Add SCITT integration section linking wid to Transparency Services

The ECT workflow identifier (wid) can serve as a correlation point
in SCITT Signed Statements, bridging per-step execution accountability
with end-to-end supply chain transparency.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-02-24 06:46:38 +01:00
parent 6676196ea9
commit d6d44285eb
4 changed files with 663 additions and 487 deletions

View File

@@ -1578,7 +1578,10 @@ regulatory frameworks.<a href="#section-abstract-1" class="pilcrow">¶</a></p>
<p id="section-toc.1-1.14.2.4.1"><a href="#appendix-A.4" class="auto internal xref"></a><a href="#name-blockchain-and-distributed-" class="internal xref">Blockchain and Distributed Ledgers</a></p>
</li>
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.14.2.5">
<p id="section-toc.1-1.14.2.5.1"><a href="#appendix-A.5" class="auto internal xref"></a><a href="#name-w3c-verifiable-credentials" class="internal xref">W3C Verifiable Credentials</a></p>
<p id="section-toc.1-1.14.2.5.1"><a href="#appendix-A.5" class="auto internal xref"></a><a href="#name-scitt-supply-chain-integrit" class="internal xref">SCITT (Supply Chain Integrity, Transparency, and Trust)</a></p>
</li>
<li class="compact toc ulBare ulEmpty" id="section-toc.1-1.14.2.6">
<p id="section-toc.1-1.14.2.6.1"><a href="#appendix-A.6" class="auto internal xref"></a><a href="#name-w3c-verifiable-credentials" class="internal xref">W3C Verifiable Credentials</a></p>
</li>
</ul>
</li>
@@ -3760,6 +3763,10 @@ the "JSON Web Token Claims" registry maintained by IANA:<a href="#section-12.3-1
<dd>
<span class="refAuthor">U.S. Food and Drug Administration</span>, <span class="refTitle">"Title 21, Code of Federal Regulations, Part 11: Electronic Records; Electronic Signatures"</span>, <span>&lt;<a href="https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11">https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11</a>&gt;</span>. </dd>
<dd class="break"></dd>
<dt id="I-D.ietf-scitt-architecture">[I-D.ietf-scitt-architecture]</dt>
<dd>
<span class="refAuthor">Birkholz, H.</span>, <span class="refAuthor">Delignat-Lavaud, A.</span>, <span class="refAuthor">Fournet, C.</span>, <span class="refAuthor">Deshpande, Y.</span>, and <span class="refAuthor">S. Lasker</span>, <span class="refTitle">"An Architecture for Trustworthy and Transparent Digital Supply Chains"</span>, <span class="refContent">Work in Progress</span>, <span class="seriesInfo">Internet-Draft, draft-ietf-scitt-architecture-22</span>, <time datetime="2025-10-10" class="refDate">10 October 2025</time>, <span>&lt;<a href="https://datatracker.ietf.org/doc/html/draft-ietf-scitt-architecture-22">https://datatracker.ietf.org/doc/html/draft-ietf-scitt-architecture-22</a>&gt;</span>. </dd>
<dd class="break"></dd>
<dt id="I-D.ni-wimse-ai-agent-identity">[I-D.ni-wimse-ai-agent-identity]</dt>
<dd>
<span class="refAuthor">Yuan, N.</span> and <span class="refAuthor">P. C. Liu</span>, <span class="refTitle">"WIMSE Applicability for AI Agents"</span>, <span class="refContent">Work in Progress</span>, <span class="seriesInfo">Internet-Draft, draft-ni-wimse-ai-agent-identity-01</span>, <time datetime="2025-10-20" class="refDate">20 October 2025</time>, <span>&lt;<a href="https://datatracker.ietf.org/doc/html/draft-ni-wimse-ai-agent-identity-01">https://datatracker.ietf.org/doc/html/draft-ni-wimse-ai-agent-identity-01</a>&gt;</span>. </dd>
@@ -3862,16 +3869,40 @@ blockchain networks, or any storage providing the required
properties defined in <a href="#ledger-interface" class="auto internal xref">Section 8</a>.<a href="#appendix-A.4-1" class="pilcrow"></a></p>
</section>
</div>
<div id="w3c-verifiable-credentials">
<div id="scitt-supply-chain-integrity-transparency-and-trust">
<section id="appendix-A.5">
<h3 id="name-scitt-supply-chain-integrit">
<a href="#name-scitt-supply-chain-integrit" class="section-name selfRef">SCITT (Supply Chain Integrity, Transparency, and Trust)</a>
</h3>
<p id="appendix-A.5-1">The SCITT architecture <span>[<a href="#I-D.ietf-scitt-architecture" class="cite xref">I-D.ietf-scitt-architecture</a>]</span> defines a
framework for creating transparent and auditable supply chain
records through Transparency Services, Signed Statements, and
Receipts. ECTs and SCITT are naturally complementary: the ECT
"wid" (Workflow Identifier) claim can serve as a correlation
identifier referenced in SCITT Signed Statements, linking a
complete ECT audit trail to a supply chain transparency record.
For example, in a regulated manufacturing workflow, each agent
step produces an ECT (recording what was done, by whom, under
what policy), while the overall workflow identified by "wid" is
registered as a SCITT Signed Statement on a Transparency Service.
This enables auditors to verify both the individual execution
steps (via ECT DAG validation) and the end-to-end supply chain
integrity (via SCITT Receipts) using the "wid" as the shared
correlation point. The "ext" claim in ECTs (<a href="#exec-claims" class="auto internal xref">Section 4.2.2</a>)
can carry SCITT-specific metadata such as Transparency Service
identifiers or Receipt references for tighter integration.<a href="#appendix-A.5-1" class="pilcrow"></a></p>
</section>
</div>
<div id="w3c-verifiable-credentials">
<section id="appendix-A.6">
<h3 id="name-w3c-verifiable-credentials">
<a href="#name-w3c-verifiable-credentials" class="section-name selfRef">W3C Verifiable Credentials</a>
</h3>
<p id="appendix-A.5-1">W3C Verifiable Credentials represent claims about subjects (e.g.,
<p id="appendix-A.6-1">W3C Verifiable Credentials represent claims about subjects (e.g.,
identity, qualifications). ECTs represent execution records of
actions (what happened, in what order, under what policy). While
both use JWT/JWS as a serialization format, their semantics and
use cases are distinct.<a href="#appendix-A.5-1" class="pilcrow"></a></p>
use cases are distinct.<a href="#appendix-A.6-1" class="pilcrow"></a></p>
</section>
</div>
</section>