{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:6CISV6MWFINDD7LJ5WT6E4A6NL","short_pith_number":"pith:6CISV6MW","canonical_record":{"source":{"id":"1605.09115","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-05-30T06:33:15Z","cross_cats_sorted":[],"title_canon_sha256":"4bad7220e54cd35f60b228a6d40ef7e052f7f0ffef26e3e7842c7e2bcaa3ffe7","abstract_canon_sha256":"6d80d78d42665244c05eb2fbe8f8ecb35a71716375b7e36cc98b78182e1763f5"},"schema_version":"1.0"},"canonical_sha256":"f0912af9962a1a31fd69eda7e2701e6ae7390d3227949dbb9d746541b10d0ab0","source":{"kind":"arxiv","id":"1605.09115","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1605.09115","created_at":"2026-05-18T01:13:22Z"},{"alias_kind":"arxiv_version","alias_value":"1605.09115v1","created_at":"2026-05-18T01:13:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1605.09115","created_at":"2026-05-18T01:13:22Z"},{"alias_kind":"pith_short_12","alias_value":"6CISV6MWFIND","created_at":"2026-05-18T12:30:01Z"},{"alias_kind":"pith_short_16","alias_value":"6CISV6MWFINDD7LJ","created_at":"2026-05-18T12:30:01Z"},{"alias_kind":"pith_short_8","alias_value":"6CISV6MW","created_at":"2026-05-18T12:30:01Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:6CISV6MWFINDD7LJ5WT6E4A6NL","target":"record","payload":{"canonical_record":{"source":{"id":"1605.09115","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-05-30T06:33:15Z","cross_cats_sorted":[],"title_canon_sha256":"4bad7220e54cd35f60b228a6d40ef7e052f7f0ffef26e3e7842c7e2bcaa3ffe7","abstract_canon_sha256":"6d80d78d42665244c05eb2fbe8f8ecb35a71716375b7e36cc98b78182e1763f5"},"schema_version":"1.0"},"canonical_sha256":"f0912af9962a1a31fd69eda7e2701e6ae7390d3227949dbb9d746541b10d0ab0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T01:13:22.069730Z","signature_b64":"b+mR0QozXXBW988E8CcxEQOHS/dNCHMVHQ2Sgq7ve4DT1DxCG+uCvn85/Q7YaC31nQXVPdCPYfwDY42g/yWaDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f0912af9962a1a31fd69eda7e2701e6ae7390d3227949dbb9d746541b10d0ab0","last_reissued_at":"2026-05-18T01:13:22.069153Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T01:13:22.069153Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1605.09115","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:13:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UISYPJ6Rz4tVIW95XdAfbAMpedaZlieNXVllP/tr/6OM/3GSQ5qBtC1n3u1AE8oUByrzBasNmwYC0T2TLEE+Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T21:54:28.289495Z"},"content_sha256":"fee69d5710ed302bde87afcff4e2dae946c3a0b16ef640179edc760ea1a9e0f7","schema_version":"1.0","event_id":"sha256:fee69d5710ed302bde87afcff4e2dae946c3a0b16ef640179edc760ea1a9e0f7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:6CISV6MWFINDD7LJ5WT6E4A6NL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Mathematical Foundations for Mapping Policies to Network Devices (Technical Report)","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dinesha Ranathunga, Matthew Roughan, Nick Falkner, Phil Kernick","submitted_at":"2016-05-30T06:33:15Z","abstract_excerpt":"A common requirement in policy specification languages is the ability to map policies to the underlying network devices. Doing so, in a provably correct way, is important in a security policy context, so administrators can be confident of the level of protection provided by the policies for their networks. Existing policy languages allow policy composition but lack formal semantics to allocate policy to network devices.\n  Our research tackles this from first principles: we ask how network policies can be described at a high-level, independent of firewall-vendor and network minutiae. We identif"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1605.09115","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:13:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZRE5X5gb5cB4TlqbtITFEWzAexw/Vr3U+Eb8E4FgWsyNuFz0+Hto3YyyW14r6dhDeNFeCcEJRpVlqGBGehzBBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T21:54:28.290181Z"},"content_sha256":"31443e600aa05a67bff5cf6eaab56bcc24573345fedeefbb0c34c191fdc6b9b8","schema_version":"1.0","event_id":"sha256:31443e600aa05a67bff5cf6eaab56bcc24573345fedeefbb0c34c191fdc6b9b8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6CISV6MWFINDD7LJ5WT6E4A6NL/bundle.json","state_url":"https://pith.science/