacks must be executed under time pressure.</li>
<li>Observability pipelines can be attacked (log injection, PII leaks).</li>
<li>Policy enforcement must be consistent across environments.</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Manual policy enforcement or manual security review as the only control.</li>
<li>Trusting CI environments by default.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A policy gate is a predicate over metadata:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi></mrow><mo stretchy="false">(</mo><mtext>deploy</mtext><mo stretchy="false">)</mo><mo>⇔</mo><mi>P</mi><mo stretchy="false">(</mo><mtext>attestation</mtext><mo separator="true">,</mo><mtext> scan</mtext><mo separator="true">,</mo><mtext> env</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{allow}(\text{deploy}) \Leftrightarrow P(\text{attestation},\ \text{scan},\ \text{env}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">allow</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">deploy</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇔</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">(</span><span class="mord text"><span class="mord">attestation</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">scan</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">env</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  pr<span class="token text string">["PR"]</span> <span class="token arrow operator">--></span> checks<span class="token text string">["Checks"]</span>
  checks <span class="token arrow operator">--></span> merge<span class="token text string">["Merge"]</span>
  merge <span class="token arrow operator">--></span> release<span class="token text string">["Release"]</span>
  release <span class="token arrow operator">--></span> canary<span class="token text string">["Canary"]</span>
  canary <span class="token arrow operator">--></span> prod<span class="token text string">["Prod"]</span>
  prod <span class="token arrow operator">--></span> rollback<span class="token text string">["Rollback Plan"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Build systems that can prove what happened after an incident.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Backup/Restore as a Protocol: RPO/RTO with Adversaries]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-09-backup-restore-as-a-protocol-rpo-rto-with-adversaries</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-09-backup-restore-as-a-protocol-rpo-rto-with-adversaries"/>
        <updated>2022-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (September 2022): Backup/Restore as a Protocol: RPO/RTO with Adversaries.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Backup/Restore as a Protocol: RPO/RTO with Adversaries</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Short-lived credentials (OIDC) beat long-lived tokens in pipelines.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Rollouts are where incidents happen; safe rollback is a security feature.</li>
<li>Supply-chain attacks target your CI/CD because it has keys and reach.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollbacks must be executed under time pressure.</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Policy enforcement must be consistent across environments.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming deploy equals success without runtime evidence.</li>
<li>Manual policy enforcement or manual security review as the only control.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A policy gate is a predicate over metadata:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi></mrow><mo stretchy="false">(</mo><mtext>deploy</mtext><mo stretchy="false">)</mo><mo>⇔</mo><mi>P</mi><mo stretchy="false">(</mo><mtext>attestation</mtext><mo separator="true">,</mo><mtext> scan</mtext><mo separator="true">,</mo><mtext> env</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{allow}(\text{deploy}) \Leftrightarrow P(\text{attestation},\ \text{scan},\ \text{env}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">allow</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">deploy</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇔</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">(</span><span class="mord text"><span class="mord">attestation</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">scan</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">env</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  pr<span class="token text string">["PR"]</span> <span class="token arrow operator">--></span> checks<span class="token text string">["Checks"]</span>
  checks <span class="token arrow operator">--></span> merge<span class="token text string">["Merge"]</span>
  merge <span class="token arrow operator">--></span> release<span class="token text string">["Release"]</span>
  release <span class="token arrow operator">--></span> canary<span class="token text string">["Canary"]</span>
  canary <span class="token arrow operator">--></span> prod<span class="token text string">["Prod"]</span>
  prod <span class="token arrow operator">--></span> rollback<span class="token text string">["Rollback Plan"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer short-lived credentials (OIDC) and explicit policy gates.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Audit who can ship and how; remove implicit paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Observability at Scale: Traces, Cardinality, and Cost]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-08-observability-at-scale-traces-cardinality-and-cost</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-08-observability-at-scale-traces-cardinality-and-cost"/>
        <updated>2022-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (August 2022): Observability at Scale: Traces, Cardinality, and Cost.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Observability at Scale: Traces, Cardinality, and Cost</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Short-lived credentials (OIDC) beat long-lived tokens in pipelines.</li>
<li>Define safety properties before performance goals.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Infrastructure-as-code without policy is just scripting the attack surface.</li>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the minimum set of humans who can ship to production?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>How do you do safe rollouts (canary, blast-radius, rapid rollback)?</li>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Policy enforcement must be consistent across environments.</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Observability pipelines can be attacked (log injection, PII leaks).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Manual policy enforcement or manual security review as the only control.</li>
<li>Assuming deploy equals success without runtime evidence.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Build provenance is a cryptographic statement:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>build</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>artifact</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{attest} \leftarrow \mathrm{Sign}_{k_\text{build}}(\mathrm{hash}(\text{artifact})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">attest</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">build</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">artifact</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Build systems that can prove what happened after an incident.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Treat CI as untrusted: keep tokens short-lived and scoped.</span>
<span class="token keyword">type</span> Token <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  Value <span class="token builtin">string</span>
  ExpiresAtUnix <span class="token builtin">int64</span>
  Scope <span class="token builtin">string</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Audit who can ship and how; remove implicit paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Rate Limiting & Load Shedding: Protecting Reliability SLOs]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-07-rate-limiting-load-shedding-protecting-reliability-slos</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-07-rate-limiting-load-shedding-protecting-reliability-slos"/>
        <updated>2022-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (July 2022): Rate Limiting & Load Shedding: Protecting Reliability SLOs.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Rate Limiting &#x26; Load Shedding: Protecting Reliability SLOs</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Short-lived credentials (OIDC) beat long-lived tokens in pipelines.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
<li>Infrastructure-as-code without policy is just scripting the attack surface.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>What is the minimum set of humans who can ship to production?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollbacks must be executed under time pressure.</li>
<li>Observability pipelines can be attacked (log injection, PII leaks).</li>
<li>Policy enforcement must be consistent across environments.</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Manual policy enforcement or manual security review as the only control.</li>
<li>Long-lived credentials embedded in pipelines.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A policy gate is a predicate over metadata:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi></mrow><mo stretchy="false">(</mo><mtext>deploy</mtext><mo stretchy="false">)</mo><mo>⇔</mo><mi>P</mi><mo stretchy="false">(</mo><mtext>attestation</mtext><mo separator="true">,</mo><mtext> scan</mtext><mo separator="true">,</mo><mtext> env</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{allow}(\text{deploy}) \Leftrightarrow P(\text{attestation},\ \text{scan},\ \text{env}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">allow</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">deploy</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇔</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">(</span><span class="mord text"><span class="mord">attestation</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">scan</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">env</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Build systems that can prove what happened after an incident.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Treat CI as untrusted: keep tokens short-lived and scoped.</span>
<span class="token keyword">type</span> Token <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  Value <span class="token builtin">string</span>
  ExpiresAtUnix <span class="token builtin">int64</span>
  Scope <span class="token builtin">string</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Multi-Region Design: Failover That You Can Actually Test]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-06-multi-region-design-failover-that-you-can-actually-test</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-06-multi-region-design-failover-that-you-can-actually-test"/>
        <updated>2022-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (June 2022): Multi-Region Design: Failover That You Can Actually Test.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Multi-Region Design: Failover That You Can Actually Test</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Make rollback a first-class operation with explicit triggers and rehearsal.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Supply-chain attacks target your CI/CD because it has keys and reach.</li>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>What is the minimum set of humans who can ship to production?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollbacks must be executed under time pressure.</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Policy enforcement must be consistent across environments.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming deploy equals success without runtime evidence.</li>
<li>Trusting CI environments by default.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A policy gate is a predicate over metadata:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi></mrow><mo stretchy="false">(</mo><mtext>deploy</mtext><mo stretchy="false">)</mo><mo>⇔</mo><mi>P</mi><mo stretchy="false">(</mo><mtext>attestation</mtext><mo separator="true">,</mo><mtext> scan</mtext><mo separator="true">,</mo><mtext> env</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{allow}(\text{deploy}) \Leftrightarrow P(\text{attestation},\ \text{scan},\ \text{env}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">allow</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">deploy</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇔</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">(</span><span class="mord text"><span class="mord">attestation</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">scan</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">env</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  pr<span class="token text string">["PR"]</span> <span class="token arrow operator">--></span> checks<span class="token text string">["Checks"]</span>
  checks <span class="token arrow operator">--></span> merge<span class="token text string">["Merge"]</span>
  merge <span class="token arrow operator">--></span> release<span class="token text string">["Release"]</span>
  release <span class="token arrow operator">--></span> canary<span class="token text string">["Canary"]</span>
  canary <span class="token arrow operator">--></span> prod<span class="token text string">["Prod"]</span>
  prod <span class="token arrow operator">--></span> rollback<span class="token text string">["Rollback Plan"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The pipeline is production: it has credentials, network reach, and authority.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-05-kubernetes-hardening-rbac-networkpolicy-and-pod-security</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-05-kubernetes-hardening-rbac-networkpolicy-and-pod-security"/>
        <updated>2022-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (May 2022): Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Kubernetes Hardening: RBAC, NetworkPolicy, and Pod Security</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Short-lived credentials (OIDC) beat long-lived tokens in pipelines.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Supply-chain attacks target your CI/CD because it has keys and reach.</li>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Rollouts are where incidents happen; safe rollback is a security feature.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>How do you do safe rollouts (canary, blast-radius, rapid rollback)?</li>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Policy enforcement must be consistent across environments.</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>Rollbacks must be executed under time pressure.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Long-lived credentials embedded in pipelines.</li>
<li>Assuming deploy equals success without runtime evidence.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Build provenance is a cryptographic statement:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>build</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>artifact</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{attest} \leftarrow \mathrm{Sign}_{k_\text{build}}(\mathrm{hash}(\text{artifact})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">attest</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">build</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">artifact</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  pr<span class="token text string">["PR"]</span> <span class="token arrow operator">--></span> checks<span class="token text string">["Checks"]</span>
  checks <span class="token arrow operator">--></span> merge<span class="token text string">["Merge"]</span>
  merge <span class="token arrow operator">--></span> release<span class="token text string">["Release"]</span>
  release <span class="token arrow operator">--></span> canary<span class="token text string">["Canary"]</span>
  canary <span class="token arrow operator">--></span> prod<span class="token text string">["Prod"]</span>
  prod <span class="token arrow operator">--></span> rollback<span class="token text string">["Rollback Plan"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Build systems that can prove what happened after an incident.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Runtime Security: eBPF, Policy, and Drift Detection]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-04-runtime-security-ebpf-policy-and-drift-detection</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-04-runtime-security-ebpf-policy-and-drift-detection"/>
        <updated>2022-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (April 2022): Runtime Security: eBPF, Policy, and Drift Detection.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Runtime Security: eBPF, Policy, and Drift Detection</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make rollback a first-class operation with explicit triggers and rehearsal.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Make failure modes explicit and observable.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Rollouts are where incidents happen; safe rollback is a security feature.</li>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>How do you do safe rollouts (canary, blast-radius, rapid rollback)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rollbacks must be executed under time pressure.</li>
<li>Policy enforcement must be consistent across environments.</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Trusting CI environments by default.</li>
<li>Long-lived credentials embedded in pipelines.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Build provenance is a cryptographic statement:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>build</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>artifact</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{attest} \leftarrow \mathrm{Sign}_{k_\text{build}}(\mathrm{hash}(\text{artifact})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">attest</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">build</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">artifact</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The pipeline is production: it has credentials, network reach, and authority.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Rehearse incident response for the pipeline itself.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secrets Hygiene: Rotation, Scoping, and Runtime Delivery]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-03-secrets-hygiene-rotation-scoping-and-runtime-delivery</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-03-secrets-hygiene-rotation-scoping-and-runtime-delivery"/>
        <updated>2022-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (March 2022): Secrets Hygiene: Rotation, Scoping, and Runtime Delivery.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secrets Hygiene: Rotation, Scoping, and Runtime Delivery</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Make rollback a first-class operation with explicit triggers and rehearsal.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Rollouts are where incidents happen; safe rollback is a security feature.</li>
<li>Supply-chain attacks target your CI/CD because it has keys and reach.</li>
<li>Infrastructure-as-code without policy is just scripting the attack surface.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>How do you do safe rollouts (canary, blast-radius, rapid rollback)?</li>
<li>What is the minimum set of humans who can ship to production?</li>
<li>Which signals prove correctness (not just availability) in production?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>Rollbacks must be executed under time pressure.</li>
<li>Policy enforcement must be consistent across environments.</li>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Trusting CI environments by default.</li>
<li>Long-lived credentials embedded in pipelines.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A policy gate is a predicate over metadata:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">w</mi></mrow><mo stretchy="false">(</mo><mtext>deploy</mtext><mo stretchy="false">)</mo><mo>⇔</mo><mi>P</mi><mo stretchy="false">(</mo><mtext>attestation</mtext><mo separator="true">,</mo><mtext> scan</mtext><mo separator="true">,</mo><mtext> env</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{allow}(\text{deploy}) \Leftrightarrow P(\text{attestation},\ \text{scan},\ \text{env}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">allow</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">deploy</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇔</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">P</span><span class="mopen">(</span><span class="mord text"><span class="mord">attestation</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">scan</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">env</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Policy should be code with diffs and reviews—guardrails, not guidelines.</p>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  pr<span class="token text string">["PR"]</span> <span class="token arrow operator">--></span> checks<span class="token text string">["Checks"]</span>
  checks <span class="token arrow operator">--></span> merge<span class="token text string">["Merge"]</span>
  merge <span class="token arrow operator">--></span> release<span class="token text string">["Release"]</span>
  release <span class="token arrow operator">--></span> canary<span class="token text string">["Canary"]</span>
  canary <span class="token arrow operator">--></span> prod<span class="token text string">["Prod"]</span>
  prod <span class="token arrow operator">--></span> rollback<span class="token text string">["Rollback Plan"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The pipeline is production: it has credentials, network reach, and authority.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">CI hardening checklist:
- No long-lived secrets in CI
- OIDC to obtain short-lived creds
- Pin dependencies and verify integrity
- Reproducible builds + provenance attestation
- Policy-as-code gates (deploy blocked on evidence)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Reproducible CI/CD: Determinism as Defense]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-02-reproducible-ci-cd-determinism-as-defense</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-02-reproducible-ci-cd-determinism-as-defense"/>
        <updated>2022-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (February 2022): Reproducible CI/CD: Determinism as Defense.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Reproducible CI/CD: Determinism as Defense</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make rollback a first-class operation with explicit triggers and rehearsal.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Treat CI/CD as attacker-controlled until proven otherwise; minimize secrets and privileges.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Infrastructure-as-code without policy is just scripting the attack surface.</li>
<li>Policy drift is the default; guardrails must be automated and enforced.</li>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>What is the minimum set of humans who can ship to production?</li>
<li>What is your supply-chain threat model (dependency poisoning, CI compromise)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Rollbacks must be executed under time pressure.</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>Policy enforcement must be consistent across environments.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Long-lived credentials embedded in pipelines.</li>
<li>Manual policy enforcement or manual security review as the only control.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Build provenance is a cryptographic statement:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>build</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>artifact</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{attest} \leftarrow \mathrm{Sign}_{k_\text{build}}(\mathrm{hash}(\text{artifact})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">attest</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">build</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">artifact</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The pipeline is production: it has credentials, network reach, and authority.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Treat CI as untrusted: keep tokens short-lived and scoped.</span>
<span class="token keyword">type</span> Token <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  Value <span class="token builtin">string</span>
  ExpiresAtUnix <span class="token builtin">int64</span>
  Scope <span class="token builtin">string</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Supply Chain Security: SLSA, SBOM, and Build Provenance]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2022-01-supply-chain-security-slsa-sbom-and-build-provenance</id>
        <link href="https://mayckongiovani.xyz/pensieve/2022-01-supply-chain-security-slsa-sbom-and-build-provenance"/>
        <updated>2022-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (January 2022): Supply Chain Security: SLSA, SBOM, and Build Provenance.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>DevSecOps &#x26; Resilience Engineering</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Supply Chain Security: SLSA, SBOM, and Build Provenance</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make rollback a first-class operation with explicit triggers and rehearsal.</li>
<li>Policy-as-code needs tests, rollout, and rollback like any other production system.</li>
<li>Provenance is a cryptographic statement; ship evidence with artifacts.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Reproducibility is how you know what you shipped is what you built.</li>
<li>Runtime security needs evidence pipelines, not just dashboards.</li>
<li>Rollouts are where incidents happen; safe rollback is a security feature.</li>
<li>Secrets in CI turn “one compromised job” into “full compromise.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent “break glass” from becoming the standard path?</li>
<li>How do you rehearse incident response as code (runbooks, chaos, drills)?</li>
<li>Where do you enforce policy (pre-merge, build, deploy, runtime)?</li>
<li>How do you manage secrets without long-lived credentials in CI?</li>
<li>Which signals prove correctness (not just availability) in production?</li>
<li>How do you do safe rollouts (canary, blast-radius, rapid rollback)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>CI runners are exposed to untrusted code (PRs, dependencies).</li>
<li>Dependencies can be compromised upstream (typosquatting, maintainer takeover).</li>
<li>Policy enforcement must be consistent across environments.</li>
<li>Observability pipelines can be attacked (log injection, PII leaks).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Manual policy enforcement or manual security review as the only control.</li>
<li>Assuming deploy equals success without runtime evidence.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Build provenance is a cryptographic statement:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>build</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>artifact</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{attest} \leftarrow \mathrm{Sign}_{k_\text{build}}(\mathrm{hash}(\text{artifact})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6151em;"></span><span class="mord"><span class="mord mathrm">attest</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">build</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">artifact</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat CI as attacker-controlled until proven otherwise; minimize secrets and privileges.</p>
<p>Make provenance verifiable: “what built this” must be cryptographically bound.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  src<span class="token text string">["Source"]</span> <span class="token arrow operator">--></span> build<span class="token text string">["Build (reproducible)"]</span>
  build <span class="token arrow operator">--></span> attest<span class="token text string">["Attestation"]</span>
  attest <span class="token arrow operator">--></span> scan<span class="token text string">["SAST/DAST/SCA"]</span>
  scan <span class="token arrow operator">--></span> deploy<span class="token text string">["Deploy (policy gates)"]</span>
  deploy <span class="token arrow operator">--></span> runtime<span class="token text string">["Runtime Policy + Observability"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer short-lived credentials (OIDC) and explicit policy gates.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Treat CI as untrusted: keep tokens short-lived and scoped.</span>
<span class="token keyword">type</span> Token <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  Value <span class="token builtin">string</span>
  ExpiresAtUnix <span class="token builtin">int64</span>
  Scope <span class="token builtin">string</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Rollback tests</strong> as part of release (not “if needed”).</li>
<li><strong>Runtime conformance</strong>: detect drift between desired and actual state.</li>
<li><strong>Policy tests</strong>: unit tests for policy-as-code rules.</li>
<li><strong>Dependency tampering drills</strong>: lockfile changes, integrity failures.</li>
<li><strong>Pipeline attack simulations</strong>: compromise a runner and measure blast radius.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse incident response for the pipeline itself.</li>
<li>Continuously scan and inventory dependencies; prioritize by exposure.</li>
<li>Keep a provenance trail for every artifact deployed to production.</li>
<li>Audit who can ship and how; remove implicit paths.</li>
<li>Treat policy changes as security-sensitive deploys (review + rollout).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke all pipeline credentials in an incident?</li>
<li>Can you answer “what code is running” with cryptographic evidence?</li>
<li>What is the smallest CI compromise that becomes a prod compromise today?</li>
<li>Which deploy actions are irreversible and how do you mitigate that?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-218/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-218 (SSDF)</a> — Secure software development practices as an engineering framework.</li>
<li><a href="https://in-toto.io/" target="_blank" rel="nofollow noopener noreferrer">in-toto</a> — Securing the integrity of software supply chains with attestations.</li>
<li><a href="https://www.sigstore.dev/" target="_blank" rel="nofollow noopener noreferrer">Sigstore</a> — Signing and verifying artifacts at scale with transparency logs.</li>
<li><a href="https://slsa.dev/spec/v1.0/" target="_blank" rel="nofollow noopener noreferrer">SLSA v1.0 Specification</a> — Supply-chain levels and provenance requirements.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="DevSecOps"/>
        <category label="security"/>
        <category label="resilience"/>
        <category label="security-critical-infrastructure"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Post-Quantum Readiness at the Edge: Constraints and Migration]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-12-post-quantum-readiness-at-the-edge-constraints-and-migration</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-12-post-quantum-readiness-at-the-edge-constraints-and-migration"/>
        <updated>2021-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (December 2021): Post-Quantum Readiness at the Edge: Constraints and Migration.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Post-Quantum Readiness at the Edge: Constraints and Migration</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Secure updates need rollback protection and staged rollout with safety rails.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
<li>Fleet-scale updates turn bugs into global incidents; rollback must be engineered.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some devices are physically accessible to attackers.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming firmware updates always complete successfully.</li>
<li>Relying on the cloud to enforce edge-local safety properties.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Fleet rollout safety is a monotone constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>rollout</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mrow><mi>k</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mo>⇒</mo><mtext>can_rollback</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mi>k</mi></msub><mo stretchy="false">)</mo><mtext> </mtext><mo>∧</mo><mtext> telemetry_healthy</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{rollout}(v_{k+1}) \Rightarrow \text{can\_rollback}(v_k)\ \wedge\ \text{telemetry\_healthy}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">rollout</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">can_rollback</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">telemetry_healthy</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat device identity as a lifecycle: provision → attest → rotate → revoke → forensics.</p>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  dev<span class="token text string">["Device (identity + attestation)"]</span> <span class="token arrow operator">--></span> gw<span class="token text string">["Gateway"]</span>
  gw <span class="token arrow operator">--></span> bus<span class="token text string">["Message Bus"]</span>
  bus <span class="token arrow operator">--></span> ingest<span class="token text string">["Ingestion"]</span>
  ingest <span class="token arrow operator">--></span> tsdb<span class="token text string">["Time-Series Store"]</span>
  tsdb <span class="token arrow operator">--></span> apps<span class="token text string">["Analytics / Control Plane"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Edge security is about recovery: safe defaults, staged updates, and fast revocation.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the blast radius of a compromised gateway?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Anomaly Detection: What 'Baseline' Means in Industrial Systems]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-11-anomaly-detection-what-baseline-means-in-industrial-systems</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-11-anomaly-detection-what-baseline-means-in-industrial-systems"/>
        <updated>2021-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (November 2021): Anomaly Detection: What 'Baseline' Means in Industrial Systems.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Anomaly Detection: What 'Baseline' Means in Industrial Systems</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Secure updates need rollback protection and staged rollout with safety rails.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
<li>What does incident response look like at fleet scale?</li>
<li>How do devices enroll securely (no shared secrets, minimal manual steps)?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
<li>Devices experience power loss and abrupt restarts.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on the cloud to enforce edge-local safety properties.</li>
<li>Treating identity as a static certificate file.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Fleet rollout safety is a monotone constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>rollout</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mrow><mi>k</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mo>⇒</mo><mtext>can_rollback</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mi>k</mi></msub><mo stretchy="false">)</mo><mtext> </mtext><mo>∧</mo><mtext> telemetry_healthy</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{rollout}(v_{k+1}) \Rightarrow \text{can\_rollback}(v_k)\ \wedge\ \text{telemetry\_healthy}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">rollout</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">can_rollback</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">telemetry_healthy</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<p>Treat device identity as a lifecycle: provision → attest → rotate → revoke → forensics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  dev<span class="token text string">["Device (identity + attestation)"]</span> <span class="token arrow operator">--></span> gw<span class="token text string">["Gateway"]</span>
  gw <span class="token arrow operator">--></span> bus<span class="token text string">["Message Bus"]</span>
  bus <span class="token arrow operator">--></span> ingest<span class="token text string">["Ingestion"]</span>
  ingest <span class="token arrow operator">--></span> tsdb<span class="token text string">["Time-Series Store"]</span>
  tsdb <span class="token arrow operator">--></span> apps<span class="token text string">["Analytics / Control Plane"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat the gateway as a security boundary, not a dumb proxy.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the blast radius of a compromised gateway?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secure Remote Access: Bastions, Just-in-Time, and Audit]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-10-secure-remote-access-bastions-just-in-time-and-audit</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-10-secure-remote-access-bastions-just-in-time-and-audit"/>
        <updated>2021-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (October 2021): Secure Remote Access: Bastions, Just-in-Time, and Audit.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secure Remote Access: Bastions, Just-in-Time, and Audit</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Fleet-scale updates turn bugs into global incidents; rollback must be engineered.</li>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>What does incident response look like at fleet scale?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Devices experience power loss and abrupt restarts.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Some devices are physically accessible to attackers.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming firmware updates always complete successfully.</li>
<li>Treating identity as a static certificate file.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Fleet rollout safety is a monotone constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>rollout</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mrow><mi>k</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mo>⇒</mo><mtext>can_rollback</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mi>k</mi></msub><mo stretchy="false">)</mo><mtext> </mtext><mo>∧</mo><mtext> telemetry_healthy</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{rollout}(v_{k+1}) \Rightarrow \text{can\_rollback}(v_k)\ \wedge\ \text{telemetry\_healthy}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">rollout</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">can_rollback</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">telemetry_healthy</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  dev<span class="token text string">["Device (identity + attestation)"]</span> <span class="token arrow operator">--></span> gw<span class="token text string">["Gateway"]</span>
  gw <span class="token arrow operator">--></span> bus<span class="token text string">["Message Bus"]</span>
  bus <span class="token arrow operator">--></span> ingest<span class="token text string">["Ingestion"]</span>
  ingest <span class="token arrow operator">--></span> tsdb<span class="token text string">["Time-Series Store"]</span>
  tsdb <span class="token arrow operator">--></span> apps<span class="token text string">["Analytics / Control Plane"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat the gateway as a security boundary, not a dumb proxy.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Design rollouts to be interruptible and reversible.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>What is the blast radius of a compromised gateway?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Offline-First Edge: Consistency During Intermittent Connectivity]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-09-offline-first-edge-consistency-during-intermittent-connectiv</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-09-offline-first-edge-consistency-during-intermittent-connectiv"/>
        <updated>2021-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (September 2021): Offline-First Edge: Consistency During Intermittent Connectivity.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Offline-First Edge: Consistency During Intermittent Connectivity</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Secure updates need rollback protection and staged rollout with safety rails.</li>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Make failure modes explicit and observable.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>What does incident response look like at fleet scale?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
<li>Devices experience power loss and abrupt restarts.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on the cloud to enforce edge-local safety properties.</li>
<li>Assuming firmware updates always complete successfully.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Fleet rollout safety is a monotone constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>rollout</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mrow><mi>k</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mo>⇒</mo><mtext>can_rollback</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mi>k</mi></msub><mo stretchy="false">)</mo><mtext> </mtext><mo>∧</mo><mtext> telemetry_healthy</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{rollout}(v_{k+1}) \Rightarrow \text{can\_rollback}(v_k)\ \wedge\ \text{telemetry\_healthy}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">rollout</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">can_rollback</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">telemetry_healthy</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  dev<span class="token text string">["Device (identity + attestation)"]</span> <span class="token arrow operator">--></span> gw<span class="token text string">["Gateway"]</span>
  gw <span class="token arrow operator">--></span> bus<span class="token text string">["Message Bus"]</span>
  bus <span class="token arrow operator">--></span> ingest<span class="token text string">["Ingestion"]</span>
  ingest <span class="token arrow operator">--></span> tsdb<span class="token text string">["Time-Series Store"]</span>
  tsdb <span class="token arrow operator">--></span> apps<span class="token text string">["Analytics / Control Plane"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer protocols that degrade safely under packet loss and skew.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What is the blast radius of a compromised gateway?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Safety-Critical vs Security-Critical: Integrating Two Worlds]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-08-safety-critical-vs-security-critical-integrating-two-worlds</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-08-safety-critical-vs-security-critical-integrating-two-worlds"/>
        <updated>2021-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (August 2021): Safety-Critical vs Security-Critical: Integrating Two Worlds.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Safety-Critical vs Security-Critical: Integrating Two Worlds</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Define safety properties before performance goals.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Fleet-scale updates turn bugs into global incidents; rollback must be engineered.</li>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>What does incident response look like at fleet scale?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Devices experience power loss and abrupt restarts.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
<li>Some devices are physically accessible to attackers.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect time synchronization at the edge.</li>
<li>Assuming firmware updates always complete successfully.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat device identity as a lifecycle: provision → attest → rotate → revoke → forensics.</p>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> D as Device
  <span class="token keyword">participant</span> G as Gateway
  <span class="token keyword">participant</span> C as Cloud
  D<span class="token arrow operator">->></span>G<span class="token operator">:</span> telemetry<span class="token text string">(nonce, ctr, sig)</span>
  G<span class="token arrow operator">->></span>C<span class="token operator">:</span> forward + policy tags
  C<span class="token arrow operator">-->></span>G<span class="token operator">:</span> update policy
  G<span class="token arrow operator">-->></span>D<span class="token operator">:</span> commands <span class="token text string">(bounded)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Edge security is about recovery: safe defaults, staged updates, and fast revocation.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>What is the blast radius of a compromised gateway?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Gateway Architecture: Protocol Translation Without Becoming a Bottleneck]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-07-gateway-architecture-protocol-translation-without-becoming-a</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-07-gateway-architecture-protocol-translation-without-becoming-a"/>
        <updated>2021-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (July 2021): Gateway Architecture: Protocol Translation Without Becoming a Bottleneck.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Gateway Architecture: Protocol Translation Without Becoming a Bottleneck</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
<li>Fleet-scale updates turn bugs into global incidents; rollback must be engineered.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you provision identity and rotate it over years?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>How do devices enroll securely (no shared secrets, minimal manual steps)?</li>
<li>What does incident response look like at fleet scale?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
<li>Some devices are physically accessible to attackers.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming firmware updates always complete successfully.</li>
<li>Relying on the cloud to enforce edge-local safety properties.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> D as Device
  <span class="token keyword">participant</span> G as Gateway
  <span class="token keyword">participant</span> C as Cloud
  D<span class="token arrow operator">->></span>G<span class="token operator">:</span> telemetry<span class="token text string">(nonce, ctr, sig)</span>
  G<span class="token arrow operator">->></span>C<span class="token operator">:</span> forward + policy tags
  C<span class="token arrow operator">-->></span>G<span class="token operator">:</span> update policy
  G<span class="token arrow operator">-->></span>D<span class="token operator">:</span> commands <span class="token text string">(bounded)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat the gateway as a security boundary, not a dumb proxy.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Design rollouts to be interruptible and reversible.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What is the blast radius of a compromised gateway?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Time-Series at Scale: Ingestion, Downsampling, and Query Isolation]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-06-time-series-at-scale-ingestion-downsampling-and-query-isolat</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-06-time-series-at-scale-ingestion-downsampling-and-query-isolat"/>
        <updated>2021-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (June 2021): Time-Series at Scale: Ingestion, Downsampling, and Query Isolation.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Time-Series at Scale: Ingestion, Downsampling, and Query Isolation</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Define safety properties before performance goals.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle intermittent connectivity without corrupting state?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>What does incident response look like at fleet scale?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
<li>Some devices are physically accessible to attackers.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming firmware updates always complete successfully.</li>
<li>Assuming perfect time synchronization at the edge.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<p>Treat device identity as a lifecycle: provision → attest → rotate → revoke → forensics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  dev<span class="token text string">["Device (identity + attestation)"]</span> <span class="token arrow operator">--></span> gw<span class="token text string">["Gateway"]</span>
  gw <span class="token arrow operator">--></span> bus<span class="token text string">["Message Bus"]</span>
  bus <span class="token arrow operator">--></span> ingest<span class="token text string">["Ingestion"]</span>
  ingest <span class="token arrow operator">--></span> tsdb<span class="token text string">["Time-Series Store"]</span>
  tsdb <span class="token arrow operator">--></span> apps<span class="token text string">["Analytics / Control Plane"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer protocols that degrade safely under packet loss and skew.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the blast radius of a compromised gateway?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Zero Trust for IIoT: Network Segmentation and Policy Enforcement]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-05-zero-trust-for-iiot-network-segmentation-and-policy-enforcem</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-05-zero-trust-for-iiot-network-segmentation-and-policy-enforcem"/>
        <updated>2021-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (May 2021): Zero Trust for IIoT: Network Segmentation and Policy Enforcement.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Zero Trust for IIoT: Network Segmentation and Policy Enforcement</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Secure updates need rollback protection and staged rollout with safety rails.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Fleet-scale updates turn bugs into global incidents; rollback must be engineered.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do devices enroll securely (no shared secrets, minimal manual steps)?</li>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
<li>What does incident response look like at fleet scale?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Devices experience power loss and abrupt restarts.</li>
<li>Some devices are physically accessible to attackers.</li>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating identity as a static certificate file.</li>
<li>Assuming firmware updates always complete successfully.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<p>Treat device identity as a lifecycle: provision → attest → rotate → revoke → forensics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> D as Device
  <span class="token keyword">participant</span> G as Gateway
  <span class="token keyword">participant</span> C as Cloud
  D<span class="token arrow operator">->></span>G<span class="token operator">:</span> telemetry<span class="token text string">(nonce, ctr, sig)</span>
  G<span class="token arrow operator">->></span>C<span class="token operator">:</span> forward + policy tags
  C<span class="token arrow operator">-->></span>G<span class="token operator">:</span> update policy
  G<span class="token arrow operator">-->></span>D<span class="token operator">:</span> commands <span class="token text string">(bounded)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer protocols that degrade safely under packet loss and skew.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Anti-replay sketch: monotonic counter + bounded window.</span>
<span class="token keyword">type</span> Counter <span class="token builtin">uint64</span>
<span class="token keyword">type</span> SeenStore <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">MaxCounter</span><span class="token punctuation">(</span>deviceID <span class="token builtin">string</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>Counter<span class="token punctuation">,</span> <span class="token builtin">error</span><span class="token punctuation">)</span>
  <span class="token function">UpdateMax</span><span class="token punctuation">(</span>deviceID <span class="token builtin">string</span><span class="token punctuation">,</span> c Counter<span class="token punctuation">)</span> <span class="token builtin">error</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What is the blast radius of a compromised gateway?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Firmware Update Pipelines: Rollouts, Canary, and Recovery]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-04-firmware-update-pipelines-rollouts-canary-and-recovery</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-04-firmware-update-pipelines-rollouts-canary-and-recovery"/>
        <updated>2021-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (April 2021): Firmware Update Pipelines: Rollouts, Canary, and Recovery.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Firmware Update Pipelines: Rollouts, Canary, and Recovery</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Secure updates need rollback protection and staged rollout with safety rails.</li>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does incident response look like at fleet scale?</li>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>How do devices enroll securely (no shared secrets, minimal manual steps)?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
<li>Some devices are physically accessible to attackers.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming firmware updates always complete successfully.</li>
<li>Relying on the cloud to enforce edge-local safety properties.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat device identity as a lifecycle: provision → attest → rotate → revoke → forensics.</p>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> D as Device
  <span class="token keyword">participant</span> G as Gateway
  <span class="token keyword">participant</span> C as Cloud
  D<span class="token arrow operator">->></span>G<span class="token operator">:</span> telemetry<span class="token text string">(nonce, ctr, sig)</span>
  G<span class="token arrow operator">->></span>C<span class="token operator">:</span> forward + policy tags
  C<span class="token arrow operator">-->></span>G<span class="token operator">:</span> update policy
  G<span class="token arrow operator">-->></span>D<span class="token operator">:</span> commands <span class="token text string">(bounded)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat the gateway as a security boundary, not a dumb proxy.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Anti-replay sketch: monotonic counter + bounded window.</span>
<span class="token keyword">type</span> Counter <span class="token builtin">uint64</span>
<span class="token keyword">type</span> SeenStore <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">MaxCounter</span><span class="token punctuation">(</span>deviceID <span class="token builtin">string</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>Counter<span class="token punctuation">,</span> <span class="token builtin">error</span><span class="token punctuation">)</span>
  <span class="token function">UpdateMax</span><span class="token punctuation">(</span>deviceID <span class="token builtin">string</span><span class="token punctuation">,</span> c Counter<span class="token punctuation">)</span> <span class="token builtin">error</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What is the blast radius of a compromised gateway?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Edge-to-Cloud Messaging: MQTT, OPC UA, and Threat Models]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-03-edge-to-cloud-messaging-mqtt-opc-ua-and-threat-models</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-03-edge-to-cloud-messaging-mqtt-opc-ua-and-threat-models"/>
        <updated>2021-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (March 2021): Edge-to-Cloud Messaging: MQTT, OPC UA, and Threat Models.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Edge-to-Cloud Messaging: MQTT, OPC UA, and Threat Models</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Make failure modes explicit and observable.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>How do devices enroll securely (no shared secrets, minimal manual steps)?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>What does incident response look like at fleet scale?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some devices are physically accessible to attackers.</li>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
<li>Devices experience power loss and abrupt restarts.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on the cloud to enforce edge-local safety properties.</li>
<li>Assuming firmware updates always complete successfully.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> D as Device
  <span class="token keyword">participant</span> G as Gateway
  <span class="token keyword">participant</span> C as Cloud
  D<span class="token arrow operator">->></span>G<span class="token operator">:</span> telemetry<span class="token text string">(nonce, ctr, sig)</span>
  G<span class="token arrow operator">->></span>C<span class="token operator">:</span> forward + policy tags
  C<span class="token arrow operator">-->></span>G<span class="token operator">:</span> update policy
  G<span class="token arrow operator">-->></span>D<span class="token operator">:</span> commands <span class="token text string">(bounded)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer protocols that degrade safely under packet loss and skew.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Design rollouts to be interruptible and reversible.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>What is the blast radius of a compromised gateway?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secure Telemetry: Integrity, Nonce Discipline, and Replay Protection]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-02-secure-telemetry-integrity-nonce-discipline-and-replay-prote</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-02-secure-telemetry-integrity-nonce-discipline-and-replay-prote"/>
        <updated>2021-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (February 2021): Secure Telemetry: Integrity, Nonce Discipline, and Replay Protection.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Secure Telemetry: Integrity, Nonce Discipline, and Replay Protection</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Device identity is a lifecycle: provision → attest → rotate → revoke → forensics.</li>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Secure updates need rollback protection and staged rollout with safety rails.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Identity and freshness are the foundation of telemetry integrity.</li>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
<li>Fleet-scale updates turn bugs into global incidents; rollback must be engineered.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does incident response look like at fleet scale?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>What is your offline behavior (safe mode vs degraded mode)?</li>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you handle intermittent connectivity without corrupting state?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Devices experience power loss and abrupt restarts.</li>
<li>Some devices are physically accessible to attackers.</li>
<li>Gateways can be compromised; isolate blast radius.</li>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating identity as a static certificate file.</li>
<li>Assuming perfect time synchronization at the edge.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Fleet rollout safety is a monotone constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>rollout</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mrow><mi>k</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mo>⇒</mo><mtext>can_rollback</mtext><mo stretchy="false">(</mo><msub><mi>v</mi><mi>k</mi></msub><mo stretchy="false">)</mo><mtext> </mtext><mo>∧</mo><mtext> telemetry_healthy</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{rollout}(v_{k+1}) \Rightarrow \text{can\_rollback}(v_k)\ \wedge\ \text{telemetry\_healthy}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">rollout</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.06em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">can_rollback</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03588em;">v</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0359em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord text"><span class="mord">telemetry_healthy</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> D as Device
  <span class="token keyword">participant</span> G as Gateway
  <span class="token keyword">participant</span> C as Cloud
  D<span class="token arrow operator">->></span>G<span class="token operator">:</span> telemetry<span class="token text string">(nonce, ctr, sig)</span>
  G<span class="token arrow operator">->></span>C<span class="token operator">:</span> forward + policy tags
  C<span class="token arrow operator">-->></span>G<span class="token operator">:</span> update policy
  G<span class="token arrow operator">-->></span>D<span class="token operator">:</span> commands <span class="token text string">(bounded)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Edge security is about recovery: safe defaults, staged updates, and fast revocation.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What is the blast radius of a compromised gateway?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Device Identity: Provisioning, Attestation, and Lifecycle]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2021-01-device-identity-provisioning-attestation-and-lifecycle</id>
        <link href="https://mayckongiovani.xyz/pensieve/2021-01-device-identity-provisioning-attestation-and-lifecycle"/>
        <updated>2021-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (January 2021): Device Identity: Provisioning, Attestation, and Lifecycle.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>IIoT Platforms &#x26; Edge Security</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Device Identity: Provisioning, Attestation, and Lifecycle</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Design for power loss and intermittent links; recovery is the primary feature.</li>
<li>Gateways are security boundaries; isolate blast radius and enforce policy early.</li>
<li>Replay protection must not rely on wall-clock time alone (counters + windows).</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Edge systems fail differently: power loss, intermittent links, and physical access.</li>
<li>Gateways become choke points; design them as security boundaries.</li>
<li>Operational constraints (bandwidth, CPU) drive protocol choices.</li>
<li>Adversaries can replay and spoof data to mislead control planes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you terminate trust (device, gateway, cloud) and why?</li>
<li>How do you prevent replay and reordering from becoming false control signals?</li>
<li>What does incident response look like at fleet scale?</li>
<li>How do you do secure updates (rollback protection, staged rollout, recovery)?</li>
<li>How do you provision identity and rotate it over years?</li>
<li>How do devices enroll securely (no shared secrets, minimal manual steps)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Firmware updates can fail mid-flight; partial installation is possible.</li>
<li>Devices experience power loss and abrupt restarts.</li>
<li>Connectivity is intermittent and high-latency; retries amplify costs.</li>
<li>Time sync is weak; clocks drift and may be manipulated.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming perfect time synchronization at the edge.</li>
<li>Treating identity as a static certificate file.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>At the edge, identity and freshness are everything. A typical anti-replay constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>accept</mtext><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">n</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">e</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo mathvariant="normal">∉</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi></mrow><mtext> </mtext><mo>∧</mo><mtext> </mtext><mrow><mi mathvariant="normal">t</mi><mi mathvariant="normal">s</mi></mrow><mo stretchy="false">(</mo><mi>m</mi><mo stretchy="false">)</mo><mo>∈</mo><mo stretchy="false">[</mo><mi>t</mi><mo>−</mo><mi mathvariant="normal">Δ</mi><mo separator="true">,</mo><mi>t</mi><mo>+</mo><mi mathvariant="normal">Δ</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{accept}(m)\Rightarrow \mathrm{nonce}(m)\notin \mathrm{Seen}\ \wedge\ \mathrm{ts}(m)\in [t-\Delta,t+\Delta].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">accept</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">nonce</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mord"><span class="mrel">∈</span></span><span class="mord vbox"><span class="thinbox"><span class="llap"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="inner"><span class="mord"><span class="mord">/</span><span class="mspace" style="margin-right:0.0556em;"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm">Seen</span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">ts</span></span><span class="mopen">(</span><span class="mord mathnormal">m</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∈</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mopen">[</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">−</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord">Δ</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">Δ</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Use monotonic counters when time is untrusted; combine with nonces and bounded windows.</p>
<p>Define safe modes explicitly: what do devices do when policy can’t be fetched?</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  dev<span class="token text string">["Device (identity + attestation)"]</span> <span class="token arrow operator">--></span> gw<span class="token text string">["Gateway"]</span>
  gw <span class="token arrow operator">--></span> bus<span class="token text string">["Message Bus"]</span>
  bus <span class="token arrow operator">--></span> ingest<span class="token text string">["Ingestion"]</span>
  ingest <span class="token arrow operator">--></span> tsdb<span class="token text string">["Time-Series Store"]</span>
  tsdb <span class="token arrow operator">--></span> apps<span class="token text string">["Analytics / Control Plane"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Prefer protocols that degrade safely under packet loss and skew.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Firmware update safety checklist:
- Signed manifest with version + hash
- Rollback protection (anti-downgrade)
- A/B partitions or staged apply
- Health check + watchdog
- Telemetry proves rollout state</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Key rotation drills</strong> across device + gateway + cloud.</li>
<li><strong>Hardware-in-the-loop</strong> tests for update and recovery paths.</li>
<li><strong>Replay/reorder</strong> simulations for telemetry and control messages.</li>
<li><strong>Power-loss</strong> fault injection during flash writes and installs.</li>
<li><strong>Scale tests</strong>: provisioning bursts, reconnect storms, gateway failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Maintain an identity inventory: device → cert/keys → firmware version.</li>
<li>Make revocation fast: emergency disable, quarantine, and re-enrollment.</li>
<li>Treat time sync alerts as security signals (NTP manipulation).</li>
<li>Design rollouts to be interruptible and reversible.</li>
<li>Monitor fleet health by cohort (version, region, gateway).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the blast radius of a compromised gateway?</li>
<li>Which messages are allowed to cause physical effects and under what conditions?</li>
<li>How quickly can you revoke a compromised device identity globally?</li>
<li>What does “safe behavior” mean when the cloud is unreachable?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/pubs/ir/8259/a/final" target="_blank" rel="nofollow noopener noreferrer">NISTIR 8259A: IoT Device Cybersecurity Capability Core Baseline</a> — Baseline capabilities and lifecycle expectations for devices.</li>
<li><a href="https://uptane.github.io/" target="_blank" rel="nofollow noopener noreferrer">Uptane</a> — Secure software updates for fleets with realistic threat models.</li>
<li><a href="https://theupdateframework.github.io/specification/latest/" target="_blank" rel="nofollow noopener noreferrer">The Update Framework (TUF) Specification</a> — Secure update metadata, compromise recovery, and key rotation.</li>
<li><a href="https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html" target="_blank" rel="nofollow noopener noreferrer">MQTT Version 5.0 (OASIS)</a> — Messaging semantics, session behavior, and constraints at the edge.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="IIoT"/>
        <category label="security-critical-infrastructure"/>
        <category label="distributed-systems"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Spec-Driven Development: Making the Spec the Center of Gravity]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-12-spec-driven-development-making-the-spec-the-center-of-gravit</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-12-spec-driven-development-making-the-spec-the-center-of-gravit"/>
        <updated>2020-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (December 2020): Spec-Driven Development: Making the Spec the Center of Gravity.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Spec-Driven Development: Making the Spec the Center of Gravity</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Refinement boundaries prevent “spec drift” between paper and code.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>What is the refinement boundary between spec and implementation?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
<li>How do you convert counterexamples into test harnesses?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
<li>Teams need workflows that keep models and code aligned over time.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating verification as a one-time event rather than a process.</li>
<li>Proving the whole system end-to-end with all implementation details.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Write properties in plain language next to the formal version.</p>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  props<span class="token text string">["Properties"]</span> <span class="token arrow operator">--></span> inv<span class="token text string">["Invariants"]</span>
  inv <span class="token arrow operator">--></span> model<span class="token text string">["Model"]</span>
  model <span class="token arrow operator">--></span> cex<span class="token text string">["Counterexamples"]</span>
  cex <span class="token arrow operator">--></span> tests<span class="token text string">["Regression Tests"]</span>
  tests <span class="token arrow operator">--></span> model</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep refinement boundaries explicit: what the spec promises vs what code enforces.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Workflow:
1) Write a model with a few state variables.
2) State invariants (safety) and progress conditions (liveness).
3) Run model checker with tight bounds.
4) Minimize counterexamples into test cases.
5) Iterate until failures are boring.</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the smallest model that reproduces your worst incident class?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>How will you keep models aligned during rapid iteration?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Boosting quantum computer hardware performance with TensorFlow]]></title>
        <id>https://mayckongiovani.xyz/pensieve/boosting-quantum-computer-hardware</id>
        <link href="https://mayckongiovani.xyz/pensieve/boosting-quantum-computer-hardware"/>
        <updated>2020-11-03T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Boosting quantum computer hardware performance with TensorFlow]]></summary>
        <content type="html"><![CDATA[<p>Google recently announced the release of TensorFlow Quantum - a toolset for combining state-of-the-art machine learning techniques with quantum algorithm design. This was an important step to build tools for developers working on quantum applications - users operating primarily at the “top of the stack”.</p>
<p>In parallel we’ve been building a complementary TensorFlow-based toolset working from the hardware level up - from the bottom of the stack. Our efforts have focused on improving the performance of quantum computing hardware through the integration of a set of techniques we call quantum firmware.</p>
<p>In this article we’ll provide an overview of the fundamental driver for this work - combating noise and error in quantum computers - and describe how the team at Q-CTRL uses TensorFlow to efficiently characterize and suppress the impact of noise and imperfections in quantum hardware. These are key challenges in the global effort to make quantum computers useful.</p>
<p>The Achilles heel of quantum computers - noise and error
Quantum computing, simply put, is a new way to process information using the laws of quantum physics - the rules that govern nature on tiny size scales. Through decades of effort in science and engineering we’re now ready to put this physics to work solving problems that are exceptionally difficult for regular computers.</p>
<p>Realizing useful computations on today’s systems requires a recognition that performance is predominantly limited by hardware imperfections and failures, not system size. Susceptibility to noise and error remains the Achilles heel of quantum computers, and ultimately limits the range and utility of algorithms run on quantum computing hardware.</p>
<p>As a broad community average, most quantum computer hardware can run just a few dozen calculations over a time much less than one millisecond before requiring a reset due to the influence of noise. Depending on the specifics that’s about 1024 times worse than the hardware in a laptop!</p>
<p>This is the heart of why quantum computing is really hard. In this context, “noise” describes all of the things that cause interference in a quantum computer. Just like a mobile phone call can suffer interference leading it to break up, a quantum computer is susceptible to interference from all sorts of sources, like electromagnetic signals coming from WiFi or disturbances in the Earth’s magnetic field.</p>
<p>When qubits in a quantum computer are exposed to this kind of noise, the information in them gets degraded just the way sound quality is degraded by interference on a call. In a quantum system this process is known as decoherence. Decoherence causes the information encoded in a quantum computer to become randomized - and this leads to errors when we execute an algorithm. The greater the influence of noise, the shorter the algorithm that can be run.</p>
<p>So what do we do about this? To start, for the past two decades teams have been working to make their hardware more passively stable - shielding it from the noise that causes decoherence. At the same time theorists have designed a clever algorithm called Quantum Error Correction that can identify and fix errors in the hardware, based in large part on classical error correction codes. This is essential in principle, but the downside is that to make it work you have to spread the information in one qubit over lots of qubits; it may take 1000 or more physical qubits to realize just one error-corrected “logical qubit”. Today’s machines are nowhere near capable of getting benefits from this kind of Quantum Error Correction.</p>
<p>Q-CTRL adds something extra - quantum firmware - which can stabilize the qubits against noise and decoherence without the need for extra resources. It does this by adding new solutions at the lowest layer of the quantum computing stack that improve the hardware’s robustness to error.</p>
<p>Building quantum firmware with TensorFlow</p>
<p>Quantum firmware describes a set of protocols whose purpose is to deliver quantum hardware with augmented performance to higher levels of abstraction in the quantum computing stack. The choice of the term firmware reflects the fact that the relevant routines are usually software-defined but embedded proximal to the physical layer and effectively invisible to higher layers of abstraction.</p>
<p>Quantum computing hardware generally relies on a form of precisely engineered light-matter interaction in order to enact quantum logic operations. These operations in a sense constitute the native machine language for a quantum computer; a timed pulse of microwaves on resonance with a superconducting qubit can translate to an effective bit-flip operation while another pulse may implement a conditional logic operation between a pair of qubits. An appropriate composition of these electromagnetic signals then implements the target quantum algorithm.</p>
<p>Quantum firmware determines how the physical hardware should be manipulated, redefining the hardware machine language in a way that improves stability against decoherence. Key to this process is the calculation of noise-robust operations using information gleaned from the hardware itself.</p>
<p>Building in TensorFlow was essential to moving beyond “home-built’’ code to commercial-grade products for Q-CTRL. Underpinning these techniques (formally coming from the field of quantum control) are tools allowing us to perform complex gradient-based optimizations. We express all optimization problems as data flow graphs, which describe how optimization variables (variables that can be tuned by the optimizer) are transformed into the cost function (the objective that the optimizer attempts to minimize). We combine custom convenience functions with access to TensorFlow primitives in order to efficiently perform optimizations as used in many different parts of our workflow. And critically, we exploit TensorFlow’s efficient gradient calculation tools to address what is often the weakest link in home-built implementations, especially as the analytic form of the relevant function is often nonlinear and contains many complex dependencies.</p>
<p>For example, consider the case of defining a numerically optimized error-robust quantum bit flip used to manipulate a qubit - the analog of a classical NOT gate. As mentioned above, in a superconducting qubit this is achieved using a pulse of microwaves. We have the freedom to “shape” various aspects of the envelope of the pulse in order to enact the same mathematical transformation in a way that exhibits robustness against common noise sources, such as fluctuations in the strength or frequency of the microwaves.</p>
<p>To do this we first define the data flow graph used to optimize the manipulation of this qubit - it includes objects that describe available “knobs” to adjust, the sources of noise, and the target operation .</p>
<p>Once the graph has been defined inside our context manager, an object must be created that ties together the objective function (in this case minimizing the resultant gate error) and the desired outputs defining the shape of the microwave pulse. With the graph object created, an optimization can be run using a service that returns a new graph object containing the results of the optimization.</p>
<p>This structure allows us to simply create helper functions which enable physically motivated constraints to be built directly into the graph. For instance, these might be symmetry requirements, limits on how a signal changes in time, or even incorporation of characteristics of the electronics systems used to generate the microwave pulses. Any other capabilities not directly covered by this library of helper functions can also be directly coded as TensorFlow primitives.</p>
<p>With this approach we achieve an extremely flexible and high-performance optimization engine; our direct benchmarking has revealed order-of-magnitude benefits in time to solution relative to the best available alternative architectures.</p>
<p>The capabilities enabled by this toolkit span the space of tasks required to stabilize quantum computing hardware and reduce errors at the lowest layer of the quantum computing stack. And importantly they’re experimentally verified on real quantum computing hardware; quantum firmware has been shown to reduce the likelihood of errors, mitigate system performance variations across devices, stabilize hardware against slowly drifting out of calibration, and even make quantum logic operations more compatible with higher level abstractions in quantum computing such as quantum error correction. All of these capabilities and real hardware demonstrations are accessible via our publicly available User Guides and Application Notes in executable Jupyter notebook form.</p>
<p>Ultimately, we believe that building and operating large-scale quantum computing systems will be effectively impossible without the integration of the capabilities encapsulated in quantum firmware. There are many concepts to be drawn from across the fields of machine learning and robotic control in the drive for performance and autonomy, and TensorFlow has proven an efficient language to support the development of the critical toolsets.</p>
<p>A brief history of QC, from Shor to quantum machine learning
The quantum computing boom started in 1994 with the discovery of Shor’s algorithm for factoring large numbers. Public key cryptosystems — which is to say, most encryption — rely on the mathematical complexity of factoring primes to keep messages safe from prying computers. By virtue of their approach to encoding and processing information, however, quantum computers are conjectured to be able to factor primes faster — exponentially faster — than a classical machine. In principle this poses an existential threat not only to national security, but also emerging technologies such as cryptocurrencies.</p>
<p>This realization set in motion the development of the entire field of quantum computing. Shor’s algorithm spurred the NSA to begin one of its first ever open, University-driven research programs asking the question of whether such systems could be built. Fast forward to 2020 and quantum supremacy has been achieved, meaning that a real quantum computing hardware system has performed a task that’s effectively impossible for even the world’s largest supercomputers.</p>
<p>Quantum supremacy is an important technical milestone whose practical importance in solving problems of relevance to end users remains a bit unclear. Our community is continuing to make great progress towards quantum advantage - a threshold indicating that it’s actually cheaper or faster to use a quantum computer for a problem of practical relevance. And for the right problems, we think that within the next 5-10 years we’ll cross that threshold with a quantum computer that isn’t that much bigger than the ones we have today. It just needs to perform much better.</p>
<p>So, which problems are the right problems for quantum computers to address first?</p>
<p>In many respects, Shor’s algorithm has receded in importance as the scale of the challenge emerged. A recent technical analysis suggests that we’re unlikely to see Shor deployed at a useful scale until 2039. Today, small-scale machines with a couple of dozen interacting qubits exist in labs around the world, built from superconducting circuits, individual trapped atoms, or similarly exotic materials. The problem is that these early machines are just too small and too fragile to solve problems relevant to factoring.</p>
<p>To factor a number sufficiently large to be relevant in cryptography, one would need a system composed of thousands of qubits capable of handling trillions of operations each. This is nothing for a conventional machine where hardware can run for a billion years at a billion operations per second and never be likely to suffer a fault. But as we’ve seen it’s quite a different story for quantum computers.</p>
<p>These limits have driven the emergence of a new class of applications in materials science and chemistry that could prove equally impactful, using much smaller systems. Quantum computing in the near term could also help develop new classes of artificial intelligence systems. Recent efforts have demonstrated a strong and unexpected link between quantum computation and artificial neural networks, potentially portending new approaches to machine learning.</p>
<p>This class of problem can often be cast as optimizations where input into a classical machine learning algorithm comes from a small quantum computation, or where data is represented in the quantum domain and a learning procedure implemented. TensorFlow Quantum provides an exciting toolset for developers seeking new and improved ways to exploit the small quantum computers existing now and in the near future.</p>
<p>Still, even those small machines don’t perform particularly well. Q-CTRL’s quantum firmware enables users to extract maximum performance from hardware. Thus we see that TensorFlow has a critical role to play across the emerging quantum computing software stack - from quantum firmware through to algorithms for quantum machine learning.</p>
<p>Resources if you’d like to learn more
We appreciate that members of the TensorFlow community may have varying levels of familiarity with quantum computing, and that this overview was only a starting point. To help readers interested in learning more about quantum computing we’re happy to provide a few resources:</p>
<p>For those knowledgeable about machine learning, Q-CTRL has also produced a series of webinars introducing the concept of Robust Control in quantum computing and even demonstrating reinforcement learning to discover gates on real quantum hardware.
If you need to start from zero, Q-CTRL has produced a series of introductory video tutorials helping the uninitiated begin their quantum journey via our learning center. We also offer a visual interface enabling new users to discover and build intuition for the core concepts underlying quantum computing - including the impact of noise on quantum hardware.
Jack Hidary from X wrote a great text focused on linking the foundations of quantum computing with how teams today write code for quantum machines.
The traditional “formal” starting point for those interested in quantum computing is the timeless textbook from “Mike and Ike”</p>]]></content>
        <category label="Quantum Computing"/>
        <category label="TensorFlow"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Simulating subatomic physics on a quantum computer]]></title>
        <id>https://mayckongiovani.xyz/pensieve/simulating-subatomic-physics-on-a-quantum-computer</id>
        <link href="https://mayckongiovani.xyz/pensieve/simulating-subatomic-physics-on-a-quantum-computer"/>
        <updated>2020-11-03T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[How quantum computing could be a game-changer in our understanding of quantum processes.]]></summary>
        <content type="html"><![CDATA[<p>When two heavy ions collide inside a particle accelerator, they produce a near-perfect fluid through which an assortment of fundamental particles swim. For scientists to accurately simulate even a tiny drop of this hot and dense subatomic brew with a classical computer, it would take longer than the age of the universe.</p>
<p>A collaboration of theorists, experimentalists and computer scientists are exploring how they could crack the mathematics with the help of a powerful and emerging tool: quantum computing.</p>
<p>“It’s time for us to start thinking about how we can benefit from advances in quantum hardware,” says James Mulligan, a postdoc at the US Department of Energy’s Lawrence Berkeley National Laboratory working on the ALICE Experiment.</p>
<p>Today, physicists use clusters of high-powered classical computers to crunch numbers and generate simulations of the subatomic world. Classical computers reduce complex information into combinations of ones and zeros called bits. A computer’s hardware processes and encodes these bits by releasing tiny bursts of electrons (for example, a one could be represented by a charge and a zero with no charge). From these simple building blocks, computers can perform incredibly complex calculations, but they require a huge amount of time and resources.</p>
<p>A quantum computer takes this principle of classical computing and adds a thick layer of nuance.</p>
<p>“It hinges on the fact that quantum space has properties that classical bits of information do not,” Mulligan says. “A quantum object [such as a particle] can simultaneously be in two states at once, something we call superposition.”</p>
<p>Quantum computing swaps the deterministic property of “charge vs. no charge” for a quantum property such as an electron’s spin. Spin is an intrinsic characteristic that—when measured—will settle into one of two possible states: ‘spin-up’ or ‘spin-down.’ But because it’s a quantum property, until a measurement is made, the electron’s spin is a superposition of both possibilities.</p>
<p>“If you think of the electron’s spin like a needle rotating around inside a sphere, it could point in any direction,” says Xiaojun Yao, a postdoc at the Massachusetts Institute of Technology. “When a measurement is made, it will be either spin up or spin down, but what matters is what happens before we do the measurement. We can gain some advantage.”</p>
<p>Each qubit—that is, the quantum equivalent of a bit—behaves like a microscopic probability spinner that can be tuned and controlled by the computer’s programming. The tuning (which is represented by a complex number) replaces the binary ‘one or zero’ notation of classical bits.</p>
<p>“In practice, one qubit cannot be more powerful than a classical bit,” Yao says. "But multiple qubits can be more powerful than multiple classical bits. Theoretically, a small collection of qubits could store a huge amount of information.”</p>
<p>This switcheroo from binary to non-binary dramatically increases a quantum computer’s ability to perform multifaceted calculations. “It’s exponential,” says Felix Ringer, a postdoc at Berkeley Lab. “A calculation using n number of qubits on a quantum computer would need 2n classical bits on a standard computer.”</p>
<p>While quantum computers carry little advantage for simple tasks like typing text messages or streaming videos, the implications for certain types of complex calculations are enormous.</p>
<p>“We can use the quantum processes happening inside a quantum computer to simulate the quantum processes happening inside our experiment,” Ringer says. “Eventually, we could use quantum computers to solve big outstanding problems in our theoretical understanding of the world.”</p>
<p>Today’s quantum computers are still in their infancy and lack the intricacy and reliability of classical computers. But Mulligan, Yao and Ringer want to be ready when the technology matures.</p>
<p>Recently, they performed a proof-of-principle study—with funding from DOE’s Office of Science and Berkeley Lab—that examined how the properties of a heavy particle could be impacted after it traversed through a quark-gluon plasma. Quark gluon plasmas are the hottest and densest known state of matter and produced during heavy ion collisions, such as those inside the Relativists Heavy Ion Collider at the DOE’s Brookhaven National Laboratory and the Large Hadron Collider at CERN. The team of scientists ran their simulation on both a real quantum computer built by IBM and on a classical computer configured to imitate a quantum computer.</p>
<p>“It was slightly more difficult than I expected,” Yao says. “The current quantum machines are noisy, and you have to apply error mitigations to account for the noise and get meaningful results."</p>
<p>After several months of honing their code and testing the outcomes, they were able to demonstrate that these kinds of calculations are already feasible on today’s quantum computers.</p>
<p>“It’s important to start now and to explore these techniques,” Ringer says. “Potentially, the particle physics community could even have an impact on shaping the evolution of quantum computing by proposing interesting problems that the next generation of machines could solve. There’s many opportunities for collaboration and innovation.”</p>]]></content>
        <category label="Quantum Computing"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Designing APIs for Correctness: Types, Lifetimes, and Capabilities]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-11-designing-apis-for-correctness-types-lifetimes-and-capabilit</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-11-designing-apis-for-correctness-types-lifetimes-and-capabilit"/>
        <updated>2020-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (November 2020): Designing APIs for Correctness: Types, Lifetimes, and Capabilities.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Designing APIs for Correctness: Types, Lifetimes, and Capabilities</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
<li>Refinement boundaries prevent “spec drift” between paper and code.</li>
<li>Counterexamples are better than intuition—they are executable bug reports.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>What is the refinement boundary between spec and implementation?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming the spec and the code share the same definitions implicitly.</li>
<li>Writing models that can’t produce counterexamples quickly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Refinement is a simulation relation between spec and impl:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi></mrow><mo>⊑</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mspace width="1em"></mspace><mo>⇒</mo><mspace width="1em"></mspace><mi mathvariant="normal">∀</mi><mtext>behaviors</mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">m</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">)</mo><mo>⊆</mo><mtext>behaviors</mtext><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">c</mi></mrow><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Impl} \sqsubseteq \mathrm{Spec}\quad\Rightarrow\quad \forall \text{behaviors}(\mathrm{Impl}) \subseteq \text{behaviors}(\mathrm{Spec}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">Impl</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⊑</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8778em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm">Spec</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:1em;"></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">∀</span><span class="mord text"><span class="mord">behaviors</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">Impl</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⊆</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">behaviors</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">Spec</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<p>Treat counterexamples as regression tests: reduce, encode, and replay.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  spec<span class="token text string">["Spec (TLA+/PlusCal)"]</span> <span class="token arrow operator">--></span> mc<span class="token text string">["Model Check"]</span>
  mc <span class="token arrow operator">--></span> refine<span class="token text string">["Refinement / Invariants"]</span>
  refine <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (Rust/Go)"]</span>
  impl <span class="token arrow operator">--></span> tests<span class="token text string">["Fuzz / PBT / Differential"]</span>
  tests <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make the model executable enough to generate counterexamples quickly.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>How will you keep models aligned during rapid iteration?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Verified Crypto Interfaces: Constant-Time Boundaries and Misuse Resistance]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-10-verified-crypto-interfaces-constant-time-boundaries-and-misu</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-10-verified-crypto-interfaces-constant-time-boundaries-and-misu"/>
        <updated>2020-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (October 2020): Verified Crypto Interfaces: Constant-Time Boundaries and Misuse Resistance.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Verified Crypto Interfaces: Constant-Time Boundaries and Misuse Resistance</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Make failure modes explicit and observable.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>What is the refinement boundary between spec and implementation?</li>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving the whole system end-to-end with all implementation details.</li>
<li>Assuming the spec and the code share the same definitions implicitly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  spec<span class="token text string">["Spec (TLA+/PlusCal)"]</span> <span class="token arrow operator">--></span> mc<span class="token text string">["Model Check"]</span>
  mc <span class="token arrow operator">--></span> refine<span class="token text string">["Refinement / Invariants"]</span>
  refine <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (Rust/Go)"]</span>
  impl <span class="token arrow operator">--></span> tests<span class="token text string">["Fuzz / PBT / Differential"]</span>
  tests <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat invariants as code: version, review, and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>How will you keep models aligned during rapid iteration?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Symbolic Execution: When Brute Force Becomes Logic]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-09-symbolic-execution-when-brute-force-becomes-logic</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-09-symbolic-execution-when-brute-force-becomes-logic"/>
        <updated>2020-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (September 2020): Symbolic Execution: When Brute Force Becomes Logic.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Symbolic Execution: When Brute Force Becomes Logic</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Counterexamples are better than intuition—they are executable bug reports.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
<li>How do you convert counterexamples into test harnesses?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating verification as a one-time event rather than a process.</li>
<li>Writing models that can’t produce counterexamples quickly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common way to state linearizability is existence of a sequential history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∃</mi><msub><mi>H</mi><mi>s</mi></msub><mo>:</mo><mtext> </mtext><msub><mi>H</mi><mi>s</mi></msub><mtext> is sequential </mtext><mo>∧</mo><msub><mi>H</mi><mi>s</mi></msub><mo>∼</mo><msub><mi>H</mi><mi>c</mi></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\exists H_s:\ H_s \text{ is sequential } \wedge H_s \sim H_c.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord">∃</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord text"><span class="mord"> is sequential </span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∼</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat counterexamples as regression tests: reduce, encode, and replay.</p>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  spec<span class="token text string">["Spec (TLA+/PlusCal)"]</span> <span class="token arrow operator">--></span> mc<span class="token text string">["Model Check"]</span>
  mc <span class="token arrow operator">--></span> refine<span class="token text string">["Refinement / Invariants"]</span>
  refine <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (Rust/Go)"]</span>
  impl <span class="token arrow operator">--></span> tests<span class="token text string">["Fuzz / PBT / Differential"]</span>
  tests <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make the model executable enough to generate counterexamples quickly.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep a library of “known hard schedules” from past failures.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How will you keep models aligned during rapid iteration?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Concurrency Testing in Rust: Loom, Schedules, and Determinism]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-08-concurrency-testing-in-rust-loom-schedules-and-determinism</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-08-concurrency-testing-in-rust-loom-schedules-and-determinism"/>
        <updated>2020-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (August 2020): Concurrency Testing in Rust: Loom, Schedules, and Determinism.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Concurrency Testing in Rust: Loom, Schedules, and Determinism</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Counterexamples are better than intuition—they are executable bug reports.</li>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you convert counterexamples into test harnesses?</li>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>What is the refinement boundary between spec and implementation?</li>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Teams need workflows that keep models and code aligned over time.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving the whole system end-to-end with all implementation details.</li>
<li>Writing models that can’t produce counterexamples quickly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common way to state linearizability is existence of a sequential history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∃</mi><msub><mi>H</mi><mi>s</mi></msub><mo>:</mo><mtext> </mtext><msub><mi>H</mi><mi>s</mi></msub><mtext> is sequential </mtext><mo>∧</mo><msub><mi>H</mi><mi>s</mi></msub><mo>∼</mo><msub><mi>H</mi><mi>c</mi></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\exists H_s:\ H_s \text{ is sequential } \wedge H_s \sim H_c.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord">∃</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord text"><span class="mord"> is sequential </span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∼</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  props<span class="token text string">["Properties"]</span> <span class="token arrow operator">--></span> inv<span class="token text string">["Invariants"]</span>
  inv <span class="token arrow operator">--></span> model<span class="token text string">["Model"]</span>
  model <span class="token arrow operator">--></span> cex<span class="token text string">["Counterexamples"]</span>
  cex <span class="token arrow operator">--></span> tests<span class="token text string">["Regression Tests"]</span>
  tests <span class="token arrow operator">--></span> model</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep refinement boundaries explicit: what the spec promises vs what code enforces.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep a library of “known hard schedules” from past failures.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
<li>How will you keep models aligned during rapid iteration?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fuzzing Protocol Parsers: When Inputs Are Adversarial]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-07-fuzzing-protocol-parsers-when-inputs-are-adversarial</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-07-fuzzing-protocol-parsers-when-inputs-are-adversarial"/>
        <updated>2020-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (July 2020): Fuzzing Protocol Parsers: When Inputs Are Adversarial.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Fuzzing Protocol Parsers: When Inputs Are Adversarial</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Counterexamples are better than intuition—they are executable bug reports.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
<li>How do you convert counterexamples into test harnesses?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating verification as a one-time event rather than a process.</li>
<li>Writing models that can’t produce counterexamples quickly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat counterexamples as regression tests: reduce, encode, and replay.</p>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  spec<span class="token text string">["Spec (TLA+/PlusCal)"]</span> <span class="token arrow operator">--></span> mc<span class="token text string">["Model Check"]</span>
  mc <span class="token arrow operator">--></span> refine<span class="token text string">["Refinement / Invariants"]</span>
  refine <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (Rust/Go)"]</span>
  impl <span class="token arrow operator">--></span> tests<span class="token text string">["Fuzz / PBT / Differential"]</span>
  tests <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat invariants as code: version, review, and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Workflow:
1) Write a model with a few state variables.
2) State invariants (safety) and progress conditions (liveness).
3) Run model checker with tight bounds.
4) Minimize counterexamples into test cases.
5) Iterate until failures are boring.</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How will you keep models aligned during rapid iteration?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Differential Testing: Using Other Implementations as Oracles]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-06-differential-testing-using-other-implementations-as-oracles</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-06-differential-testing-using-other-implementations-as-oracles"/>
        <updated>2020-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (June 2020): Differential Testing: Using Other Implementations as Oracles.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Differential Testing: Using Other Implementations as Oracles</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Model the smallest system that can still fail in the way you fear.</li>
<li>Make failure modes explicit and observable.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Refinement boundaries prevent “spec drift” between paper and code.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>What is the refinement boundary between spec and implementation?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Teams need workflows that keep models and code aligned over time.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving the whole system end-to-end with all implementation details.</li>
<li>Treating verification as a one-time event rather than a process.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  props<span class="token text string">["Properties"]</span> <span class="token arrow operator">--></span> inv<span class="token text string">["Invariants"]</span>
  inv <span class="token arrow operator">--></span> model<span class="token text string">["Model"]</span>
  model <span class="token arrow operator">--></span> cex<span class="token text string">["Counterexamples"]</span>
  cex <span class="token arrow operator">--></span> tests<span class="token text string">["Regression Tests"]</span>
  tests <span class="token arrow operator">--></span> model</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep refinement boundaries explicit: what the spec promises vs what code enforces.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Workflow:
1) Write a model with a few state variables.
2) State invariants (safety) and progress conditions (liveness).
3) Run model checker with tight bounds.
4) Minimize counterexamples into test cases.
5) Iterate until failures are boring.</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How will you keep models aligned during rapid iteration?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Property-Based Testing: Finding Bugs You Didn’t Imagine]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-05-property-based-testing-finding-bugs-you-didn-t-imagine</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-05-property-based-testing-finding-bugs-you-didn-t-imagine"/>
        <updated>2020-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (May 2020): Property-Based Testing: Finding Bugs You Didn’t Imagine.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Property-Based Testing: Finding Bugs You Didn’t Imagine</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Write properties in plain language next to the formal statement.</li>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
<li>Refinement boundaries prevent “spec drift” between paper and code.</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>How do you convert counterexamples into test harnesses?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>What is the refinement boundary between spec and implementation?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Teams need workflows that keep models and code aligned over time.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming the spec and the code share the same definitions implicitly.</li>
<li>Writing models that can’t produce counterexamples quickly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Write properties in plain language next to the formal version.</p>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  props<span class="token text string">["Properties"]</span> <span class="token arrow operator">--></span> inv<span class="token text string">["Invariants"]</span>
  inv <span class="token arrow operator">--></span> model<span class="token text string">["Model"]</span>
  model <span class="token arrow operator">--></span> cex<span class="token text string">["Counterexamples"]</span>
  cex <span class="token arrow operator">--></span> tests<span class="token text string">["Regression Tests"]</span>
  tests <span class="token arrow operator">--></span> model</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat invariants as code: version, review, and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Workflow:
1) Write a model with a few state variables.
2) State invariants (safety) and progress conditions (liveness).
3) Run model checker with tight bounds.
4) Minimize counterexamples into test cases.
5) Iterate until failures are boring.</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
<li>How will you keep models aligned during rapid iteration?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Refinement: Proving Your Implementation Matches the Spec]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-04-refinement-proving-your-implementation-matches-the-spec</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-04-refinement-proving-your-implementation-matches-the-spec"/>
        <updated>2020-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (April 2020): Refinement: Proving Your Implementation Matches the Spec.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Refinement: Proving Your Implementation Matches the Spec</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Keep models small enough to run in seconds or they will rot.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>How do you convert counterexamples into test harnesses?</li>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving the whole system end-to-end with all implementation details.</li>
<li>Writing models that can’t produce counterexamples quickly.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common way to state linearizability is existence of a sequential history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∃</mi><msub><mi>H</mi><mi>s</mi></msub><mo>:</mo><mtext> </mtext><msub><mi>H</mi><mi>s</mi></msub><mtext> is sequential </mtext><mo>∧</mo><msub><mi>H</mi><mi>s</mi></msub><mo>∼</mo><msub><mi>H</mi><mi>c</mi></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\exists H_s:\ H_s \text{ is sequential } \wedge H_s \sim H_c.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord">∃</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord text"><span class="mord"> is sequential </span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∼</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<p>Write properties in plain language next to the formal version.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  props<span class="token text string">["Properties"]</span> <span class="token arrow operator">--></span> inv<span class="token text string">["Invariants"]</span>
  inv <span class="token arrow operator">--></span> model<span class="token text string">["Model"]</span>
  model <span class="token arrow operator">--></span> cex<span class="token text string">["Counterexamples"]</span>
  cex <span class="token arrow operator">--></span> tests<span class="token text string">["Regression Tests"]</span>
  tests <span class="token arrow operator">--></span> model</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat invariants as code: version, review, and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>How will you keep models aligned during rapid iteration?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Model Checking at Scale: State Explosion and How to Cheat]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-03-model-checking-at-scale-state-explosion-and-how-to-cheat</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-03-model-checking-at-scale-state-explosion-and-how-to-cheat"/>
        <updated>2020-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (March 2020): Model Checking at Scale: State Explosion and How to Cheat.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Model Checking at Scale: State Explosion and How to Cheat</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Write properties in plain language next to the formal statement.</li>
<li>Model the smallest system that can still fail in the way you fear.</li>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Refinement boundaries prevent “spec drift” between paper and code.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>Formal models force you to name assumptions (time, ordering, failure).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>What is the refinement boundary between spec and implementation?</li>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
<li>Teams need workflows that keep models and code aligned over time.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Writing models that can’t produce counterexamples quickly.</li>
<li>Proving the whole system end-to-end with all implementation details.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common way to state linearizability is existence of a sequential history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∃</mi><msub><mi>H</mi><mi>s</mi></msub><mo>:</mo><mtext> </mtext><msub><mi>H</mi><mi>s</mi></msub><mtext> is sequential </mtext><mo>∧</mo><msub><mi>H</mi><mi>s</mi></msub><mo>∼</mo><msub><mi>H</mi><mi>c</mi></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\exists H_s:\ H_s \text{ is sequential } \wedge H_s \sim H_c.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord">∃</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord text"><span class="mord"> is sequential </span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">s</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">∼</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.1514em;"><span style="top:-2.55em;margin-left:-0.0813em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">c</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<p>Write properties in plain language next to the formal version.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  spec<span class="token text string">["Spec (TLA+/PlusCal)"]</span> <span class="token arrow operator">--></span> mc<span class="token text string">["Model Check"]</span>
  mc <span class="token arrow operator">--></span> refine<span class="token text string">["Refinement / Invariants"]</span>
  refine <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (Rust/Go)"]</span>
  impl <span class="token arrow operator">--></span> tests<span class="token text string">["Fuzz / PBT / Differential"]</span>
  tests <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat invariants as code: version, review, and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>How will you keep models aligned during rapid iteration?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[TLA+ for Engineers: Modeling the Minimal Thing That Can Break You]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-02-tla-for-engineers-modeling-the-minimal-thing-that-can-break-</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-02-tla-for-engineers-modeling-the-minimal-thing-that-can-break-"/>
        <updated>2020-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (February 2020): TLA+ for Engineers: Modeling the Minimal Thing That Can Break You.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>TLA+ for Engineers: Modeling the Minimal Thing That Can Break You</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Model the smallest system that can still fail in the way you fear.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>Refinement boundaries prevent “spec drift” between paper and code.</li>
<li>Counterexamples are better than intuition—they are executable bug reports.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the environment model (adversary actions, scheduling, failures)?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>How do you convert counterexamples into test harnesses?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>What is the refinement boundary between spec and implementation?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Adversaries choose the worst schedule, not the average one.</li>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Specifications omit details; implementations invent them. That gap is risk.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Proving the whole system end-to-end with all implementation details.</li>
<li>Treating verification as a one-time event rather than a process.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Write properties in plain language next to the formal version.</p>
<p>Model the scheduler explicitly when concurrency is part of the threat model.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  spec<span class="token text string">["Spec (TLA+/PlusCal)"]</span> <span class="token arrow operator">--></span> mc<span class="token text string">["Model Check"]</span>
  mc <span class="token arrow operator">--></span> refine<span class="token text string">["Refinement / Invariants"]</span>
  refine <span class="token arrow operator">--></span> impl<span class="token text string">["Implementation (Rust/Go)"]</span>
  impl <span class="token arrow operator">--></span> tests<span class="token text string">["Fuzz / PBT / Differential"]</span>
  tests <span class="token arrow operator">--></span> spec</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat invariants as code: version, review, and test them.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Practical tip: make the model "executable" enough to emit traces you can replay.</span>
<span class="token comment">// Then treat traces as regression inputs for your implementation.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> bounded versions of the core protocol.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How will you keep models aligned during rapid iteration?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Why the 2020s Belong to Quantum Computing]]></title>
        <id>https://mayckongiovani.xyz/pensieve/quantum-computing</id>
        <link href="https://mayckongiovani.xyz/pensieve/quantum-computing"/>
        <updated>2020-01-13T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Why the 2020s Belong to Quantum Computing]]></summary>
        <content type="html"><![CDATA[<p>When was the day that quantum became normalised?
‘Quantum’, as a modifier within a sentence, has typically denoted something entirely beyond the realm of ordinary comprehension — the demesne of cats at once undead and unliving, of profound theoretical breakthroughs regretted, of keys to new dimensions. Sat on the lip of the 2020s, however, it is both exciting and oddly disconcerting to discover that quantum, such a synonym for the terminally unpredictable, has become a sure shot, an all-but-safe bet.
Or, at least, quantum computing has. Since the 1990s it has been one of the most anticipated tickmarks on the developmental technological calendar. Now, we are passing between decisive phases in the lifecycle of this unique branch of computing. No longer merely a theoretical preserve, or a lab-bound pursuit, quantum computing is now a major channel of investment for large companies, small companies, VCs, academic institutions, and states. More and more, we are finding applied usage for the prime descendant of the classical computer; to the extent that, come the end of the 20s, quantum computing might be feasibly considered the decade’s definitive technology.
But why? And how?
What Are Quantum Computers?
Quantum computers, and quantum computing, make use of quantum phenomena to execute processes faster. ‘Classical’ computing processes information through regular binaries, often colloquially referred to as ‘0s and 1s’. Quantum principles like superposition (wherein a particle exists in multiple quantum states simultaneously, instead of in one place and state) and entanglement (wherein multiple particles share spatial proximity in such a way as understanding the nature of one divests greater understanding of the other, or others), on the other hand, can be used to allow a computer to process beyond regular binary principles.
The basic unit of quantum computing is, therefore, not the bit — a value set to 0 or 1, then arranged into long denotative strings — but the qubit, a value that can be both 0 and 1 simultaneously. Special kinds of atoms that can entertain such two-way states, like “ions, photons, or tiny superconducting circuits”, are therefore the building blocks of quantum computing. The quantum computer reads the degree to which a given qubit is ‘0’ and how much of it is ‘1’. This is often mapped out on a sort of qubit ‘globe’, whereon one point on the globe denotes the quantity of ‘0’ and of ‘1’ that the qubit possesses. To this end, you might more easily think of a value of ‘0’ being represented by the globe’s latitude and a value of ‘1’ by its longitude. Once the ‘coordinates’ of the qubit, and others in the string, have been determined, the computer can proceed with the function denoted.
Our present computing models were founded on machines essentially designed to make calculus more straightforward — despite our almost deific conception of computing intelligence, the classical computing model is not necessarily as well-optimised for certain among the other tasks we now seek to use it for. As put in a recent report by Morgan Stanley, “While the classical computer is very good at calculus, the quantum computer is even better at sorting, finding prime numbers, simulating molecules, and optimization, and thus could open the door to a new computing era.”
Quantum computing does not concern one single computing model. There are a variety of viable methods of quantum computing, including via quantum gate array (otherwise known as the quantum circuit), one-way, adiabatic, and topological methods. The adiabatic model is one of the most-implemented at present, and best for solving optimisation problems, though it cannot thoroughly outstrip a classical supercomputer in performance. The gate array model, the other most-implemented model to this point, is more powerful but considerably more difficult and expensive to build.
Just as there are multiple quantum computing models, there are an array of floated physical realisations of quantum computers. These include the use of superconductors, trapped ions, linear optics, and even the Bose-Einstein condensate we saw be momentously recreated a couple of months back on the ISS.
Building a Qubit
For anyone who’s sat with a laptop straining through activity, and burning a hole through their trouser-leg in the process, it may come as a surprise to discover that quantum computers operate at very low temperatures. Colder temperatures, in fact, than can be found in the vacuum of space. Qubits, however powerful, are delicate things, and can be disturbed from their course very easily by any number of complicating elements, heat included.
In order to make one of these fine, profound things, you need first an atomic or subatomic substance capable of sustaining a coherent quantum superposition between two states. There are a number of ways of doing so. Cosmos magazine reported that an Australian team led by Michelle Simmons at the University of New South Wales created atomic qubits by placing a single phosphorus atom on a silicon chip, determining the position of the resulting qubit in the crystal lattice from its quantum spin information. You could also run a current through a superconductor, and chart the resultant superposition.
An additional means of creating qubits is to dislodge an electron from an atom, thereby making an ion. This ion is then held captive by electromagnetism, and lasers fired at it to provokes changes in quantum state. By such a means, you have a ‘trapped ion’ quantum computer.
Why Quantum Computers?
It all sounds perfectly impressive, all quite nice — but what takes quantum computing from being blarney-exclusive of the theoretical-scientific community, and into blarney-incipient of the world of applied science, is the vast range of possibilities in use that a quantum computer possesses.
Having been freed from the restrictions of binary processing, quantum computers are able to move through operations at an exponentially faster rate than a regular computer, all the while using considerably less energy. This gives quantum computers a tremendous implementation advantage over regular computers — for instance, being able to solve more difficult NP-complete problems in a fraction of the time it would take a classical computer — and that’s before you even get to specific use-cases.
“The advent proper of quantum computing does not sound the death knell for classical computing.”
It should be said — the advent proper of quantum computing does not sound the death knell for classical computing, anymore than the advent of quantum physics rendered all the gains of classical mechanics moot. As in science, quantum computing is merely poised to succeed, and spectacularly so, in the realms where the classical falters. Consumers need not fear a mass-obsolescence of their gear; developers need not be concerned, if any were or continue to be, about the outmoding of their skills. Just as we’ve observed limitations in the powers of classical computers — to optimise, to simulate, to factorise — quantum computers will have weaker areas of their own, including in such everyday tasks as emailing, and the creation and use of documents. Just as a society entirely made up of professionals, and no tradespeople, wouldn’t get very far, the profundity of quantum computing is not the answer to each and every one of our needs and problems.
It stands a good chance at solving quite a few of them, however.
All Vectors to Brace Position
Quantum computing has progressed relatively rapidly as a field, beginning ostensibly with Heisenberg’s coining of the Uncertainty Principle in 1927. Its mythological phase was announced via Richard Feynman’s challenge at an IBM/MIT conference in 1981, and the field enjoyed its first practical breakthrough in 1994, when Peter Shor demonstrated that a quantum circuit could factor primes exponentially faster than a classical computer.
Many years hence, quantum computing is a fixture of interest for large corporations (IBM), specialist start-ups, and, increasingly, the public sector. States are investing billions of dollars in quantum technologies. That’s because, from policy creation to data analysis, and all the way out to some of the most fanciful reaches of experimental physics and chemistry, this new technology will have a pronounced effect.
Chemistry, Cybersecurity &#x26; Search
You may already have begun guessing which industry vectors are most likely to be upended by a coming quantum revolution — it’s a good bet to suggest that any industry whose bread and butter is composed of complex logical problems will be among the first and most dramatically affected.
Cybersecurity, for one, will be changed beyond much present recognition by a widespread adoption of quantum computing. There is some thought even now that as a society we are relatively haphazard when it comes to taking steps to secure ourselves online, even aside from those whom do less than is strictly advisable in the cause of this effort. This impression is likely to be compounded by a post-quantum-computing status quo. Rules of encryption will be rewritten overnight. There is no extant factorisation-based cryptographic system that a quantum computer could not break with contemptuous ease. Cryptographic systems will, as a result, presumably get more creative (using more problem- or lattice-based encryption), and we may see a move to more secure quantum-based encrypted systems for storing valuable information and warding against hacking.
Likewise, any field of technology where optimisation is important will undergo pronounced changes following the adoption of quantum computing. No database is a match for the speed of processing native to a quantum computer. Quantum search, facilitated by quantum algorithms like Grover’s algorithm, allow a more comprehensive return of pertinent results from a database, in fewer queries of that database, than could ever be accomplished by a classical computer. As an unsurprising result, Google has proven one of the keenest parties when it comes to investing in research into the possibilities of quantum computing.
Of course, quite another set of possibilities in innovation and research will be made possible by quantum computing owing to the fact that, with them in our hands, we will have an authentic environment in which to run quantum simulations. Trying to simulate quantum environments classically is inexact and highly inefficient at best and, as one’s experimental ambitions grow, impossible at the most interesting degrees. Given access to a real quantum computing environment, capable of accurately modelling and simulating quantum conditions, we will see exponential gains made in the kinds of chemistry and nanotechnology which rely on better understandings of quantum mechanics.
The Machine Learning Question
Whenever developments in technology are the subject of discussion, everyone wants to know — “What is this new gear’s effect on machine learning likely to be?” And, if your inquisitor is among the more enthusiastic variety, “Is it likely to destroy us all?”
Well, machine learning, as conventionally understood, will be introduced to a new era by quantum computing — it is already the subject of major initiatives to demonstrate quantum supremacy[2]. An algorithm for integer factorisation, which is already understood to be a preserve exclusive to quantum computing, will instantly obsole any conventionally held understandings of the limits of the systematic intelligence, even against unintuitive patterns, which can be achieved by a computer.
The sheer volume of data which a quantum computer can get through disposes it well to machine learning. Non-supervised learning and reinforcement learning will almost certainly accelerate in development thanks to quantum technologies. As we’ve seen, quantum computers can support considerably more ambitious algorithms than classical computers, which, as a result, are coming near to exhaustion of their possibilities, as far as the interests of certain fields run (including fields “pharmaceutical, life scientific and [financial]”).
Communication via the Flaws of Diamonds
Quantum computing doesn’t begin and end with the quantum ‘desktops’[1] of the future — information networks based on quantum phenomena are high up on the list of desirable outcomes from the next chapters of quantum computational research.
In accordance with what we just saw vis-a-vis quantum cryptography, any quantum internet would be considerably faster than the classical kind. It would also be more secure; after all, as this report by Princeton notes, “[a]ny attempt to eavesdrop on[a quantum internet] transmission [by hackers] will perturb its state.” As we noted above, the principles of quantum entanglement are central to the feasibility of a quantum computer and a quantum internet. One qubit being unlawfully observed or disrupted? You’ll have an equivalent ‘twin’ qubit that can tell you all about it. In a quantum network, the state of one qubit will tell you a great deal about others with which it is entangled, no matter the physical distance between them.
“In a quantum network, the state of one qubit will tell you a great deal about others with which it is entangled, no matter the physical distance between them.”
One of the suggested means by which a quantum internet might be built is quite stirring to the imagination. It’s the work of Princeton’s assistant professor of electrical engineering, Nathalie de Leon, who believes that the key to this new kind of informational network is held in the body of diamond. To be more specific, in the flaws of a diamond.
The colours we see in the sparkle of a diamond are in fact flaws in the body; but, with a slight modification to their chemical makeup (replacing two carbon atoms with a silicon atom), these regions of flaw are made into perfect photon receptacles. Perfect, in other words, for the transmission of information within a quantum internet. We could in an imaginable future find ourselves communicating on a quantum net, via the flaws of diamonds.
Aside from speed and security, a quantum internet could represent a considerable energy saving, owing to the lower rate of consumption by quantum computers. The Internet at present uses approximately 10% of the world’s total electricity, and more if you factor in the additional energy costs of data centres and the cloud. Not only do single quantum computer units use less energy than their classical counterparts; they have scope for architecture and a cloud system of their own, both of which could represent small but direct reductions of the global-digital carbon footprint.
Quantum Disruption
There is, as we’ve seen, ample disruptive potential in quantum computing as a distinct field of technology — and it seems as though a vast amount of that disruption will be additive and positive, increasing overall knowledge capital and augmenting existing processes and infrastructure instead of sweeping it away.
It is harder to imagine any region of scientific and technological inquiry having a higher barrier-to-start-up-entry than quantum computing. Nevertheless, there are a number of promising outfits with quantum computing applications at their core, all of them heavily backed by venture capital.
Rahko
Rahko have set out to go about “solving chemistry with quantum machine learning”. Comprised of a team based in London, Rahko’s quantum machine learning platform is focused on the creation of applied and commercially purposeful insights into quantum chemistry. They raised £1.3M seed from Balderton in their latest funding round.
Quantifi
Quantifi, founded in New York, sit at the further frontier of what’s commercially possible with quantum computing solutions, as regards risk and deal analytics.
Crypto Quantique
Crypto Quantique are attempting to pre-empt the seismic shifts in crytographic best practices by developing an end-to-end quantum IoT security platform that is, they suggest, all but impregnable.
Further Down the Quantum Tunnel
As fabulous as many of these applied uses of this fantastic new technology are, I would be remiss were I to suggest that looking further afield, and permitting ourselves some slightly more fanciful speculation about what quantum computing advances will bring, is anything other than the most fun part of any article like this one. What’s more, given quantum computing technology has such a broad church of potential uses, we have even freer license to speculate on things to come in a future full of quantum technology.
There are hosts of medical applications for quantum computing. More detailed models of molecular structures will be built; new pharmaceutical products created thereby; and, it’s as likely as not, long-standing illnesses cured at last.
We might see erosion-free industrial process; the addition of sufficient mile-range to make electric cars not merely an option, but the option;
Looking into somewhat darker harbours, there have been suggestions in some quarters that quantum computing might be purposed as a kind of natural enemy of blockchain, though the increase of institutional interest in blockchain, which is rising almost as fast as interest in quantum computing, may put paid to this by itself. Nevertheless, major blockchain initiatives like cryptocurrency could be made extinct through security compromise — in the words of representatives of UK cybersecurity firm Post Quantum, bitcoin is “not quantum computer proof.”
Quantum computing is also of particular stated interest to military institutions, including the U.S. Airforce. Speaking to SpaceNews, Michael Hayduk, chief of the computing and communications division at the Air Force Research Laboratory approvingly adjudged quantum computing “a very disruptive technology.” Quantum computing could be used to perfect the synchrony of weaponry; as the Chinese example proves, it can also be used to produce unhackable satellites.
Looking more broadly still, one thing that quantum computing widely adopted does promise is pace. Pace of learning, pace of processing, pace of optimisation — well used, such rapid mastication of such vast troves of data will indubitably lead to greater innovation. Indeed, it would stimulate a race of innovation, one whose dimensions are tailored precisely to the degree of competitive implementations of quantum technologies enacted by rival commercial actors, sector-by-sector.
“Quantum computing could initiate a different kind of ‘quantum supremacy’, geopolitical in nature, that few nations will wish to be on the receiving end of.”
As it is, technological innovation is already proceeding rapidly towards a kind of actuarial escape velocity. As China’s own pace of innovation accelerates in tandem with the global west, even more pressurised incentive is created to continue innovating. Given quantum computing will only accelerate the gains of material science even faster and further, it’s possible that it will create nightmares of scaling, and of the industrial-scale deployment of new technologies.
This bottlenecking may, inasmuch, create a huge incentive for greater international collaboration. There is already one mooted and contested notion of quantum supremacy; there might, in the instance of scale-adoption of quantum computing, come the possibility of a more practical quantum supremacy, geopolitical in nature, that few nations will wish to be on the receiving end of.
The Trouble with Quanta
That’s not to say that quantum computing is a sure-shot for the near future, though it does seem progressively more likely that we’ll see the method graduate from the emergent stage into tackling classically impractical problems — like ultra-rapid integer factorisation, or elite cryptography — in the next decade at least.
Stability
There is the potential for instability in quantum processes, as qubits are liable to profound distortion by only minor complications in the context in which they work. The collective attempt to find a panacea for this issue is known as quantum error correction. Decoherence[3] is, understandably, a big problem for particles (or, for that matter, human-sized congregations of particles) that insist on occupying multiple states of being at once. This represents a potential compromise to the utility of even the most powerful of quantum computers.
One of the primary means of combatting decoherence, which is to some extent inevitable at some stage of a quantum event, is to have quantum gates faster than decoherence time —and as we observed earlier, quantum gate models are the most demanding and expensive to construct and maintain. Similarly, any functional quantum computer would have to physically scale to accommodate the number of qubits, and furthermore would have to develop a rubric by which qubits could be ‘read’ for the operative functions they denote.
Not an intrinsic, but an infrastructural ‘drawback’ of quantum computing is the degree of platform transitioning and upgrading it will oblige of service providers across the internet. A company able to develop and scale a solution based on quantum computing — whether in cybersecurity, finance, instance messaging or data science — would rapidly develop an almost unimpeachable advantage over its classical competitors, though doing so would be difficult. The transition would have to be managed and, one would hope, reasonably cooperative. Of course, developed for political ends, a quantum computer that does not have to worry about non-quantum defence mechanisms standing in its way could make for a rather potent weapon.
In a Super Position
The panorama visible at the vanguard of developments in quantum computing is the kind liable to make your mouth dry. Quantum computers come to us not, in the manner of classical computers, as portals to a strange new world, but rather one which allows us to take our present world in a revised definition.
Of the manifold issues, sociopolitical and ecological, facing the world at present, some of which can be partially attributable to the principle, as opposed to the fact, of innovation[4], there are two ostensible solutions — to moderate ourselves out of the hole we’ve dug for ourselves, or innovate out of it. The speed, efficiency and cleanliness by which quantum computing is capable of doing its work makes the latter option, by far the most reconcilable to this most sybaritic and consumptive of times, more palatable.
[1] Many experts find it unlikely that quantum computing will have everyday home uses — your laptop or desktop is unlikely to feature a quantum engine.
[2] Quantum supremacy can be defined as a kind of proof of a quantum computer’s performance, wherein it completes a function or operation that no classical computer could do, or could do in a feasible amount of time. For quantum researchers, instances of quantum supremacy proven are rather like Pieces of Eight.
[3] Decoherence is a form of quantum noise, quantum noise itself pertaining to an uncertainty of a physical quantity’s quantum origin and, therefore, its nature. As a discrete kind of quantum noise, decoherence concerns a disrupted wave function — qubits must remain in a consistent wave function (i.e. must remain coherent) in order to be computational intelligible.
[4] That’s to say — an unduly worshipful approach to innovation-as-end-in-itself, which privileges disruption and excess as proof of concept, instead of innovation considered as a means to a practicable end.</p>]]></content>
        <category label="Quantum Computing 2020"/>
        <category label="Science"/>
        <category label="Technology"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Safety/Liveness Catalog: A Practical Checklist for Protocol Specs]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2020-01-safety-liveness-catalog-a-practical-checklist-for-protocol-s</id>
        <link href="https://mayckongiovani.xyz/pensieve/2020-01-safety-liveness-catalog-a-practical-checklist-for-protocol-s"/>
        <updated>2020-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (January 2020): Safety/Liveness Catalog: A Practical Checklist for Protocol Specs.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Formal Methods &#x26; Verification</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Safety/Liveness Catalog: A Practical Checklist for Protocol Specs</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Counterexamples are engineering artifacts—minimize them and turn them into tests.</li>
<li>Refinement boundaries prevent spec drift between paper and code.</li>
<li>Write properties in plain language next to the formal statement.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Counterexamples are better than intuition—they are executable bug reports.</li>
<li>Most catastrophic bugs are small: a missing condition, a stale variable, a rare interleaving.</li>
<li>Verification complements testing by exploring adversarial schedules systematically.</li>
<li>The goal is not a perfect proof—it’s reducing the space of unknown failure modes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the smallest model that still captures the bug class you fear?</li>
<li>How do you ensure proofs stay valid through refactors and upgrades?</li>
<li>Which properties belong in the model vs in tests vs in monitoring?</li>
<li>How do you handle state explosion (symmetry, abstraction, bounds)?</li>
<li>Which invariants must hold under every interleaving and crash point?</li>
<li>How do you convert counterexamples into test harnesses?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Concurrency introduces interleavings humans don’t reason about reliably.</li>
<li>Most systems have implicit assumptions about timeouts and ordering.</li>
<li>Teams need workflows that keep models and code aligned over time.</li>
<li>Adversaries choose the worst schedule, not the average one.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating verification as a one-time event rather than a process.</li>
<li>Proving the whole system end-to-end with all implementation details.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>In temporal logic terms, the common shape is:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">f</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">y</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mtext> </mtext><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mspace width="2em"></mspace><mspace width="2em"></mspace><mrow><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">v</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mo>≡</mo><mi mathvariant="normal">□</mi><mi mathvariant="normal">◊</mi><mtext> </mtext><mrow><mi mathvariant="normal">P</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{Safety} \equiv \Box\,\mathrm{Inv}\qquad\qquad
\mathrm{Liveness} \equiv \Box\Diamond\,\mathrm{Progress}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Safety</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord amsrm">□</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathrm">Liveness</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≡</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8867em;vertical-align:-0.1944em;"></span><span class="mord amsrm">□◊</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">Progress</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat counterexamples as regression tests: reduce, encode, and replay.</p>
<p>Keep the model small enough to run in seconds; large models rot.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  props<span class="token text string">["Properties"]</span> <span class="token arrow operator">--></span> inv<span class="token text string">["Invariants"]</span>
  inv <span class="token arrow operator">--></span> model<span class="token text string">["Model"]</span>
  model <span class="token arrow operator">--></span> cex<span class="token text string">["Counterexamples"]</span>
  cex <span class="token arrow operator">--></span> tests<span class="token text string">["Regression Tests"]</span>
  tests <span class="token arrow operator">--></span> model</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Keep refinement boundaries explicit: what the spec promises vs what code enforces.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Workflow:
1) Write a model with a few state variables.
2) State invariants (safety) and progress conditions (liveness).
3) Run model checker with tight bounds.
4) Minimize counterexamples into test cases.
5) Iterate until failures are boring.</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Property-based tests</strong> derived from invariants.</li>
<li><strong>Proof maintenance</strong>: keep models in CI with a time budget.</li>
<li><strong>Runtime assertions</strong> for invariants that are cheap to check.</li>
<li><strong>Refinement tests</strong>: compare model traces to implementation traces.</li>
<li><strong>Differential tests</strong> against other implementations/specs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Run the model checker in CI with explicit timeouts and bounds.</li>
<li>Treat counterexamples as incidents: track, root-cause, regression-test.</li>
<li>Version properties and invariants like code; review changes carefully.</li>
<li>Keep a library of “known hard schedules” from past failures.</li>
<li>Use models to evaluate protocol upgrades before shipping.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical workflow and examples.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are cheap enough to monitor in production?</li>
<li>How will you keep models aligned during rapid iteration?</li>
<li>Which properties are you currently assuming but not testing or proving?</li>
<li>What is the smallest model that reproduces your worst incident class?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A small protocol that demonstrates why specs matter.</li>
<li><a href="https://lamport.azurewebsites.net/tla/book.html" target="_blank" rel="nofollow noopener noreferrer">Specifying Systems (Lamport)</a> — The TLA+ reference for safety/liveness and system specs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical workflow and examples.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="formal-methods"/>
        <category label="verification"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Validator Ops: Key Security, Slashing, and Fault Containment]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-12-validator-ops-key-security-slashing-and-fault-containment</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-12-validator-ops-key-security-slashing-and-fault-containment"/>
        <updated>2019-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (December 2019): Validator Ops: Key Security, Slashing, and Fault Containment.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Validator Ops: Key Security, Slashing, and Fault Containment</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Light clients shift assumptions; they must be written down.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>MEV turns protocol details into adversarial strategy.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Allowing execution nondeterminism for performance convenience.</li>
<li>Assuming honest majority without defining the adversary’s budget.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>State commitments bind execution to succinct proofs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mi>t</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi></mrow><mi>t</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mrow><mi mathvariant="normal">w</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi>t</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{root}_{t+1} = H(\mathrm{root}_t,\ \mathrm{block}_t,\ \mathrm{witness}_t).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8234em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">root</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">root</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">block</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">witness</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Determinism is a boundary: every nondeterministic input is an attack surface.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>What is the worst-case work a single transaction can force?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Rust Node Architecture: Storage, Networking, and Deterministic Execution]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-11-rust-node-architecture-storage-networking-and-deterministic-</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-11-rust-node-architecture-storage-networking-and-deterministic-"/>
        <updated>2019-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (November 2019): Rust Node Architecture: Storage, Networking, and Deterministic Execution.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Rust Node Architecture: Storage, Networking, and Deterministic Execution</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Make failure modes explicit and observable.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>Topology attacks (eclipse, partition) change who sees which transactions.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
<li>Treating mempool policy as “local preference” when it affects security.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A ledger is a replicated state machine. Safety is uniqueness of finalized history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><msub><mi>h</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>h</mi><mn>2</mn></msub><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo>⇒</mo><msub><mi>h</mi><mn>1</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>2</mn></msub><mtext> </mtext><mo>∨</mo><mtext> </mtext><msub><mi>h</mi><mn>2</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>1</mn></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall h_1,h_2:\ \mathrm{Final}(h_1)\wedge \mathrm{Final}(h_2)\Rightarrow h_1 \preceq h_2 \ \vee\ h_2 \preceq h_1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">∀</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the mempool as an adversarial scheduler: it chooses which work gets executed.</p>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Encode resource accounting and limits early; retrofits are painful.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case work a single transaction can force?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Formalizing a Blockchain Protocol: Properties Worth Proving]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-10-formalizing-a-blockchain-protocol-properties-worth-proving</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-10-formalizing-a-blockchain-protocol-properties-worth-proving"/>
        <updated>2019-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (October 2019): Formalizing a Blockchain Protocol: Properties Worth Proving.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Formalizing a Blockchain Protocol: Properties Worth Proving</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Define safety properties before performance goals.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Light clients shift assumptions; they must be written down.</li>
<li>MEV turns protocol details into adversarial strategy.</li>
<li>Topology attacks (eclipse, partition) change who sees which transactions.</li>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
<li>Allowing execution nondeterminism for performance convenience.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A simple resource-admission constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><munder><mo>∑</mo><mrow><mi>t</mi><mi>x</mi><mo>∈</mo><mi>B</mi></mrow></munder><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>t</mi><mi>x</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mspace width="2em"></mspace><mtext>(gas/bytes/sigchecks)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\sum_{tx \in B} \mathrm{cost}(tx) \le \mathrm{budget}(B)\qquad\text{(gas/bytes/sigchecks)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:2.3717em;vertical-align:-1.3217em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8557em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mord mathnormal mtight">x</span><span class="mrel mtight">∈</span><span class="mord mathnormal mtight" style="margin-right:0.05017em;">B</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.3217em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">cost</span></span><span class="mopen">(</span><span class="mord mathnormal">t</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">budget</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">(gas/bytes/sigchecks)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the mempool as an adversarial scheduler: it chooses which work gets executed.</p>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> U as User
  <span class="token keyword">participant</span> N as Node
  <span class="token keyword">participant</span> P as Peers
  U<span class="token arrow operator">->></span>N<span class="token operator">:</span> submit<span class="token text string">(tx)</span>
  N<span class="token arrow operator">->></span>P<span class="token operator">:</span> gossip<span class="token text string">(tx)</span>
  P<span class="token arrow operator">-->></span>N<span class="token operator">:</span> gossip<span class="token text string">(more tx)</span>
  <span class="token keyword">Note over</span> N<span class="token operator">:</span> admission + ordering
  N<span class="token arrow operator">-->></span>U<span class="token operator">:</span> inclusion/finality signal</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat mempool policy as part of the protocol if it changes security outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Keep execution resource limits explicit and enforced.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case work a single transaction can force?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[ZK in Protocols: Proof Systems as Network Primitives]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-09-zk-in-protocols-proof-systems-as-network-primitives</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-09-zk-in-protocols-proof-systems-as-network-primitives"/>
        <updated>2019-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (September 2019): ZK in Protocols: Proof Systems as Network Primitives.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>ZK in Protocols: Proof Systems as Network Primitives</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Mempools are an attack surface: spam, pinning, and incentive manipulation.</li>
<li>Bridges reintroduce trust; you must model it explicitly.</li>
<li>Light clients shift assumptions; they must be written down.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming honest majority without defining the adversary’s budget.</li>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A ledger is a replicated state machine. Safety is uniqueness of finalized history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><msub><mi>h</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>h</mi><mn>2</mn></msub><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo>⇒</mo><msub><mi>h</mi><mn>1</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>2</mn></msub><mtext> </mtext><mo>∨</mo><mtext> </mtext><msub><mi>h</mi><mn>2</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>1</mn></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall h_1,h_2:\ \mathrm{Final}(h_1)\wedge \mathrm{Final}(h_2)\Rightarrow h_1 \preceq h_2 \ \vee\ h_2 \preceq h_1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">∀</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Encode resource accounting and limits early; retrofits are painful.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>What is the worst-case work a single transaction can force?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Bridges: Where Trust Comes Back to Collect]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-08-bridges-where-trust-comes-back-to-collect</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-08-bridges-where-trust-comes-back-to-collect"/>
        <updated>2019-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (August 2019): Bridges: Where Trust Comes Back to Collect.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Bridges: Where Trust Comes Back to Collect</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Make failure modes explicit and observable.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
<li>Mempools are an attack surface: spam, pinning, and incentive manipulation.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming honest majority without defining the adversary’s budget.</li>
<li>Allowing execution nondeterminism for performance convenience.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>State commitments bind execution to succinct proofs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mi>t</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi></mrow><mi>t</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mrow><mi mathvariant="normal">w</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi>t</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{root}_{t+1} = H(\mathrm{root}_t,\ \mathrm{block}_t,\ \mathrm{witness}_t).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8234em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">root</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">root</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">block</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">witness</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Separate consensus safety from execution safety; both must hold.</p>
<p>Model the mempool as an adversarial scheduler: it chooses which work gets executed.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat mempool policy as part of the protocol if it changes security outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Deterministic execution is a security boundary.</span>
<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">Executor</span> <span class="token punctuation">{</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">apply_block</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">mut</span> <span class="token keyword">self</span><span class="token punctuation">,</span> block<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token class-name">String</span><span class="token operator">></span><span class="token punctuation">;</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">state_root</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">;</span> <span class="token number">32</span><span class="token punctuation">]</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Avoid nondeterminism: time, RNG, unordered maps, floating-point.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>What is the worst-case work a single transaction can force?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fee Markets and MEV: Incentives as an Adversary]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-07-fee-markets-and-mev-incentives-as-an-adversary</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-07-fee-markets-and-mev-incentives-as-an-adversary"/>
        <updated>2019-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (July 2019): Fee Markets and MEV: Incentives as an Adversary.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Fee Markets and MEV: Incentives as an Adversary</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Bridges reintroduce trust; you must model it explicitly.</li>
<li>MEV turns protocol details into adversarial strategy.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>Mempools are an attack surface: spam, pinning, and incentive manipulation.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
<li>Allowing execution nondeterminism for performance convenience.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A simple resource-admission constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><munder><mo>∑</mo><mrow><mi>t</mi><mi>x</mi><mo>∈</mo><mi>B</mi></mrow></munder><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>t</mi><mi>x</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mspace width="2em"></mspace><mtext>(gas/bytes/sigchecks)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\sum_{tx \in B} \mathrm{cost}(tx) \le \mathrm{budget}(B)\qquad\text{(gas/bytes/sigchecks)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:2.3717em;vertical-align:-1.3217em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8557em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mord mathnormal mtight">x</span><span class="mrel mtight">∈</span><span class="mord mathnormal mtight" style="margin-right:0.05017em;">B</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.3217em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">cost</span></span><span class="mopen">(</span><span class="mord mathnormal">t</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">budget</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">(gas/bytes/sigchecks)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the mempool as an adversarial scheduler: it chooses which work gets executed.</p>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat mempool policy as part of the protocol if it changes security outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case work a single transaction can force?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[State Commitments: Merkle, Verkle, and Proof Sizes]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-06-state-commitments-merkle-verkle-and-proof-sizes</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-06-state-commitments-merkle-verkle-and-proof-sizes"/>
        <updated>2019-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (June 2019): State Commitments: Merkle, Verkle, and Proof Sizes.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>State Commitments: Merkle, Verkle, and Proof Sizes</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Mempools are an attack surface: spam, pinning, and incentive manipulation.</li>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
<li>Bridges reintroduce trust; you must model it explicitly.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating mempool policy as “local preference” when it affects security.</li>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A simple resource-admission constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><munder><mo>∑</mo><mrow><mi>t</mi><mi>x</mi><mo>∈</mo><mi>B</mi></mrow></munder><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>t</mi><mi>x</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mspace width="2em"></mspace><mtext>(gas/bytes/sigchecks)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\sum_{tx \in B} \mathrm{cost}(tx) \le \mathrm{budget}(B)\qquad\text{(gas/bytes/sigchecks)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:2.3717em;vertical-align:-1.3217em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8557em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mord mathnormal mtight">x</span><span class="mrel mtight">∈</span><span class="mord mathnormal mtight" style="margin-right:0.05017em;">B</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.3217em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">cost</span></span><span class="mopen">(</span><span class="mord mathnormal">t</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">budget</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">(gas/bytes/sigchecks)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Separate consensus safety from execution safety; both must hold.</p>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Encode resource accounting and limits early; retrofits are painful.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Deterministic execution is a security boundary.</span>
<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">Executor</span> <span class="token punctuation">{</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">apply_block</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">mut</span> <span class="token keyword">self</span><span class="token punctuation">,</span> block<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token class-name">String</span><span class="token operator">></span><span class="token punctuation">;</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">state_root</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">;</span> <span class="token number">32</span><span class="token punctuation">]</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Avoid nondeterminism: time, RNG, unordered maps, floating-point.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>What is the worst-case work a single transaction can force?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Light Clients: Trust Minimization Without Full Replication]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-05-light-clients-trust-minimization-without-full-replication</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-05-light-clients-trust-minimization-without-full-replication"/>
        <updated>2019-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (May 2019): Light Clients: Trust Minimization Without Full Replication.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Light Clients: Trust Minimization Without Full Replication</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>Mempools are an attack surface: spam, pinning, and incentive manipulation.</li>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
<li>MEV turns protocol details into adversarial strategy.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming honest majority without defining the adversary’s budget.</li>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A ledger is a replicated state machine. Safety is uniqueness of finalized history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><msub><mi>h</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>h</mi><mn>2</mn></msub><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo>⇒</mo><msub><mi>h</mi><mn>1</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>2</mn></msub><mtext> </mtext><mo>∨</mo><mtext> </mtext><msub><mi>h</mi><mn>2</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>1</mn></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall h_1,h_2:\ \mathrm{Final}(h_1)\wedge \mathrm{Final}(h_2)\Rightarrow h_1 \preceq h_2 \ \vee\ h_2 \preceq h_1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">∀</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the mempool as an adversarial scheduler: it chooses which work gets executed.</p>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Determinism is a boundary: every nondeterministic input is an attack surface.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Deterministic execution is a security boundary.</span>
<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">Executor</span> <span class="token punctuation">{</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">apply_block</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">mut</span> <span class="token keyword">self</span><span class="token punctuation">,</span> block<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token class-name">String</span><span class="token operator">></span><span class="token punctuation">;</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">state_root</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">;</span> <span class="token number">32</span><span class="token punctuation">]</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Avoid nondeterminism: time, RNG, unordered maps, floating-point.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>What is the worst-case work a single transaction can force?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Finality and Reorgs: What Users Think vs What Protocols Provide]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-04-finality-and-reorgs-what-users-think-vs-what-protocols-provi</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-04-finality-and-reorgs-what-users-think-vs-what-protocols-provi"/>
        <updated>2019-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (April 2019): Finality and Reorgs: What Users Think vs What Protocols Provide.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Finality and Reorgs: What Users Think vs What Protocols Provide</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Bridges reintroduce trust; you must model it explicitly.</li>
<li>Light clients shift assumptions; they must be written down.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Allowing execution nondeterminism for performance convenience.</li>
<li>Assuming honest majority without defining the adversary’s budget.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A ledger is a replicated state machine. Safety is uniqueness of finalized history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><msub><mi>h</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>h</mi><mn>2</mn></msub><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo>⇒</mo><msub><mi>h</mi><mn>1</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>2</mn></msub><mtext> </mtext><mo>∨</mo><mtext> </mtext><msub><mi>h</mi><mn>2</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>1</mn></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall h_1,h_2:\ \mathrm{Final}(h_1)\wedge \mathrm{Final}(h_2)\Rightarrow h_1 \preceq h_2 \ \vee\ h_2 \preceq h_1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">∀</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Model the mempool as an adversarial scheduler: it chooses which work gets executed.</p>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> U as User
  <span class="token keyword">participant</span> N as Node
  <span class="token keyword">participant</span> P as Peers
  U<span class="token arrow operator">->></span>N<span class="token operator">:</span> submit<span class="token text string">(tx)</span>
  N<span class="token arrow operator">->></span>P<span class="token operator">:</span> gossip<span class="token text string">(tx)</span>
  P<span class="token arrow operator">-->></span>N<span class="token operator">:</span> gossip<span class="token text string">(more tx)</span>
  <span class="token keyword">Note over</span> N<span class="token operator">:</span> admission + ordering
  N<span class="token arrow operator">-->></span>U<span class="token operator">:</span> inclusion/finality signal</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Encode resource accounting and limits early; retrofits are painful.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>What is the worst-case work a single transaction can force?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Gossip Networks: Propagation, Eclipse Attacks, and Topology]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-03-gossip-networks-propagation-eclipse-attacks-and-topology</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-03-gossip-networks-propagation-eclipse-attacks-and-topology"/>
        <updated>2019-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (March 2019): Gossip Networks: Propagation, Eclipse Attacks, and Topology.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Gossip Networks: Propagation, Eclipse Attacks, and Topology</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Upgrades must be compatibility-aware: mixed rulesets are a threat model.</li>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Topology attacks (eclipse, partition) change who sees which transactions.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>Light clients shift assumptions; they must be written down.</li>
<li>MEV turns protocol details into adversarial strategy.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on client-side heuristics to paper over protocol ambiguity.</li>
<li>Allowing execution nondeterminism for performance convenience.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A simple resource-admission constraint:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><munder><mo>∑</mo><mrow><mi>t</mi><mi>x</mi><mo>∈</mo><mi>B</mi></mrow></munder><mrow><mi mathvariant="normal">c</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>t</mi><mi>x</mi><mo stretchy="false">)</mo><mo>≤</mo><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">u</mi><mi mathvariant="normal">d</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">t</mi></mrow><mo stretchy="false">(</mo><mi>B</mi><mo stretchy="false">)</mo><mspace width="2em"></mspace><mtext>(gas/bytes/sigchecks)</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\sum_{tx \in B} \mathrm{cost}(tx) \le \mathrm{budget}(B)\qquad\text{(gas/bytes/sigchecks)}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:2.3717em;vertical-align:-1.3217em;"></span><span class="mop op-limits"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.05em;"><span style="top:-1.8557em;margin-left:0em;"><span class="pstrut" style="height:3.05em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mord mathnormal mtight">x</span><span class="mrel mtight">∈</span><span class="mord mathnormal mtight" style="margin-right:0.05017em;">B</span></span></span></span><span style="top:-3.05em;"><span class="pstrut" style="height:3.05em;"></span><span><span class="mop op-symbol large-op">∑</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:1.3217em;"><span></span></span></span></span></span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathrm">cost</span></span><span class="mopen">(</span><span class="mord mathnormal">t</span><span class="mord mathnormal">x</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≤</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">budget</span></span><span class="mopen">(</span><span class="mord mathnormal" style="margin-right:0.05017em;">B</span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">(gas/bytes/sigchecks)</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<p>Separate consensus safety from execution safety; both must hold.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> U as User
  <span class="token keyword">participant</span> N as Node
  <span class="token keyword">participant</span> P as Peers
  U<span class="token arrow operator">->></span>N<span class="token operator">:</span> submit<span class="token text string">(tx)</span>
  N<span class="token arrow operator">->></span>P<span class="token operator">:</span> gossip<span class="token text string">(tx)</span>
  P<span class="token arrow operator">-->></span>N<span class="token operator">:</span> gossip<span class="token text string">(more tx)</span>
  <span class="token keyword">Note over</span> N<span class="token operator">:</span> admission + ordering
  N<span class="token arrow operator">-->></span>U<span class="token operator">:</span> inclusion/finality signal</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Determinism is a boundary: every nondeterministic input is an attack surface.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Deterministic execution is a security boundary.</span>
<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">Executor</span> <span class="token punctuation">{</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">apply_block</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">mut</span> <span class="token keyword">self</span><span class="token punctuation">,</span> block<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token class-name">String</span><span class="token operator">></span><span class="token punctuation">;</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">state_root</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">;</span> <span class="token number">32</span><span class="token punctuation">]</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Avoid nondeterminism: time, RNG, unordered maps, floating-point.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the worst-case work a single transaction can force?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Mempool Design Under Adversarial Load: Admission, Fees, and Spam]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-02-mempool-design-under-adversarial-load-admission-fees-and-spa</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-02-mempool-design-under-adversarial-load-admission-fees-and-spa"/>
        <updated>2019-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (February 2019): Mempool Design Under Adversarial Load: Admission, Fees, and Spam.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Mempool Design Under Adversarial Load: Admission, Fees, and Spam</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Consensus safety is meaningless if execution is nondeterministic across nodes.</li>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
<li>State growth is a security problem: it impacts decentralization and verification.</li>
<li>Mempools are an attack surface: spam, pinning, and incentive manipulation.</li>
<li>MEV turns protocol details into adversarial strategy.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do upgrades change security assumptions (fork choice, state transition rules)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
<li>Where do you enforce resource limits (gas, bandwidth, storage, signature checks)?</li>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Upgrades happen under partial adoption; mixed-version is inevitable.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming honest majority without defining the adversary’s budget.</li>
<li>Treating mempool policy as “local preference” when it affects security.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>State commitments bind execution to succinct proofs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>H</mi><mo stretchy="false">(</mo><msub><mrow><mi mathvariant="normal">r</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">t</mi></mrow><mi>t</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mrow><mi mathvariant="normal">b</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">c</mi><mi mathvariant="normal">k</mi></mrow><mi>t</mi></msub><mo separator="true">,</mo><mtext> </mtext><msub><mrow><mi mathvariant="normal">w</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">s</mi></mrow><mi>t</mi></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{root}_{t+1} = H(\mathrm{root}_t,\ \mathrm{block}_t,\ \mathrm{witness}_t).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8234em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">root</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.08125em;">H</span><span class="mopen">(</span><span class="mord"><span class="mord"><span class="mord mathrm">root</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">block</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">witness</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Separate consensus safety from execution safety; both must hold.</p>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat mempool policy as part of the protocol if it changes security outcomes.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Mempool hardening checklist:
- Per-peer rate limits + global admission budget
- Duplicate detection and eviction policy
- Signature verification batching with caps
- Anti-DoS: bounded decode/parse cost
- Fairness: per-sender quotas (avoid hot-account starvation)</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Cross-implementation tests</strong> when multiple clients exist.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Keep execution resource limits explicit and enforced.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
<li>What is the worst-case work a single transaction can force?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[The Ledger as a State Machine: Execution, Determinism, and Reproducibility]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2019-01-the-ledger-as-a-state-machine-execution-determinism-and-repr</id>
        <link href="https://mayckongiovani.xyz/pensieve/2019-01-the-ledger-as-a-state-machine-execution-determinism-and-repr"/>
        <updated>2019-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (January 2019): The Ledger as a State Machine: Execution, Determinism, and Reproducibility.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Blockchain Protocols</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>The Ledger as a State Machine: Execution, Determinism, and Reproducibility</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Finality guarantees are user security guarantees—document and enforce them.</li>
<li>Topology attacks (eclipse/partition) change security outcomes; harden peer selection.</li>
<li>Mempools are adversarial schedulers: admission and fairness are protocol concerns.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Bridges reintroduce trust; you must model it explicitly.</li>
<li>Topology attacks (eclipse, partition) change who sees which transactions.</li>
<li>Light clients shift assumptions; they must be written down.</li>
<li>Finality guarantees are user security guarantees; ambiguity is a UX vulnerability.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which invariants need proofs (supply, balances, ordering, slashing)?</li>
<li>Where is the economic/DoS pressure applied (mempool, gossip, execution, storage)?</li>
<li>What is the determinism story (byte-for-byte re-execution across platforms)?</li>
<li>What is the finality guarantee users can rely on (and when does it break)?</li>
<li>How do you defend against topology attacks (eclipse, partition, sybil)?</li>
<li>What is the reorg budget for applications and how do you communicate it?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Users and apps rely on probabilistic finality until proven otherwise.</li>
<li>Attackers can buy bandwidth and compute; they can also bribe and censor.</li>
<li>Nodes are heterogeneous; determinism must survive platform differences.</li>
<li>Peers are untrusted; gossip can be manipulated for delay or isolation.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Allowing execution nondeterminism for performance convenience.</li>
<li>Treating mempool policy as “local preference” when it affects security.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A ledger is a replicated state machine. Safety is uniqueness of finalized history:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><msub><mi>h</mi><mn>1</mn></msub><mo separator="true">,</mo><msub><mi>h</mi><mn>2</mn></msub><mo>:</mo><mtext> </mtext><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo>∧</mo><mrow><mi mathvariant="normal">F</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">l</mi></mrow><mo stretchy="false">(</mo><msub><mi>h</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mo>⇒</mo><msub><mi>h</mi><mn>1</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>2</mn></msub><mtext> </mtext><mo>∨</mo><mtext> </mtext><msub><mi>h</mi><mn>2</mn></msub><mo>⪯</mo><msub><mi>h</mi><mn>1</mn></msub><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall h_1,h_2:\ \mathrm{Final}(h_1)\wedge \mathrm{Final}(h_2)\Rightarrow h_1 \preceq h_2 \ \vee\ h_2 \preceq h_1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">∀</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">Final</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∨</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⪯</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal">h</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mord">.</span></span></span></span></span></div>
<p>Explicitly model upgrade boundaries: old rules vs new rules during transition.</p>
<p>Treat reorgs as a user-visible security event; encode reorg-aware semantics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  tx<span class="token text string">["Transaction"]</span> <span class="token arrow operator">--></span> mp<span class="token text string">["Mempool (admission + prioritization)"]</span>
  mp <span class="token arrow operator">--></span> prop<span class="token text string">["Block Proposal"]</span>
  prop <span class="token arrow operator">--></span> cons<span class="token text string">["Consensus / Finality"]</span>
  cons <span class="token arrow operator">--></span> exec<span class="token text string">["Deterministic Execution"]</span>
  exec <span class="token arrow operator">--></span> root<span class="token text string">["State Root Commitment"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Determinism is a boundary: every nondeterministic input is an attack surface.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token comment">// Deterministic execution is a security boundary.</span>
<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">Executor</span> <span class="token punctuation">{</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">apply_block</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">mut</span> <span class="token keyword">self</span><span class="token punctuation">,</span> block<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">]</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token class-name">String</span><span class="token operator">></span><span class="token punctuation">;</span>
  <span class="token keyword">fn</span> <span class="token function-definition function">state_root</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token keyword">self</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token punctuation">[</span><span class="token keyword">u8</span><span class="token punctuation">;</span> <span class="token number">32</span><span class="token punctuation">]</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Avoid nondeterminism: time, RNG, unordered maps, floating-point.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Fuzzing</strong> transaction decoding and state transition edge cases.</li>
<li><strong>Adversarial mempool tests</strong>: spam, pinning, worst-case signature patterns.</li>
<li><strong>Determinism tests</strong> across architectures (x86/ARM) and OSes.</li>
<li><strong>Formal invariants</strong> for supply/balance conservation where appropriate.</li>
<li><strong>Fork/reorg simulations</strong>: application-facing invariants under reorgs.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Keep execution resource limits explicit and enforced.</li>
<li>Protect peer tables against eclipse attempts (diversity, scoring, rotation).</li>
<li>Measure invalid tx rejection reasons and rates (spam signature).</li>
<li>Rehearse upgrades with mixed versions and rollback paths.</li>
<li>Monitor reorg depth and frequency; treat increases as incidents.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you communicate finality uncertainty to users without lying?</li>
<li>Where does your implementation accidentally depend on local wall-clock time?</li>
<li>What is the worst-case work a single transaction can force?</li>
<li>Which invariants should be proven vs tested vs monitored?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://bitcoin.org/bitcoin.pdf" target="_blank" rel="nofollow noopener noreferrer">Bitcoin: A Peer-to-Peer Electronic Cash System</a> — The original replicated-ledger model and threat assumptions.</li>
<li><a href="https://ethereum.github.io/yellowpaper/paper.pdf" target="_blank" rel="nofollow noopener noreferrer">Ethereum Yellow Paper</a> — A formal-ish specification for execution and state transitions.</li>
<li><a href="https://eips.ethereum.org/EIPS/eip-1559" target="_blank" rel="nofollow noopener noreferrer">EIP-1559</a> — Fee market mechanics and incentive surfaces.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="blockchain-protocols"/>
        <category label="distributed-systems"/>
        <category label="cryptography"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Incident Response for Crypto Systems: Key Compromise Playbooks]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-12-incident-response-for-crypto-systems-key-compromise-playbook</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-12-incident-response-for-crypto-systems-key-compromise-playbook"/>
        <updated>2018-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (December 2018): Incident Response for Crypto Systems: Key Compromise Playbooks.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Incident Response for Crypto Systems: Key Compromise Playbooks</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Bind purpose and context (domain separation) so keys can’t be misused accidentally.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Cryptographic agility is useless if rollout and rollback are unsafe.</li>
<li>Side channels turn performance details into security boundaries.</li>
<li>Key management failures are systemic: the breach is “a workflow,” not a bug.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do you handle key erasure and “right to be forgotten” constraints?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Certificate chains and policies evolve; clients won’t all update together.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Passing raw private keys across process boundaries.</li>
<li>Assuming “HSM = secure” without defining the threat model.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Audit integrity is a cryptographic property:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>audit</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>event</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{log\_entry} \leftarrow \mathrm{Sign}_{k_\text{audit}}(\mathrm{hash}(\text{event})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">log_entry</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">audit</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">event</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Audit logs are evidence. Make them tamper-evident and operationally accessible.</p>
<p>Treat key identifiers as capabilities with purpose constraints—enforce in code and policy.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Never pass secrets around; pass handles with purpose constraints.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Separate duties and restrict production key access paths.</li>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--2">(<a href="#bib-rfc8446">2</a>)</span> — Modern handshake design, key schedule, and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What is your plan for emergency revocation at global scale?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe']]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-11-kms-hsm-threat-models-when-managed-doesnt-mean-safe</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-11-kms-hsm-threat-models-when-managed-doesnt-mean-safe"/>
        <updated>2018-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (November 2018): KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe'.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>KMS/HSM Threat Models: When 'Managed' Doesn't Mean 'Safe'</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Bind purpose and context (domain separation) so keys can’t be misused accidentally.</li>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Auditability must not become a secret-leaking logging pipeline.</li>
<li>Managed services shift responsibilities; they don’t remove them.</li>
<li>Operational reality (rotation, audit, rollback) is where crypto systems fail.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>How do you handle key erasure and “right to be forgotten” constraints?</li>
<li>Which operations must be constant-time and how do you validate that?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Rotation must occur under incident pressure; automation must be safe.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on manual rotation procedures for fleet-scale systems.</li>
<li>Passing raw private keys across process boundaries.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Audit integrity is a cryptographic property:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>audit</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>event</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{log\_entry} \leftarrow \mathrm{Sign}_{k_\text{audit}}(\mathrm{hash}(\text{event})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">log_entry</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">audit</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">event</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Assume compromise and design for recovery: rotation, revocation, and forensics.</p>
<p>Treat key identifiers as capabilities with purpose constraints—enforce in code and policy.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make policy explicit and enforce it in the narrowest component possible.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--2">(<a href="#bib-rfc5869">2</a>)</span> — Domain separation and key derivation done sanely.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>What is your plan for emergency revocation at global scale?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-10-multi-tenant-isolation-crypto-boundaries-vs-kernel-boundarie</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-10-multi-tenant-isolation-crypto-boundaries-vs-kernel-boundarie"/>
        <updated>2018-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (October 2018): Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Multi-Tenant Isolation: Crypto Boundaries vs Kernel Boundaries</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Managed services shift responsibilities; they don’t remove them.</li>
<li>Key management failures are systemic: the breach is “a workflow,” not a bug.</li>
<li>Operational reality (rotation, audit, rollback) is where crypto systems fail.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>Which operations must be constant-time and how do you validate that?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Passing raw private keys across process boundaries.</li>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A practical safety statement for key usage is least authority:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>capability</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> purpose</mtext><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">¬</mi><mtext>use</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> other purpose</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{capability}(\text{key},\ \text{purpose}) \Rightarrow \neg \text{use}(\text{key},\ \text{other purpose}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">capability</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">purpose</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">¬</span><span class="mord text"><span class="mord">use</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">other purpose</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Audit logs are evidence. Make them tamper-evident and operationally accessible.</p>
<p>Treat key identifiers as capabilities with purpose constraints—enforce in code and policy.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make policy explicit and enforce it in the narrowest component possible.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Capability-style API: callers get a handle scoped to purpose + TTL.</span>
<span class="token keyword">type</span> KeyPurpose <span class="token builtin">string</span>
<span class="token keyword">type</span> KeyHandle <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  ID <span class="token builtin">string</span>
  Purpose KeyPurpose
  ExpiresAtUnix <span class="token builtin">int64</span>
<span class="token punctuation">}</span>

