Solarion AI ™ · Compute Passport ™ technical system

Cryptographic identity

The CPID, the key hierarchy, issuance and validation, and the verification material any relying party can fetch.

CompanySolarion AI ™
ProductCompute Passport ™
StatusMVP
Edition2026
IssuerSolarion AI Systems ™
Compute Passport Identifier

Persistent identifier. Short-lived proof. Continuous status.

The CPID is persistent, non-secret and globally unique. It carries no names, no email addresses, no citizen identifiers and no mission detail — identity claims live in the signed passport, where access, retention and disclosure policy can reach them.

What proves control of a CPID is separate and deliberately fragile: a signed, audience-bound, single-use credential that expires in minutes.

Live sample from this issuer urn:cpid:v1:solarion-ai-systems:t-04a48908d600:workload:01a0ab93-420a-787b-b0ea-c59abb776492
Issuer
Solarion AI Systems ™
Technical issuer id
solarion-ai-systems
Tenant id
t-04a48908d600
Object type
agent · model · workload · compute · tool · policy · evidence
Unique value
UUIDv7 — time-ordered, 128-bit
Privacy rule

Do not encode names, email addresses, citizen identifiers, mission details or customer data in a CPID. The tenant segment is an opaque value for exactly this reason.

Key hierarchy

Four tiers, so a compromise at one level does not become a compromise of the trust domain.

Tier 1

Root trust key

Offline or HSM-protected. Signs tenant issuer certificates. Root operations require quorum and immutable audit.

Tier 2

Tenant issuer

One trust boundary per tenant. Signs passport keys, and is the key relying parties resolve.

Tier 3

Passport key

Signs the CPID credential and the policy binding attached to it.

Tier 4

Runtime key

Ephemeral proof for one task or session. Minutes, not months.

01

Register

Owner, purpose, object.

02

Attest

Workload or key context.

03

Issue

Signed passport.

04

Present

Passport and token.

05

Verify

Signature, status, policy.

06

Enforce

Permit, restrict or revoke.

This instance
Algorithm
ES256
Issuer key id
issuer-fa94e2712ecd23c9
Thumbprint
fa94e2712ecd23c9393ec1a628c0484672c5102c3d139e80f583452a2aa1a1b1
Verification
Fetch the JWKS →
Properties
JWS signatures; audience and nonce binding; expiry; replay detection; key rotation; algorithm agility.
Custody

This build generates and holds its signing keys in software on the host. Signatures are real and verifiable, but the custody model is not production-grade: production requires HSM or KMS custody, offline root operations, quorum for root actions and independent cryptographic review.