
key-transparency-auditor v20260818.0.0
Continuously fetches and cryptographically verifies key transparency log updates, maintains a condensed prefix and log tree view, and returns signed tree heads when updates are valid.
key-transparency-auditor
A reference implementation of a third-party auditor for Signal's key transparency service, based on the key transparency specification.
Overview
This service is written in Java using the Micronaut framework. To build and unit test, run
./mvnw clean test
in the root directory.
The main class is the Auditor, which runs a scheduled job that requests a
stream of updates from the key transparency service. It maintains a condensed view of the key transparency service's prefix tree
and log tree,
storing just enough information to verify and accept each update sequentially. If the auditor has processed a certain number of updates or a certain amount of time has elapsed, the auditor sends back a
signed tree head
to the key transparency service, indicating that its view of the prefix and log trees up to the given update matches.
If the remote call succeeds, the auditor writes its state data to an AuditorStateRepository,
which it may use to resume from its most recent position in the key transparency log if the auditor is restarted.
If the auditor encounters an inconsistency in verifying an update, it throws an InvalidProofException and stops
sending signed tree heads back to the key transparency service.
Configuration
The service needs Auditor, KeyTransparencyServiceClient, and AuditorStateRepository beans to run.
The table below describes the configuration properties necessary to instantiate those beans.