<span class="token keyword">type</span> Signer <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Sign</span><span class="token punctuation">(</span>h KeyHandle<span class="token punctuation">,</span> msg <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>sig <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Separate duties and restrict production key access paths.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your plan for emergency revocation at global scale?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-09-cryptographic-agility-designing-for-the-algorithm-you-havent</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-09-cryptographic-agility-designing-for-the-algorithm-you-havent"/>
        <updated>2018-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (September 2018): Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Cryptographic Agility: Designing for the Algorithm You Haven't Met Yet</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Policy drift silently turns strong crypto into weak practice.</li>
<li>Managed services shift responsibilities; they don’t remove them.</li>
<li>Cryptographic agility is useless if rollout and rollback are unsafe.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>How do you handle key erasure and “right to be forgotten” constraints?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Certificate chains and policies evolve; clients won’t all update together.</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Passing raw private keys across process boundaries.</li>
<li>Relying on manual rotation procedures for fleet-scale systems.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Key derivation is where protocols quietly succeed or fail. A sane default is domain-separated HKDF:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>k</mi><mo>←</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><mtext>salt</mtext><mo separator="true">,</mo><mtext> ikm</mtext><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mtext>context</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">k \leftarrow \mathrm{HKDF}(\text{salt},\ \text{ikm},\ \text{info}=\text{context}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">salt</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">ikm</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">context</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Bind every derived key to context: protocol, role, version, and transcript.</p>
<p>Audit logs are evidence. Make them tamper-evident and operationally accessible.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  policy<span class="token text string">["Policy (purpose + TTL)"]</span> <span class="token arrow operator">--></span> service<span class="token text string">["Signer Service"]</span>
  service <span class="token arrow operator">--></span> hsm<span class="token text string">["HSM/KMS"]</span>
  service <span class="token arrow operator">--></span> audit<span class="token text string">["Audit Stream"]</span>
  audit <span class="token arrow operator">--></span> siem<span class="token text string">["Detection/Response"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Never pass secrets around; pass handles with purpose constraints.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Capability-style API: callers get a handle scoped to purpose + TTL.</span>
<span class="token keyword">type</span> KeyPurpose <span class="token builtin">string</span>
<span class="token keyword">type</span> KeyHandle <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  ID <span class="token builtin">string</span>
  Purpose KeyPurpose
  ExpiresAtUnix <span class="token builtin">int64</span>
<span class="token punctuation">}</span>

