specs/device/shared/v0_1/device_binding
library
Classes
-
DeviceBinding
-
DeviceBinding
-
KeyCustody
-
How a device custodies its private key material — maintainer policy input,
mirroring
attestation. See docs/design-notes/mobile-key-custody-profile.md.
-
WakeHandle
-
An opaque, gateway-issued reference to a device's push channel (push wake-up
binding, https://trusttasks.org/binding/push/0.1). The push gateway returns it to
the device at registration; the device conveys it to its VTA (device/set-wake), and
the VTA provisions it to authorized triggers (its mediator and/or itself). The raw
platform push token (APNs/FCM/WebPush) is held ONLY by the gateway and is never
represented here — the handle abstracts the platform, so adding new push methods
(e.g. PWA Web Push) needs no change to triggers or VTA config. A handle is a bearer
capability to request a wake (subject to the gateway's allowlist), never to read
the channel.
-
WakeTriggerPolicy
-
VTA-owned allowlist of the DIDs permitted to trigger a wake for a given WakeHandle
(push wake-up binding, https://trusttasks.org/binding/push/0.1). The VTA is the
source of truth for this policy — all device config state resides at the VTA — and
provisions it to the gateway, which ENFORCES it: a wake request from a DID not on
the list is refused. Typically holds the device's mediator DID (queue-driven wake,
where the mediator alone knows the device is offline) and/or the VTA's own DID
(policy-driven wake, e.g. a step-up the VTA is delegating to this device).
Extension Types
-
Capability
-
Fine-grained capability flag scoped to the device's allowed contexts. See SPEC.md
for the full semantics of each. Capability values are additive: a consumer MUST
ignore a value it does not recognise rather than reject the binding, and MUST NOT
treat an unrecognised value as conferring anything.
-
KeyCustodyTier
-
hardware: the key is non-exportable in the secure keystore (iOS Secure Enclave /
Android StrongBox) and every signing / key-agreement operation runs in-chip —
achievable only with P-256. software: the key is held in app memory during use,
stored hardware-wrapped at rest. Maintainers MAY apply stricter policy (shorter
sessions, more frequent step-up) to software-tier devices.
Typedefs
-
ConsumerKind
= Object?
-
Discriminator: is this consumer a user-driven Companion or a headless Service?
-
DeviceAttestation
= Object?
-
Producer-supplied attestation at registration time, verifiable by the maintainer
against the platform's attestation infrastructure. Tagged union over the
discriminator
kind.
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.
-
PushRegistration
= Object?
-
A device's platform push channel — the body the device registers with its push
GATEWAY (push wake-up binding, https://trusttasks.org/binding/push/0.1; modeled on
Aries RFC 0699/0734). The gateway holds this token and returns an opaque WakeHandle
in exchange; the token is held by the gateway ONLY, never by the mediator or the
maintainer/VTA. The gateway uses it to send a contentless wake-up when an
authorized trigger asks — the push payload never carries Trust Task content. Tagged
union over the discriminator
platform.