Diagrams
Visual reference for CNML concepts. Click any diagram to view full-size.
System Architecture
CNML ecosystem: Ruby source, TS web app, keys, verifier
Certificate Model Layers
CORE to modules to per-R to instance
Signing Flow
From form to downloadable signed CNML
Verification Flow
Sequential checks with short-circuit failure
Trust Chain
PKI hierarchy from root through issuer to certificate
UnitsML Embedding
How UnitsDB units are encoded in CNML XML
PKI: typical TLS vs CNML
Side-by-side architecture comparison
Issuance flow comparison
ACME-automated versus human-reviewed air-gapped
Scope governance comparison
How CNML cryptographically encodes per-IA authorization
Security architecture
Six-layer defense-in-depth view
Five-tier certificate hierarchy
BIML Root through IA through TL through Manufacturer Model to Instance
Async signing flow
Director participation across time zones via the coordinator
Distributed management
Geographic distribution of threshold signing authority
Redundancy and fault tolerance
How operations continue under component loss
Re-sharing and recovery
Director departure preserves the aggregate public key
Scope enforcement flow
Four-layer enforcement of per-IA per-Recommendation scope
Transparency flow
Merkle log with mirror agreement and Bitcoin anchor
Threshold encryption flow
Confidential test report protection via threshold KEM
Confium integration points
Ruby FFI, browser WASM, and TCP bindings to the threshold core
Institutional architecture
OIML bodies and their authority relationships