# HXP-004 — Threat Model and Security Goals

Status: Candidate Standard 0.1
Public article edition: 2026-09-09

## Overview

Helix's threat model starts with the decisions a reader wants to make: whether a digital record changed, whether its signer was authorized, whether its history belongs to the same credential, and whether a presented physical object satisfies a declared observation method. Security controls must support those questions without turning uncertainty into an unsupported authenticity claim.

The model considers dishonest submitters, counterfeiters, copied carriers, malicious manufacturing activity, compromised operational keys, misleading historical records, and unavailable services. It also considers ordinary mistakes: incorrect captures, incomplete uploads, interrupted signing, unsupported hardware, and confusing user interfaces. An honest error can create the same misleading display as a deliberate attack if state and evidence are not distinguished.

This is a public description of assets, trust boundaries, and evaluation goals. It does not publish deployment credentials, secret key material, protected manufacturing procedures, or instructions for exploiting a live service. It must be read alongside the actual validation status of each capability.

## Assets and trust boundaries

| Asset or boundary | What must be protected | What does not follow automatically |
| --- | --- | --- |
| Evidence assertion | Integrity of the subject, inventory, policy, and signed commitments | The issuer's factual assertion is not independently proven merely by signing it. |
| Signing authority | Authorized keys, delegated purposes, and independently established roots | A key carried by an object is not self-authenticating authority. |
| Custody history | Correct credential linkage, prior-event continuity, and authorized state changes | Platform control is not a complete legal-title determination. |
| Private evidence | Confidentiality and authorized disclosure of captures and notes | A digest does not encrypt the underlying information. |
| Physical association | Correct design, unit enrollment, and qualified attachment observations | A deterministic pattern or copied NFC payload does not establish uniqueness. |
| Relying-party decision | Accurate results, limitations, and observation times | A convenient interface cannot replace missing evidence. |

Trust should be granted for a defined purpose. An issuer's ability to sign a credential does not authorize arbitrary changes to another party's records. A manufacturer can receive the material needed to fabricate a candidate unit without receiving signing authority. A reader's measurement has a declared execution class and quality, rather than unlimited authority over the registry.

## Digital record attacks

The digital model includes package mutation, altered nested metadata, unsafe archive construction, missing evidence, profile confusion, empty or duplicated signature policies, and substitution of algorithms, keys, or delegations. Verification must recompute commitments and evaluate the actual policy rather than trusting a displayed identifier or a success flag embedded in the input.

Domain separation prevents a signed statement intended for one purpose from being accepted as another kind of statement. Canonical encoding removes ambiguity in the bytes being committed. Safe package handling rejects dangerous paths, duplicates, excessive expansion, and unsupported mandatory formats before ordinary rendering or extraction.

These controls aim to make unauthorized changes detectable. They do not prevent an authorized issuer from recording a false description. Identity assurance, evidence collection, operating procedures, and dispute handling therefore remain necessary parts of a real deployment.

## Authority and key compromise

A forged record may include a complete attacker-generated chain of signatures. Mathematical consistency is insufficient when the trust root itself came only from that record. Independently pinned roots, delegated purposes, validity context, and explicit trust-source reporting prevent the artifact from appointing its own authority.

Compromise of an operational key is a different event from ordinary signature invalidity. A signature may be mathematically valid while the key's current use is no longer trusted. Relying parties need the applicable revocation, rotation, and recovery policy, together with the observation time of the status information they used.

Recovery must preserve the distinction between historical validity and current acceptability. Silently replacing keys, accepting an arbitrary root to regain availability, or rewriting past packages obscures what happened. Public corrections should identify affected versions or claims without exposing private recovery procedures.

## History, replay, and transfer

A valid event from one credential must not become valid history for another. Provenance material is bound to the certificate, original evidence root, previous event, and relevant state and authority context. Inclusion proofs must be evaluated against the checkpoint they actually reference.

Ownership operations also need authorization and freshness at the time they change state. An offer is not an accepted transfer. An expired, cancelled, mismatched, or already-consumed offer must not create a new handoff. Retrying a completed operation should recover its acknowledgement rather than append another event.