<span class="token keyword">type</span> Signer <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Sign</span><span class="token punctuation">(</span>h KeyHandle<span class="token punctuation">,</span> msg <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>sig <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Separate duties and restrict production key access paths.</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Domain separation and key derivation done sanely.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What is your plan for emergency revocation at global scale?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Logging for Forensics: Tamper Evident Event Pipelines]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-08-logging-for-forensics-tamper-evident-event-pipelines</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-08-logging-for-forensics-tamper-evident-event-pipelines"/>
        <updated>2018-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (August 2018): Logging for Forensics: Tamper Evident Event Pipelines.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Logging for Forensics: Tamper Evident Event Pipelines</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational reality (rotation, audit, rollback) is where crypto systems fail.</li>
<li>Cryptographic agility is useless if rollout and rollback are unsafe.</li>
<li>Managed services shift responsibilities; they don’t remove them.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Attackers can observe timing and resource usage in shared environments.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming “HSM = secure” without defining the threat model.</li>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A practical safety statement for key usage is least authority:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>capability</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> purpose</mtext><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">¬</mi><mtext>use</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> other purpose</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{capability}(\text{key},\ \text{purpose}) \Rightarrow \neg \text{use}(\text{key},\ \text{other purpose}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">capability</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">purpose</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">¬</span><span class="mord text"><span class="mord">use</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">other purpose</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Assume compromise and design for recovery: rotation, revocation, and forensics.</p>
<p>Bind every derived key to context: protocol, role, version, and transcript.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  policy<span class="token text string">["Policy (purpose + TTL)"]</span> <span class="token arrow operator">--></span> service<span class="token text string">["Signer Service"]</span>
  service <span class="token arrow operator">--></span> hsm<span class="token text string">["HSM/KMS"]</span>
  service <span class="token arrow operator">--></span> audit<span class="token text string">["Audit Stream"]</span>
  audit <span class="token arrow operator">--></span> siem<span class="token text string">["Detection/Response"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Never pass secrets around; pass handles with purpose constraints.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Separate duties and restrict production key access paths.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>What is your plan for emergency revocation at global scale?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-07-tls-beyond-defaults-ciphersuites-alpn-and-operational-realit</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-07-tls-beyond-defaults-ciphersuites-alpn-and-operational-realit"/>
        <updated>2018-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (July 2018): TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>TLS Beyond Defaults: Ciphersuites, ALPN, and Operational Reality</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Bind purpose and context (domain separation) so keys can’t be misused accidentally.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Side channels turn performance details into security boundaries.</li>
<li>Cryptographic agility is useless if rollout and rollback are unsafe.</li>
<li>Key management failures are systemic: the breach is “a workflow,” not a bug.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which operations must be constant-time and how do you validate that?</li>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Rotation must occur under incident pressure; automation must be safe.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
<li>Assuming “HSM = secure” without defining the threat model.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A practical safety statement for key usage is least authority:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>capability</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> purpose</mtext><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">¬</mi><mtext>use</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> other purpose</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{capability}(\text{key},\ \text{purpose}) \Rightarrow \neg \text{use}(\text{key},\ \text{other purpose}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">capability</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">purpose</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">¬</span><span class="mord text"><span class="mord">use</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">other purpose</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat key identifiers as capabilities with purpose constraints—enforce in code and policy.</p>
<p>Assume compromise and design for recovery: rotation, revocation, and forensics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Never pass secrets around; pass handles with purpose constraints.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
<li>Separate duties and restrict production key access paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--1">(<a href="#bib-rfc8446">1</a>)</span> — Modern handshake design, key schedule, and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What is your plan for emergency revocation at global scale?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secure Firmware Updates: Signed Manifests and Rollback Protection]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-06-secure-firmware-updates-signed-manifests-and-rollback-protec</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-06-secure-firmware-updates-signed-manifests-and-rollback-protec"/>
        <updated>2018-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (June 2018): Secure Firmware Updates: Signed Manifests and Rollback Protection.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secure Firmware Updates: Signed Manifests and Rollback Protection</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Make failure modes explicit and observable.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Side channels turn performance details into security boundaries.</li>
<li>Policy drift silently turns strong crypto into weak practice.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Operational reality (rotation, audit, rollback) is where crypto systems fail.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
<li>Which operations must be constant-time and how do you validate that?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Certificate chains and policies evolve; clients won’t all update together.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
<li>Passing raw private keys across process boundaries.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Audit integrity is a cryptographic property:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>audit</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>event</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{log\_entry} \leftarrow \mathrm{Sign}_{k_\text{audit}}(\mathrm{hash}(\text{event})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">log_entry</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">audit</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">event</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat key identifiers as capabilities with purpose constraints—enforce in code and policy.</p>
<p>Bind every derived key to context: protocol, role, version, and transcript.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Crypto infra is a product: UX, policy, audit, and rollback must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Separate duties and restrict production key access paths.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--1">(<a href="#bib-rfc8446">1</a>)</span> — Modern handshake design, key schedule, and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Real-world PKI incidents and operational lessons.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>What is your plan for emergency revocation at global scale?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Side Channels: Constant-Time, Cache Attacks, and Real Threat Models]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-05-side-channels-constant-time-cache-attacks-and-real-threat-mo</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-05-side-channels-constant-time-cache-attacks-and-real-threat-mo"/>
        <updated>2018-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (May 2018): Side Channels: Constant-Time, Cache Attacks, and Real Threat Models.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Side Channels: Constant-Time, Cache Attacks, and Real Threat Models</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Key management failures are systemic: the breach is “a workflow,” not a bug.</li>
<li>Policy drift silently turns strong crypto into weak practice.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Side channels turn performance details into security boundaries.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
<li>Relying on manual rotation procedures for fleet-scale systems.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Key derivation is where protocols quietly succeed or fail. A sane default is domain-separated HKDF:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>k</mi><mo>←</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><mtext>salt</mtext><mo separator="true">,</mo><mtext> ikm</mtext><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mtext>context</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">k \leftarrow \mathrm{HKDF}(\text{salt},\ \text{ikm},\ \text{info}=\text{context}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">salt</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">ikm</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">context</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Assume compromise and design for recovery: rotation, revocation, and forensics.</p>
<p>Bind every derived key to context: protocol, role, version, and transcript.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  policy<span class="token text string">["Policy (purpose + TTL)"]</span> <span class="token arrow operator">--></span> service<span class="token text string">["Signer Service"]</span>
  service <span class="token arrow operator">--></span> hsm<span class="token text string">["HSM/KMS"]</span>
  service <span class="token arrow operator">--></span> audit<span class="token text string">["Audit Stream"]</span>
  audit <span class="token arrow operator">--></span> siem<span class="token text string">["Detection/Response"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Crypto infra is a product: UX, policy, audit, and rollback must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Separate duties and restrict production key access paths.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your plan for emergency revocation at global scale?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Hardware Roots of Trust: TPM, Secure Boot, and Attestation]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-04-hardware-roots-of-trust-tpm-secure-boot-and-attestation</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-04-hardware-roots-of-trust-tpm-secure-boot-and-attestation"/>
        <updated>2018-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (April 2018): Hardware Roots of Trust: TPM, Secure Boot, and Attestation.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Hardware Roots of Trust: TPM, Secure Boot, and Attestation</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Managed services shift responsibilities; they don’t remove them.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Cryptographic agility is useless if rollout and rollback are unsafe.</li>
<li>Auditability must not become a secret-leaking logging pipeline.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>How do you handle key erasure and “right to be forgotten” constraints?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Rotation must occur under incident pressure; automation must be safe.</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
<li>Certificate chains and policies evolve; clients won’t all update together.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Passing raw private keys across process boundaries.</li>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Key derivation is where protocols quietly succeed or fail. A sane default is domain-separated HKDF:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>k</mi><mo>←</mo><mrow><mi mathvariant="normal">H</mi><mi mathvariant="normal">K</mi><mi mathvariant="normal">D</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><mtext>salt</mtext><mo separator="true">,</mo><mtext> ikm</mtext><mo separator="true">,</mo><mtext> info</mtext><mo>=</mo><mtext>context</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">k \leftarrow \mathrm{HKDF}(\text{salt},\ \text{ikm},\ \text{info}=\text{context}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm">HKDF</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">salt</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">ikm</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">info</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">context</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Audit logs are evidence. Make them tamper-evident and operationally accessible.</p>
<p>Bind every derived key to context: protocol, role, version, and transcript.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Crypto infra is a product: UX, policy, audit, and rollback must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Capability-style API: callers get a handle scoped to purpose + TTL.</span>
<span class="token keyword">type</span> KeyPurpose <span class="token builtin">string</span>
<span class="token keyword">type</span> KeyHandle <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  ID <span class="token builtin">string</span>
  Purpose KeyPurpose
  ExpiresAtUnix <span class="token builtin">int64</span>
<span class="token punctuation">}</span>

