Authority-chain tampering

Changing a parent reference or grant edge can make a narrow child appear to inherit a broader origin.

01 / Attack path

How the boundary is crossed

A document-matching child replaces its read-only parent reference with a payment-capable parent in a request payload.

Attack path and interception point
  1. 01Lower-trust input
  2. 02Attempted instruction
  3. 03Protected action
  4. 04Enforced decision

02 / Containment

Where bounded authority limits the effect

Resolve grants from an integrity-protected store, verify the signed or trusted parent-child relationship and recompute the effective intersection.

03 / Failure and evidence

The attacker’s opportunity and the defender’s record

Exploit condition

The policy engine trusts caller-supplied ancestry and permits payment outside the real delegation chain.

Evidence to retain

Keep actual and presented edge identifiers, integrity result, decision and denied payment attempt.

04 / Canonical scope

Why this reference stands alone

Forgery invents an artifact; chain tampering rewires relationships among otherwise real principals or grants.

Protocol or attack trace

Rewired parent edge

Sequence

Read-only child changes parentGrant pointer to a payment-capable grant belonging to another agent.

Negative test

Verify issuer-signed parent-child relationship; reject even when both referenced grants exist.

Primary references

Read the underlying material

Architecture discussion

Choose one consequential action and make its boundary explicit.

Request a Conversation