S4 – KAP Key Delivery Message Schema
Version: 0.9.0
Status: Release Candidate
Type: Normative Schema Specification
Copyright © 2026 inside workspace GmbH
This work is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) License.
1. Introduction
1.1 Purpose
This specification defines the data model, property semantics, validation requirements, and normative JSON Schema for the KAP Key Delivery Message (KAP-KDM) of the KAPRI Specification Suite.
A KAP-KDM is a digitally signed document that provides recipient-specific cryptographic information required to access encrypted content of an existing Knowledge Asset Package.
1.2 Scope
This specification defines
- the KAP-KDM data model,
- the semantics of its properties,
- KAP-KDM-specific validation requirements,
- the normative JSON Schema.
General serialization rules are defined by SC0 – Common Serialization Rules.
Common reusable data types are defined by SC1 – Common Data Types.
1.3 Relationship to Other Specifications
This specification forms part of the KAPRI Specification Suite.
It builds upon:
- S0 – Knowledge Asset Package Architecture Specification
- SC0 – Common Serialization Rules
- SC1 – Common Data Types
A KAP-KDM references an existing Knowledge Asset Package but is not part of the Package. It is distributed independently of the Package.
Whereas the Package Manifest protects the published Package metadata, the KAP-KDM protects the recipient-specific key delivery information.
Each KAP-KDM contains its own digital signature.
The encrypted files referenced by a KAP-KDM are defined by the Packing List specified in S2 – Packing List Schema.
2. Overview
2.1 Purpose
A KAP-KDM enables an authorized recipient to decrypt the encrypted files of an existing Knowledge Asset Package.
It provides the Encrypted File Keys required to access protected Package content.
Its digital signature protects the integrity and authenticity of the KAP-KDM.
2.2 Responsibilities
The KAP-KDM provides the information required to
- identify the referenced Knowledge Asset Package,
- identify the intended recipient,
- deliver Encrypted File Keys,
- associate Key Identifiers with Encrypted File Keys,
- enable decryption of protected Package content,
- protect the integrity and authenticity of the KAP-KDM through a digital signature.
The KAP-KDM does not define
- publication metadata,
- semantic organization,
- file integrity,
- trust relationships,
- authorization policies.
These aspects are defined by other specifications of the KAPRI Specification Suite or by the receiving implementation.
3. Data Model
3.1 Structure
A KAP-KDM contains the recipient-specific cryptographic information required to decrypt the encrypted files of an existing Knowledge Asset Package.
The following top-level properties are defined:
PropertyTypeCardinalitydocument_type | String | 1
schema_version | Schema Version | 1
kdm_id | URI | 1
package_id | URI | 1
recipient | Organization | 1
key_entries | Key Entry[] | 1..n
signature | Signature | 1
Each Key Entry consists of the following properties:
PropertyTypeCardinalitykey_id | Key Identifier | 1
encrypted_file_key | Encrypted File Key | 1
The data types of these properties are defined by SC1 – Common Data Types.
3.2 Property Semantics
The following clauses define the normative semantics of each KAP-KDM property.
3.2.1 document_type
Identifies the document as a KAP-KDM.
The value SHALL be
kap_kdm
3.2.2 schema_version
Identifies the version of this specification used to serialize the KAP-KDM.
Consumers SHALL validate the KAP-KDM according to the specified schema version.
3.2.3 kdm_id
Uniquely identifies the KAP-KDM.
The KAP-KDM Identifier SHALL remain immutable after creation.
3.2.4 package_id
Identifies the referenced Knowledge Asset Package.
The referenced Package SHALL exist independently of the KAP-KDM.
3.2.5 recipient
Identifies the intended recipient of the KAP-KDM.
The recipient SHALL correspond to the entity for which the enclosed Encrypted File Keys have been encrypted.
3.2.6 key_entries
Contains the Encrypted File Keys required to decrypt the protected files of the referenced Knowledge Asset Package.
Each Key Entry SHALL associate exactly one Encrypted File Key with exactly one Key Identifier.
3.2.7 signature
Contains the digital signature protecting the integrity and authenticity of the KAP-KDM.
Before signature generation and signature validation, the KAP-KDM SHALL be transformed into its canonical JSON representation according to RFC 8785 – JSON Canonicalization Scheme (JCS). The signature property SHALL be excluded from the canonical representation.
The signature property SHALL conform to the Signature data type defined by SC1 – Common Data Types.
3.2.8 key_id
Identifies the Key Identifier referenced by the Packing List.