<span class="token keyword">type</span> Signer <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Sign</span><span class="token punctuation">(</span>h KeyHandle<span class="token punctuation">,</span> msg <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>sig <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Separate duties and restrict production key access paths.</li>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> <span class="citation" id="citation--rfc5869--1">(<a href="#bib-rfc5869">1</a>)</span> — Domain separation and key derivation done sanely.
<ul>
<li><strong>Evidence:</strong> HKDF is the workhorse for domain separation; bind purpose/context to avoid cross-protocol key reuse.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is your plan for emergency revocation at global scale?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc5869">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Krawczyk H, Eronen P. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) [Internet]. RFC Editor; 2010. Report No.: 5869. Available from: https://www.rfc-editor.org/rfc/rfc5869</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Secrets vs Capabilities: Token Design in Microservices]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-03-secrets-vs-capabilities-token-design-in-microservices</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-03-secrets-vs-capabilities-token-design-in-microservices"/>
        <updated>2018-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (March 2018): Secrets vs Capabilities: Token Design in Microservices.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Secrets vs Capabilities: Token Design in Microservices</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Audit logs are evidence: make them tamper-evident and queryable during incidents.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Auditability must not become a secret-leaking logging pipeline.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Operational reality (rotation, audit, rollback) is where crypto systems fail.</li>
<li>Side channels turn performance details into security boundaries.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do keys rotate safely (overlap windows, dual-sign, staged rollout)?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>How do you handle key erasure and “right to be forgotten” constraints?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Certificate chains and policies evolve; clients won’t all update together.</li>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
<li>Relying on manual rotation procedures for fleet-scale systems.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A practical safety statement for key usage is least authority:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>capability</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> purpose</mtext><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">¬</mi><mtext>use</mtext><mo stretchy="false">(</mo><mtext>key</mtext><mo separator="true">,</mo><mtext> other purpose</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\text{capability}(\text{key},\ \text{purpose}) \Rightarrow \neg \text{use}(\text{key},\ \text{other purpose}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">capability</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">purpose</span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">¬</span><span class="mord text"><span class="mord">use</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">key</span></span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">other purpose</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Assume compromise and design for recovery: rotation, revocation, and forensics.</p>
<p>Bind every derived key to context: protocol, role, version, and transcript.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Crypto infra is a product: UX, policy, audit, and rollback must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Capability-style API: callers get a handle scoped to purpose + TTL.</span>
<span class="token keyword">type</span> KeyPurpose <span class="token builtin">string</span>
<span class="token keyword">type</span> KeyHandle <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  ID <span class="token builtin">string</span>
  Purpose KeyPurpose
  ExpiresAtUnix <span class="token builtin">int64</span>
<span class="token punctuation">}</span>

