Development phase

Cryptographic review authentication

Zero-knowledge infrastructure that lets platforms distinguish reviews carrying cryptographic evidence of configured eligibility from unverified feedback — without suppressing the latter. In active development, with working prototypes and five hash-locked Phase 1 evidence bundles.

REF establishes cryptographic provenance between a review and an eligible customer event.

It does not determine whether the review is true.

Development status

Four subsystems, each with an implemented state and the evidence that establishes it.

Cryptography

Working
Groth16 ZK-SNARK system with 1,155 R1CS constraints. BN254 curve; current exTNFS-aware estimates place the curve at no more than 100-bit security.

Consensus

PBFT
Byzantine fault-tolerant consensus implemented and tested. TLA+ model-checked with 0 invariant violations.

Testing

Implementation tests
Automated implementation tests are maintained; no aggregate pass-count claim is presented without a bound run artifact.

Verification

5 evidence bundles
Five Phase 1 evidence bundles are hash-locked. They cover consensus and token-lifecycle model checking, threat-model analysis, circuit-audit evidence, and MC-500 mechanism analysis; assurance scope differs by artifact.
1,155
Circuit constraints
8/8
Negative vectors rejected
4
Test-network nodes
4
EV-008 safety invariants checked

Verification evidence

Every claim on this page traces to a locked, hashed artifact in the REF verification repository. Internal verification follows Rigorous Digital Engineering methodology.

Consensus TLA+

Locked
EV-008Bounded single-view TLC run (MaxView=0): 152,658,351 states generated; 17,588,825 distinct; queue exhausted; no error found for Agreement, LockedValueSafety, UniqueHonestProposalPerRound, and PrepareVotesReferenceProposals.

Token lifecycle TLA+

Locked
EV-009Seven invariants model-checked across 269 states, including AtMostOneTokenPerPurchase and NullifierUniqueness. 0 violations.

Mechanism validation

Locked
MC-500Analytic mechanism guard: for α > 0, marginal modeled capture cost exceeds marginal modeled reward for all v ≥ 0 iff α·C₀·N^γ > k. All 500 archived parameter rows satisfy the guard; minimum observed ratio 652.217×. Generator lineage for the archived rows is not established in the current repository.

Threat model

Locked
EV-010Fourteen attack scenarios across six adversary classes. Six tracked properties are mapped to threat/evidence artifacts where recorded; assurance scope differs by property.

Internal ZK circuit audit

Locked
EV-011Internal constraint audit of the token circuit. Eight findings documented. The v1.1 record shows code changes for F-001, F-002, F-004, F-005, and F-007; F-003 is documented for a v2 fix, F-006 is documented as a v1 design boundary, and F-008 is monitored. 8/8 recorded negative vectors were rejected at witness generation.
5/5
Evidence bundles hash-locked
1,155
R1CS constraints
0
EV-008 invariant violations
500/500
Archived rows satisfy guard
8/8
Vectors rejected

Technical foundation

Zero-knowledge proofs

  • Circom token circuit implemented; internal EV-011 constraint audit recorded
  • Groth16 on BN254 with trusted setup
  • Python SDK operational
  • FastAPI REST endpoints

Consensus protocol

  • PBFT with Ed25519 signatures
  • Rotating committee design
  • BFT fault model: f < n/3
  • Bounded TLA+ safety model checking

Security model

  • Dolev-Yao network adversary
  • Minority validator compromise
  • Constraint-level circuit evidence and negative-vector testing
  • Phase 1 evidence bundle hash-locked; independent external audit not yet completed
  • Not yet production-audited — independent review planned

Development roadmap

PHASE 1 — COMPLETE

Cryptographic foundation

Zero-knowledge proof system implemented and tested.

PHASE 2 — COMPLETE

Consensus protocol

PBFT consensus with Byzantine fault tolerance.

PHASE 3 — COMPLETE

Evidence bundle lock

Five Phase 1 evidence bundles are hash-locked: consensus and token-lifecycle model checking, threat-model analysis, circuit-audit evidence, and MC-500 mechanism analysis. Assurance scope differs by artifact.

PHASE 4 — NEXT

Planned external review and network expansion

Target independent protocol review. Scale the validator network and optimise performance.

PHASE 5 — PLANNED

Production deployment

Enterprise pilots and compliance certification.

Technical collaboration

Five Phase 1 evidence bundles are hash-locked. Independent external audit remains a planned next-stage activity; we welcome academic collaboration on advanced formal properties.

TLA+ modellingCOMPLETE
SAW / CryptolSCOPED
Game theoryCOMPLETE
Information flowSCOPED