# HXP-004 — Threat Model and Security Goals

Status: Candidate Standard 0.1

## Adversaries

The model includes digital package mutation, key substitution, replay, malicious ZIP construction, tag-memory copying, photographed or printed hologram imitation, relief copying, 3D scanning and refabrication, careful carrier removal, solvent and thermal transfer, malicious manufacturing overruns, template reconstruction, reader emulation, model-extraction attacks, registry denial of service, and compromised operational keys.

## Security goals

Helix detects unauthorized digital changes; binds a commissioned token to an immutable evidence root; distinguishes deterministic design from stochastic unit enrollment; makes qualified transfer measurably destructive; and reports uncertainty instead of silently accepting missing observations.

## Non-goals

The protocol does not establish legal title, guarantee that any physical structure is impossible to clone, replace conservation review, provide current revocation without current data, or make a root trustworthy merely because it is carried by the object.

## Manufacturer threat

Vendors receive design assets and serial allocation only. They do not receive signing keys or unrestricted source evidence. Unit-specific randomness is enrolled after manufacture, so an overrun made from the same deterministic design does not inherit the commissioned PUF template. Qualification must include same-mask and malicious-vendor samples.