<span class="token keyword">type</span> Signer <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Sign</span><span class="token punctuation">(</span>h KeyHandle<span class="token punctuation">,</span> msg <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>sig <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Separate duties and restrict production key access paths.</li>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--1">(<a href="#bib-letsencryptincidents">1</a>)</span> — Real-world PKI incidents and operational lessons.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> <span class="citation" id="citation--rfc8446--2">(<a href="#bib-rfc8446">2</a>)</span> — Modern handshake design, key schedule, and downgrade resistance patterns.
<ul>
<li><strong>Evidence:</strong> Handshake transcript binding and downgrade resistance patterns; monitor negotiation paths and failure reasons.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What is your plan for emergency revocation at global scale?</li>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
  <div class="csl-entry" id="bib-rfc8446">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Rescorla E. The Transport Layer Security (TLS) Protocol Version 1.3 [Internet]. RFC Editor; 2018. Report No.: 8446. Available from: https://www.rfc-editor.org/rfc/rfc8446</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Key Management at Scale: Rotation, Audit, and Blast Radius]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-02-key-management-at-scale-rotation-audit-and-blast-radius</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-02-key-management-at-scale-rotation-audit-and-blast-radius"/>
        <updated>2018-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (February 2018): Key Management at Scale: Rotation, Audit, and Blast Radius.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Key Management at Scale: Rotation, Audit, and Blast Radius</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Rotation and rollback are core features—design them before you ship.</li>
<li>Bind purpose and context (domain separation) so keys can’t be misused accidentally.</li>
<li>Make failure modes explicit and observable.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational reality (rotation, audit, rollback) is where crypto systems fail.</li>
<li>Cryptographic agility is useless if rollout and rollback are unsafe.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Side channels turn performance details into security boundaries.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
<li>Which operations must be constant-time and how do you validate that?</li>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Attackers can observe timing and resource usage in shared environments.</li>
<li>Certificate chains and policies evolve; clients won’t all update together.</li>
<li>Rotation must occur under incident pressure; automation must be safe.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming “HSM = secure” without defining the threat model.</li>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Audit integrity is a cryptographic property:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>audit</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>event</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{log\_entry} \leftarrow \mathrm{Sign}_{k_\text{audit}}(\mathrm{hash}(\text{event})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">log_entry</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">audit</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">event</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat key identifiers as capabilities with purpose constraints—enforce in code and policy.</p>
<p>Audit logs are evidence. Make them tamper-evident and operationally accessible.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> LR
  policy<span class="token text string">["Policy (purpose + TTL)"]</span> <span class="token arrow operator">--></span> service<span class="token text string">["Signer Service"]</span>
  service <span class="token arrow operator">--></span> hsm<span class="token text string">["HSM/KMS"]</span>
  service <span class="token arrow operator">--></span> audit<span class="token text string">["Audit Stream"]</span>
  audit <span class="token arrow operator">--></span> siem<span class="token text string">["Detection/Response"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make policy explicit and enforce it in the narrowest component possible.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Capability-style API: callers get a handle scoped to purpose + TTL.</span>
<span class="token keyword">type</span> KeyPurpose <span class="token builtin">string</span>
<span class="token keyword">type</span> KeyHandle <span class="token keyword">struct</span> <span class="token punctuation">{</span>
  ID <span class="token builtin">string</span>
  Purpose KeyPurpose
  ExpiresAtUnix <span class="token builtin">int64</span>
<span class="token punctuation">}</span>

<span class="token keyword">type</span> Signer <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Sign</span><span class="token punctuation">(</span>h KeyHandle<span class="token punctuation">,</span> msg <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>sig <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
<li><strong>Rotation drills</strong>: staged rollout, dual-sign windows, and rollback.</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Test backup/restore for crypto material with the same rigor as databases.</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Separate duties and restrict production key access paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Real-world PKI incidents and operational lessons.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>What is your plan for emergency revocation at global scale?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[PKI as an Operating System: Certificates, Policies, and Expiration]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2018-01-pki-as-an-operating-system-certificates-policies-and-expirat</id>
        <link href="https://mayckongiovani.xyz/pensieve/2018-01-pki-as-an-operating-system-certificates-policies-and-expirat"/>
        <updated>2018-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (January 2018): PKI as an Operating System: Certificates, Policies, and Expiration.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Cryptographic Infrastructure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>PKI as an Operating System: Certificates, Policies, and Expiration</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat key IDs as capabilities; never pass raw private key material across boundaries.</li>
<li>Side-channel constraints turn performance details into security boundaries.</li>
<li>Bind purpose and context (domain separation) so keys can’t be misused accidentally.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Managed services shift responsibilities; they don’t remove them.</li>
<li>Most organizations don’t know where their keys live—until an incident.</li>
<li>Side channels turn performance details into security boundaries.</li>
<li>Policy drift silently turns strong crypto into weak practice.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the blast radius of compromise (tenant, service, region, environment)?</li>
<li>What is your disaster recovery story for KMS/HSM outages?</li>
<li>What is the rollback plan when a new algorithm breaks production?</li>
<li>What is the root of trust (HSM, TPM, offline CA, threshold ceremony)?</li>
<li>How do you separate duties (operators vs developers vs security responders)?</li>
<li>How do you prove usage (who signed what, when, and why) without leaking secrets?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Secrets leak through logs, metrics, crash dumps, and backups unless prevented.</li>
<li>Some environments are hostile (CI, ephemeral runners, shared build agents).</li>
<li>Rotation must occur under incident pressure; automation must be safe.</li>
<li>Key usage is high-volume; audit pipelines must scale without sampling away truth.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Designing audit trails that expose sensitive plaintext or identifiers.</li>
<li>Assuming “HSM = secure” without defining the threat model.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Audit integrity is a cryptographic property:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">l</mi><mi mathvariant="normal">o</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">_</mi><mi mathvariant="normal">e</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">t</mi><mi mathvariant="normal">r</mi><mi mathvariant="normal">y</mi></mrow><mo>←</mo><msub><mrow><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi><mi mathvariant="normal">g</mi><mi mathvariant="normal">n</mi></mrow><msub><mi>k</mi><mtext>audit</mtext></msub></msub><mo stretchy="false">(</mo><mrow><mi mathvariant="normal">h</mi><mi mathvariant="normal">a</mi><mi mathvariant="normal">s</mi><mi mathvariant="normal">h</mi></mrow><mo stretchy="false">(</mo><mtext>event</mtext><mo stretchy="false">)</mo><mtext> </mtext><mi mathvariant="normal">∥</mi><mtext> metadata</mtext><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{log\_entry} \leftarrow \mathrm{Sign}_{k_\text{audit}}(\mathrm{hash}(\text{event})\ \Vert\ \text{metadata}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1.0044em;vertical-align:-0.31em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">log_entry</span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">←</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.1em;vertical-align:-0.35em;"></span><span class="mord"><span class="mord"><span class="mord mathrm">Sign</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mtight"><span class="mord mathnormal mtight" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3448em;"><span style="top:-2.3488em;margin-left:-0.0315em;margin-right:0.0714em;"><span class="pstrut" style="height:2.5em;"></span><span class="sizing reset-size3 size1 mtight"><span class="mord text mtight"><span class="mord mtight">audit</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.1512em;"><span></span></span></span></span></span></span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.35em;"><span></span></span></span></span></span></span><span class="mopen">(</span><span class="mord"><span class="mord mathrm">hash</span></span><span class="mopen">(</span><span class="mord text"><span class="mord">event</span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord">∥</span><span class="mspace"> </span><span class="mord text"><span class="mord">metadata</span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Audit logs are evidence. Make them tamper-evident and operationally accessible.</p>
<p>Assume compromise and design for recovery: rotation, revocation, and forensics.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  gen<span class="token text string">["KeyGen (HSM/KMS)"]</span> <span class="token arrow operator">--></span> use<span class="token text string">["Use (TLS/VPN/Signing)"]</span>
  use <span class="token arrow operator">--></span> rot<span class="token text string">["Rotate (policy + automation)"]</span>
  rot <span class="token arrow operator">--></span> revoke<span class="token text string">["Revoke (incident)"]</span>
  revoke <span class="token arrow operator">--></span> audit<span class="token text string">["Audit/Forensics"]</span>
  audit <span class="token arrow operator">--></span> gen</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Crypto infra is a product: UX, policy, audit, and rollback must compose.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token attribute attr-name">#[derive(Clone, Copy, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Purpose</span> <span class="token punctuation">{</span> <span class="token class-name">Tls</span><span class="token punctuation">,</span> <span class="token class-name">Jwt</span><span class="token punctuation">,</span> <span class="token class-name">Firmware</span><span class="token punctuation">,</span> <span class="token class-name">Ledger</span> <span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">struct</span> <span class="token type-definition class-name">KeyHandle</span> <span class="token punctuation">{</span> id<span class="token punctuation">:</span> <span class="token class-name">String</span><span class="token punctuation">,</span> purpose<span class="token punctuation">:</span> <span class="token class-name">Purpose</span> <span class="token punctuation">}</span>