The public History panel should explain the resulting record without exposing private recipient details or acceptance material. A published exhibition or restoration note is an attributed assertion; its publication and integrity can be checked separately from any external evidence supporting its content.

## Copying the physical carrier

A QR code or ordinary NFC locator can be copied. A signed token envelope can also be copied byte-for-byte without invalidating its signature. A deterministic optical design can be reproduced in principle. These facts do not defeat digital integrity, but they limit what digital integrity alone says about the physical object.

A stronger physical claim needs an enrolled, unit-specific response and a qualified attachment relationship. The physical program therefore considers photographic imitations, printed or relief copies, refabrication, copied memory, carrier transplantation, and emulated observations at the level required by the selected profile. Specific fabrication or reader recipes are not needed in a public threat-model article.

The relevant success condition is not simply whether a copy looks convincing. It is whether a non-enrolled unit or host can satisfy all required checks under the declared operating conditions. The attack population, inspection method, and claim must be stated before evaluating the result.

## Manufacturing and enrollment separation

The candidate architecture separates intended design from measured unit behavior. Design material is tied to the credential's evidence commitment. Post-manufacture enrollment records the response of an individual unit under a defined reader profile. A same-design manufacturing overrun does not automatically inherit that unit's enrolled template.

This is a security objective to validate, not proof that every manufacturing process provides useful unclonability. Same-design units, deliberate overruns, reconstructed responses, and malicious-manufacturer samples belong in the qualification set. The dataset must include realistic variation and plausible substitutes, not only visibly dissimilar controls.

Vendor access should remain limited to the approved handoff. Signing keys and unrestricted source evidence do not become manufacturing inputs. Public reports can identify the tested profile, evidence-dossier digest, limitations, and result while keeping proprietary process details and protected raw measurements controlled.

## Reader, environment, and attachment uncertainty

A reader can be misaligned, contaminated, uncalibrated, or outside its supported conditions. A genuine unit may age or be damaged. An attachment can lose continuity while its digital envelope remains intact. Quality gates and separate result axes are necessary to distinguish these situations.

Low-quality input should produce an unresolved result when the method cannot decide. Treating every unreadable sample as counterfeit is misleading; treating it as valid is unsafe. Repeatedly retrying until one favorable measurement appears can also bias an assessment unless the retry policy was specified in advance.

Attachment qualification must consider the actual host material, allowed treatment, service environment, and inspection method. A result on a rigid industrial coupon cannot be generalized to paper, leather, painted surfaces, or every fine-art mounting arrangement.

## Availability, privacy, and interface behavior

A registry outage prevents a current observation; it does not imply a positive current status. A saved issuance operation should be recoverable without weakening its signature requirements. A failed evidence upload should preserve a truthful saved or unsaved state rather than manufacture a finished credential.

Public readers should receive only the material authorized for publication. Private source files, personal contacts, internal notes, and confidential operational records remain separately controlled. A signed payload may contain data that should not appear in a public interface, so publication must be an explicit projection rather than an indiscriminate dump.

The interface is part of the assurance system. It should name the evaluated claim, expose uncertainty, keep pending operations visibly pending, and offer the appropriate next action. Labels such as “secure,” “verified,” or “authentic” are useful only when their scope is clear.

## Evaluation and residual risk

Digital conformance tests should cover mutation, substitution, unsafe packages, replay, untrusted roots, interrupted operations, and privacy boundaries. Physical qualification requires controlled experiments, adversarial samples, environmental evidence, and independent review appropriate to the claim. Neither a simulation nor a vendor quotation advances a physical claim gate.

The model does not establish legal title, guarantee an impossible-to-copy structure, replace conservation review, provide current status without current information, or eliminate every risk from a compromised authorized participant. Residual risks should be reported with the method, assumptions, and evidence available.

[ISO 22383:2020](https://www.iso.org/standard/50285.html) provides a relevant material-goods authentication evaluation reference; it is not a certification of Helix. Read [HXP-003](/standards/open-verifier) for result interpretation and [HXP-009](/standards/conformance) for the claim-gate process.
