Matrix Scroll: signed machine-action records with offline verification, an independent verifier, a post-quantum overlay and NIST ACVP evidence (technical report v1.0, release 0.8.0)
Technical report describing release 0.8.0 of Matrix Scroll (github.com/SSX360/matrixscroll, Apache-2.0; specification and vectors CC0 1.0): an open protocol and Python SDK that records Git commits, machine actions and MCP tool surfaces as Ed25519-signed envelopes over a canonical JSON encoding, verifiable offline, with a CI gate that fails closed on an empty or unsigned commit range. The report states the protocol (canonical encoding, device identifier, signature block, verification procedure, document types, range verification), the evidence that the implementation follows the specification (thirteen committed conformance vectors; a second, independent verifier written from the specification text that agrees with the SDK on every vector and on 500 random documents; TLA+ models checked by TLC in CI), the optional post-quantum overlay (FIPS 204 ML-DSA-87 by default, FIPS 205 SLH-DSA available) with its NIST ACVP known-answer results, the ML-KEM-1024 primitives that open the CNSA 2.0 full-suite track, the hardware signer (NXP SE050 behind an RP2350 USB bridge, Ed25519 only), a dated comparison with Sigstore, GitHub attestations, gittuf, MCP scanners and 2025-2026 agent-receipt projects, and the claims the project does not make. Not peer reviewed. Evidence mapping, not a certification claim: no CAVP or CMVP validation is claimed, and the Open Quantum Safe project does not recommend relying on liboqs in production.
Authors
- Ryan James York (ORCID: https://orcid.org/0009-0007-5979-7949)
Institutions
- IDEX Corporation (United States) (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-12
- DOI
- https://doi.org/10.5281/zenodo.22730567
- Primary Topic
- Scientific Computing and Data Management
- Type
- article
- Field-Weighted Citation Impact
- 0.00