<span class="token comment">// Enforce purpose and algorithm policy at the boundary, not in the caller.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Config drift detection</strong>: policy-as-code with diffs treated as security events.</li>
<li><strong>Constant-time validation</strong>: microbenchmarks + side-channel tooling where feasible.</li>
<li><strong>Forensics tests</strong>: can you reconstruct “who signed what” under load?</li>
<li><strong>Misuse resistance tests</strong>: wrong purpose, wrong context, wrong key type must fail.</li>
<li><strong>Chaos for KMS</strong>: inject throttling, partial outages, and latency spikes.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Automate rotation with safety rails (canary, dual-sign, fast rollback).</li>
<li>Make audit streams append-only and queryable during incidents.</li>
<li>Alert on policy drift: cipher suites, key sizes, algorithm toggles, TTL changes.</li>
<li>Inventory keys and usage paths; treat unknown usage as an incident.</li>
<li>Separate duties and restrict production key access paths.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> <span class="citation" id="citation--letsencryptincidents--2">(<a href="#bib-letsencryptincidents">2</a>)</span> — Real-world PKI incidents and operational lessons.
<ul>
<li><strong>Evidence:</strong> Rotation and revocation are operational protocols; extract failure patterns into drills and automated rollbacks.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which secrets must remain confidential for 10+ years and where are they stored today?</li>
<li>How do you guarantee that audit does not become a data exfiltration channel?</li>
<li>What would a KMS compromise look like in your telemetry?</li>
<li>What is your plan for emergency revocation at global scale?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final" target="_blank" rel="nofollow noopener noreferrer">NIST SP 800-57 Part 1 Rev. 5</a> — Key management guidance: lifecycle, strength, and policy.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc5869" target="_blank" rel="nofollow noopener noreferrer">RFC 5869: HKDF</a> — Domain separation and key derivation done sanely.</li>
<li><a href="https://community.letsencrypt.org/c/incidents/16/l/top" target="_blank" rel="nofollow noopener noreferrer">Let's Encrypt Incident Reports</a> — Real-world PKI incidents and operational lessons.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc8446" target="_blank" rel="nofollow noopener noreferrer">RFC 8446: TLS 1.3</a> — Modern handshake design, key schedule, and downgrade resistance patterns.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-letsencryptincidents">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Let’s Encrypt. Let’s Encrypt Incident Reports [Internet]. Web; Available from: https://community.letsencrypt.org/c/incidents/16/l/top</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="cryptography"/>
        <category label="security"/>
        <category label="security-critical-infrastructure"/>
        <category label="DevSecOps"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[A Minimal TLA+ Workflow for Distributed Protocols]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-12-a-minimal-tla-workflow-for-distributed-protocols</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-12-a-minimal-tla-workflow-for-distributed-protocols"/>
        <updated>2017-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (December 2017): A Minimal TLA+ Workflow for Distributed Protocols.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>A Minimal TLA+ Workflow for Distributed Protocols</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Mixed-version operation is the default state of real deployments.</li>
<li>Most protocol bugs hide in timeouts, retries, and membership changes.</li>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
<li>If your protocol isn’t testable under reordering, it isn’t deployable.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which components require determinism for reproducibility?</li>
<li>What is the compaction story (snapshots, log truncation, state transfer)?</li>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>How do you prevent overload from becoming inconsistency?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Partitions happen at multiple layers (network, DNS, LB, service mesh).</li>
<li>Delays are unbounded during incidents; timeouts are guesses.</li>
<li>Clocks drift; leases can be violated under GC pauses or VM stalls.</li>
<li>Nodes restart with partial state unless you prove durability.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating membership as static or human-managed only.</li>
<li>Relying on global time for ordering without strong synchronization assumptions.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For quorum-based protocols, the intersection property is the backbone of safety:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>Crash-fault: </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>></mo><mfrac><mi>n</mi><mn>2</mn></mfrac><mspace width="2em"></mspace><mspace width="2em"></mspace><mtext>Byzantine: </mtext><mi>n</mi><mo>≥</mo><mn>3</mn><mi>f</mi><mo>+</mo><mn>1</mn><mo separator="true">,</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>≥</mo><mn>2</mn><mi>f</mi><mo>+</mo><mn>1.</mn></mrow><annotation encoding="application/x-tex">\text{Crash-fault: } |Q| > \frac{n}{2}\qquad\qquad
\text{Byzantine: } n \ge 3f+1,\ |Q| \ge 2f+1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Crash-fault: </span></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.7936em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.1076em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">2</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">Byzantine: </span></span><span class="mord mathnormal">n</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">3</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.</span></span></span></span></span></div>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> L as Leader
  <span class="token keyword">participant</span> F1 as Follower 1
  <span class="token keyword">participant</span> F2 as Follower 2
  C<span class="token arrow operator">->></span>L<span class="token operator">:</span> propose<span class="token text string">(cmd)</span>
  L<span class="token arrow operator">->></span>F1<span class="token operator">:</span> appendEntries
  L<span class="token arrow operator">->></span>F2<span class="token operator">:</span> appendEntries
  F1<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  F2<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  L<span class="token arrow operator">-->></span>C<span class="token operator">:</span> commit<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Your protocol is an interface between failures and invariants. Encode both.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> <span class="citation" id="citation--lamport1978--2">(<a href="#bib-lamport1978">2</a>)</span> — Causality, ordering, and why clocks are tricky.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Designing for Network Partitions: Degraded Modes That Still Make Sense]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-11-designing-for-network-partitions-degraded-modes-that-still-m</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-11-designing-for-network-partitions-degraded-modes-that-still-m"/>
        <updated>2017-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (November 2017): Designing for Network Partitions: Degraded Modes That Still Make Sense.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Designing for Network Partitions: Degraded Modes That Still Make Sense</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational simplicity is a security property: fewer modes, fewer surprises.</li>
<li>Tail latency is a protocol input: it changes who retries and when.</li>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
<li>Backpressure and fairness are part of correctness when resources are finite.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you prevent overload from becoming inconsistency?</li>
<li>Which components require determinism for reproducibility?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>What does “read” mean under replication lag?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Clients retry and amplify load right when the system is weakest.</li>
<li>Delays are unbounded during incidents; timeouts are guesses.</li>
<li>Workload is skewed: hot keys exist and dominate.</li>
<li>Partitions happen at multiple layers (network, DNS, LB, service mesh).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Relying on global time for ordering without strong synchronization assumptions.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>Under partial synchrony, progress depends on a stabilizing period:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∃</mi><mi>T</mi><mo>:</mo><mtext> </mtext><mi mathvariant="normal">∀</mi><mi>t</mi><mo>≥</mo><mi>T</mi><mo separator="true">,</mo><mtext> messages delivered within </mtext><mi mathvariant="normal">Δ</mi><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\exists T:\ \forall t \ge T,\ \text{messages delivered within } \Delta.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∃</span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8304em;vertical-align:-0.136em;"></span><span class="mord">∀</span><span class="mord mathnormal">t</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord mathnormal" style="margin-right:0.13889em;">T</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord text"><span class="mord">messages delivered within </span></span><span class="mord">Δ.</span></span></span></span></span></div>
<p>Make overload explicit: admission control is a protocol boundary.</p>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> L as Leader
  <span class="token keyword">participant</span> F1 as Follower 1
  <span class="token keyword">participant</span> F2 as Follower 2
  C<span class="token arrow operator">->></span>L<span class="token operator">:</span> propose<span class="token text string">(cmd)</span>
  L<span class="token arrow operator">->></span>F1<span class="token operator">:</span> appendEntries
  L<span class="token arrow operator">->></span>F2<span class="token operator">:</span> appendEntries
  F1<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  F2<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  L<span class="token arrow operator">-->></span>C<span class="token operator">:</span> commit<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Protocols fail at the boundaries: timeouts, membership, compaction, and overload.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Testing correctness under partitions and faults.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> <span class="citation" id="citation--lamport1978--2">(<a href="#bib-lamport1978">2</a>)</span> — Causality, ordering, and why clocks are tricky.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Rate Limiting and Fairness: Protecting Critical Paths]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-10-rate-limiting-and-fairness-protecting-critical-paths</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-10-rate-limiting-and-fairness-protecting-critical-paths"/>
        <updated>2017-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (October 2017): Rate Limiting and Fairness: Protecting Critical Paths.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Rate Limiting and Fairness: Protecting Critical Paths</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most protocol bugs hide in timeouts, retries, and membership changes.</li>
<li>Mixed-version operation is the default state of real deployments.</li>
<li>Tail latency is a protocol input: it changes who retries and when.</li>
<li>Observability must explain protocol state, not just latency.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>Which components require determinism for reproducibility?</li>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
<li>What does “read” mean under replication lag?</li>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Reconfigurations happen mid-incident (the worst time).</li>
<li>Clocks drift; leases can be violated under GC pauses or VM stalls.</li>
<li>Workload is skewed: hot keys exist and dominate.</li>
<li>Clients retry and amplify load right when the system is weakest.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating membership as static or human-managed only.</li>
<li>Relying on global time for ordering without strong synchronization assumptions.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common safety shape for replicated logs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>i</mi><mo>:</mo><mtext> Committed</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>:</mo><mtext> </mtext><msub><mtext>Log</mtext><mi>r</mi></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mo>=</mo><msub><mtext>Log</mtext><mtext>leader</mtext></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall i:\ \text{Committed}(i)\Rightarrow \forall r:\ \text{Log}_r[i] = \text{Log}_\text{leader}[i].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">leader</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Liveness is always conditional: specify <em>when</em> progress is expected and what you do otherwise.</p>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">stateDiagram-v2</span>
  <span class="token text string">[*]</span> <span class="token arrow operator">--></span> Follower
  Follower <span class="token arrow operator">--></span> Candidate<span class="token operator">:</span> timeout
  Candidate <span class="token arrow operator">--></span> Leader<span class="token operator">:</span> win quorum
  Candidate <span class="token arrow operator">--></span> Follower<span class="token operator">:</span> lose
  Leader <span class="token arrow operator">--></span> Follower<span class="token operator">:</span> stepdown</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Your protocol is an interface between failures and invariants. Encode both.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Deterministic replay</strong> of network traces to reproduce rare failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> <span class="citation" id="citation--ongaro2014raft--1">(<a href="#bib-ongaro2014raft">1</a>)</span> — Consensus with explicit state machines and practical tradeoffs.
<ul>
<li><strong>Evidence:</strong> Track term/commitIndex as explicit evidence; test leader changes and log conflicts as part of rollback behavior.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-ongaro2014raft">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Ongaro D, Ousterhout J. In Search of an Understandable Consensus Algorithm (Raft). In: 2014 USENIX Annual Technical Conference (USENIX ATC 14) [Internet]. 2014. Available from: https://raft.github.io/raft.pdf</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Queues & Streams: Exactly-Once Semantics Without Lying to Yourself]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-09-queues-streams-exactly-once-semantics-without-lying-to-yours</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-09-queues-streams-exactly-once-semantics-without-lying-to-yours"/>
        <updated>2017-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (September 2017): Queues & Streams: Exactly-Once Semantics Without Lying to Yourself.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Queues &#x26; Streams: Exactly-Once Semantics Without Lying to Yourself</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Backpressure and admission control are correctness mechanisms under load.</li>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational simplicity is a security property: fewer modes, fewer surprises.</li>
<li>Observability must explain protocol state, not just latency.</li>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
<li>If your protocol isn’t testable under reordering, it isn’t deployable.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does “read” mean under replication lag?</li>
<li>What is the unit of ordering (per key, per partition, global)?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
<li>How do you prevent overload from becoming inconsistency?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Delays are unbounded during incidents; timeouts are guesses.</li>
<li>Reconfigurations happen mid-incident (the worst time).</li>
<li>Clocks drift; leases can be violated under GC pauses or VM stalls.</li>
<li>Partitions happen at multiple layers (network, DNS, LB, service mesh).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Assuming the network eventually behaves “nicely” under load.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For quorum-based protocols, the intersection property is the backbone of safety:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>Crash-fault: </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>></mo><mfrac><mi>n</mi><mn>2</mn></mfrac><mspace width="2em"></mspace><mspace width="2em"></mspace><mtext>Byzantine: </mtext><mi>n</mi><mo>≥</mo><mn>3</mn><mi>f</mi><mo>+</mo><mn>1</mn><mo separator="true">,</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>≥</mo><mn>2</mn><mi>f</mi><mo>+</mo><mn>1.</mn></mrow><annotation encoding="application/x-tex">\text{Crash-fault: } |Q| > \frac{n}{2}\qquad\qquad
\text{Byzantine: } n \ge 3f+1,\ |Q| \ge 2f+1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Crash-fault: </span></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.7936em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.1076em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">2</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">Byzantine: </span></span><span class="mord mathnormal">n</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">3</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.</span></span></span></span></span></div>
<p>Make overload explicit: admission control is a protocol boundary.</p>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">stateDiagram-v2</span>
  <span class="token text string">[*]</span> <span class="token arrow operator">--></span> Follower
  Follower <span class="token arrow operator">--></span> Candidate<span class="token operator">:</span> timeout
  Candidate <span class="token arrow operator">--></span> Leader<span class="token operator">:</span> win quorum
  Candidate <span class="token arrow operator">--></span> Follower<span class="token operator">:</span> lose
  Leader <span class="token arrow operator">--></span> Follower<span class="token operator">:</span> stepdown</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make the state machine explicit; then make persistence and networking boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">type</span> <span class="token type-definition class-name">LogIndex</span> <span class="token operator">=</span> <span class="token keyword">u64</span><span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">struct</span> <span class="token type-definition class-name">Entry</span> <span class="token punctuation">{</span>
  index<span class="token punctuation">:</span> <span class="token class-name">LogIndex</span><span class="token punctuation">,</span>
  term<span class="token punctuation">:</span> <span class="token keyword">u64</span><span class="token punctuation">,</span>
  bytes<span class="token punctuation">:</span> <span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token comment">// Persist(term, vote, log) before acknowledging anything.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Deterministic replay</strong> of network traces to reproduce rare failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> <span class="citation" id="citation--lamport1978--2">(<a href="#bib-lamport1978">2</a>)</span> — Causality, ordering, and why clocks are tricky.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Geo-Replication: Latency Budgets and Cross-Region Failure Modes]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-08-geo-replication-latency-budgets-and-cross-region-failure-mod</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-08-geo-replication-latency-budgets-and-cross-region-failure-mod"/>
        <updated>2017-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (August 2017): Geo-Replication: Latency Budgets and Cross-Region Failure Modes.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Geo-Replication: Latency Budgets and Cross-Region Failure Modes</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Backpressure and admission control are correctness mechanisms under load.</li>
<li>Make failure modes explicit and observable.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Tail latency is a protocol input: it changes who retries and when.</li>
<li>Mixed-version operation is the default state of real deployments.</li>
<li>Operational simplicity is a security property: fewer modes, fewer surprises.</li>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>What is the compaction story (snapshots, log truncation, state transfer)?</li>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
<li>Which components require determinism for reproducibility?</li>
<li>What is the unit of ordering (per key, per partition, global)?</li>
<li>How do you prevent overload from becoming inconsistency?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Partitions happen at multiple layers (network, DNS, LB, service mesh).</li>
<li>Clients retry and amplify load right when the system is weakest.</li>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Reconfigurations happen mid-incident (the worst time).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Relying on global time for ordering without strong synchronization assumptions.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For quorum-based protocols, the intersection property is the backbone of safety:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>Crash-fault: </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>></mo><mfrac><mi>n</mi><mn>2</mn></mfrac><mspace width="2em"></mspace><mspace width="2em"></mspace><mtext>Byzantine: </mtext><mi>n</mi><mo>≥</mo><mn>3</mn><mi>f</mi><mo>+</mo><mn>1</mn><mo separator="true">,</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>≥</mo><mn>2</mn><mi>f</mi><mo>+</mo><mn>1.</mn></mrow><annotation encoding="application/x-tex">\text{Crash-fault: } |Q| > \frac{n}{2}\qquad\qquad
\text{Byzantine: } n \ge 3f+1,\ |Q| \ge 2f+1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Crash-fault: </span></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.7936em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.1076em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">2</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">Byzantine: </span></span><span class="mord mathnormal">n</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">3</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.</span></span></span></span></span></div>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> L as Leader
  <span class="token keyword">participant</span> F1 as Follower 1
  <span class="token keyword">participant</span> F2 as Follower 2
  C<span class="token arrow operator">->></span>L<span class="token operator">:</span> propose<span class="token text string">(cmd)</span>
  L<span class="token arrow operator">->></span>F1<span class="token operator">:</span> appendEntries
  L<span class="token arrow operator">->></span>F2<span class="token operator">:</span> appendEntries
  F1<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  F2<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  L<span class="token arrow operator">-->></span>C<span class="token operator">:</span> commit<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Protocols fail at the boundaries: timeouts, membership, compaction, and overload.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> <span class="citation" id="citation--lamport1978--2">(<a href="#bib-lamport1978">2</a>)</span> — Causality, ordering, and why clocks are tricky.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Gossip & Epidemic Dissemination: Fast, Probabilistic, and Weird]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-07-gossip-epidemic-dissemination-fast-probabilistic-and-weird</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-07-gossip-epidemic-dissemination-fast-probabilistic-and-weird"/>
        <updated>2017-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (July 2017): Gossip & Epidemic Dissemination: Fast, Probabilistic, and Weird.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Gossip &#x26; Epidemic Dissemination: Fast, Probabilistic, and Weird</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Backpressure and admission control are correctness mechanisms under load.</li>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Tail latency is a protocol input: it changes who retries and when.</li>
<li>Safety failures are permanent; liveness failures are (sometimes) recoverable.</li>
<li>Global systems fail in correlated ways (regions, dependencies, routing).</li>
<li>Observability must explain protocol state, not just latency.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>What is the compaction story (snapshots, log truncation, state transfer)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Clients retry and amplify load right when the system is weakest.</li>
<li>Packets can be duplicated and reordered; acks can be lost.</li>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Delays are unbounded during incidents; timeouts are guesses.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Assuming the network eventually behaves “nicely” under load.</li>
<li>Pretending backpressure is an implementation detail.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common safety shape for replicated logs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>i</mi><mo>:</mo><mtext> Committed</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>:</mo><mtext> </mtext><msub><mtext>Log</mtext><mi>r</mi></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mo>=</mo><msub><mtext>Log</mtext><mtext>leader</mtext></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall i:\ \text{Committed}(i)\Rightarrow \forall r:\ \text{Log}_r[i] = \text{Log}_\text{leader}[i].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">leader</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<p>Liveness is always conditional: specify <em>when</em> progress is expected and what you do otherwise.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">stateDiagram-v2</span>
  <span class="token text string">[*]</span> <span class="token arrow operator">--></span> Follower
  Follower <span class="token arrow operator">--></span> Candidate<span class="token operator">:</span> timeout
  Candidate <span class="token arrow operator">--></span> Leader<span class="token operator">:</span> win quorum
  Candidate <span class="token arrow operator">--></span> Follower<span class="token operator">:</span> lose
  Leader <span class="token arrow operator">--></span> Follower<span class="token operator">:</span> stepdown</code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Protocols fail at the boundaries: timeouts, membership, compaction, and overload.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Deterministic replay</strong> of network traces to reproduce rare failures.</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Testing correctness under partitions and faults.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> <span class="citation" id="citation--lamport1978--2">(<a href="#bib-lamport1978">2</a>)</span> — Causality, ordering, and why clocks are tricky.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Transactions: 2PC, 3PC, and Coordinators You Can't Trust]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-06-transactions-2pc-3pc-and-coordinators-you-cant-trust</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-06-transactions-2pc-3pc-and-coordinators-you-cant-trust"/>
        <updated>2017-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (June 2017): Transactions: 2PC, 3PC, and Coordinators You Can't Trust.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Transactions: 2PC, 3PC, and Coordinators You Can't Trust</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Backpressure and admission control are correctness mechanisms under load.</li>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Operational simplicity is a security property: fewer modes, fewer surprises.</li>
<li>If your protocol isn’t testable under reordering, it isn’t deployable.</li>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
<li>Observability must explain protocol state, not just latency.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
<li>What does “read” mean under replication lag?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>Which components require determinism for reproducibility?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Delays are unbounded during incidents; timeouts are guesses.</li>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Workload is skewed: hot keys exist and dominate.</li>
<li>Packets can be duplicated and reordered; acks can be lost.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Assuming the network eventually behaves “nicely” under load.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common safety shape for replicated logs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>i</mi><mo>:</mo><mtext> Committed</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>:</mo><mtext> </mtext><msub><mtext>Log</mtext><mi>r</mi></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mo>=</mo><msub><mtext>Log</mtext><mtext>leader</mtext></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall i:\ \text{Committed}(i)\Rightarrow \forall r:\ \text{Log}_r[i] = \text{Log}_\text{leader}[i].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">leader</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<p>Liveness is always conditional: specify <em>when</em> progress is expected and what you do otherwise.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  client<span class="token text string">["Client"]</span> <span class="token arrow operator">--></span> leader<span class="token text string">["Leader"]</span>
  leader <span class="token arrow operator">--></span> log<span class="token text string">["Replicated Log"]</span>
  log <span class="token arrow operator">--></span> snap<span class="token text string">["Snapshot"]</span>
  snap <span class="token arrow operator">--></span> recover<span class="token text string">["Recovery / Catch-up"]</span>
  leader <span class="token arrow operator">--></span> reconfig<span class="token text string">["Reconfiguration"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make the state machine explicit; then make persistence and networking boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> <span class="citation" id="citation--ongaro2014raft--2">(<a href="#bib-ongaro2014raft">2</a>)</span> — Consensus with explicit state machines and practical tradeoffs.
<ul>
<li><strong>Evidence:</strong> Track term/commitIndex as explicit evidence; test leader changes and log conflicts as part of rollback behavior.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-ongaro2014raft">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Ongaro D, Ousterhout J. In Search of an Understandable Consensus Algorithm (Raft). In: 2014 USENIX Annual Technical Conference (USENIX ATC 14) [Internet]. 2014. Available from: https://raft.github.io/raft.pdf</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Consistency Models: Linearizability, Serializability, and What You Actually Need]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-05-consistency-models-linearizability-serializability-and-what-</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-05-consistency-models-linearizability-serializability-and-what-"/>
        <updated>2017-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (May 2017): Consistency Models: Linearizability, Serializability, and What You Actually Need.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Consistency Models: Linearizability, Serializability, and What You Actually Need</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Backpressure and admission control are correctness mechanisms under load.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Observability must explain protocol state, not just latency.</li>
<li>Tail latency is a protocol input: it changes who retries and when.</li>
<li>Backpressure and fairness are part of correctness when resources are finite.</li>
<li>Global systems fail in correlated ways (regions, dependencies, routing).</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
<li>What is the unit of ordering (per key, per partition, global)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Clocks drift; leases can be violated under GC pauses or VM stalls.</li>
<li>Reconfigurations happen mid-incident (the worst time).</li>
<li>Partitions happen at multiple layers (network, DNS, LB, service mesh).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Assuming the network eventually behaves “nicely” under load.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common safety shape for replicated logs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>i</mi><mo>:</mo><mtext> Committed</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>:</mo><mtext> </mtext><msub><mtext>Log</mtext><mi>r</mi></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mo>=</mo><msub><mtext>Log</mtext><mtext>leader</mtext></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall i:\ \text{Committed}(i)\Rightarrow \forall r:\ \text{Log}_r[i] = \text{Log}_\text{leader}[i].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">leader</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> L as Leader
  <span class="token keyword">participant</span> F1 as Follower 1
  <span class="token keyword">participant</span> F2 as Follower 2
  C<span class="token arrow operator">->></span>L<span class="token operator">:</span> propose<span class="token text string">(cmd)</span>
  L<span class="token arrow operator">->></span>F1<span class="token operator">:</span> appendEntries
  L<span class="token arrow operator">->></span>F2<span class="token operator">:</span> appendEntries
  F1<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  F2<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  L<span class="token arrow operator">-->></span>C<span class="token operator">:</span> commit<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Your protocol is an interface between failures and invariants. Encode both.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">type</span> <span class="token type-definition class-name">LogIndex</span> <span class="token operator">=</span> <span class="token keyword">u64</span><span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">struct</span> <span class="token type-definition class-name">Entry</span> <span class="token punctuation">{</span>
  index<span class="token punctuation">:</span> <span class="token class-name">LogIndex</span><span class="token punctuation">,</span>
  term<span class="token punctuation">:</span> <span class="token keyword">u64</span><span class="token punctuation">,</span>
  bytes<span class="token punctuation">:</span> <span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token comment">// Persist(term, vote, log) before acknowledging anything.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Deterministic replay</strong> of network traces to reproduce rare failures.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--1">(<a href="#bib-beyer2016sre">1</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Membership & Reconfiguration: Changing the Set Without Breaking Safety]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-04-membership-reconfiguration-changing-the-set-without-breaking</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-04-membership-reconfiguration-changing-the-set-without-breaking"/>
        <updated>2017-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (April 2017): Membership & Reconfiguration: Changing the Set Without Breaking Safety.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Membership &#x26; Reconfiguration: Changing the Set Without Breaking Safety</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Write the safety property first; liveness is always conditional on timing assumptions.</li>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Safety failures are permanent; liveness failures are (sometimes) recoverable.</li>
<li>Most protocol bugs hide in timeouts, retries, and membership changes.</li>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
<li>Observability must explain protocol state, not just latency.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>What does “read” mean under replication lag?</li>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>Which components require determinism for reproducibility?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Packets can be duplicated and reordered; acks can be lost.</li>
<li>Clients retry and amplify load right when the system is weakest.</li>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Workload is skewed: hot keys exist and dominate.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Relying on global time for ordering without strong synchronization assumptions.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common safety shape for replicated logs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>i</mi><mo>:</mo><mtext> Committed</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>:</mo><mtext> </mtext><msub><mtext>Log</mtext><mi>r</mi></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mo>=</mo><msub><mtext>Log</mtext><mtext>leader</mtext></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall i:\ \text{Committed}(i)\Rightarrow \forall r:\ \text{Log}_r[i] = \text{Log}_\text{leader}[i].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">leader</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<p>Make overload explicit: admission control is a protocol boundary.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  client<span class="token text string">["Client"]</span> <span class="token arrow operator">--></span> leader<span class="token text string">["Leader"]</span>
  leader <span class="token arrow operator">--></span> log<span class="token text string">["Replicated Log"]</span>
  log <span class="token arrow operator">--></span> snap<span class="token text string">["Snapshot"]</span>
  snap <span class="token arrow operator">--></span> recover<span class="token text string">["Recovery / Catch-up"]</span>
  leader <span class="token arrow operator">--></span> reconfig<span class="token text string">["Reconfiguration"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Your protocol is an interface between failures and invariants. Encode both.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">type</span> <span class="token type-definition class-name">LogIndex</span> <span class="token operator">=</span> <span class="token keyword">u64</span><span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">struct</span> <span class="token type-definition class-name">Entry</span> <span class="token punctuation">{</span>
  index<span class="token punctuation">:</span> <span class="token class-name">LogIndex</span><span class="token punctuation">,</span>
  term<span class="token punctuation">:</span> <span class="token keyword">u64</span><span class="token punctuation">,</span>
  bytes<span class="token punctuation">:</span> <span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token comment">// Persist(term, vote, log) before acknowledging anything.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> <span class="citation" id="citation--ongaro2014raft--1">(<a href="#bib-ongaro2014raft">1</a>)</span> — Consensus with explicit state machines and practical tradeoffs.
<ul>
<li><strong>Evidence:</strong> Track term/commitIndex as explicit evidence; test leader changes and log conflicts as part of rollback behavior.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Testing correctness under partitions and faults.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-ongaro2014raft">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Ongaro D, Ousterhout J. In Search of an Understandable Consensus Algorithm (Raft). In: 2014 USENIX Annual Technical Conference (USENIX ATC 14) [Internet]. 2014. Available from: https://raft.github.io/raft.pdf</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[BFT from First Principles: Safety, Liveness, and Quorums]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-03-bft-from-first-principles-safety-liveness-and-quorums</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-03-bft-from-first-principles-safety-liveness-and-quorums"/>
        <updated>2017-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (March 2017): BFT from First Principles: Safety, Liveness, and Quorums.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>BFT from First Principles: Safety, Liveness, and Quorums</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Make boundaries boring: validate inputs, cap costs, and be deterministic where needed.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>State compaction and snapshots are where correctness goes to die quietly.</li>
<li>Most protocol bugs hide in timeouts, retries, and membership changes.</li>
<li>If your protocol isn’t testable under reordering, it isn’t deployable.</li>
<li>Observability must explain protocol state, not just latency.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which components require determinism for reproducibility?</li>
<li>What is the unit of ordering (per key, per partition, global)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
<li>What is the compaction story (snapshots, log truncation, state transfer)?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>What is the failure model (crash, byzantine, partitions, reordering)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Workload is skewed: hot keys exist and dominate.</li>
<li>Reconfigurations happen mid-incident (the worst time).</li>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Partitions happen at multiple layers (network, DNS, LB, service mesh).</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on global time for ordering without strong synchronization assumptions.</li>
<li>Pretending backpressure is an implementation detail.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For quorum-based protocols, the intersection property is the backbone of safety:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>Crash-fault: </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>></mo><mfrac><mi>n</mi><mn>2</mn></mfrac><mspace width="2em"></mspace><mspace width="2em"></mspace><mtext>Byzantine: </mtext><mi>n</mi><mo>≥</mo><mn>3</mn><mi>f</mi><mo>+</mo><mn>1</mn><mo separator="true">,</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>≥</mo><mn>2</mn><mi>f</mi><mo>+</mo><mn>1.</mn></mrow><annotation encoding="application/x-tex">\text{Crash-fault: } |Q| > \frac{n}{2}\qquad\qquad
\text{Byzantine: } n \ge 3f+1,\ |Q| \ge 2f+1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Crash-fault: </span></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.7936em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.1076em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">2</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">Byzantine: </span></span><span class="mord mathnormal">n</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">3</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.</span></span></span></span></span></div>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<p>Make overload explicit: admission control is a protocol boundary.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  client<span class="token text string">["Client"]</span> <span class="token arrow operator">--></span> leader<span class="token text string">["Leader"]</span>
  leader <span class="token arrow operator">--></span> log<span class="token text string">["Replicated Log"]</span>
  log <span class="token arrow operator">--></span> snap<span class="token text string">["Snapshot"]</span>
  snap <span class="token arrow operator">--></span> recover<span class="token text string">["Recovery / Catch-up"]</span>
  leader <span class="token arrow operator">--></span> reconfig<span class="token text string">["Reconfiguration"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Make the state machine explicit; then make persistence and networking boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Testing correctness under partitions and faults.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Consensus Under Partial Synchrony: From Paxos to Raft]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-02-consensus-under-partial-synchrony-from-paxos-to-raft</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-02-consensus-under-partial-synchrony-from-paxos-to-raft"/>
        <updated>2017-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (February 2017): Consensus Under Partial Synchrony: From Paxos to Raft.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Consensus Under Partial Synchrony: From Paxos to Raft</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Mixed-version operation is the default; upgrades must preserve invariants.</li>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most protocol bugs hide in timeouts, retries, and membership changes.</li>
<li>If your protocol isn’t testable under reordering, it isn’t deployable.</li>
<li>Global systems fail in correlated ways (regions, dependencies, routing).</li>
<li>Safety failures are permanent; liveness failures are (sometimes) recoverable.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which components require determinism for reproducibility?</li>
<li>What is the unit of ordering (per key, per partition, global)?</li>
<li>Which safety property is non-negotiable (no double-commit, no forks, no split brain)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>How do you prevent overload from becoming inconsistency?</li>
<li>What is the compaction story (snapshots, log truncation, state transfer)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Clients retry and amplify load right when the system is weakest.</li>
<li>Reconfigurations happen mid-incident (the worst time).</li>
<li>Workload is skewed: hot keys exist and dominate.</li>
<li>Packets can be duplicated and reordered; acks can be lost.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating membership as static or human-managed only.</li>
<li>Assuming the network eventually behaves “nicely” under load.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For quorum-based protocols, the intersection property is the backbone of safety:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mtext>Crash-fault: </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>></mo><mfrac><mi>n</mi><mn>2</mn></mfrac><mspace width="2em"></mspace><mspace width="2em"></mspace><mtext>Byzantine: </mtext><mi>n</mi><mo>≥</mo><mn>3</mn><mi>f</mi><mo>+</mo><mn>1</mn><mo separator="true">,</mo><mtext> </mtext><mi mathvariant="normal">∣</mi><mi>Q</mi><mi mathvariant="normal">∣</mi><mo>≥</mo><mn>2</mn><mi>f</mi><mo>+</mo><mn>1.</mn></mrow><annotation encoding="application/x-tex">\text{Crash-fault: } |Q| > \frac{n}{2}\qquad\qquad
\text{Byzantine: } n \ge 3f+1,\ |Q| \ge 2f+1.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Crash-fault: </span></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1.7936em;vertical-align:-0.686em;"></span><span class="mord"><span class="mopen nulldelimiter"></span><span class="mfrac"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:1.1076em;"><span style="top:-2.314em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord">2</span></span></span><span style="top:-3.23em;"><span class="pstrut" style="height:3em;"></span><span class="frac-line" style="border-bottom-width:0.04em;"></span></span><span style="top:-3.677em;"><span class="pstrut" style="height:3em;"></span><span class="mord"><span class="mord mathnormal">n</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.686em;"><span></span></span></span></span></span><span class="mclose nulldelimiter"></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">Byzantine: </span></span><span class="mord mathnormal">n</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">3</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">1</span><span class="mpunct">,</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord">∣</span><span class="mord mathnormal">Q</span><span class="mord">∣</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">≥</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">2</span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">+</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.6444em;"></span><span class="mord">1.</span></span></span></span></span></div>
<p>Liveness is always conditional: specify <em>when</em> progress is expected and what you do otherwise.</p>
<p>Write down the safety property first. If it’s not written, it’s not implemented.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> L as Leader
  <span class="token keyword">participant</span> F1 as Follower 1
  <span class="token keyword">participant</span> F2 as Follower 2
  C<span class="token arrow operator">->></span>L<span class="token operator">:</span> propose<span class="token text string">(cmd)</span>
  L<span class="token arrow operator">->></span>F1<span class="token operator">:</span> appendEntries
  L<span class="token arrow operator">->></span>F2<span class="token operator">:</span> appendEntries
  F1<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  F2<span class="token arrow operator">-->></span>L<span class="token operator">:</span> ack
  L<span class="token arrow operator">-->></span>C<span class="token operator">:</span> commit<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Your protocol is an interface between failures and invariants. Encode both.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
<li><strong>Linearizability checks</strong> for read/write APIs that claim it.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
<li>Prefer monotonic time sources for leases; alert on clock discontinuities.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Testing correctness under partitions and faults.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — Practical entry point for specification and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Where does your protocol assume synchrony without admitting it?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[State Machine Replication: Log Design, Snapshots, and Compaction]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2017-01-state-machine-replication-log-design-snapshots-and-compactio</id>
        <link href="https://mayckongiovani.xyz/pensieve/2017-01-state-machine-replication-log-design-snapshots-and-compactio"/>
        <updated>2017-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (January 2017): State Machine Replication: Log Design, Snapshots, and Compaction.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Distributed Systems Under Failure</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>State Machine Replication: Log Design, Snapshots, and Compaction</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Expose protocol state (epoch/term/commit index) as first-class telemetry.</li>
<li>Treat membership changes and compaction as protocol events—not operational details.</li>
<li>Backpressure and admission control are correctness mechanisms under load.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Bind security decisions to evidence (audit, invariants, telemetry).</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Safety failures are permanent; liveness failures are (sometimes) recoverable.</li>
<li>Global systems fail in correlated ways (regions, dependencies, routing).</li>
<li>If your protocol isn’t testable under reordering, it isn’t deployable.</li>
<li>Observability must explain protocol state, not just latency.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does “read” mean under replication lag?</li>
<li>What is the unit of ordering (per key, per partition, global)?</li>
<li>What is your reconfiguration model (joint consensus, epochs, leases)?</li>
<li>How do clients discover leaders safely (and what happens during flaps)?</li>
<li>Where do you pay for liveness (timeouts, leader election, reconfiguration)?</li>
<li>How do you prevent overload from becoming inconsistency?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Workload is skewed: hot keys exist and dominate.</li>
<li>Nodes restart with partial state unless you prove durability.</li>
<li>Clients retry and amplify load right when the system is weakest.</li>
<li>Packets can be duplicated and reordered; acks can be lost.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Pretending backpressure is an implementation detail.</li>
<li>Assuming the network eventually behaves “nicely” under load.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common safety shape for replicated logs:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi mathvariant="normal">∀</mi><mi>i</mi><mo>:</mo><mtext> Committed</mtext><mo stretchy="false">(</mo><mi>i</mi><mo stretchy="false">)</mo><mo>⇒</mo><mi mathvariant="normal">∀</mi><mi>r</mi><mo>:</mo><mtext> </mtext><msub><mtext>Log</mtext><mi>r</mi></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mo>=</mo><msub><mtext>Log</mtext><mtext>leader</mtext></msub><mo stretchy="false">[</mo><mi>i</mi><mo stretchy="false">]</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\forall i:\ \text{Committed}(i)\Rightarrow \forall r:\ \text{Log}_r[i] = \text{Log}_\text{leader}[i].</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal">i</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord text"><span class="mord">Committed</span></span><span class="mopen">(</span><span class="mord mathnormal">i</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord">∀</span><span class="mord mathnormal" style="margin-right:0.02778em;">r</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">:</span><span class="mspace"> </span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.0573em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight" style="margin-right:0.02778em;">r</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord text"><span class="mord">Log</span></span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.242em;"><span style="top:-2.4559em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">leader</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2441em;"><span></span></span></span></span></span></span><span class="mopen">[</span><span class="mord mathnormal">i</span><span class="mclose">]</span><span class="mord">.</span></span></span></span></span></div>
<p>Liveness is always conditional: specify <em>when</em> progress is expected and what you do otherwise.</p>
<p>Treat membership changes as protocol events, not control-plane side effects.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  client<span class="token text string">["Client"]</span> <span class="token arrow operator">--></span> leader<span class="token text string">["Leader"]</span>
  leader <span class="token arrow operator">--></span> log<span class="token text string">["Replicated Log"]</span>
  log <span class="token arrow operator">--></span> snap<span class="token text string">["Snapshot"]</span>
  snap <span class="token arrow operator">--></span> recover<span class="token text string">["Recovery / Catch-up"]</span>
  leader <span class="token arrow operator">--></span> reconfig<span class="token text string">["Reconfiguration"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Your protocol is an interface between failures and invariants. Encode both.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>If you can’t explain a timeout outcome, you can’t make retries safe.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Operational invariants to monitor:
- leader_changes_per_minute
- commit_index_monotonic
- snapshot_install_failures
- quorum_acks_latency_p99
- rejected_requests_due_to_admission_control</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Jepsen-style</strong> fault injection: partitions + reordering + client retries.</li>
<li><strong>Upgrade tests</strong>: mixed versions and rolling deploy invariants.</li>
<li><strong>Deterministic replay</strong> of network traces to reproduce rare failures.</li>
<li><strong>Model checking</strong> the smallest core (timeouts, election, reconfiguration).</li>
<li><strong>Stress + skew</strong> tests: hot keys, slow disks, noisy neighbors.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Expose protocol state: term/epoch, leader, commit index, config version.</li>
<li>Make client behavior part of the system: document retry semantics.</li>
<li>Treat compaction and snapshot install as first-class SLOs.</li>
<li>Rehearse region failover and reconfiguration under load.</li>
<li>Rate-limit retries and apply admission control before saturation.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> <span class="citation" id="citation--lamport1978--1">(<a href="#bib-lamport1978">1</a>)</span> — Causality, ordering, and why clocks are tricky.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Testing correctness under partitions and faults.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which invariants are violated first under overload: latency, availability, or correctness?</li>
<li>What is the worst-case recovery time after a leader + disk failure?</li>
<li>How do you prevent “operator fixes” from changing safety properties?</li>
<li>Where does your protocol assume synchrony without admitting it?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Testing correctness under partitions and faults.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport)</a> — Causality, ordering, and why clocks are tricky.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — Agreement basics and the invariants that matter.</li>
<li><a href="https://raft.github.io/raft.pdf" target="_blank" rel="nofollow noopener noreferrer">In Search of an Understandable Consensus Algorithm (Raft)</a> — Consensus with explicit state machines and practical tradeoffs.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — Practical entry point for specification and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="distributed-systems"/>
        <category label="protocol-design"/>
        <category label="resilience"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Security vs Reliability: When the Same Bug Has Two Names]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-12-security-vs-reliability-when-the-same-bug-has-two-names</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-12-security-vs-reliability-when-the-same-bug-has-two-names"/>
        <updated>2016-12-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (December 2016): Security vs Reliability: When the Same Bug Has Two Names.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Security vs Reliability: When the Same Bug Has Two Names</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Make retries semantic: idempotency keys, monotonic versions, and explicit ambiguity.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Correctness is a property you enforce at boundaries: parsing, persistence, concurrency, RPC.</li>
<li>The cost of unclear invariants is paid in production, under load, during an incident.</li>
<li>Correctness bugs are indistinguishable from security incidents when the system is adversarial.</li>
<li>Most outages are “state management” failures: partial writes, ambiguous outcomes, invalid transitions.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>What is your ordering model: FIFO per key, per partition, or none at all?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>How do you ensure deduplication is scoped correctly (tenant, resource, operation)?</li>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Deployments are mixed-version for longer than you think.</li>
<li>Requests can be duplicated, reordered, delayed, and replayed across restarts.</li>
<li>Partial failure is normal: one replica slow, one unavailable, one returning stale data.</li>
<li>Input is hostile: malformed, oversized, boundary values, protocol confusion.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Baking invariants into tribal knowledge instead of code.</li>
<li>Letting recovery be “restart the service and hope.”</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>We want a transition function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>δ</mi></mrow><annotation encoding="application/x-tex">\delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span></span></span></span></span> and invariant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><annotation encoding="application/x-tex">\mathrm{Inv}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>δ</mi><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo separator="true">,</mo><msub><mi>e</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mspace width="2em"></mspace><mo>∧</mo><mspace width="2em"></mspace><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s_{t+1} = \delta(s_t, e_t)\qquad\wedge\qquad \mathrm{Inv}(s_t)\Rightarrow \mathrm{Inv}(s_{t+1}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6389em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">e</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>If you can’t define what a timeout means, you can’t implement retries safely. Make ambiguity explicit in the API.</p>
<p>Crash points matter: define what happens if the process stops after each line that mutates state or acknowledges work.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The goal isn’t cleverness—it’s eliminating ambiguity at boundaries and making recovery boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Idempotency sketch: reserve -> execute -> commit result (or return cached).</span>
<span class="token keyword">type</span> Key <span class="token builtin">string</span>

