Skip to content

Glossary

Shared vocabulary across Bedrock. Each term lists where it is authoritative.

Term Definition
Principal An identity the Directory issues tokens for — an operator, a device, or a server. Identified by principal_id.
principal_id Stable Directory-assigned UUID, constant across devices and key rotations. The authoritative identity after envelope verify.
device_id Stable per-device anchor — SHA-256(FIDO credential id) (operators) / SHA-256(device id) (devices). Keys one node row per physical device.
IdentityToken Directory-signed (Ed25519) token carried in every AuthEnvelope; under the PETRA 1.0 contract it binds a principal to roles, classification, canonical callsign, principal_sign_key, and key epoch. Verified by verify_identity_token.
ServerToken Directory-signed token for a router — pins its principal, hostname/port, clearance, coverage cells, opaque router segment, and retained-replay signing public key. Does not ride AuthEnvelope.
AuthEnvelope The wire wrapper: { identity_token, payload, nonce, issued_at_ms, device_signature }. Authenticity = the device signature. Canonical: common/src/auth_envelope.rs.
device_signature 64-byte Ed25519 signature over the canonical signing input, by the device's per-principal key. The per-message authenticity mechanism.
principal_sign_key The public half of the device's per-batch Ed25519 signing key, embedded in the IdentityToken; receivers verify device_signature against it.
Callsign A Directory-controlled tactical label, never a config, session, payload, or UI self-claim. Under the PETRA 1.0 contract every IdentityToken carries a canonical non-blank value. Humans resolve a verified ORBAT appointment first and fall back to the token; things and services always use the token. SitReps and web replay rows snapshot the resolved value; other surfaces resolve live. See operational-tactical-flow.md.
Group key Directory-issued symmetric AES-256 key (/api/group-key, versioned by key_epoch) used by authorized endpoints for payload confidentiality. Relay + Storage never receives it.
Key epoch Monotonic counter for Directory-owned group-key rotation; stamped on the IdentityToken (key_epoch) and returned in the authenticated group-key bundle.
Nonce 12 random bytes per envelope; (principal_id, nonce) is cached for the 60 s replay window.
Replay window ±DEFAULT_REPLAY_WINDOW_MS (60 s) freshness/skew + replay-cache window.
RevocationList Directory-signed, sequence-monotonic snapshot of revoked_principals + devices (revoked device sign-keys). No cert-level revocation (token-only).
Directory The identity authority (directory repo) — FIDO2 login, token + group-key issuance, signing-key publication, revocation feed. Root of trust.
FIDO2 WebAuthn assertion used for operator login; no client certificate is involved.
Token-only identity Identity rests on the Directory's Ed25519 signature over the token. No X.509 client certificate; bound_cert_serial is reserved/removed. Certificates appear only in transport/federation TLS (see pki.md).
Zenoh The pub/sub transport (org.eclipse.zenoh). Routing is by key expression. Production native links use quic/ or tls/; browsers reach the bridge over WSS.
Router / relay A server instance acting as a Zenoh transport router — relays, stores bounded retained prefixes, and federates with equivalent peers over private-CA TLS or QUIC.
Node router attachment A Node connects to exactly one configured tls/ or quic/ router locator. It accepts the router only when the live certificate identity, Zenoh ZID, locator host/port, opaque router key, and current verified ServerToken all agree. Node has no dynamic transport discovery.
Coverage cell / geohash-5 A 5-char geohash in ServerToken.coverage_cells that bounds ordinary field position/heartbeat traffic; Web's separate Directory-issued HQ profile has registered all-cell powers. The key namespace remains cell-first (waypoint/<cell>/...).
Key expression The Zenoh routing path, e.g. waypoint/global/chat/<chat_id>/<msg_id>. See protocol/wire-protocol.md.
Classification banner Client UI indicator of the classification ceiling derived from verified, non-expired sources. It reflects the receive policy but is not itself an enforcement boundary.
Classification floor The lowest applicable Directory-signed ceiling. Retained storage includes ServerToken.clearance; non-retained LIVE receivers enforce the subject and capability ceilings before decode.
Outbox Per-server store-and-forward queue on clients so messages to a disconnected server are not lost. Contract: protocol/outbox.md.
SIDC APP-6E (NATO ADATP-37, MIL-STD-2525E equivalent) Symbol Identification Code. APP-6E is mandatory; internally Bedrock uses the 30-char form only — the native parser (SIDC_PATTERN) matches 30-char codes only, and the wire/persistence carry 30-char. The interop gateway may accept 20-char legacy / pre-E codes on ingress but normalizes them to 30-char before they enter Bedrock; non-normalizable codes are rejected. Parser in common/src/sidc/; rendered on Android via mil-sym-android and on web via mil-sym-ts (parity renderer).
APP-6 / MIL-STD-2525 NATO military map-symbology standard. The only supported edition is APP-6E (ADATP-37 / MIL-STD-2525E), which the SIDC encodes; earlier editions are not accepted.
CoT / TAK Cursor-on-Target / TAK — the ATAK ecosystem interop format handled by the gateway.
Trust bundle Device-managed bootstrap root or CA used to validate a router's TLS certificate. With no custom CA configured, the client uses system trust. Persistence or write failure for a configured CA is terminal and must never fall back to system trust.
COP Common operational picture — the shared, fused tactical map view operators work from.

