codexproof

glossary / SCITT

the IETF's Supply Chain Integrity, Transparency and Trust working group - an architecture for append-only transparency registries where issuers publish signed statements about artifacts and verifiers check registry receipts.

sigstorerats and attestation
SCITT - The shelf: SCITT's registries could pin envelope existence in time - the composition that closes the backdating edge

The shelf: SCITT's registries could pin envelope existence in time - the composition that closes the backdating edge.

Etymology and backstory

chartered at the IETF in 2022-2023 to generalize the certificate-transparency trick (public append-only logs forcing honesty) beyond certificates to arbitrary supply-chain claims - SBOMs, attestations, audit statements. COSE-signed statements, Merkle-tree registries, receipts as inclusion proofs.

Ecosystem

early adopters in firmware and critical-infrastructure supply chains; the standards-track sibling of Sigstore's Rekor log.

In codexproof

cited as the transparency-layer neighbor and a natural future composition: SCITT-style receipts could give codexproof envelopes third-party existence proofs (this envelope was registered at time T), patching the one thing self-contained verification cannot prove alone - that an artifact existed before a given moment. The paper's external-timestamping gap (Q19's backdating edge) is exactly SCITT-shaped.

"SCITT builds public bulletin boards for signed claims - pin our envelopes to one and the backdating edge in our threat model closes."
References: IETF SCITT working group architecture drafts; Laurie, Langley, Kasper, RFC 6962 Certificate Transparency (2013) - the ancestral trick.

All terms · Questions & answers · The verifier