<span class="token keyword">type</span> Store <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Get</span><span class="token punctuation">(</span>key Key<span class="token punctuation">)</span> <span class="token punctuation">(</span>value <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> ok <span class="token builtin">bool</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
  <span class="token function">PutIfAbsent</span><span class="token punctuation">(</span>key Key<span class="token punctuation">,</span> value <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>stored <span class="token builtin">bool</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span>

<span class="token comment">// Security vs Reliability: When the Same Bug Has Two Names: "timeout" must not mean "try again and maybe double-apply".</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Fault injection</strong>: latency, partial writes, dropped acks, and duplicated messages.</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
<li>Track invariant violations as pages, not dashboards.</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--1">(<a href="#bib-learntla">1</a>)</span> — A pragmatic workflow for invariants and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--2">(<a href="#bib-kleppmann2017ddia">2</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>What is the minimal durable record needed to recover safely?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Reproducible Builds: Trusting Artifacts in a Hostile World]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-11-reproducible-builds-trusting-artifacts-in-a-hostile-world</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-11-reproducible-builds-trusting-artifacts-in-a-hostile-world"/>
        <updated>2016-11-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (November 2016): Reproducible Builds: Trusting Artifacts in a Hostile World.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Reproducible Builds: Trusting Artifacts in a Hostile World</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make retries semantic: idempotency keys, monotonic versions, and explicit ambiguity.</li>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Define safety properties before performance goals.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Interfaces that allow invalid state guarantee someone will eventually produce it.</li>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>A system without explicit contracts becomes a collection of folklore and dashboards.</li>
<li>“Works in tests” often means “fails under reordering and retries.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>What must be durable before you acknowledge?</li>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>How do you ensure deduplication is scoped correctly (tenant, resource, operation)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Clients retry with backoff but not with perfect discipline (bursts happen).</li>
<li>Deployments are mixed-version for longer than you think.</li>
<li>Errors are lossy: transient vs permanent is often indistinguishable at the boundary.</li>
<li>Observability is incomplete: you will debug from partial evidence.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Letting recovery be “restart the service and hope.”</li>
<li>Perfect exactly-once semantics across an untrusted network without coordination.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For idempotent operations, the contract is <em>set-like</em>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><mi>k</mi><mo stretchy="false">)</mo><mo>=</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><mi>k</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mtext>and</mtext><mspace width="1em"></mspace><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><msub><mi>k</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo mathvariant="normal">≠</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><msub><mi>k</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mtext> in general</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{apply}(s, op, k) = \mathrm{apply}(s, op, k) \quad\text{and}\quad
\mathrm{apply}(s, op, k_1) \neq \mathrm{apply}(s, op, k_2)\ \text{in general}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0315em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mrel"><span class="mord vbox"><span class="thinbox"><span class="rlap"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="inner"><span class="mord"><span class="mrel"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace nobreak"></span><span class="mrel">=</span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0315em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord text"><span class="mord">in general</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Treat invariants as a first-class interface: a function that cannot check its invariants cannot be safely composed. Start with the smallest invariant that is both meaningful and enforceable at your boundaries.</p>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Correctness lives in the seams: encoding, persistence, concurrency, and retries.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">use</span> <span class="token namespace">core<span class="token punctuation">::</span></span>fmt<span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Event</span> <span class="token punctuation">{</span>
    <span class="token class-name">Input</span><span class="token punctuation">(</span><span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">)</span><span class="token punctuation">,</span>
    <span class="token class-name">Tick</span><span class="token punctuation">,</span>
    <span class="token class-name">Fault</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token lifetime-annotation symbol">'static</span> <span class="token keyword">str</span><span class="token punctuation">)</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">StateMachine</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">State</span><span class="token punctuation">:</span> <span class="token class-name">Clone</span> <span class="token operator">+</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Error</span><span class="token punctuation">:</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">step</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> event<span class="token punctuation">:</span> <span class="token class-name">Event</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Error</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">invariant</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Reproducible Builds: Trusting Artifacts in a Hostile World: invariants are part of the API contract.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
<li><strong>Differential tests</strong> against a reference model (even a slow one).</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
<li>Make rollbacks safe: schema and protocol compatibility is a security boundary.</li>
<li>Track invariant violations as pages, not dashboards.</li>
<li>Validate time assumptions: alert on clock steps, skew, and monotonicity issues.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--2">(<a href="#bib-rfc9110">2</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What would you do if you had to replay a month of traffic into a rebuilt system?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Observability as Specification: SLOs, Error Budgets, and Contracts]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-10-observability-as-specification-slos-error-budgets-and-contra</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-10-observability-as-specification-slos-error-budgets-and-contra"/>
        <updated>2016-10-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (October 2016): Observability as Specification: SLOs, Error Budgets, and Contracts.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Observability as Specification: SLOs, Error Budgets, and Contracts</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make retries semantic: idempotency keys, monotonic versions, and explicit ambiguity.</li>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
<li>Make failure modes explicit and observable.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Your on-call runbook is part of the specification—make it match the code.</li>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>In distributed code, retries and duplication are the common case—not the edge case.</li>
<li>A system without explicit contracts becomes a collection of folklore and dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Requests can be duplicated, reordered, delayed, and replayed across restarts.</li>
<li>Observability is incomplete: you will debug from partial evidence.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
<li>Time is untrusted: clock skew, NTP steps, monotonic vs wall-clock confusion.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Letting recovery be “restart the service and hope.”</li>
<li>Assuming a single authoritative clock that never moves backwards.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common pattern is splitting state into durable vs derived:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>S</mi><mo>=</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo>×</mo><msub><mi>S</mi><mtext>derived</mtext></msub><mspace width="2em"></mspace><mtext>and</mtext><mspace width="2em"></mspace><msub><mi>S</mi><mtext>derived</mtext></msub><mo>=</mo><mi>f</mi><mo stretchy="false">(</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">S = S_\text{durable} \times S_\text{derived}\qquad\text{and}\qquad S_\text{derived} = f(S_\text{durable}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Prefer <em>monotonic</em> identifiers at boundaries (sequence numbers, epochs, version vectors) so that replays are detectable and order can be reasoned about.</p>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The goal isn’t cleverness—it’s eliminating ambiguity at boundaries and making recovery boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">use</span> <span class="token namespace">core<span class="token punctuation">::</span></span>fmt<span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Event</span> <span class="token punctuation">{</span>
    <span class="token class-name">Input</span><span class="token punctuation">(</span><span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">)</span><span class="token punctuation">,</span>
    <span class="token class-name">Tick</span><span class="token punctuation">,</span>
    <span class="token class-name">Fault</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token lifetime-annotation symbol">'static</span> <span class="token keyword">str</span><span class="token punctuation">)</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">StateMachine</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">State</span><span class="token punctuation">:</span> <span class="token class-name">Clone</span> <span class="token operator">+</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Error</span><span class="token punctuation">:</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">step</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> event<span class="token punctuation">:</span> <span class="token class-name">Event</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Error</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">invariant</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Observability as Specification: SLOs, Error Budgets, and Contracts: invariants are part of the API contract.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Differential tests</strong> against a reference model (even a slow one).</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
<li><strong>Fault injection</strong>: latency, partial writes, dropped acks, and duplicated messages.</li>
<li><strong>Crash/restart tests</strong>: persist mid-transition and validate recovery correctness.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
<li>Track invariant violations as pages, not dashboards.</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--1">(<a href="#bib-rfc9110">1</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — A pragmatic workflow for invariants and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the minimal durable record needed to recover safely?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
<li>What would you do if you had to replay a month of traffic into a rebuilt system?</li>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Fault Injection: Turning Unknown Unknowns into Test Cases]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-09-fault-injection-turning-unknown-unknowns-into-test-cases</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-09-fault-injection-turning-unknown-unknowns-into-test-cases"/>
        <updated>2016-09-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Spec-driven research note (September 2016): Fault Injection: Turning Unknown Unknowns into Test Cases.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Fault Injection: Turning Unknown Unknowns into Test Cases</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Separate durable state from derived state; derived must be recomputable or reconcilable.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Correctness is a property you enforce at boundaries: parsing, persistence, concurrency, RPC.</li>
<li>The cost of unclear invariants is paid in production, under load, during an incident.</li>
<li>If recovery is not specified, recovery becomes improvisation.</li>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>What is your ordering model: FIFO per key, per partition, or none at all?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>How do you ensure deduplication is scoped correctly (tenant, resource, operation)?</li>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Time is untrusted: clock skew, NTP steps, monotonic vs wall-clock confusion.</li>
<li>Deployments are mixed-version for longer than you think.</li>
<li>Errors are lossy: transient vs permanent is often indistinguishable at the boundary.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Treating retries as a transport detail rather than a semantic constraint.</li>
<li>Assuming a single authoritative clock that never moves backwards.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common pattern is splitting state into durable vs derived:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>S</mi><mo>=</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo>×</mo><msub><mi>S</mi><mtext>derived</mtext></msub><mspace width="2em"></mspace><mtext>and</mtext><mspace width="2em"></mspace><msub><mi>S</mi><mtext>derived</mtext></msub><mo>=</mo><mi>f</mi><mo stretchy="false">(</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">S = S_\text{durable} \times S_\text{derived}\qquad\text{and}\qquad S_\text{derived} = f(S_\text{durable}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Crash points matter: define what happens if the process stops after each line that mutates state or acknowledges work.</p>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">stateDiagram-v2</span>
  <span class="token text string">[*]</span> <span class="token arrow operator">--></span> Init
  Init <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> bootstrap<span class="token punctuation">(</span><span class="token punctuation">)</span>
  Ready <span class="token arrow operator">--></span> Processing<span class="token operator">:</span> event<span class="token text string">(e)</span>
  Processing <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> commit<span class="token punctuation">(</span><span class="token punctuation">)</span>
  Processing <span class="token arrow operator">--></span> Error<span class="token operator">:</span> violate<span class="token text string">(Inv)</span>
  Error <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> recover<span class="token punctuation">(</span><span class="token punctuation">)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The goal isn’t cleverness—it’s eliminating ambiguity at boundaries and making recovery boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">use</span> <span class="token namespace">core<span class="token punctuation">::</span></span>fmt<span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Event</span> <span class="token punctuation">{</span>
    <span class="token class-name">Input</span><span class="token punctuation">(</span><span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">)</span><span class="token punctuation">,</span>
    <span class="token class-name">Tick</span><span class="token punctuation">,</span>
    <span class="token class-name">Fault</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token lifetime-annotation symbol">'static</span> <span class="token keyword">str</span><span class="token punctuation">)</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">StateMachine</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">State</span><span class="token punctuation">:</span> <span class="token class-name">Clone</span> <span class="token operator">+</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Error</span><span class="token punctuation">:</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">step</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> event<span class="token punctuation">:</span> <span class="token class-name">Event</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Error</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">invariant</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Fault Injection: Turning Unknown Unknowns into Test Cases: invariants are part of the API contract.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Crash/restart tests</strong>: persist mid-transition and validate recovery correctness.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--1">(<a href="#bib-rfc9110">1</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Failure testing focused on correctness under partitions and reordering.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What would you do if you had to replay a month of traffic into a rebuilt system?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Memory Models and Concurrency: Reasoning About Races]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-08-memory-models-and-concurrency-reasoning-about-races</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-08-memory-models-and-concurrency-reasoning-about-races"/>
        <updated>2016-08-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (August 2016): Memory Models and Concurrency: Reasoning About Races.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Memory Models and Concurrency: Reasoning About Races</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Make retries semantic: idempotency keys, monotonic versions, and explicit ambiguity.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Most outages are “state management” failures: partial writes, ambiguous outcomes, invalid transitions.</li>
<li>Correctness bugs are indistinguishable from security incidents when the system is adversarial.</li>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>The cost of unclear invariants is paid in production, under load, during an incident.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>What must be durable before you acknowledge?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>What is your ordering model: FIFO per key, per partition, or none at all?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Deployments are mixed-version for longer than you think.</li>
<li>Input is hostile: malformed, oversized, boundary values, protocol confusion.</li>
<li>Observability is incomplete: you will debug from partial evidence.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Letting recovery be “restart the service and hope.”</li>
<li>Perfect exactly-once semantics across an untrusted network without coordination.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>We want a transition function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>δ</mi></mrow><annotation encoding="application/x-tex">\delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span></span></span></span></span> and invariant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><annotation encoding="application/x-tex">\mathrm{Inv}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>δ</mi><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo separator="true">,</mo><msub><mi>e</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mspace width="2em"></mspace><mo>∧</mo><mspace width="2em"></mspace><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s_{t+1} = \delta(s_t, e_t)\qquad\wedge\qquad \mathrm{Inv}(s_t)\Rightarrow \mathrm{Inv}(s_{t+1}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6389em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">e</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<p>If you can’t define what a timeout means, you can’t implement retries safely. Make ambiguity explicit in the API.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> API as API
  <span class="token keyword">participant</span> DB as Durable Store
  C<span class="token arrow operator">->></span>API<span class="token operator">:</span> request<span class="token text string">(op, idempotency_key)</span>
  API<span class="token arrow operator">->></span>DB<span class="token operator">:</span> check_or_reserve<span class="token text string">(key)</span>
  DB<span class="token arrow operator">-->></span>API<span class="token operator">:</span> miss | hit<span class="token text string">(result)</span>
  API<span class="token arrow operator">->></span>DB<span class="token operator">:</span> commit<span class="token text string">(result)</span>
  API<span class="token arrow operator">-->></span>C<span class="token operator">:</span> ack<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Correctness lives in the seams: encoding, persistence, concurrency, and retries.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Correctness checklist:
1) Define state (durable vs derived).
2) Enumerate transitions.
3) Write invariants (safety) and progress conditions (liveness).
4) Pick crash points and specify recovery.
5) Make retries part of semantics (idempotency keys, monotonic versions).</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Differential tests</strong> against a reference model (even a slow one).</li>
<li><strong>Fault injection</strong>: latency, partial writes, dropped acks, and duplicated messages.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Make rollbacks safe: schema and protocol compatibility is a security boundary.</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Validate time assumptions: alert on clock steps, skew, and monotonicity issues.</li>
<li>Track invariant violations as pages, not dashboards.</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> <span class="citation" id="citation--learntla--2">(<a href="#bib-learntla">2</a>)</span> — A pragmatic workflow for invariants and model checking.
<ul>
<li><strong>Evidence:</strong> Model the smallest thing that can break; use model checking to validate invariants before optimizing.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>What is the minimal durable record needed to recover safely?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-learntla">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">LearnTLA. Learn TLA+ [Internet]. Web; Available from: https://learntla.com/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Crash Consistency: Durable State Without Mysticism]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-07-crash-consistency-durable-state-without-mysticism</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-07-crash-consistency-durable-state-without-mysticism"/>
        <updated>2016-07-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Engineering notebook entry (July 2016): Crash Consistency: Durable State Without Mysticism.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Crash Consistency: Durable State Without Mysticism</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Most failures are boundary failures: parsing, persistence, concurrency, retries, and upgrades.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Separate durable state from derived state; derived must be recomputable or reconcilable.</li>
<li>Make retries semantic: idempotency keys, monotonic versions, and explicit ambiguity.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>The cost of unclear invariants is paid in production, under load, during an incident.</li>
<li>Performance work that changes semantics is a correctness regression with a nicer latency chart.</li>
<li>In distributed code, retries and duplication are the common case—not the edge case.</li>
<li>A system without explicit contracts becomes a collection of folklore and dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>Where do you need atomicity (and where is eventual consistency acceptable)?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>What is your ordering model: FIFO per key, per partition, or none at all?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Requests can be duplicated, reordered, delayed, and replayed across restarts.</li>
<li>Clients retry with backoff but not with perfect discipline (bursts happen).</li>
<li>Time is untrusted: clock skew, NTP steps, monotonic vs wall-clock confusion.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on “best effort” client behavior for safety properties.</li>
<li>Baking invariants into tribal knowledge instead of code.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>For idempotent operations, the contract is <em>set-like</em>:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><mi>k</mi><mo stretchy="false">)</mo><mo>=</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><mi>k</mi><mo stretchy="false">)</mo><mspace width="1em"></mspace><mtext>and</mtext><mspace width="1em"></mspace><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><msub><mi>k</mi><mn>1</mn></msub><mo stretchy="false">)</mo><mo mathvariant="normal">≠</mo><mrow><mi mathvariant="normal">a</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">p</mi><mi mathvariant="normal">l</mi><mi mathvariant="normal">y</mi></mrow><mo stretchy="false">(</mo><mi>s</mi><mo separator="true">,</mo><mi>o</mi><mi>p</mi><mo separator="true">,</mo><msub><mi>k</mi><mn>2</mn></msub><mo stretchy="false">)</mo><mtext> in general</mtext><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">\mathrm{apply}(s, op, k) = \mathrm{apply}(s, op, k) \quad\text{and}\quad
\mathrm{apply}(s, op, k_1) \neq \mathrm{apply}(s, op, k_2)\ \text{in general}.</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="mclose">)</span><span class="mspace" style="margin-right:1em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:1em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0315em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">1</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel"><span class="mrel"><span class="mord vbox"><span class="thinbox"><span class="rlap"><span class="strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="inner"><span class="mord"><span class="mrel"></span></span></span><span class="fix"></span></span></span></span></span><span class="mspace nobreak"></span><span class="mrel">=</span></span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">apply</span></span><span class="mopen">(</span><span class="mord mathnormal">s</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal">o</span><span class="mord mathnormal">p</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.03148em;">k</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:-0.0315em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight">2</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace"> </span><span class="mord text"><span class="mord">in general</span></span><span class="mord">.</span></span></span></span></span></div>
<p>Prefer <em>monotonic</em> identifiers at boundaries (sequence numbers, epochs, version vectors) so that replays are detectable and order can be reasoned about.</p>
<p>Crash points matter: define what happens if the process stops after each line that mutates state or acknowledges work.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Observability gaps during incidents (missing evidence).</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Implementation is the act of making invalid state unrepresentable (or at least unignorable).</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">use</span> <span class="token namespace">core<span class="token punctuation">::</span></span>fmt<span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Event</span> <span class="token punctuation">{</span>
    <span class="token class-name">Input</span><span class="token punctuation">(</span><span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">)</span><span class="token punctuation">,</span>
    <span class="token class-name">Tick</span><span class="token punctuation">,</span>
    <span class="token class-name">Fault</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token lifetime-annotation symbol">'static</span> <span class="token keyword">str</span><span class="token punctuation">)</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">StateMachine</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">State</span><span class="token punctuation">:</span> <span class="token class-name">Clone</span> <span class="token operator">+</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Error</span><span class="token punctuation">:</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">step</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> event<span class="token punctuation">:</span> <span class="token class-name">Event</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Error</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">invariant</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Crash Consistency: Durable State Without Mysticism: invariants are part of the API contract.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
<li><strong>Differential tests</strong> against a reference model (even a slow one).</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
<li>Make rollbacks safe: schema and protocol compatibility is a security boundary.</li>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Design playbooks as protocols: predictable steps, bounded risk, and clear ownership.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> <span class="citation" id="citation--lamport1978--1">(<a href="#bib-lamport1978">1</a>)</span> — The mental model for causality and ordering in distributed systems.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--2">(<a href="#bib-rfc9110">2</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
<li>What would you do if you had to replay a month of traffic into a rebuilt system?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Cryptographic Hygiene: Domain Separation, KDFs, and Context Binding]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-06-cryptographic-hygiene-domain-separation-kdfs-and-context-bin</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-06-cryptographic-hygiene-domain-separation-kdfs-and-context-bin"/>
        <updated>2016-06-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Threat-model-first analysis (June 2016): Cryptographic Hygiene: Domain Separation, KDFs, and Context Binding.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Cryptographic Hygiene: Domain Separation, KDFs, and Context Binding</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Separate durable state from derived state; derived must be recomputable or reconcilable.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Treat retries, reordering, and partial failure as default conditions.</li>
<li>Automate guardrails; humans are for judgment, not for consistent enforcement.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>Correctness bugs are indistinguishable from security incidents when the system is adversarial.</li>
<li>Correctness is a property you enforce at boundaries: parsing, persistence, concurrency, RPC.</li>
<li>A system without explicit contracts becomes a collection of folklore and dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>How do you ensure deduplication is scoped correctly (tenant, resource, operation)?</li>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>Where do you need atomicity (and where is eventual consistency acceptable)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Clients retry with backoff but not with perfect discipline (bursts happen).</li>
<li>Input is hostile: malformed, oversized, boundary values, protocol confusion.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
<li>Requests can be duplicated, reordered, delayed, and replayed across restarts.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Letting recovery be “restart the service and hope.”</li>
<li>Baking invariants into tribal knowledge instead of code.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Observability pipelines can be attacked (cardinality explosions, log injection). Protect them.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>We want a transition function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>δ</mi></mrow><annotation encoding="application/x-tex">\delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span></span></span></span></span> and invariant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><annotation encoding="application/x-tex">\mathrm{Inv}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>δ</mi><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo separator="true">,</mo><msub><mi>e</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mspace width="2em"></mspace><mo>∧</mo><mspace width="2em"></mspace><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s_{t+1} = \delta(s_t, e_t)\qquad\wedge\qquad \mathrm{Inv}(s_t)\Rightarrow \mathrm{Inv}(s_{t+1}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6389em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">e</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Treat invariants as a first-class interface: a function that cannot check its invariants cannot be safely composed. Start with the smallest invariant that is both meaningful and enforceable at your boundaries.</p>
<p>Prefer <em>monotonic</em> identifiers at boundaries (sequence numbers, epochs, version vectors) so that replays are detectable and order can be reasoned about.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Make the “impossible state” observable: a metric or alert that fires when invariants drift.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Config drift that weakens security posture over time.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>A recovery plan that isn’t exercised will fail when you need it.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Implementation is the act of making invalid state unrepresentable (or at least unignorable).</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Correctness checklist:
1) Define state (durable vs derived).
2) Enumerate transitions.
3) Write invariants (safety) and progress conditions (liveness).
4) Pick crash points and specify recovery.
5) Make retries part of semantics (idempotency keys, monotonic versions).</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Differential tests</strong> against a reference model (even a slow one).</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
<li><strong>Fault injection</strong>: latency, partial writes, dropped acks, and duplicated messages.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Validate time assumptions: alert on clock steps, skew, and monotonicity issues.</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Fault injection and correctness testing for distributed systems.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Fault injection and correctness testing for distributed systems.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Threat Modeling for Engineers: Assumptions as Interfaces]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-05-threat-modeling-for-engineers-assumptions-as-interfaces</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-05-threat-modeling-for-engineers-assumptions-as-interfaces"/>
        <updated>2016-05-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (May 2016): Threat Modeling for Engineers: Assumptions as Interfaces.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Threat Modeling for Engineers: Assumptions as Interfaces</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Measure correctness signals, not only latency/throughput.</li>
<li>Write assumptions down; treat them as interfaces.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>Correctness bugs are indistinguishable from security incidents when the system is adversarial.</li>
<li>Performance work that changes semantics is a correctness regression with a nicer latency chart.</li>
<li>Your on-call runbook is part of the specification—make it match the code.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where do you need atomicity (and where is eventual consistency acceptable)?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Input is hostile: malformed, oversized, boundary values, protocol confusion.</li>
<li>Observability is incomplete: you will debug from partial evidence.</li>
<li>Deployments are mixed-version for longer than you think.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on “best effort” client behavior for safety properties.</li>
<li>Letting recovery be “restart the service and hope.”</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common pattern is splitting state into durable vs derived:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>S</mi><mo>=</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo>×</mo><msub><mi>S</mi><mtext>derived</mtext></msub><mspace width="2em"></mspace><mtext>and</mtext><mspace width="2em"></mspace><msub><mi>S</mi><mtext>derived</mtext></msub><mo>=</mo><mi>f</mi><mo stretchy="false">(</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">S = S_\text{durable} \times S_\text{derived}\qquad\text{and}\qquad S_\text{derived} = f(S_\text{durable}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Prefer <em>monotonic</em> identifiers at boundaries (sequence numbers, epochs, version vectors) so that replays are detectable and order can be reasoned about.</p>
<p>Treat invariants as a first-class interface: a function that cannot check its invariants cannot be safely composed. Start with the smallest invariant that is both meaningful and enforceable at your boundaries.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Config drift that weakens security posture over time.</li>
<li>Recovery paths that only work when nothing is broken.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Implementation is the act of making invalid state unrepresentable (or at least unignorable).</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Idempotency sketch: reserve -> execute -> commit result (or return cached).</span>
<span class="token keyword">type</span> Key <span class="token builtin">string</span>

<span class="token keyword">type</span> Store <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Get</span><span class="token punctuation">(</span>key Key<span class="token punctuation">)</span> <span class="token punctuation">(</span>value <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> ok <span class="token builtin">bool</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
  <span class="token function">PutIfAbsent</span><span class="token punctuation">(</span>key Key<span class="token punctuation">,</span> value <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>stored <span class="token builtin">bool</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span>

