Skip to content
← selected work

Protocol · Move Industries

Move Attestation Framework

An on-chain attestation framework for the Movement framework: sources assert facts about addresses, and businesses consume them through policies without deploying any code.

Period
2026 - in review
Role
Author
Source
Public

The problem

Apps that need to know something about an address, such as whether it is verified or excluded, each end up building their own allowlist. Nothing lets independent sources publish those facts once, lets two sources disagree, and lets each consumer choose which ones it trusts.

What I did

  • Wrote five new framework modules: attestation, attestation_policy, attestation_authorization, zktls and merkle_proof.
  • Made sources and policies resource accounts, following the timelock pattern, with separate admin, issuer, sentinel, remover and guardian roles. The deployer gains no role unless it is listed.
  • Routed every positive write path (issuer batches, permissionless relay of signed attestations, and zkTLS enrollment) through one private function, so precedence lives in one place. Denials sit in a separate table that no positive write can touch.
  • Added O(1) revocation through per-issuer epochs and a source-wide floor, and kept the read path conflict-free under Block-STM.
  • Built policies with three-valued evaluation (allow, deny or step-up) and staged activation, plus short-lived ed25519 authorizations for step-up with replay protection.
  • Enrolled users from zkTLS attestations with m-of-n secp256k1 attestor signatures, epoch grace windows and single-use claims.
  • Tested with 149 Move unit tests and 34 Rust end-to-end tests against the real VM, and proved all five modules with the Move Prover.

Stack

MoveAptos frameworkMove ProverRust