Security Model
A passport is only as good as its resistance to forgery.
Immutability
Data payloads are hashed using SHA-256. The hash is anchored to a distributed ledger. If a single comma in the BOM is altered, the hash changes, invalidating the passport.
Verifiable Credentials
Passports are issued as W3C Verifiable Credentials. The issuer signs the payload with their private key. Anyone can verify the authenticity using the issuer's public DID document.
Key Rotation & Revocation
If an issuer's private key is compromised, they can update their DID document to revoke the old key. The passports issued before the breach remain valid (provable via timestamping), while new issuances require the new key.
Data Sovereignty
The passport schema does not require a central database. The JSON-LD data can live on a manufacturer's server, be pinned to IPFS, or be physically encoded into a high-capacity 2D matrix on the cable itself.