pith/6CISV6MWFINDD7LJ5WT6E4A6NL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6CISV6MWFINDD7LJ5WT6E4A6NL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-05T21:54:28Z","links":{"resolver":"https://pith.science/pith/6CISV6MWFINDD7LJ5WT6E4A6NL","bundle":"https://pith.science/pith/6CISV6MWFINDD7LJ5WT6E4A6NL/bundle.json","state":"https://pith.science/pith/6CISV6MWFINDD7LJ5WT6E4A6NL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6CISV6MWFINDD7LJ5WT6E4A6NL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:6CISV6MWFINDD7LJ5WT6E4A6NL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6d80d78d42665244c05eb2fbe8f8ecb35a71716375b7e36cc98b78182e1763f5","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-05-30T06:33:15Z","title_canon_sha256":"4bad7220e54cd35f60b228a6d40ef7e052f7f0ffef26e3e7842c7e2bcaa3ffe7"},"schema_version":"1.0","source":{"id":"1605.09115","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1605.09115","created_at":"2026-05-18T01:13:22Z"},{"alias_kind":"arxiv_version","alias_value":"1605.09115v1","created_at":"2026-05-18T01:13:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1605.09115","created_at":"2026-05-18T01:13:22Z"},{"alias_kind":"pith_short_12","alias_value":"6CISV6MWFIND","created_at":"2026-05-18T12:30:01Z"},{"alias_kind":"pith_short_16","alias_value":"6CISV6MWFINDD7LJ","created_at":"2026-05-18T12:30:01Z"},{"alias_kind":"pith_short_8","alias_value":"6CISV6MW","created_at":"2026-05-18T12:30:01Z"}],"graph_snapshots":[{"event_id":"sha256:31443e600aa05a67bff5cf6eaab56bcc24573345fedeefbb0c34c191fdc6b9b8","target":"graph","created_at":"2026-05-18T01:13:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"A common requirement in policy specification languages is the ability to map policies to the underlying network devices. Doing so, in a provably correct way, is important in a security policy context, so administrators can be confident of the level of protection provided by the policies for their networks. Existing policy languages allow policy composition but lack formal semantics to allocate policy to network devices.\n  Our research tackles this from first principles: we ask how network policies can be described at a high-level, independent of firewall-vendor and network minutiae. We identif","authors_text":"Dinesha Ranathunga, Matthew Roughan, Nick Falkner, Phil Kernick","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-05-30T06:33:15Z","title":"The Mathematical Foundations for Mapping Policies to Network Devices (Technical Report)"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1605.09115","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fee69d5710ed302bde87afcff4e2dae946c3a0b16ef640179edc760ea1a9e0f7","target":"record","created_at":"2026-05-18T01:13:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6d80d78d42665244c05eb2fbe8f8ecb35a71716375b7e36cc98b78182e1763f5","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-05-30T06:33:15Z","title_canon_sha256":"4bad7220e54cd35f60b228a6d40ef7e052f7f0ffef26e3e7842c7e2bcaa3ffe7"},"schema_version":"1.0","source":{"id":"1605.09115","kind":"arxiv","version":1}},"canonical_sha256":"f0912af9962a1a31fd69eda7e2701e6ae7390d3227949dbb9d746541b10d0ab0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f0912af9962a1a31fd69eda7e2701e6ae7390d3227949dbb9d746541b10d0ab0","first_computed_at":"2026-05-18T01:13:22.069153Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T01:13:22.069153Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"b+mR0QozXXBW988E8CcxEQOHS/dNCHMVHQ2Sgq7ve4DT1DxCG+uCvn85/Q7YaC31nQXVPdCPYfwDY42g/yWaDw==","signature_status":"signed_v1","signed_at":"2026-05-18T01:13:22.069730Z","signed_message":"canonical_sha256_bytes"},"source_id":"1605.09115","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fee69d5710ed302bde87afcff4e2dae946c3a0b16ef640179edc760ea1a9e0f7","sha256:31443e600aa05a67bff5cf6eaab56bcc24573345fedeefbb0c34c191fdc6b9b8"],"state_sha256":"72401be00fc1ba4a92897b0c59f6300d99b926bdc22a3c73b510e080c81bdc18"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"G55/3Xsgya3KqncuZhXNombqjP9PiB0jhH3zNhuSdjKfqpDxhWUSLjwjfbfrH4PUSVkiUdnFY1nkmi5IOI/tDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-05T21:54:28.293555Z","bundle_sha256":"2bd0a4e9a3a43c6bedac760df93522b673e08cacb1de2e478041cbbc7fd4e3cf"}}