Provisioning and key lifecycle
Status: STUB (2026-07-05). Fills distillation gap 4. Lifts from: v4.1 §23 (five auth layers), Blog 03 attestation chain, v4.1 §10 (BSrE re-issuance on rotation).
Purpose
The lifecycle spec for device and human keys: secure-element provisioning at assembly, institutional provisioning at install, staff enrollment, certificate expiry and rotation, revocation, and decommissioning. The registry that federation trust depends on.
Outline
- Factory/batch provisioning: key generation in-element, attestation cert issuance, registry pre-enrollment
- Field provisioning ceremony: administrator identity verification, institution binding, conversational offline setup
- Staff enrollment: fingerprint templates (device-local only), role scoping
- Officer certificates: BSrE issuance via OPD/Diskominfo RA, expiry means re-issue not renew, rotation procedure tied to Frozen Intent handover events
- Revocation: lost device (disk encryption keyed to element, registry revocation), compromised staff role, dewan quorum changes
- Registry operation: who runs it, what it stores, offline verification cache format
Open questions
- Registry in Fase 0: single file on the managed server, signed? (simplest honest version)
Settled
- Secure element: ATECC608B, frozen per D10; Zymkey dropped (supply and price, research/2026-07-05_stack-hardware-sota.md §F5). This spec writes against ATECC608B only.