Summary

  • draft-mih-scitt-checkpointed-local-log-01 lets a producer keep records private while signing compact Merkle Mountain Range checkpoints, but an offline consistency proof shows only that one presented branch extends its own predecessor.
  • Continuity against equivocation requires an independent checkpoint-aware witness that remembers the last checkpoint it accepted for the same log identity. Ordinary SCITT registration proves inclusion—and time only when signed time is present—not that no competing branch exists.

Suppose an automated service signs every decision it makes. At the end of the month, its operator presents a neat sequence of receipts. Every signature verifies. Every checkpoint links to the preceding one. A range proof says nothing was removed between positions 4,000 and 5,000.

That collection still may not be the collection another auditor received.

The first revision of The Checkpointed Local Log, posted on 26 September, attacks this exact weakness. A CLL keeps its records local, appends their digests to a Merkle Mountain Range, and periodically signs a small checkpoint. The checkpoint commits to the current size and accumulator. It can leave the producer without revealing private entries. This makes independent oversight cheaper than registering every receipt with a public service.

But cheap commitment creates a dangerous shorthand: “the checkpoint verifies, therefore the history is unique.” Revision 01 explicitly refuses that conclusion.

One valid extension is not the only possible extension

Each checkpoint includes the current log_size and commitment, plus prev_size and prev_commitment. Given a consistency proof, a verifier can confirm that the later commitment extends the earlier state without deleting, reordering or rewriting the entries already committed on that branch.

A dishonest producer can nevertheless maintain two branches. Fork A extends checkpoint A1 to A2. Fork B extends B1 to B2. Both chains can satisfy their own internal relation. A verifier shown only A sees a coherent history. A different verifier shown only B sees another coherent history. Neither mathematical check compares the checkpoint against state it never received.

The missing ingredient is memory held outside the producer. A checkpoint-aware witness records the last checkpoint it accepted for a particular log identity—the combination of producer identity and log identifier. On the next submission, it compares the submitted predecessor with its retained state. If they differ, the draft requires refusal and treatment as evidence of log mutation, not a transient error that software should retry away.

This is a small state transition with large governance consequences. Continuity does not emerge from a signature field. It emerges from an independent party preserving prior state, applying the correct comparison and refusing the conflict.

Registration and continuity are different services

The draft can use SCITT registration unchanged. A producer submits the checkpoint as a Signed Statement; a Transparency Service returns a COSE Receipt. That receipt is third-party evidence that the service included the checkpoint under its key. It also provides time evidence only if the Receipt actually carries a signed time claim.

A Transparency Service can perform that registration without knowing the CLL continuity rule. In that case its Receipt does not say that the checkpoint extends the last checkpoint the service accepted for this log. Only a checkpoint-aware service that keeps the previous state and performs the predecessor comparison adds that meaning.

The distinction matters in procurement and incident response. “Registered with a transparency service” is not a sufficient control description. Operators need to know whether the service merely stored or witnessed the statement, whether it checked CLL continuity, which log identity keyed the state, how long that state is retained and what happens on a mismatch.

A direct countersigning witness has the same obligation. It must perform the continuity check before countersigning. Revision 01 is also honest about a nearby unfinished feature: local stub countersignatures remain future work because no shipping implementation constructs the proposed RFC 9338 structure. A private test marker must not be sold as witnessing.

Independence cannot be self-declared

The producer must name the witnesses on which a claim of witnessed status relies. A witness operated by the producer is a replica, not an independent witness. It may improve availability; it does not move the decisive memory outside the authority capable of maintaining both forks.

Multiple witnesses improve the position only under a real independence assumption. A producer trying to sustain equivocation must keep each consulted witness on its assigned branch. More witnesses make that partition harder, but not impossible if they collude, share control or are isolated from one another. A relying party therefore needs a witness roster and a consultation policy, not merely a count.

The coverage edge is equally precise. Entries appended after the last witnessed checkpoint are exactly as strong as entries in an unwitnessed log. A dashboard must not color the live tail green because an older checkpoint was independently accepted. The honest frontier is the last witnessed log_size.

Cadence gives silence a boundary. Publishing is optional, but once a producer elects the regime it must declare a maximum interval between checkpoints and may declare maximum entry lag. A missing checkpoint can then be detected rather than rationalized indefinitely. The backdating window is still not zero: it is bounded by checkpoint cadence plus witness latency.

The witness sees the shape, not the records

CLL deliberately keeps entries local. The witness receives commitments, not the individual receipts, decisions, attestations or SBOM revisions. It can help establish that a committed entry existed no later than the first witnessed checkpoint covering it; that the committed sequence was not rewritten; and that a presented range is complete under that checkpoint.

It cannot independently look up an entry it never received. The producer or another holder must present the record and inclusion proof. If the corresponding archived segment is unavailable, the checkpoint can show that something existed, but it cannot restore the bytes. Revision 01 recommends the honest result “retention expired” rather than pretending the entry never existed.

Nor does witnessing make the content true. A perfectly witnessed log of false records remains false. The checkpoint does not prove that a signer was authorized, that an automated action occurred, that a declared outcome was observed, that this was the producer's only log or that every record the producer created was appended. It constrains one committed history.

This is the useful limit. A local log can make curation inside a committed branch detectable without becoming an oracle for everything outside that branch.

Revision 01 chooses a wire truth

The new revision tightens another boundary that operators often discover too late. An MMR accumulator can be represented as an ordered peak list or folded into one bagged root. The fold is not standardized by the dependencies. Revision 01 therefore requires a canonical-CBOR peak list on the wire and keeps any bagged root as an internal optimization.

That choice prevents two implementations from signing values that look equivalent locally but cannot verify one another's proofs. The document says independent implementations have converged on this split, but the frozen sources contain no interoperability report. The prudent claim is narrower: the draft now defines one checkable wire representation and refuses to standardize the undocumented internal one.

The same discipline applies to maturity. This is an individual Internet-Draft with no stream and no formal IETF standing. Its architecture can inform present control design; it does not establish adoption, deployment or conformance.

Sources