DEV Community

Cover image for AUDIENCE ALGEBRA
Sui Gn
Sui Gn

Posted on

AUDIENCE ALGEBRA

In [.me](https://cleaker.me), who can read a value isn't a permission check. It's a property of the ciphertext: you can open it only if you can derive the key.

Audience Algebra is the spec for writing that "who" as an expression:

A ::= identity | OR(A1, …, An) | AND(A1, …, An)

(alice AND bob) OR carol means carol alone opens, alice and bob together open, and alice alone doesn't.
Every expression reduces to its minimal coalitions, { {alice, bob}, {carol} }, so two ways of writing the same audience get the same id. OR wraps the same key to each member. AND splits the key into XOR shares, one per member.
Nesting is just recursion.

Audience Algebra

Who can open a value, as a closed algebra: monotone formulas over kernel identities, compiled to a tree of key envelopes.

favicon suign.github.io

There's no NOT and no XOR. Encryption can grant access but can't take it away: if you can open, people added next to you don't change that. "Everyone except X" only exists at seal time, and revoking means sealing a new version.
Groups are immutable. The same members make the same group. Adding someone makes a new group, and a name in the tree points to the current one.

Status: the kernel has single-recipient wrapping today, so OR works by composition. AND, nesting and groups are specified and come next.

The nine laws on the page are the test contract.
Full spec: SuiGn.Github.io

Top comments (0)