Members on this page
Meshline.Sdk
Meshline.Models.Protocol
DeviceCertificate Class
Binds device signing and encryption keys to an account for a fixed validity period.
public sealed record DeviceCertificate : Meshline.Models.Protocol.TypedProtocolModel, System.IEquatable<Meshline.Models.Protocol.DeviceCertificate>
Inheritance System.Object → ProtocolModel → TypedProtocolModel → DeviceCertificate
Implements System.IEquatable<DeviceCertificate>
Constructors
DeviceCertificate() Constructor
Binds device signing and encryption keys to an account for a fixed validity period.
public DeviceCertificate();
Properties
DeviceCertificate.Account Property
The account's CAIP-10 identifier.
public string Account { get; init; }
Property Value
DeviceCertificate.AccountPublicKey Property
The public key used to verify the account's signature and identifier.
public System.Collections.Immutable.ImmutableArray<byte> AccountPublicKey { get; init; }
Property Value
System.Collections.Immutable.ImmutableArray<System.Byte>
DeviceCertificate.AccountSignature Property
The account signature over the model's account signing input.
public System.Collections.Immutable.ImmutableArray<byte> AccountSignature { get; init; }
Property Value
System.Collections.Immutable.ImmutableArray<System.Byte>
DeviceCertificate.DeviceSignature Property
The device signature over the model's device signing input.
public System.Collections.Immutable.ImmutableArray<byte> DeviceSignature { get; init; }
Property Value
System.Collections.Immutable.ImmutableArray<System.Byte>
DeviceCertificate.EncryptionPublicKey Property
The device's 32-byte X25519 encryption public key.
public System.Collections.Immutable.ImmutableArray<byte> EncryptionPublicKey { get; init; }
Property Value
System.Collections.Immutable.ImmutableArray<System.Byte>
DeviceCertificate.ExpiresAt Property
The expiration time, in Unix seconds.
public long ExpiresAt { get; init; }
Property Value
DeviceCertificate.NotBefore Property
The inclusive start of the certificate validity window, in Unix seconds.
public long NotBefore { get; init; }
Property Value
DeviceCertificate.SigningPublicKey Property
The device's 32-byte Ed25519 signing public key.
public System.Collections.Immutable.ImmutableArray<byte> SigningPublicKey { get; init; }
Property Value
System.Collections.Immutable.ImmutableArray<System.Byte>
Methods
DeviceCertificate.GetAccountSigningInput(NetworkContext) Method
Builds the canonical, network-bound bytes used to sign or verify this document.
public byte[] GetAccountSigningInput(Meshline.Models.NetworkContext context);
Parameters
context NetworkContext
The network context bound into identifiers or signing input.
Returns
System.Byte[]
The canonical UTF-8 signing input bound to the network context, with the applicable signature fields omitted.
Exceptions
System.Text.Json.JsonException
The signing payload cannot be represented as canonical protocol JSON, contains conflicting extension fields, or already contains a root $context property.
DeviceCertificate.GetDeviceId(NetworkContext) Method
Derives the device identifier from the account, device public keys, and network context.
public string GetDeviceId(Meshline.Models.NetworkContext context);
Parameters
context NetworkContext
The network context bound into identifiers or signing input.
Returns
System.String
The canonical network-bound device identifier.
Exceptions
System.Text.Json.JsonException
The signing payload cannot be represented as canonical protocol JSON, contains conflicting extension fields, or already contains a root $context property.
DeviceCertificate.GetDeviceSigningInput(NetworkContext) Method
Builds the canonical, network-bound bytes used to sign or verify this document.
public byte[] GetDeviceSigningInput(Meshline.Models.NetworkContext context);
Parameters
context NetworkContext
The network context bound into identifiers or signing input.
Returns
System.Byte[]
The canonical UTF-8 signing input bound to the network context, with the applicable signature fields omitted.
Exceptions
System.Text.Json.JsonException
The signing payload cannot be represented as canonical protocol JSON, contains conflicting extension fields, or already contains a root $context property.
DeviceCertificate.Validate(NetworkContext) Method
Validates the certificate's keys, identity, validity-window structure, size, and both device and account signatures.
public override Meshline.Validation.ProtocolViolation? Validate(Meshline.Models.NetworkContext? context);
Parameters
context NetworkContext
The required network context for identity and signature validation.
Returns
ProtocolViolation
The first detected protocol violation, or null if the implemented checks pass.
Exceptions
System.ArgumentNullException
context is null.
System.Security.Cryptography.CryptographicException
The cryptographic provider cannot perform account or relay signature verification; ordinary invalid signatures are returned as protocol violations.
Remarks
This checks both signatures and the certificate validity-window structure. It does not require the current time to lie within that window; check account device authorization separately.