The control model
PastWipe adds a policy-bound trust condition at a control point. Underneath, the RepSec protocol carries and verifies that condition. A live request presented with the required evidence is allowed; a copied or replayed payload without valid evidence is denied.
Allowed path
- The producer associates the asset with the agreed policy context.
- The request reaches the selected enforcement point with its attestation.
- The enforcement point validates the evidence and current policy condition.
- If the condition is satisfied, the request is allowed and the decision is recorded.
Denied path
- A copied or replayed payload reaches the enforcement point.
- The required attestation is missing, invalid or no longer permitted by policy.
- Validation fails and the request is denied with an auditable reason.
What to demonstrate
A useful demonstration shows both paths, a policy change or revocation, and the resulting evidence record. Performance observations come from the agreed evaluation environment.
