| Principal |
An identity the Directory issues tokens for — an operator, a device, or a server. Identified by principal_id. |
principal_id |
Stable Directory-assigned UUID, constant across devices and key rotations. The authoritative identity after envelope verify. |
device_id |
Stable per-device anchor — SHA-256(FIDO credential id) (operators) / SHA-256(device id) (devices). Keys one node row per physical device. |
IdentityToken |
Directory-signed (Ed25519) token carried in every AuthEnvelope; under the PETRA 1.0 contract it binds a principal to roles, classification, canonical callsign, principal_sign_key, and key epoch. Verified by verify_identity_token. |
ServerToken |
Directory-signed token for a router — pins its principal, hostname/port, clearance, coverage cells, opaque router segment, and retained-replay signing public key. Does not ride AuthEnvelope. |
AuthEnvelope |
The wire wrapper: { identity_token, payload, nonce, issued_at_ms, device_signature }. Authenticity = the device signature. Canonical: common/src/auth_envelope.rs. |
device_signature |
64-byte Ed25519 signature over the canonical signing input, by the device's per-principal key. The per-message authenticity mechanism. |
principal_sign_key |
The public half of the device's per-batch Ed25519 signing key, embedded in the IdentityToken; receivers verify device_signature against it. |
| Callsign |
A Directory-controlled tactical label, never a config, session, payload, or UI self-claim. Under the PETRA 1.0 contract every IdentityToken carries a canonical non-blank value. Humans resolve a verified ORBAT appointment first and fall back to the token; things and services always use the token. SitReps and web replay rows snapshot the resolved value; other surfaces resolve live. See operational-tactical-flow.md. |
| Group key |
Directory-issued symmetric AES-256 key (/api/group-key, versioned by key_epoch) used by authorized endpoints for payload confidentiality. Relay + Storage never receives it. |
| Key epoch |
Monotonic counter for Directory-owned group-key rotation; stamped on the IdentityToken (key_epoch) and returned in the authenticated group-key bundle. |
| Nonce |
12 random bytes per envelope; (principal_id, nonce) is cached for the 60 s replay window. |
| Replay window |
±DEFAULT_REPLAY_WINDOW_MS (60 s) freshness/skew + replay-cache window. |
RevocationList |
Directory-signed, sequence-monotonic snapshot of revoked_principals + devices (revoked device sign-keys). No cert-level revocation (token-only). |
| Directory |
The identity authority (directory repo) — FIDO2 login, token + group-key issuance, signing-key publication, revocation feed. Root of trust. |
| FIDO2 |
WebAuthn assertion used for operator login; no client certificate is involved. |
| Token-only identity |
Identity rests on the Directory's Ed25519 signature over the token. No X.509 client certificate; bound_cert_serial is reserved/removed. Certificates appear only in transport/federation TLS (see pki.md). |
| Zenoh |
The pub/sub transport (org.eclipse.zenoh). Routing is by key expression. Production native links use quic/ or tls/; browsers reach the bridge over WSS. |
| Router / relay |
A server instance acting as a Zenoh transport router — relays, stores bounded retained prefixes, and federates with equivalent peers over private-CA TLS or QUIC. |
| Node router attachment |
A Node connects to exactly one configured tls/ or quic/ router locator. It accepts the router only when the live certificate identity, Zenoh ZID, locator host/port, opaque router key, and current verified ServerToken all agree. Node has no dynamic transport discovery. |
| Coverage cell / geohash-5 |
A 5-char geohash in ServerToken.coverage_cells that bounds ordinary field position/heartbeat traffic; Web's separate Directory-issued HQ profile has registered all-cell powers. The key namespace remains cell-first (waypoint/<cell>/...). |
| Key expression |
The Zenoh routing path, e.g. waypoint/global/chat/<chat_id>/<msg_id>. See protocol/wire-protocol.md. |
| Classification banner |
Client UI indicator of the classification ceiling derived from verified, non-expired sources. It reflects the receive policy but is not itself an enforcement boundary. |
| Classification floor |
The lowest applicable Directory-signed ceiling. Retained storage includes ServerToken.clearance; non-retained LIVE receivers enforce the subject and capability ceilings before decode. |
| Outbox |
Per-server store-and-forward queue on clients so messages to a disconnected server are not lost. Contract: protocol/outbox.md. |
| SIDC |
APP-6E (NATO ADATP-37, MIL-STD-2525E equivalent) Symbol Identification Code. APP-6E is mandatory; internally Bedrock uses the 30-char form only — the native parser (SIDC_PATTERN) matches 30-char codes only, and the wire/persistence carry 30-char. The interop gateway may accept 20-char legacy / pre-E codes on ingress but normalizes them to 30-char before they enter Bedrock; non-normalizable codes are rejected. Parser in common/src/sidc/; rendered on Android via mil-sym-android and on web via mil-sym-ts (parity renderer). |
| APP-6 / MIL-STD-2525 |
NATO military map-symbology standard. The only supported edition is APP-6E (ADATP-37 / MIL-STD-2525E), which the SIDC encodes; earlier editions are not accepted. |
| CoT / TAK |
Cursor-on-Target / TAK — the ATAK ecosystem interop format handled by the gateway. |
| Trust bundle |
Device-managed bootstrap root or CA used to validate a router's TLS certificate. With no custom CA configured, the client uses system trust. Persistence or write failure for a configured CA is terminal and must never fall back to system trust. |
| COP |
Common operational picture — the shared, fused tactical map view operators work from. |