@techreport{vso-cpp-core-03, number = {draft-vso-cpp-core-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-vso-cpp-core/03/}, author = {TOKACHI KAMIMURA}, title = {{Content Provenance Profile (CPP) Core}}, pagetotal = 48, year = 2026, month = aug, day = 2, abstract = {The Content Provenance Profile (CPP) is an open specification for cryptographically verifiable media capture provenance. This document defines the core data model, hashing conventions, Merkle tree construction rules, RFC 3161 Time-Stamp Authority (TSA) anchoring protocol, and offline verification procedures for CPP. CPP enables capture devices to produce tamper-evident provenance records that bind media content to external timestamps via trusted third parties. Unlike self-attestation models, CPP requires independent timestamp verification through RFC 3161 TSA services, providing externally verifiable proof of when media was captured. CPP defines self-attested signer identity, hardware-backed key requirements, chain context for partial submission detection, a Completeness Invariant for omission detection, an OPTIONAL depth analysis extension for screen detection, and an OPTIONAL Pre-Publish Verification Extension. It also defines interoperability mappings with the C2PA specification. This revision (-03) corrects a normative length constraint on the LeafHashMethod value, corrects the description of the relationship between the CPP Merkle construction and Certificate Transparency, adds a verifier obligation to cross-check TreeSize against the sealed event count, documents the limits of leaf-duplication padding, and positions CPP within the Verifiable AI Provenance Framework (VAP) profile family and relative to the SCITT architecture (RFC 9943).}, }