The identifier SHALL correspond to a key_id defined in the referenced Packing List.
3.2.9 encrypted_file_key
Contains the Encrypted File Key associated with the referenced Key Identifier.
The key SHALL be encrypted for the intended recipient.
4. JSON Representation
The following example illustrates the JSON representation of a KAP-KDM.
{
"document_type": "kap_kdm",
"schema_version": "0.9.0",
"kdm_id": "urn:uuid:69957253-8e3e-48ff-9215-9c5230790f77",
"package_id": "urn:uuid:3573f619-952d-40d6-bc38-d7f7072ff519",
"recipient": {
"organization_id": "urn:kap:organization:kapri-reference-recipient",
"name": "KAPRI Reference Recipient"
},
"key_entries": [
{
"key_id": "urn:uuid:e82e2e47-615f-4e74-af4d-f5601c2e0cff",
"encrypted_file_key": "SxqxUP54T7U02nfEijRkJz3jvZjshrLa4nMGjTTUgOjfxJDaR9vHZjG21HVmgZqxF5Ose1awW6kzWrKS0T8zpUBxivMZ-S7ULYFDTogLm6AJS20Hyxz8goYvpApfbZ-WYlBb_cBMX30Wa9tUfBxJZnTbtRN1jE7Rq0bM8H_enrL6SRy1JgyGztXg_grXOCV1fh50y5QmAFWS9EGYbUZjaHh55zV0F0v37YqAtuCap-t4rRapxJk-YTv1UTlfgByVEQTubmiNU8Qxn2rY3--GT40xR5f7azV7fN1yOu3J4CwqH2wQewTPPF2rMfJpjHuojW690HF3w_YSu6ZlnSTVtg"
}
],
"signature": {
"algorithm": "ECDSA-P256-SHA256",
"certificate_chain": [
{
"certificate_id": "urn:kap:certificate:sha256:TxD6Y7_L54jxMAO95r7G45xjDQg9jmVgtDI0_j2ayrw",
"issuer": "dnQualifier=AS8vbsT\\+7JWZ5vULt9mjXSmGEKw=,CN=KAPRI Reference Intermediate CA,O=inside workspace GmbH,OU=KAPRI Reference Implementation,C=DE",
"serial_number": "3",
"certificate": "MIICrTCCAlOgAwIBAgIBAzAKBggqhkjOPQQDAjCBpzELMAkGA1UEBhMCREUxJzAlBgNVBAsMHktBUFJJIFJlZmVyZW5jZSBJbXBsZW1lbnRhdGlvbjEeMBwGA1UECgwVaW5zaWRlIHdvcmtzcGFjZSBHbWJIMSgwJgYDVQQDDB9LQVBSSSBSZWZlcmVuY2UgSW50ZXJtZWRpYXRlIENBMSUwIwYDVQQuExxBUzh2YnNUKzdKV1o1dlVMdDltalhTbUdFS3c9MB4XDTI2MDEwMTAwMDAwMFoXDTMwMTIzMTAwMDAwMFowgaAxCzAJBgNVBAYTAkRFMScwJQYDVQQLDB5LQVBSSSBSZWZlcmVuY2UgSW1wbGVtZW50YXRpb24xHjAcBgNVBAoMFWluc2lkZSB3b3Jrc3BhY2UgR21iSDEhMB8GA1UEAwwYS0FQUkkgUmVmZXJlbmNlIFByb2R1Y2VyMSUwIwYDVQQuExxVUi9YTGc4QUNnaGNKd0YwTDVUMXcrTVFvcmc9MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEgb5pPdPJ35RHU+FzbbIZXahrmn+1/31pXL0yLsKPwSft+rq+JxpdRL4oEWfP53Oy31X/zFIkMxyt0V3WVmKROaN1MHMwHQYDVR0OBBYEFFEf1y4PAAoIXCcBdC+U9cPjEKK4MB8GA1UdIwQYMBaAFAEvL27E/uyVmeb1C7fZo10phhCsMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgbAMBMGA1UdJQQMMAoGCCsGAQUFBwMDMAoGCCqGSM49BAMCA0gAMEUCIQDLv7W3ILoIzmEEBh1gcbzNKIaWTqkI5Vp9afRj8muU8AIgYuWw9zDSLQtB+O7Vi51/nkySAI8RVBmJq2P+lc7BnFA="
