Skip to content

Groups

A Gruppe Kollektiver Akteur mit Mitgliedern, Policy, Autoritäts-Log und Dokumenten. Identität ist der Digest der Genesis-Operation, Adresse die Gruppen-DID. GlossarGroup A collective actor with members, a policy, an authority log, and documents. Its identity is the digest of its genesis operation; its address is its group DID. Glossary is a place its Mitglied Zustand im Autoritäts-Log plus Schlüsselbesitz, kein Zertifikat. Eintritt nur durch explizite, kryptografisch gebundene Zustimmung. GlossarMember A fact in the authority log plus key possession, not a certificate. Entered only by explicit, cryptographically bound consent. Glossary hold together: an encrypted document on each member’s device, with a Autoritätslog Der nur anwachsende Operations-DAG, der in der Genesis-Operation wurzelt; die einzige Quelle des Berechtigungszustands. GlossarAuthority log The append-only operation DAG rooted in the genesis operation; the sole source of authorization state. Glossary of who joined, who left and which Policy Gruppendefinierte Daten, die je Regelschlüssel angeben, welcher Nachweis die Entscheidungsregel der Gruppe erfüllt. GlossarPolicy Group-defined data stating, per rule key, which proof satisfies the group’s decision rule. Glossary apply. Inside it is the group’s shared space: replicated state that holds the app’s data: events, places, tasks, messages. The protocol does not care what the data is; it cares who may read and change it.

The log is the group’s memory of itself. Every entry is a signed act of one member: founding the group, admitting someone, removing someone, changing a rule. Each device reads the same log in the same way and arrives at the same answer to who belongs and what is allowed. No server decides who belongs.

The group’s identity is the digest of its founding entry, not a key anyone holds, so nobody owns the group or can take it over.

Spec: Access Layer §3

The group states its own rules as data: who may invite, who may admit, who may remove, whether a newcomer needs Bürgschaft Die signierte Aussage eines Mitglieds für genau eine Aufnahme genau einer Person (vouch@2, ein DTG EndorsementCredential), gebunden an deren Annahme; eine Bürgschaftsregel der Gruppe zählt sie für diese eine Aufnahme und keine spätere. Wie der Bürge die Person kennt, begegnet oder vorgestellt, ist sein eigenes Wort, nicht geprüft; ein Begegnungs-Credential ist keine Bürgschaft. GlossarVouch A member's signed statement for exactly one admission of exactly one person (vouch@2, a DTG EndorsementCredential), bound to that person's accept; a group's vouch rule counts it for this one admission and no later one. How the voucher knows the person, met or introduced, is their own word, not verified; an encounter credential is not a vouch. Glossary, and who may change the rules. Every device checks them before it accepts a change.

A founder in charge is only the simplest rule, and the group can replace it, for example with two members deciding together, or with every member having a say in removals. The rules for changing the rules are protected in the same way, so a group cannot lock itself out of its own constitution.

Spec: Access Layer §4

Someone who knows you invites you. The Einladung Signiertes Angebot eines Mitglieds an genau eine Person, der Gruppe beizutreten: ein DTG-Einladungs-Credential, das die Gruppe über ihren Genesis-Digest und die Person über den Mitgliedsanker nennt, den sie für diese Gruppe abgeleitet hat. Es trägt die Karte der einladenden Person, kein Schlüsselmaterial und keine Operation. GlossarInvite A member's signed offer of membership to exactly one person: a DTG invitation credential naming the group by its genesis digest and the person by the member anchor they derived for that group. It carries the inviter's card, no key material and no operation. Glossary carries no keys; it names you and the group, and it expires. Nobody joins without accepting.

When you accept, a member who may admit writes your admission into the log, with the invitation and your Annahme Die signierte Zustimmung der eingeladenen Person zu genau einer Einladung, an sie gebunden über deren Credential-Digest. Sie trägt die eigene Karte der Person, an deren Schlüsselvereinbarungsschlüssel das Willkommen versiegelt wird, und sagt, ob die Person der Gruppe vor der Aufnahme als Kandidatur gezeigt werden darf. GlossarAccept The invitee's signed consent to exactly one invite, bound to it by the invite's credential digest. It carries the person's own card, to whose key-agreement key the welcome is sealed, and states whether the person may be shown to the group as a candidacy before admission. Glossary enclosed as proof. A Willkommen Das versiegelte Dokument rltp-welcome/0.1, das einer aufgenommenen Person das Schlüsselmaterial eines Schlüsselzustands bringt, gebunden an Gruppe, Person und die beantwortete Annahme. Die aufnehmende Operation verpflichtet sich über den Digest auf seinen Klartext; Geschichte trägt es nicht. GlossarWelcome The sealed rltp-welcome/0.1 document that carries the key material of one key state to an admitted person, bound to the group, the person and the accept it answers. The admitting operation commits to its plaintext by digest; it carries no history. Glossary then brings you the current key. Older content becomes readable through the group’s own copy, as far back as its keys reach.

If the group asks for vouches (Trust), other members confirm your admission before it counts. A vouch is for this one admission and never stands for a later one.

Spec: Access Layer §5.3 · Membership Tasks

You can leave at any time. A member can be removed when the group’s rule allows it. Either way, and when a device is lost, the group moves to a new Epoche Ein nummerierter Abschnitt der Schlüsselwelt der Gruppe; Durchsetzung wirkt als Epochenübergang. Begriff wie in MLS (RFC 9420). GlossarEpoch A numbered period of the group’s key world; enforcement takes effect as epoch transitions. Term aligned with MLS (RFC 9420). Glossary.

What is written afterwards stays unreadable to whoever lost access. What they already read, they keep; no protocol can make someone forget. The person who was removed is told so.

A group can also end itself. Dissolving it is one more entry in the log, made under the group’s rules like any other.

Spec: Access Layer §5.4 · §7

Members are people, not devices. Each of a member’s devices holds its own key and is tied to the person by a signed Gerätekarte Die signierte Bindung des Schlüsselmaterials eines Geräts an den Mitgliedsanker der Person, der es gehört; steht im Autoritäts-Log. GlossarDevice card The signed binding of one device's key material to the member anchor of the person it belongs to; recorded in the authority log. Glossary in the log. The person adds their own devices, up to eight.

So a lost phone can be cut off without its owner leaving the group. A member whose devices are all gone is still a member. How the keys follow such changes, and how a device gets back in, is on Group keys and replication.

Spec: Access Layer §5.1

Members often act without knowing of each other, offline or at the same moment. Devices merge such changes once they meet, and the rules decide how.

Two removals both take effect, even when two members remove each other. A dissolution made at the same time as a removal lapses and can be made again. Only one collision stops the group: a change of the rules made at the same time as a removal. The group then shows this openly and waits until a member writes a rule change that takes both sides into account.

Spec: Access Layer §3.6

The app simulator runs the same app on three devices: found a group, invite, accept, and watch every sealed envelope on the wire. The other simulators are listed under Try it.