Layer 6 · Verification, provenance & anchoring
Canonical reference:
digstore-core::merkle+dig-client-wasm/dig-node/ the DIG Browser C++ (dig_crypto.cc). The trusted root comes only from the chain (anchored-root pinning), never from the serving origin.
The four ordered integrity gates
Applied in this order on a content read:
Gate 1 — per-resource merkle inclusion proof (always-on, fail-closed)
resource_leaf(served_ciphertext) == proof.leaf AND proof.verify() folds to proof.root. See Merkle inclusion proofs. The fullest fail-closed spec is the native VerifyInclusion (dig_crypto.cc:585-677): base64-decode + bounds-check → computed_leaf == proof.leaf → fold with NODE_TAG → root check.
Gate 2 — AES-256-GCM-SIV authenticated decryption (fail-closed)
The content key decrypts each chunk; a tag failure (tamper / wrong key / decoy) yields no plaintext. chunk_lens MUST sum to ciphertext.len() (a hard framing check) — dig_crypto.cc:679-737.