Code tutorial 11 - tested
Encrypt confidential provenance metadata
Record private lineage metadata, reveal it with the correct key and prove a wrong key fails closed.
Verified against: ENTITY main commit
5be325437a63c2efaee0dc3caaae9ab0cd0773d9. Disposable tutorial state only.Watch the tutorial
This VP8 WebM terminal replay is generated from the exact published source and recorded execution shown below.
Run it yourself
$env:ENTITY_ROOT="C:\path o\ENTITY" python examples/confidential_provenance.py
Exact source
from pathlib import Path
import importlib.util, hashlib, os, shutil
ROOT=Path(os.environ.get("ENTITY_ROOT",Path.cwd())).resolve()
STATE=ROOT/".tutorial-test-state"/"confidential-provenance"
if STATE.exists(): shutil.rmtree(STATE)
def load_source(path,name):
spec=importlib.util.spec_from_file_location(name,ROOT/path); mod=importlib.util.module_from_spec(spec); spec.loader.exec_module(mod); return mod
identity_mod=load_source("src/01_Core_Runtime/identity/canonical_identity.py","entity_identity")
privacy=load_source("src/35_Global_Infrastructure/privacy_provenance.py","entity_privacy")
identity=identity_mod.EntityIdentityVault(STATE); owner=identity.create("Provenance Owner","organization")
ledger=privacy.ConfidentialProvenanceLedger(STATE,identity)
key=hashlib.sha256(b"tutorial-confidential-key").digest()
edge=ledger.add_edge(owner["entity_id"],"dataset:A","model:B","DERIVED_FROM",hashlib.sha256(b"evidence").hexdigest(),metadata={"private_detail":"sensitive lineage"},encryption_key=key)
revealed=ledger.reveal_metadata(edge["edge_id"],key)
assert revealed["commitment_valid"] and revealed["metadata"]["private_detail"]=="sensitive lineage"
wrong="NOT_BLOCKED"
try: ledger.reveal_metadata(edge["edge_id"],hashlib.sha256(b"wrong-key").digest())
except Exception: wrong="BLOCKED"
assert wrong=="BLOCKED"
print("CONFIDENTIAL_EDGE=PASS"); print("COMMITMENT_VERIFY=PASS"); print("WRONG_KEY_REVEAL=BLOCKED")
print("CLAIM_BOUNDARY=encrypted metadata commitment is provenance evidence, not universal truth")
Recorded output
CONFIDENTIAL_EDGE=PASS COMMITMENT_VERIFY=PASS WRONG_KEY_REVEAL=BLOCKED CLAIM_BOUNDARY=encrypted metadata commitment is provenance evidence, not universal truth
Claim boundary: The recorded result proves this tutorial operation executed against the pinned source. It does not establish external truth, ownership, production certification or third-party adoption.