Targeting & effects (web)

Term Definition
Target / target state machine An op-scoped engageable entity moving through detected → confirmed → allocated → engaged → assessed (terminal rejected). Every transition is recorded append-only in target_transitions (audit). Authoritative in web.
Target effect / weaponeering The HTTP side of call-for-fire: an effect offered against a target moves offered → allocated → expended. Allocating an effect drives the target confirmed → allocated; expending drives allocated → engaged. Authoritative in web.
Detection An op-scoped force observation (kind = detection | ew_emitter), distinct from the high-volume track_hits feed. Can be nominated onto the target board. Authoritative in web.
source_kind / provenance Attribution enum ai | sensor | feed | human | manual (with a free-text source_label) carried on detections and targets to record where the information came from. Authoritative in web.
CAT-1 / TLE Target-location-error category. tle_error_m is the error in metres (CAT-1 = < 6 m); tle_category buckets it cat1..cat4. Authoritative in web.

Tracks & feeds (web + NiFi)

Term Definition
track_hits The high-volume feed-track table. Rows are written by NiFi (external feeds) or by operators (self-position). Schema in web; feed producers live in bedrock-nifi-processors. Speed is stored canonically in metres/second (SI), system-wide — ingest, persistence, and the mesh all carry speed as m/s. Display layers convert to knots, km/h, etc. as needed, keyed on the track's SIDC (symbol domain), e.g. knots for air/sea symbols. Producers must push m/s.
track_feed layer / source_type A feed layer type on the COP. source_type is the feed-kind enum ais | adsb | radar | geojson and lives on the layer (a feed is all one kind), not per hit — carried onto each position at fan-out and CHECK-enforced. The provider/feed name (Telesto, Nightingale) is separate free-text provenance (source). Authoritative in web (feeds produced by NiFi).
nifi_ingest role A least-privilege Postgres role NiFi uses to INSERT into track_hits — column-scoped and validation-triggered. Defined in a web migration; used by NiFi.
Track fusion / fused track Client-side-only correlation of multi-source tracks: identity dedup + spatial gating + confidence + merge/split. A server-side fused_tracks table is deferred (see status & roadmap). Authoritative in web.
Track confidence A 0..1 confidence value surfaced on fused/feed tracks, bucketed high/medium/low for COP display. Authoritative in web.

Feed-ingest API & access control (web)

Term Definition
API credential A signed HS256 JWT plus a DB revocation-registry row, used by machine clients on /api/feed/*. Authoritative in web; see protocol/ingest-api.md.
Scope A route-level permission (e.g. detections:write) enforced by middleware; a missing scope yields 403. Authoritative in web.
ops / op-claim An operation-id allowlist on the credential (or ["*"] for all ops), enforced per-row by the controller. Authoritative in web.
Revocation registry The api_credentials table; kid is live-checked per request. Distinct from the Directory revocation list. Authoritative in web.
kid The opaque JWT key id naming the credential; looked up in the revocation registry. Authoritative in web.

Planning & replay (web)

Term Definition
Combat estimate (Seven Questions) The Seven Questions planning process — the EDGE (Android) process, not a web artifact. A completed field estimate publishes as a plan record up the record plane; web authors orders over the same records.
Comms net A planning/topology graph (units × nets × channels) with channel-health. Read-side only — not the live voice/chat transport. Authoritative in web.
Plan record A record-plane plan-of-record row (plan_records): situation / mission / tasks[] / control measures / attachments, versioned by a monotonic seq per plan id — publish stamps seq+1, latest wins on devices, every version kept for replay. Task timing (H-hour offset + duration) lives on tasks[]; execution state derives from reports, never hand-set.
Replay export / ORK An NDJSON timeline export bundle (schemaVersion: 1). Authoritative in web; see protocol/replay-export.md.

EW & control measures (web)

Term Definition
EW zone / EW emitter Authored electronic-warfare zones (jamming, gps_denial, ao, fire-control) and emitters with directional lobes / 3D coverage volumes. Geometry only — not RF propagation. Authoritative in web.
Threat ring An illustrative weapon-range envelope used as a planning default. Not authoritative threat intelligence. Authoritative in web.
TCM Tactical control measure; the web catalog mirrors Android's.