<span class="token comment">// Threat Modeling for Engineers: Assumptions as Interfaces: "timeout" must not mean "try again and maybe double-apply".</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Fault injection</strong>: latency, partial writes, dropped acks, and duplicated messages.</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
<li><strong>Crash/restart tests</strong>: persist mid-transition and validate recovery correctness.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
<li>Make rollbacks safe: schema and protocol compatibility is a security boundary.</li>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Make degraded modes explicit: fail closed vs fail open is a policy choice.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--2">(<a href="#bib-rfc9110">2</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>What is the minimal durable record needed to recover safely?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Time Is a Lie: Clocks, Causality, and Ordering]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-04-time-is-a-lie-clocks-causality-and-ordering</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-04-time-is-a-lie-clocks-causality-and-ordering"/>
        <updated>2016-04-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Adversarial-first deep dive (April 2016): Time Is a Lie: Clocks, Causality, and Ordering.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Time Is a Lie: Clocks, Causality, and Ordering</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Write assumptions down; treat them as interfaces.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>Correctness is a property you enforce at boundaries: parsing, persistence, concurrency, RPC.</li>
<li>Performance work that changes semantics is a correctness regression with a nicer latency chart.</li>
<li>Your on-call runbook is part of the specification—make it match the code.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>What is your ordering model: FIFO per key, per partition, or none at all?</li>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Concurrency is adversarial: races appear only in production schedules.</li>
<li>Observability is incomplete: you will debug from partial evidence.</li>
<li>Deployments are mixed-version for longer than you think.</li>
<li>Partial failure is normal: one replica slow, one unavailable, one returning stale data.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on “best effort” client behavior for safety properties.</li>
<li>Treating retries as a transport detail rather than a semantic constraint.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common pattern is splitting state into durable vs derived:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>S</mi><mo>=</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo>×</mo><msub><mi>S</mi><mtext>derived</mtext></msub><mspace width="2em"></mspace><mtext>and</mtext><mspace width="2em"></mspace><msub><mi>S</mi><mtext>derived</mtext></msub><mo>=</mo><mi>f</mi><mo stretchy="false">(</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">S = S_\text{durable} \times S_\text{derived}\qquad\text{and}\qquad S_\text{derived} = f(S_\text{durable}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>If you can’t define what a timeout means, you can’t implement retries safely. Make ambiguity explicit in the API.</p>
<p>Crash points matter: define what happens if the process stops after each line that mutates state or acknowledges work.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>If the system can enter an invalid state, it eventually will—usually during an incident.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Mixed-version behavior that violates assumptions silently.</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Sampling hides the rare schedule that breaks your invariants.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">stateDiagram-v2</span>
  <span class="token text string">[*]</span> <span class="token arrow operator">--></span> Init
  Init <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> bootstrap<span class="token punctuation">(</span><span class="token punctuation">)</span>
  Ready <span class="token arrow operator">--></span> Processing<span class="token operator">:</span> event<span class="token text string">(e)</span>
  Processing <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> commit<span class="token punctuation">(</span><span class="token punctuation">)</span>
  Processing <span class="token arrow operator">--></span> Error<span class="token operator">:</span> violate<span class="token text string">(Inv)</span>
  Error <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> recover<span class="token punctuation">(</span><span class="token punctuation">)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Treat every boundary (RPC, DB, queue, cache) as a semantic interface with explicit contracts.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Acknowledge only after durability (or make “ack” explicitly best-effort).</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">use</span> <span class="token namespace">core<span class="token punctuation">::</span></span>fmt<span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Event</span> <span class="token punctuation">{</span>
    <span class="token class-name">Input</span><span class="token punctuation">(</span><span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">)</span><span class="token punctuation">,</span>
    <span class="token class-name">Tick</span><span class="token punctuation">,</span>
    <span class="token class-name">Fault</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token lifetime-annotation symbol">'static</span> <span class="token keyword">str</span><span class="token punctuation">)</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">StateMachine</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">State</span><span class="token punctuation">:</span> <span class="token class-name">Clone</span> <span class="token operator">+</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Error</span><span class="token punctuation">:</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">step</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> event<span class="token punctuation">:</span> <span class="token class-name">Event</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Error</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">invariant</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Time Is a Lie: Clocks, Causality, and Ordering: invariants are part of the API contract.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Crash/restart tests</strong>: persist mid-transition and validate recovery correctness.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Track invariant violations as pages, not dashboards.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Rollback events and the conditions that triggered them.</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> <span class="citation" id="citation--kleppmann2017ddia--1">(<a href="#bib-kleppmann2017ddia">1</a>)</span> — The systems-engineering baseline for correctness, replication, and failure.
<ul>
<li><strong>Evidence:</strong> Replication and consistency tradeoffs as engineering constraints; use as reference when naming guarantees.</li>
</ul>
</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--2">(<a href="#bib-jepsen">2</a>)</span> — Failure testing focused on correctness under partitions and reordering.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/paxos-simple.pdf" target="_blank" rel="nofollow noopener noreferrer">Paxos Made Simple (Lamport)</a> — A clean reference for agreement and invariants.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-kleppmann2017ddia">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Kleppmann M. Designing Data-Intensive Applications [Internet]. O’Reilly Media; 2017. Available from: https://dataintensive.net/</div>
  </div>
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Backpressure as a Correctness Property: Stability Under Load]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-03-backpressure-as-a-correctness-property-stability-under-load</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-03-backpressure-as-a-correctness-property-stability-under-load"/>
        <updated>2016-03-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (March 2016): Backpressure as a Correctness Property: Stability Under Load.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Backpressure as a Correctness Property: Stability Under Load</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Correctness is cheaper to enforce at interfaces than to repair in production data.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Make retries semantic: idempotency keys, monotonic versions, and explicit ambiguity.</li>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Design rollbacks as part of the happy path.</li>
<li>Define safety properties before performance goals.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>Your on-call runbook is part of the specification—make it match the code.</li>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>A system without explicit contracts becomes a collection of folklore and dashboards.</li>
<li>“Works in tests” often means “fails under reordering and retries.”</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>What must be durable before you acknowledge?</li>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>Where do you need atomicity (and where is eventual consistency acceptable)?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Partial failure is normal: one replica slow, one unavailable, one returning stale data.</li>
<li>Clients retry with backoff but not with perfect discipline (bursts happen).</li>
<li>Input is hostile: malformed, oversized, boundary values, protocol confusion.</li>
<li>Concurrency is adversarial: races appear only in production schedules.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Letting recovery be “restart the service and hope.”</li>
<li>Treating retries as a transport detail rather than a semantic constraint.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Any unbounded work per request becomes a DoS primitive under adversaries.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>We want a transition function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>δ</mi></mrow><annotation encoding="application/x-tex">\delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span></span></span></span></span> and invariant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><annotation encoding="application/x-tex">\mathrm{Inv}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>δ</mi><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo separator="true">,</mo><msub><mi>e</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mspace width="2em"></mspace><mo>∧</mo><mspace width="2em"></mspace><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s_{t+1} = \delta(s_t, e_t)\qquad\wedge\qquad \mathrm{Inv}(s_t)\Rightarrow \mathrm{Inv}(s_{t+1}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6389em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">e</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Crash points matter: define what happens if the process stops after each line that mutates state or acknowledges work.</p>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">sequenceDiagram</span>
  <span class="token keyword">participant</span> C as Client
  <span class="token keyword">participant</span> API as API
  <span class="token keyword">participant</span> DB as Durable Store
  C<span class="token arrow operator">->></span>API<span class="token operator">:</span> request<span class="token text string">(op, idempotency_key)</span>
  API<span class="token arrow operator">->></span>DB<span class="token operator">:</span> check_or_reserve<span class="token text string">(key)</span>
  DB<span class="token arrow operator">-->></span>API<span class="token operator">:</span> miss | hit<span class="token text string">(result)</span>
  API<span class="token arrow operator">->></span>DB<span class="token operator">:</span> commit<span class="token text string">(result)</span>
  API<span class="token arrow operator">-->></span>C<span class="token operator">:</span> ack<span class="token text string">(result)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>The goal isn’t cleverness—it’s eliminating ambiguity at boundaries and making recovery boring.</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="rust"><pre class="language-rust"><code class="language-rust"><span class="token keyword">use</span> <span class="token namespace">core<span class="token punctuation">::</span></span>fmt<span class="token punctuation">;</span>

<span class="token attribute attr-name">#[derive(Clone, Debug)]</span>
<span class="token keyword">pub</span> <span class="token keyword">enum</span> <span class="token type-definition class-name">Event</span> <span class="token punctuation">{</span>
    <span class="token class-name">Input</span><span class="token punctuation">(</span><span class="token class-name">Vec</span><span class="token operator">&#x3C;</span><span class="token keyword">u8</span><span class="token operator">></span><span class="token punctuation">)</span><span class="token punctuation">,</span>
    <span class="token class-name">Tick</span><span class="token punctuation">,</span>
    <span class="token class-name">Fault</span><span class="token punctuation">(</span><span class="token operator">&#x26;</span><span class="token lifetime-annotation symbol">'static</span> <span class="token keyword">str</span><span class="token punctuation">)</span><span class="token punctuation">,</span>
<span class="token punctuation">}</span>

<span class="token keyword">pub</span> <span class="token keyword">trait</span> <span class="token type-definition class-name">StateMachine</span> <span class="token punctuation">{</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">State</span><span class="token punctuation">:</span> <span class="token class-name">Clone</span> <span class="token operator">+</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>
    <span class="token keyword">type</span> <span class="token type-definition class-name">Error</span><span class="token punctuation">:</span> <span class="token namespace">fmt<span class="token punctuation">::</span></span><span class="token class-name">Debug</span><span class="token punctuation">;</span>

    <span class="token keyword">fn</span> <span class="token function-definition function">step</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> event<span class="token punctuation">:</span> <span class="token class-name">Event</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token class-name">Result</span><span class="token operator">&#x3C;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">,</span> <span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">Error</span><span class="token operator">></span><span class="token punctuation">;</span>
    <span class="token keyword">fn</span> <span class="token function-definition function">invariant</span><span class="token punctuation">(</span>state<span class="token punctuation">:</span> <span class="token operator">&#x26;</span><span class="token keyword">Self</span><span class="token punctuation">::</span><span class="token class-name">State</span><span class="token punctuation">)</span> <span class="token punctuation">-></span> <span class="token keyword">bool</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>

<span class="token comment">// Backpressure as a Correctness Property: Stability Under Load: invariants are part of the API contract.</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Crash/restart tests</strong>: persist mid-transition and validate recovery correctness.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Differential tests</strong> against a reference model (even a slow one).</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Expose idempotency semantics explicitly (headers, keys, retention windows, error codes).</li>
<li>Track invariant violations as pages, not dashboards.</li>
<li>Instrument ambiguity: measure “unknown outcome” responses separately from failures.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Keep audit and config history queryable during incidents—evidence beats intuition.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> <span class="citation" id="citation--jepsen--1">(<a href="#bib-jepsen">1</a>)</span> — Failure testing focused on correctness under partitions and reordering.
<ul>
<li><strong>Evidence:</strong> Turn faults into test cases; prioritize partition and clock-skew scenarios that violate user-visible guarantees.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--2">(<a href="#bib-rfc9110">2</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What would you do if you had to replay a month of traffic into a rebuilt system?</li>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>What is the minimal durable record needed to recover safely?</li>
<li>Which invariant, if violated, would silently corrupt state for weeks?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-jepsen">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Jepsen. Jepsen: Distributed Systems Safety Analysis [Internet]. Web; Available from: https://jepsen.io/</div>
  </div>
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Idempotency Everywhere: Designing Safe Retries in Distributed APIs]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-02-idempotency-everywhere-designing-safe-retries-in-distributed</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-02-idempotency-everywhere-designing-safe-retries-in-distributed"/>
        <updated>2016-02-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Correctness-focused deep dive (February 2016): Idempotency Everywhere: Designing Safe Retries in Distributed APIs.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p><strong>Idempotency Everywhere: Designing Safe Retries in Distributed APIs</strong> as an engineering constraint: write down assumptions, make invariants executable, and design operational recovery as part of correctness.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>If the spec is implicit, the implementation becomes the spec—and you’ll learn it during incidents.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Separate durable state from derived state; derived must be recomputable or reconcilable.</li>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Define safety properties before performance goals.</li>
<li>Prefer protocols and APIs that make invalid states hard to express.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>“Works in tests” often means “fails under reordering and retries.”</li>
<li>Undefined behavior is an attack surface when inputs are adversarial.</li>
<li>If recovery is not specified, recovery becomes improvisation.</li>
<li>A system without explicit contracts becomes a collection of folklore and dashboards.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
<li>Where does concurrency create “double spend” style failures in your domain?</li>
<li>How do you make “unsafe defaults” impossible to ship?</li>
<li>What must be durable before you acknowledge?</li>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Clients retry with backoff but not with perfect discipline (bursts happen).</li>
<li>Time is untrusted: clock skew, NTP steps, monotonic vs wall-clock confusion.</li>
<li>Crashes happen mid-write (torn state) unless you prove otherwise.</li>
<li>Input is hostile: malformed, oversized, boundary values, protocol confusion.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Baking invariants into tribal knowledge instead of code.</li>
<li>Treating retries as a transport detail rather than a semantic constraint.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Parsing is an attacker-controlled interface—validate early and fail fast.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>A common pattern is splitting state into durable vs derived:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><mi>S</mi><mo>=</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo>×</mo><msub><mi>S</mi><mtext>derived</mtext></msub><mspace width="2em"></mspace><mtext>and</mtext><mspace width="2em"></mspace><msub><mi>S</mi><mtext>derived</mtext></msub><mo>=</mo><mi>f</mi><mo stretchy="false">(</mo><msub><mi>S</mi><mtext>durable</mtext></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">S = S_\text{durable} \times S_\text{derived}\qquad\text{and}\qquad S_\text{derived} = f(S_\text{durable}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:0.8333em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">×</span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:0.8444em;vertical-align:-0.15em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord text"><span class="mord">and</span></span><span class="mspace" style="margin-right:2em;"></span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">derived</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.10764em;">f</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal" style="margin-right:0.05764em;">S</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3361em;"><span style="top:-2.55em;margin-left:-0.0576em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord text mtight"><span class="mord mtight">durable</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>If you can’t define what a timeout means, you can’t implement retries safely. Make ambiguity explicit in the API.</p>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Invariants must be checkable from evidence you actually have (state + logs + counters).</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Evidence: critical actions emit verifiable audit events.</li>
<li>Downgrade resistance: negotiation can’t silently weaken security posture.</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Config drift that weakens security posture over time.</li>
<li>Timeout ambiguity causing double-apply or partial state transitions.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Mixed-version deployments create states you never tested—plan for them explicitly.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">stateDiagram-v2</span>
  <span class="token text string">[*]</span> <span class="token arrow operator">--></span> Init
  Init <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> bootstrap<span class="token punctuation">(</span><span class="token punctuation">)</span>
  Ready <span class="token arrow operator">--></span> Processing<span class="token operator">:</span> event<span class="token text string">(e)</span>
  Processing <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> commit<span class="token punctuation">(</span><span class="token punctuation">)</span>
  Processing <span class="token arrow operator">--></span> Error<span class="token operator">:</span> violate<span class="token text string">(Inv)</span>
  Error <span class="token arrow operator">--></span> Ready<span class="token operator">:</span> recover<span class="token punctuation">(</span><span class="token punctuation">)</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Implementation is the act of making invalid state unrepresentable (or at least unignorable).</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Make rollbacks boring: if rollback is a hero move, it will fail.</p>
</div>
<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">Correctness checklist:
1) Define state (durable vs derived).
2) Enumerate transitions.
3) Write invariants (safety) and progress conditions (liveness).
4) Pick crash points and specify recovery.
5) Make retries part of semantics (idempotency keys, monotonic versions).</code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
<li><strong>Fuzzing</strong> at the boundary: parsers, schema evolution, and “unknown field” handling.</li>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
<li><strong>Crash/restart tests</strong>: persist mid-transition and validate recovery correctness.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Validate time assumptions: alert on clock steps, skew, and monotonicity issues.</li>
<li>Make rollbacks safe: schema and protocol compatibility is a security boundary.</li>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
<li>Track invariant violations as pages, not dashboards.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Invariant violation rate (should be ~0).</li>
<li>Error budget burn + tail latency under load.</li>
<li>Retry/timeout rates by endpoint and client cohort.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> <span class="citation" id="citation--lamport1978--1">(<a href="#bib-lamport1978">1</a>)</span> — The mental model for causality and ordering in distributed systems.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> <span class="citation" id="citation--rfc9110--2">(<a href="#bib-rfc9110">2</a>)</span> — Defines method semantics including idempotency and safety—useful for API contracts.
<ul>
<li><strong>Evidence:</strong> Method semantics (safe/idempotent) are contracts; tie retries and dedupe behavior to these semantics, not timeouts.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
<li>Which operations need monotonic versioning vs idempotency keys vs both?</li>
<li>What is the minimal durable record needed to recover safely?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
  <div class="csl-entry" id="bib-rfc9110">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Fielding RT, Nottingham M, Reschke J. HTTP Semantics [Internet]. RFC Editor; 2022. Report No.: 9110. Available from: https://www.rfc-editor.org/rfc/rfc9110</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Protocol State Machines: Invariants, Events, and Recovery]]></title>
        <id>https://mayckongiovani.xyz/pensieve/2016-01-protocol-state-machines-invariants-events-and-recovery</id>
        <link href="https://mayckongiovani.xyz/pensieve/2016-01-protocol-state-machines-invariants-events-and-recovery"/>
        <updated>2016-01-01T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Design memo (January 2016): Protocol State Machines: Invariants, Events, and Recovery.]]></summary>
        <content type="html"><![CDATA[<blockquote>
<p>Monthly research note. Theme: <strong>Correctness &#x26; Foundations</strong>.</p>
</blockquote>
<h2 id="tldr" style="position:relative;"><a href="#tldr" aria-label="tldr permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>TL;DR</h2>
<p>A focused memo on <strong>Protocol State Machines: Invariants, Events, and Recovery</strong>: define the model, state the properties, then design the system so those properties remain true under failure and adversaries.</p>
<div class="callout callout--key-insight">
  <div class="callout-title">Key insight</div>
  <p>Treat “timeouts” as a third outcome: not success, not failure—ambiguity you must model.</p>
</div>
<h2 id="key-takeaways" style="position:relative;"><a href="#key-takeaways" aria-label="key takeaways permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key takeaways</h2>
<ul>
<li>Ack semantics must be explicit: durable, best-effort, or ambiguous.</li>
<li>Prefer monotonic counters/epochs over wall-clock timestamps at correctness boundaries.</li>
<li>Crash points are part of the design; specify recovery after each state mutation.</li>
<li>Make failure modes explicit and observable.</li>
<li>Design rollbacks as part of the happy path.</li>
</ul>
<h2 id="why-this-matters" style="position:relative;"><a href="#why-this-matters" aria-label="why this matters permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Why this matters</h2>
<ul>
<li>In distributed code, retries and duplication are the common case—not the edge case.</li>
<li>If recovery is not specified, recovery becomes improvisation.</li>
<li>The cost of unclear invariants is paid in production, under load, during an incident.</li>
<li>Correctness is a property you enforce at boundaries: parsing, persistence, concurrency, RPC.</li>
</ul>
<h2 id="key-questions" style="position:relative;"><a href="#key-questions" aria-label="key questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Key questions</h2>
<ul>
<li>Which invariants must hold across crashes, restarts, and partial deployments?</li>
<li>Which transitions are allowed, and which are impossible by construction?</li>
<li>What must be durable before you acknowledge?</li>
<li>What is your ordering model: FIFO per key, per partition, or none at all?</li>
<li>What <em>exactly</em> is the state, and what is derived or cached?</li>
<li>What does a client learn after a timeout: success, failure, or ambiguity?</li>
</ul>
<h2 id="assumptions" style="position:relative;"><a href="#assumptions" aria-label="assumptions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Assumptions</h2>
<ul>
<li>Errors are lossy: transient vs permanent is often indistinguishable at the boundary.</li>
<li>Observability is incomplete: you will debug from partial evidence.</li>
<li>Clients retry with backoff but not with perfect discipline (bursts happen).</li>
<li>Partial failure is normal: one replica slow, one unavailable, one returning stale data.</li>
</ul>
<h2 id="non-goals" style="position:relative;"><a href="#non-goals" aria-label="non goals permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Non-goals</h2>
<ul>
<li>Relying on “best effort” client behavior for safety properties.</li>
<li>Baking invariants into tribal knowledge instead of code.</li>
</ul>
<div class="callout callout--attack-surface">
  <div class="callout-title">Attack surface</div>
  <p>Negotiation and fallbacks are where security silently becomes optional—treat them as hostile.</p>
</div>
<h2 id="model--invariants" style="position:relative;"><a href="#model--invariants" aria-label="model  invariants permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Model &#x26; invariants</h2>
<p>We want a transition function <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi>δ</mi></mrow><annotation encoding="application/x-tex">\delta</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6944em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span></span></span></span></span> and invariant <span class="math math-inline"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><annotation encoding="application/x-tex">\mathrm{Inv}</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6833em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span></span></span></span></span> such that:</p>
<div class="math math-display"><span class="katex-display"><span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML" display="block"><semantics><mrow><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo>=</mo><mi>δ</mi><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo separator="true">,</mo><msub><mi>e</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mspace width="2em"></mspace><mo>∧</mo><mspace width="2em"></mspace><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mi>t</mi></msub><mo stretchy="false">)</mo><mo>⇒</mo><mrow><mi mathvariant="normal">I</mi><mi mathvariant="normal">n</mi><mi mathvariant="normal">v</mi></mrow><mo stretchy="false">(</mo><msub><mi>s</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><mo stretchy="false">)</mo><mi mathvariant="normal">.</mi></mrow><annotation encoding="application/x-tex">s_{t+1} = \delta(s_t, e_t)\qquad\wedge\qquad \mathrm{Inv}(s_t)\Rightarrow \mathrm{Inv}(s_{t+1}).</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="base"><span class="strut" style="height:0.6389em;vertical-align:-0.2083em;"></span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">=</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord mathnormal" style="margin-right:0.03785em;">δ</span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord"><span class="mord mathnormal">e</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span><span class="mbin">∧</span><span class="mspace" style="margin-right:2em;"></span><span class="mspace" style="margin-right:0.2222em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.2806em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mathnormal mtight">t</span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.15em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mspace" style="margin-right:0.2778em;"></span><span class="mrel">⇒</span><span class="mspace" style="margin-right:0.2778em;"></span></span><span class="base"><span class="strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord"><span class="mord mathrm" style="margin-right:0.01389em;">Inv</span></span><span class="mopen">(</span><span class="mord"><span class="mord mathnormal">s</span><span class="msupsub"><span class="vlist-t vlist-t2"><span class="vlist-r"><span class="vlist" style="height:0.3011em;"><span style="top:-2.55em;margin-left:0em;margin-right:0.05em;"><span class="pstrut" style="height:2.7em;"></span><span class="sizing reset-size6 size3 mtight"><span class="mord mtight"><span class="mord mathnormal mtight">t</span><span class="mbin mtight">+</span><span class="mord mtight">1</span></span></span></span></span><span class="vlist-s">​</span></span><span class="vlist-r"><span class="vlist" style="height:0.2083em;"><span></span></span></span></span></span></span><span class="mclose">)</span><span class="mord">.</span></span></span></span></span></div>
<p>Avoid “ghost state” in caches that can’t be recomputed or validated. Derived state must be either reproducible or explicitly reconciled.</p>
<p>Prefer <em>monotonic</em> identifiers at boundaries (sequence numbers, epochs, version vectors) so that replays are detectable and order can be reasoned about.</p>
<div class="callout callout--invariant">
  <div class="callout-title">Invariant</div>
  <p>Monotonicity beats timestamps: counters and epochs survive clock skew.</p>
</div>
<h2 id="security-properties" style="position:relative;"><a href="#security-properties" aria-label="security properties permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Security properties</h2>
<ul>
<li>Integrity: invalid transitions are rejected (and detectable).</li>
<li>Least authority: privileges are scoped by purpose and time.</li>
<li>Replay resistance: duplicated inputs do not change outcomes.</li>
<li>Authenticity: actions are bound to identity and purpose.</li>
</ul>
<h2 id="failure-modes" style="position:relative;"><a href="#failure-modes" aria-label="failure modes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Failure modes</h2>
<ul>
<li>Mixed-version behavior that violates assumptions silently.</li>
<li>Resource exhaustion (CPU/bandwidth/storage) turning into correctness failures.</li>
<li>Recovery paths that only work when nothing is broken.</li>
<li>Observability gaps during incidents (missing evidence).</li>
</ul>
<div class="callout callout--pitfall">
  <div class="callout-title">Pitfall</div>
  <p>Caches tend to become sources of truth unless you can recompute and validate them.</p>
</div>
<h2 id="design-sketch" style="position:relative;"><a href="#design-sketch" aria-label="design sketch permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Design sketch</h2>
<div class="gatsby-highlight" data-language="mermaid"><pre class="language-mermaid"><code class="language-mermaid"><span class="token keyword">flowchart</span> TD
  input<span class="token text string">["Input"]</span> <span class="token arrow operator">--></span> parse<span class="token text string">["Parse/Validate"]</span>
  parse <span class="token arrow operator">--></span> decide<span class="token text string">["Decide (pure)"]</span>
  decide <span class="token arrow operator">--></span> write<span class="token text string">["Durable write"]</span>
  write <span class="token arrow operator">--></span> ack<span class="token text string">["Acknowledge"]</span>
  ack <span class="token arrow operator">--></span> obs<span class="token text string">["Emit evidence (logs/metrics)"]</span></code></pre></div>
<h2 id="implementation-notes" style="position:relative;"><a href="#implementation-notes" aria-label="implementation notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Implementation notes</h2>
<p>Implementation is the act of making invalid state unrepresentable (or at least unignorable).</p>
<div class="callout callout--rule-of-thumb">
  <div class="callout-title">Rule of thumb</div>
  <p>Bound work per request: parse, validate, and cap cost before you allocate heavy resources.</p>
</div>
<div class="gatsby-highlight" data-language="go"><pre class="language-go"><code class="language-go"><span class="token comment">// Idempotency sketch: reserve -> execute -> commit result (or return cached).</span>
<span class="token keyword">type</span> Key <span class="token builtin">string</span>

<span class="token keyword">type</span> Store <span class="token keyword">interface</span> <span class="token punctuation">{</span>
  <span class="token function">Get</span><span class="token punctuation">(</span>key Key<span class="token punctuation">)</span> <span class="token punctuation">(</span>value <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">,</span> ok <span class="token builtin">bool</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
  <span class="token function">PutIfAbsent</span><span class="token punctuation">(</span>key Key<span class="token punctuation">,</span> value <span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token builtin">byte</span><span class="token punctuation">)</span> <span class="token punctuation">(</span>stored <span class="token builtin">bool</span><span class="token punctuation">,</span> err <span class="token builtin">error</span><span class="token punctuation">)</span>
<span class="token punctuation">}</span>

<span class="token comment">// Protocol State Machines: Invariants, Events, and Recovery: "timeout" must not mean "try again and maybe double-apply".</span></code></pre></div>
<h2 id="verification-strategy" style="position:relative;"><a href="#verification-strategy" aria-label="verification strategy permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Verification strategy</h2>
<ul>
<li><strong>Metamorphic tests</strong>: same operation applied twice must not change the result.</li>
<li><strong>Fault injection</strong>: latency, partial writes, dropped acks, and duplicated messages.</li>
<li><strong>Invariant monitoring</strong> in prod: encode safety properties as metrics (rate of impossible states).</li>
<li><strong>Property-based tests</strong>: generate adversarial sequences and assert invariants after every step.</li>
<li><strong>Deterministic schedulers</strong> (e.g., Loom-like) to force rare interleavings.</li>
</ul>
<h2 id="operational-notes" style="position:relative;"><a href="#operational-notes" aria-label="operational notes permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Operational notes</h2>
<ul>
<li>Run chaos drills focused on state: partial DB outages, replica lag, cache poisoning.</li>
<li>Track invariant violations as pages, not dashboards.</li>
<li>Validate time assumptions: alert on clock steps, skew, and monotonicity issues.</li>
<li>Design “degraded modes” explicitly (fail closed vs fail open per operation).</li>
<li>Log as evidence: append-only where possible; isolate logs from compromised workloads.</li>
</ul>
<div class="callout callout--operational-note">
  <div class="callout-title">Operational note</div>
  <p>Attach explicit rollout/rollback triggers to changes that touch security or correctness.</p>
</div>
<h2 id="what-to-monitor" style="position:relative;"><a href="#what-to-monitor" aria-label="what to monitor permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>What to monitor</h2>
<ul>
<li>Error budget burn + tail latency under load.</li>
<li>Rollback events and the conditions that triggered them.</li>
<li>Authz failures and policy denials (unexpected spikes).</li>
<li>Invariant violation rate (should be ~0).</li>
<li>Admission-control / rate-limit rejections (by reason).</li>
</ul>
<h2 id="rollback-plan" style="position:relative;"><a href="#rollback-plan" aria-label="rollback plan permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Rollback plan</h2>
<ul>
<li>Prefer backward-compatible changes; avoid “flag day” upgrades.</li>
<li>Preserve evidence (configs, artifacts, audit logs) to reconstruct what changed.</li>
<li>Use canaries and staged rollout; stop early when signals degrade.</li>
<li>Keep dual-write / dual-verify windows where appropriate.</li>
<li>Define an explicit rollback trigger (metrics + thresholds).</li>
</ul>
<h2 id="evidence" style="position:relative;"><a href="#evidence" aria-label="evidence permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Evidence</h2>
<ul>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> <span class="citation" id="citation--lamport1978--1">(<a href="#bib-lamport1978">1</a>)</span> — The mental model for causality and ordering in distributed systems.
<ul>
<li><strong>Evidence:</strong> Use this as the baseline for happens-before vs wall-clock; avoid embedding clock assumptions into safety properties.</li>
</ul>
</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> <span class="citation" id="citation--beyer2016sre--2">(<a href="#bib-beyer2016sre">2</a>)</span> — Error budgets, incident response, and reliability as an engineering discipline.
<ul>
<li><strong>Evidence:</strong> Error budgets and incident response are correctness controls; tie monitoring and rollback triggers to SLO burn.</li>
</ul>
</li>
</ul>
<h2 id="open-questions" style="position:relative;"><a href="#open-questions" aria-label="open questions permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Open questions</h2>
<ul>
<li>What is the minimal durable record needed to recover safely?</li>
<li>What would you do if you had to replay a month of traffic into a rebuilt system?</li>
<li>Where does your API currently allow ambiguous outcomes, and how will clients cope?</li>
<li>Which correctness properties can be enforced at compile time (types/capabilities)?</li>
</ul>
<h2 id="checklist" style="position:relative;"><a href="#checklist" aria-label="checklist permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Checklist</h2>
<ul class="contains-task-list">
<li class="task-list-item"><input type="checkbox" disabled> Failure modes enumerated with mitigations.</li>
<li class="task-list-item"><input type="checkbox" disabled> Rollback plan rehearsed and automated.</li>
<li class="task-list-item"><input type="checkbox" disabled> Safety properties stated as invariants.</li>
<li class="task-list-item"><input type="checkbox" disabled> Telemetry captures correctness signals.</li>
<li class="task-list-item"><input type="checkbox" disabled> Assumptions listed and reviewed.</li>
<li class="task-list-item"><input type="checkbox" disabled> Costs bounded (CPU/memory/bandwidth) under adversarial inputs.</li>
</ul>
<h2 id="further-reading" style="position:relative;"><a href="#further-reading" aria-label="further reading permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Further reading</h2>
<ul>
<li><a href="https://jepsen.io/" target="_blank" rel="nofollow noopener noreferrer">Jepsen</a> — Failure testing focused on correctness under partitions and reordering.</li>
<li><a href="https://learntla.com/" target="_blank" rel="nofollow noopener noreferrer">Learn TLA+</a> — A pragmatic workflow for invariants and model checking.</li>
<li><a href="https://lamport.azurewebsites.net/pubs/time-clocks.pdf" target="_blank" rel="nofollow noopener noreferrer">Time, Clocks, and the Ordering of Events (Lamport, 1978)</a> — The mental model for causality and ordering in distributed systems.</li>
<li><a href="https://www.rfc-editor.org/rfc/rfc9110" target="_blank" rel="nofollow noopener noreferrer">RFC 9110: HTTP Semantics</a> — Defines method semantics including idempotency and safety—useful for API contracts.</li>
<li><a href="https://sre.google/sre-book/table-of-contents/" target="_blank" rel="nofollow noopener noreferrer">Site Reliability Engineering (Google)</a> — Error budgets, incident response, and reliability as an engineering discipline.</li>
<li><a href="https://dataintensive.net/" target="_blank" rel="nofollow noopener noreferrer">Designing Data-Intensive Applications (Kleppmann)</a> — The systems-engineering baseline for correctness, replication, and failure.</li>
</ul><div id="refs" class="references csl-bib-body">
  <div class="csl-entry" id="bib-lamport1978">
    <div class="csl-left-margin">1. </div><div class="csl-right-inline">Lamport L. Time, Clocks, and the Ordering of Events in a Distributed System. Communications of the ACM [Internet]. 1978;21(7):558–65. Available from: https://lamport.azurewebsites.net/pubs/time-clocks.pdf</div>
  </div>
  <div class="csl-entry" id="bib-beyer2016sre">
    <div class="csl-left-margin">2. </div><div class="csl-right-inline">Beyer B, Jones C, Petoff J, Murphy NR. Site Reliability Engineering: How Google Runs Production Systems [Internet]. O’Reilly Media; 2016. Available from: https://sre.google/sre-book/table-of-contents/</div>
  </div>
</div>]]></content>
        <category label="research-notes"/>
        <category label="protocol-design"/>
        <category label="correctness"/>
        <category label="formal-methods"/>
        <category label="Rust"/>
    </entry>
</feed>