K07 · evidence-bundled critical-infrastructure assurance

Cryptographic provenance, custody, and revocation

Direct answer

Cryptographic provenance, custody, and revocation provides bounded component or provenance evidence and must be combined with authenticity, installed-state, vulnerability, custody, and recovery evidence.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Artifact class

Supply-chain record
Stable IDSCA-K07-007
Artifact typeSIGNATURE-AND-ATTESTATION-CHAIN

Required fields

  • signer or attester identity
  • key fingerprint
  • algorithm and parameters
  • signed payload hash
  • time and sequence
  • key status
  • revocation and compromise record
  • verification result

Validation expectations

  • signature verification
  • trust-root and scope check
  • key status at event time
  • replay and duplicate detection
  • revocation propagation

Limitations

  • signature proves key control and payload integrity, not factual truth, legal authority, or safe operation
  • compromised keys require supersession and re-evaluation

Source relationships

Assurance boundary

Inventory, signature, attestation, supplier status, vulnerability status, and installed configuration remain separate evidence properties. This record does not certify a product or prove that a deployed asset matches its declared bill of materials.