PageSourceSearch

https://tumitrust.com/docs/assets/js/9b0b2f86.3c852c5c.js

js tumitrust.com collected 2026-09-28 06:44:50 UTC 16,023 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkdocs_new=globalThis.webpackChunkdocs_new||[]).push([[9394],{25279:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>o,contentTitle:()=>l,default:()=>h,frontMatter:()=>c,metadata:()=>i,toc:()=>d});const i=JSON.parse('{"id":"pti/specification/v1.0/architecture","title":"Architecture Specification","description":"Normative PTI v1.0 architecture, trust planes, components, data flows, and deployment topologies.","source":"@site/docs/pti/specification/v1.0/architecture.md","sourceDirName":"pti/specification/v1.0","slug":"/pti/specification/v1.0/architecture","permalink":"/docs/pti/specification/v1.0/architecture","draft":false,"unlisted":false,"tags":[],"version":"current","sidebarPosition":2,"frontMatter":{"title":"Architecture Specification","description":"Normative PTI v1.0 architecture, trust planes, components, data flows, and deployment topologies.","sidebar_position":2},"sidebar":"ptiSidebar","previous":{"title":"PTI Specification v1.0","permalink":"/docs/pti/specification/v1.0/"},"next":{"title":"Security Specification","permalink":"/docs/pti/specification/v1.0/security"}}');var r=t(74848),s=t(28453);const c={title:"Architecture Specification",description:"Normative PTI v1.0 architecture, trust planes, components, data flows, and deployment topologies.",sidebar_position:2},l="Architecture Specification",o={},d=[{value:"Normative language",id:"normative-language",level:2},{value:"Architectural principles",id:"architectural-principles",level:2},{value:"Trust planes",id:"trust-planes",level:2},{value:"Production plane",id:"production-plane",level:3},{value:"Fabric plane",id:"fabric-plane",level:3},{value:"Consumption plane",id:"consumption-plane",level:3},{value:"Core data flow",id:"core-data-flow",level:2},{value:"Trust context binding",id:"trust-context-binding",level:2},{value:"Identity resolution",id:"identity-resolution",level:2},{value:"Deployment topologies",id:"deployment-topologies",level:2},{value:"Federated registry",id:"federated-registry",level:3},{value:"Centralized fabric",id:"centralized-fabric",level:3},{value:"Edge ingest",id:"edge-ingest",level:3},{value:"Non-functional requirements",id:"non-functional-requirements",level:2},{value:"Security architecture integration",id:"security-architecture-integration",level:2},{value:"Related documents",id:"related-documents",level:2}];function a(e){const n={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",mermaid:"mermaid",ol:"ol",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.header,{children:(0,r.jsx)(n.h1,{id:"architecture-specification",children:"Architecture Specification"})}),"\n",(0,r.jsx)(n.p,{children:"This document defines the normative architecture for Portable Trust Infrastructure (PTI) v1.0."}),"\n",(0,r.jsx)(n.h2,{id:"normative-language",children:"Normative language"}),"\n",(0,r.jsxs)(n.p,{children:["The key words ",(0,r.jsx)(n.strong,{children:"MUST:"})," ",(0,r.jsx)(n.strong,{children:"MUST NOT:"})," ",(0,r.jsx)(n.strong,{children:"REQUIRED:"})," ",(0,r.jsx)(n.strong,{children:"SHALL:"})," ",(0,r.jsx)(n.strong,{children:"SHALL NOT:"})," ",(0,r.jsx)(n.strong,{children:"SHOULD:"})," ",(0,r.jsx)(n.strong,{children:"SHOULD NOT:"})," ",(0,r.jsx)(n.strong,{children:"RECOMMENDED:"})," ",(0,r.jsx)(n.strong,{children:"MAY:"})," and ",(0,r.jsx)(n.strong,{children:"OPTIONAL"})," are to be interpreted as described in ",(0,r.jsx)(n.a,{href:"https://datatracker.ietf.org/doc/html/rfc2119",children:"RFC 2119"}),"."]}),"\n",(0,r.jsx)(n.h2,{id:"architectural-principles",children:"Architectural principles"}),"\n",(0,r.jsxs)(n.p,{children:["PTI implementations ",(0,r.jsx)(n.strong,{children:"MUST"})," adhere to the following principles:"]}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Separation of production and consumption:"})," trust signals are generated independently of institutional lookup decisions."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Context isolation:"})," signals, scores, and lookups ",(0,r.jsx)(n.strong,{children:"MUST"})," be scoped to explicit trust contexts."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Provenance by default:"})," every derived outcome ",(0,r.jsx)(n.strong,{children:"MUST"})," retain an auditable evidence chain."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Programmable exchange:"})," producers and consumers interact through versioned APIs and event schemas."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Subject-centric identity:"})," a portable identifier (",(0,r.jsx)(n.code,{children:"pti_id"}),") ",(0,r.jsx)(n.strong,{children:"MUST"})," survive partner and context changes."]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"trust-planes",children:"Trust planes"}),"\n",(0,r.jsxs)(n.p,{children:["PTI defines three logical planes. Physical deployment ",(0,r.jsx)(n.strong,{children:"MAY"})," colocate components, but logical boundaries ",(0,r.jsx)(n.strong,{children:"MUST"})," be enforced."]