Skip to content
Meshline
SDK 1.1.0 · TypeView source on GitHub

Developer guide · API index

Members on this page

Meshline.Sdk

Meshline.Models.Protocol

DeviceCertificate Class

Binds device signing and encryption keys to an account for a fixed validity period.

public sealed record DeviceCertificate : Meshline.Models.Protocol.TypedProtocolModel, System.IEquatable<Meshline.Models.Protocol.DeviceCertificate>

Inheritance System.Object → ProtocolModel → TypedProtocolModel → DeviceCertificate

Implements System.IEquatable<DeviceCertificate>

Constructors

DeviceCertificate() Constructor

Binds device signing and encryption keys to an account for a fixed validity period.

public DeviceCertificate();

Properties

DeviceCertificate.Account Property

The account's CAIP-10 identifier.

public string Account { get; init; }

Property Value

System.String

DeviceCertificate.AccountPublicKey Property

The public key used to verify the account's signature and identifier.

public System.Collections.Immutable.ImmutableArray<byte> AccountPublicKey { get; init; }

Property Value

System.Collections.Immutable.ImmutableArray<System.Byte>

DeviceCertificate.AccountSignature Property

The account signature over the model's account signing input.

public System.Collections.Immutable.ImmutableArray<byte> AccountSignature { get; init; }

Property Value

System.Collections.Immutable.ImmutableArray<System.Byte>

DeviceCertificate.DeviceSignature Property

The device signature over the model's device signing input.

public System.Collections.Immutable.ImmutableArray<byte> DeviceSignature { get; init; }

Property Value

System.Collections.Immutable.ImmutableArray<System.Byte>

DeviceCertificate.EncryptionPublicKey Property

The device's 32-byte X25519 encryption public key.

public System.Collections.Immutable.ImmutableArray<byte> EncryptionPublicKey { get; init; }

Property Value

System.Collections.Immutable.ImmutableArray<System.Byte>

DeviceCertificate.ExpiresAt Property

The expiration time, in Unix seconds.

public long ExpiresAt { get; init; }

Property Value

System.Int64

DeviceCertificate.NotBefore Property

The inclusive start of the certificate validity window, in Unix seconds.

public long NotBefore { get; init; }

Property Value

System.Int64

DeviceCertificate.SigningPublicKey Property

The device's 32-byte Ed25519 signing public key.

public System.Collections.Immutable.ImmutableArray<byte> SigningPublicKey { get; init; }

Property Value

System.Collections.Immutable.ImmutableArray<System.Byte>

Methods

DeviceCertificate.GetAccountSigningInput(NetworkContext) Method

Builds the canonical, network-bound bytes used to sign or verify this document.

public byte[] GetAccountSigningInput(Meshline.Models.NetworkContext context);

Parameters

context NetworkContext

The network context bound into identifiers or signing input.

Returns

System.Byte[]
The canonical UTF-8 signing input bound to the network context, with the applicable signature fields omitted.

Exceptions

System.Text.Json.JsonException
The signing payload cannot be represented as canonical protocol JSON, contains conflicting extension fields, or already contains a root $context property.

DeviceCertificate.GetDeviceId(NetworkContext) Method

Derives the device identifier from the account, device public keys, and network context.

public string GetDeviceId(Meshline.Models.NetworkContext context);

Parameters

context NetworkContext

The network context bound into identifiers or signing input.

Returns

System.String
The canonical network-bound device identifier.

Exceptions

System.Text.Json.JsonException
The signing payload cannot be represented as canonical protocol JSON, contains conflicting extension fields, or already contains a root $context property.

DeviceCertificate.GetDeviceSigningInput(NetworkContext) Method

Builds the canonical, network-bound bytes used to sign or verify this document.

public byte[] GetDeviceSigningInput(Meshline.Models.NetworkContext context);

Parameters

context NetworkContext

The network context bound into identifiers or signing input.

Returns

System.Byte[]
The canonical UTF-8 signing input bound to the network context, with the applicable signature fields omitted.

Exceptions

System.Text.Json.JsonException
The signing payload cannot be represented as canonical protocol JSON, contains conflicting extension fields, or already contains a root $context property.

DeviceCertificate.Validate(NetworkContext) Method

Validates the certificate's keys, identity, validity-window structure, size, and both device and account signatures.

public override Meshline.Validation.ProtocolViolation? Validate(Meshline.Models.NetworkContext? context);

Parameters

context NetworkContext

The required network context for identity and signature validation.

Returns

ProtocolViolation
The first detected protocol violation, or null if the implemented checks pass.

Exceptions

System.ArgumentNullException
context is null.

System.Security.Cryptography.CryptographicException
The cryptographic provider cannot perform account or relay signature verification; ordinary invalid signatures are returned as protocol violations.

Remarks

This checks both signatures and the certificate validity-window structure. It does not require the current time to lie within that window; check account device authorization separately.