Provenance & Century-Scale Integrity — Research Round 4
Memory Commons reference library · 6 July 2026 · adversarially verified (107 agents, 23 surviving claims — all in the prioritized provenance section; 2 refuted). Raw findings: 2026-07-06-provenance-integrity-round4-findings.json. Sections B (governance precedents), C (funding numbers), D (survey remainder) produced no verified claims and carry to round 5 — treat as unresearched, not negative.
The headline
Every relevant standards body treats century-scale signature validity as an active maintenance process, not a one-time signing act. The IETF, ETSI, and Germany’s BSI all standardize the same renewal-based model. This independently validates the Memory Commons design premise: cryptography only has to survive between renewals — and the etched Merkle root is the passive fallback no standard can offer.
What the standards actually say (all primary sources)
- The problem is standards canon (RFC 4998, IETF Standards Track, 2007, never obsoleted): signatures are not reliable unrenewed over 30+ year archives — hash and public-key algorithms weaken, certificates expire. Evidence Record Syntax exists precisely to prove existence/integrity over “long and possibly undetermined” periods.
- Exactly two renewal mechanisms: timestamp renewal (cheap — re-timestamp the old timestamp, forming a chain) when signature/TSA algorithms weaken, and hash-tree renewal (expensive — re-access and re-hash all archived data under a new archive timestamp) when the hash algorithm itself weakens. Hash-tree renewal is the dominant recurring cost of a century archive; both IETF and BSI specify the same Merkle-tree model that Memory Commons releases already use.
- It is EU law, not vendor marketing: eIDAS Art. 34 permits qualified preservation services only if they can extend signature trustworthiness “beyond the technological validity period” (retained by eIDAS 2.0); ETSI TS 119 512 normatively mandates RFC 4998/6283 renewals; German retention obligations run to 110 years or indefinite (BSI TR-ESOR is the regulator-audited implementation blueprint — the closest operationally proven precedent for our integrity chain).
Post-quantum timeline (the signing plan’s clock)
- FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) are final and in force since 14 Aug 2024. FIPS 206 (FALCON/FN-DSA) still draft as of mid-2026.
- Migration horizon: draft NIST IR 8547 proposes RSA/ECDSA/EdDSA deprecated after 2030, disallowed after 2035 (NSM-10’s federal target; EO 14412 accelerated federal high-value assets to end-2031). Implication: any classical-signed provenance created in 2026 has roughly a 9-year trusted window before its first mandatory renewal or PQC re-anchor.
- SLH-DSA is the conservative archival candidate — security rests on hash functions alone; trade-off is 7–50 KB signatures and slow signing (medium confidence: the archival-suitability conclusion is from a single non-peer-reviewed benchmark preprint).
The newer trust primitives, deflated
- C2PA Content Credentials is not an ISO standard: ISO/CD 22144 sits at stage 30.99 (“under development”); the US voted No with comments on the DIS ballot. Adopt the manifest format pragmatically; claim no compliance. Real-world camera/platform adoption remains unverified.
- Sigstore/Rekor is unsuitable for unattended deep-time reliance: Sigstore’s own docs concede misbehavior “might go undetected” without third-party monitors; the popular “append-only/tamper-proof” characterization was refuted 0–3. Tamper-evident, and only while someone watches.
- Bitcoin/OpenTimestamps anchoring is non-standardized: one unadopted individual Internet-Draft (not IETF-endorsed). Its argument is genuinely interesting for us — anchor proofs depend on no key, certificate, or authority, only artifact bytes + proof file + block headers — but residual failure modes are SHA-256 weakening and ledger availability. Usable as a free supplementary anchor, never the backbone.
Design implications for Memory Commons
- Adopt the renewal calendar as a governance artifact: each release gets an RFC 3161 timestamp at cut; timestamp renewal before algorithm/cert events; hash-tree renewal budgeted for hash migrations (cost scales with corpus size — an argument for a lean, tiered corpus).
- Sign classical now, plan the PQC re-anchor before 2035 — SLH-DSA preferred for anything meant to verify decades out.
- Keep the etched root as the terminal trust anchor. The standards model assumes a living custodian; the plates are what remain when there isn’t one. The two are complements, and we now have primary-source backing for both halves.
- Optionally add OpenTimestamps anchoring per release — zero cost, keyless, explicitly supplementary.
Refuted this round (do not reuse)
- “Rekor is append-only/tamper-proof” (0–3).
- “FIPS 203/204/205’s stated purpose frames century-scale archival rationale” (1–2 — the quantum-resistance purpose is real; the archival framing was the overreach).
Security note
One source page (an IACR ePrint) contained an embedded prompt-injection attempt aimed at automated readers; verifiers flagged and disregarded it. Worth remembering as an operational hazard of automated research pipelines.
Open for round 5
Ostrom principles & archive-governance failure cases; Wikimedia/Internet Archive/Software Heritage/Long Now budgets and Hachette fallout; verified Celestis/LifeShip/CLPS/hosted-payload/qualification pricing; survey remainder (Voyager, Pioneer, LAGEOS, KEO, MoonArk, Lunar Codex, Sanctuary); C2PA adoption reality; whether any archive has executed a full hash-tree renewal at scale and what it cost; PQC arrival in the TSA/LTV chain itself.