}),"\n",(0,r.jsx)(n.h3,{id:"production-plane",children:"Production plane"}),"\n",(0,r.jsxs)(n.p,{children:["The production plane accepts ",(0,r.jsx)(n.strong,{children:"trust events"})," from ",(0,r.jsx)(n.strong,{children:"trust producers:"})," validates them against catalogued event types, and materializes ",(0,r.jsx)(n.strong,{children:"trust signals"})," and ",(0,r.jsx)(n.strong,{children:"trust evidence"}),"."]}),"\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Component"}),(0,r.jsx)(n.th,{children:"Responsibility"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Ingest Gateway"})}),(0,r.jsx)(n.td,{children:"Authentication, schema validation, rate control, idempotency"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Event Normalizer"})}),(0,r.jsx)(n.td,{children:"Maps partner payloads to canonical trust events"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Signal Materializer"})}),(0,r.jsx)(n.td,{children:"Derives normalized trust signals with context binding"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Evidence Store"})}),(0,r.jsx)(n.td,{children:"Persists attestations, documents, and verification artifacts"})]})]})]}),"\n",(0,r.jsxs)(n.p,{children:["Producers ",(0,r.jsx)(n.strong,{children:"MUST NOT"})," write directly to consumer-facing lookup stores."]}),"\n",(0,r.jsx)(n.h3,{id:"fabric-plane",children:"Fabric plane"}),"\n",(0,r.jsxs)(n.p,{children:["The fabric plane maintains the ",(0,r.jsx)(n.strong,{children:"trust graph:"})," resolves identities, routes assertions, and executes intelligence derivation."]}),"\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Component"}),(0,r.jsx)(n.th,{children:"Responsibility"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Trust Registry"})}),(0,r.jsxs)(n.td,{children:["Subject directory, ",(0,r.jsx)(n.code,{children:"pti_id"})," allocation, entitlement registry"]})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Trust Exchange"})}),(0,r.jsx)(n.td,{children:"Assertion routing, cross-producer fan-out, policy enforcement"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Trust Intelligence Engine"})}),(0,r.jsx)(n.td,{children:"Context scoring, confidence derivation, explainability"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Trust Graph Store"})}),(0,r.jsx)(n.td,{children:"Relationships, endorsements, and temporal signal history"})]})]})]}),"\n",(0,r.jsxs)(n.p,{children:["The fabric plane ",(0,r.jsx)(n.strong,{children:"MUST"})," enforce governance policy before signals influence consumer-visible outcomes."]}),"\n",(0,r.jsx)(n.h3,{id:"consumption-plane",children:"Consumption plane"}),"\n",(0,r.jsxs)(n.p,{children:["The consumption plane serves ",(0,r.jsx)(n.strong,{children:"trust consumers"})," at decision time."]}),"\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Component"}),(0,r.jsx)(n.th,{children:"Responsibility"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Trust Lookup API"})}),(0,r.jsx)(n.td,{children:"Context-scoped intelligence retrieval"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Trust Verification API"})}),(0,r.jsx)(n.td,{children:"Assertion and report authenticity checks"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Policy Gateway"})}),(0,r.jsx)(n.td,{children:"Entitlement, consent, and data-minimization enforcement"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Explainability Renderer"})}),(0,r.jsx)(n.td,{children:"Structured drivers, coverage gaps, and provenance slices"})]})]})]}),"\n",(0,r.jsxs)(n.p,{children:["Consumers ",(0,r.jsx)(n.strong,{children:"MUST"})," receive only fields entitled under the active trust context and lookup tier."]}),"\n",(0,r.jsx)(n.h2,{id:"core-data-flow",children:"Core data flow"}),"\n",(0,r.jsx)(n.mermaid,{value:"sequenceDiagram\n  participant P as Trust Producer\n  participant IG as Ingest Gateway\n  participant EN as Event Normalizer\n  participant TX as Trust Exchange\n  participant TIE as Intelligence Engine\n  participant C as Trust Consumer\n\n  P->>IG: Submit trust event\n  IG->>EN: Validate and normalize\n  EN->>TX: Canonical event\n  TX->>TIE: Signal update\n  TIE->>TIE: Refresh context outcomes\n  C->>TIE: Trust lookup (contexts[])\n  TIE->>C: Trust intelligence + explainability"}),"\n",(0,r.jsx)(n.h2,{id:"trust-context-binding",children:"Trust context binding"}),"\n",(0,r.jsxs)(n.p,{children:["Every event, signal, and lookup ",(0,r.jsx)(n.strong,{children:"MUST"})," include a ",(0,r.jsx)(n.code,{children:"context_id"}
1)," referencing a registered trust context. Contexts ",(0,r.jsx)(n.strong,{children:"MUST"})," be declared in the registry profile and ",(0,r.jsx)(n.strong,{children:"MUST NOT"})," be inferred implicitly from producer identity."]}),"\n",(0,r.jsxs)(n.p,{children:["Lens contexts (cross-cutting views) ",(0,r.jsx)(n.strong,{children:"MAY"})," be derived from primary contexts according to published derivation rules. Derived contexts ",(0,r.jsx)(n.strong,{children:"MUST"})," declare upstream context dependencies."]}),"\n",(0,r.jsx)(n.h2,{id:"identity-resolution",children:"Identity resolution"}),"\n",(0,r.jsxs)(n.p,{children:["The Trust Registry ",(0,r.jsx)(n.strong,{children:"MUST"}),":"]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Allocate stable ",(0,r.jsx)(n.code,{children:"pti_id"})," values for portable subjects."]}),"\n",(0,r.jsx)(n.li,{children:"Maintain partner-local entity identifier mappings."}),"\n",(0,r.jsx)(n.li,{children:"Support deterministic and probabilistic resolution with explicit confidence metadata."}),"\n",(0,r.jsx)(n.li,{children:"Reject merges that violate governance or consent policy."}),"\n"]}),"\n",(0,r.jsxs)(n.p,{children:["Resolution outcomes ",(0,r.jsx)(n.strong,{children:"MUST"})," be auditable and ",(0,r.jsx)(n.strong,{children:"SHOULD"})," expose match rationale to entitled consumers."]}),"\n",(0,r.jsx)(n.h2,{id:"deployment-topologies",children:"Deployment topologies"}),"\n",(0,r.jsx)(n.h3,{id:"federated-registry",children:"Federated registry"}),"\n",(0,r.jsxs)(n.p,{children:["Multiple registry operators synchronize subject directories through signed exchange messages. This topology ",(0,r.jsx)(n.strong,{children:"MUST"})," use the interoperability profile for registry replication."]}),"\n",(0,r.jsx)(n.h3,{id:"centralized-fabric",children:"Centralized fabric"}),"\n",(0,r.jsxs)(n.p,{children:["A single operator hosts registry, exchange, and intelligence services. This topology ",(0,r.jsx)(n.strong,{children:"SHOULD"})," still expose logically separate API surfaces for producer, consumer, and admin roles."]}),"\n",(0,r.jsx)(n.h3,{id:"edge-ingest",children:"Edge ingest"}),"\n",(0,r.jsxs)(n.p,{children:["Producers deploy regional ingest gateways that forward normalized events to a central fabric. Edge gateways ",(0,r.jsx)(n.strong,{children:"MUST"})," perform schema validation and ",(0,r.jsx)(n.strong,{children:"SHOULD"})," buffer with at-least-once delivery semantics."]}),"\n",(0,r.jsx)(n.h2,{id:"non-functional-requirements",children:"Non-functional requirements"}),"\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Requirement"}),(0,r.jsx)(n.th,{children:"Normative baseline"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Availability"})}),(0,r.jsxs)(n.td,{children:["Lookup APIs ",(0,r.jsx)(n.strong,{children:"SHOULD"})," target 99.9% monthly availability for entitled tiers."]})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Latency"})}),(0,r.jsxs)(n.td,{children:["Synchronous lookups ",(0,r.jsx)(n.strong,{children:"SHOULD"})," complete within 2 seconds at P95 under nominal load."]})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Durability"})}),(0,r.jsxs)(n.td,{children:["Accepted events ",(0,r.jsx)(n.strong,{children:"MUST"})," be durably stored before acknowledgment."]})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Observability"})}),(0,r.jsxs)(n.td,{children:["All planes ",(0,r.jsx)(n.strong,{children:"MUST"})," emit correlation identifiers traceable across ingest and lookup."]})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Clock sync"})}),(0,r.jsxs)(n.td,{children:["Timestamps ",(0,r.jsx)(n.strong,{children:"MUST"})," use UTC with ISO 8601 encoding."]})]})]})]}),"\n",(0,r.jsx)(n.h2,{id:"security-architecture-integration",children:"Security architecture integration"}),"\n",(0,r.jsxs)(n.p,{children:["Cryptographic protections, tenant isolation, and audit logging ",(0,r.jsx)(n.strong,{children:"MUST"})," conform to the ",(0,r.jsx)(n.a,{href:"/docs/pti/specification/v1.0/security",children:"Security Specification"}),". Authentication and authorization ",(0,r.jsx)(n.strong,{children:"MUST"})," conform to ",(0,r.jsx)(n.a,{href:"/docs/pti/specification/v1.0/authentication-model",children:"Authentication Model"})," and ",(0,r.jsx)(n.a,{href:"/docs/pti/specification/v1.0/authorization-model",children:"Authorization Model"}),"."]}),"\n",(0,r.jsx)(n.h2,{id:"related-documents",children:"Related documents"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/specification/v1.0/reference-data-model",children:"Reference Data Model"})}),"\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/specification/v1.0/reference-event-model",children:"Reference Event Model"})}),"\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/reference-architecture/",children:"Reference Architecture"})}),"\n"]})]})}function h(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(a,{...e})}):a(e)}},28453:(e,n,t)=>{t.d(n,{R:()=>c,x:()=>l});var i=t(96540);const r={},s=i.createContext(r);function c(e){const n=i.useContext(s);return i.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function l(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:c(e.components),i.createElement(s.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.