},
{
"certificate_id": "urn:kap:certificate:sha256:_yUS4m5LAfsMARXmI_3Faw8acFWJNRCdSQS1EexGBT4",
"issuer": "dnQualifier=k/zVfoPrmhnL41\\+TSVwS1y87XLg=,CN=KAPRI Reference Root CA,O=inside workspace GmbH,OU=KAPRI Reference Implementation,C=DE",
"serial_number": "2",
"certificate": "MIICnjCCAkOgAwIBAgIBAjAKBggqhkjOPQQDAjCBnzELMAkGA1UEBhMCREUxJzAlBgNVBAsMHktBUFJJIFJlZmVyZW5jZSBJbXBsZW1lbnRhdGlvbjEeMBwGA1UECgwVaW5zaWRlIHdvcmtzcGFjZSBHbWJIMSAwHgYDVQQDDBdLQVBSSSBSZWZlcmVuY2UgUm9vdCBDQTElMCMGA1UELhMcay96VmZvUHJtaG5MNDErVFNWd1MxeTg3WExnPTAeFw0yNjAxMDEwMDAwMDBaFw0zMDEyMzEwMDAwMDBaMIGnMQswCQYDVQQGEwJERTEnMCUGA1UECwweS0FQUkkgUmVmZXJlbmNlIEltcGxlbWVudGF0aW9uMR4wHAYDVQQKDBVpbnNpZGUgd29ya3NwYWNlIEdtYkgxKDAmBgNVBAMMH0tBUFJJIFJlZmVyZW5jZSBJbnRlcm1lZGlhdGUgQ0ExJTAjBgNVBC4THEFTOHZic1QrN0pXWjV2VUx0OW1qWFNtR0VLdz0wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAS3BGN2QXfknNgFRqIp1ZurKZV4sq3s6QBZqJqlug5ND4Yvayju1+D9tXWpZs6Prcn9mEmpihPb4PM6l5XCjCILo2YwZDAdBgNVHQ4EFgQUAS8vbsT+7JWZ5vULt9mjXSmGEKwwHwYDVR0jBBgwFoAUk/zVfoPrmhnL41+TSVwS1y87XLgwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwCgYIKoZIzj0EAwIDSQAwRgIhAKYnL7h8ccYUBr2sTzommBx5YCaCwC0SwAPUrq3q2dx5AiEAgPd2d15r4joXtZHeQpb6TM7EuNrvOq2CswiMP1KH7j8="
},
{
"certificate_id": "urn:kap:certificate:sha256:CGmzikmPtIyQ2CNSRze9rioLnBuInB3Z7ifToIEzmE0",
"issuer": "dnQualifier=k/zVfoPrmhnL41\\+TSVwS1y87XLg=,CN=KAPRI Reference Root CA,O=inside workspace GmbH,OU=KAPRI Reference Implementation,C=DE",
"serial_number": "1",
"certificate": "MIICdDCCAhqgAwIBAgIBATAKBggqhkjOPQQDAjCBnzELMAkGA1UEBhMCREUxJzAlBgNVBAsMHktBUFJJIFJlZmVyZW5jZSBJbXBsZW1lbnRhdGlvbjEeMBwGA1UECgwVaW5zaWRlIHdvcmtzcGFjZSBHbWJIMSAwHgYDVQQDDBdLQVBSSSBSZWZlcmVuY2UgUm9vdCBDQTElMCMGA1UELhMcay96VmZvUHJtaG5MNDErVFNWd1MxeTg3WExnPTAeFw0yNjAxMDEwMDAwMDBaFw0zMDEyMzEwMDAwMDBaMIGfMQswCQYDVQQGEwJERTEnMCUGA1UECwweS0FQUkkgUmVmZXJlbmNlIEltcGxlbWVudGF0aW9uMR4wHAYDVQQKDBVpbnNpZGUgd29ya3NwYWNlIEdtYkgxIDAeBgNVBAMMF0tBUFJJIFJlZmVyZW5jZSBSb290IENBMSUwIwYDVQQuExxrL3pWZm9Qcm1obkw0MStUU1Z3UzF5ODdYTGc9MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAExki58Y6Hv9thf5rBoAIQjM2hK+h6qM8ko63H2wnE6Ka1dSE5VHO29EEaFgeunXw9lLQJOhG35Qf0bSUOEzxBh6NFMEMwHQYDVR0OBBYEFJP81X6D65oZy+Nfk0lcEtcvO1y4MBIGA1UdEwEB/wQIMAYBAf8CAQEwDgYDVR0PAQH/BAQDAgEGMAoGCCqGSM49BAMCA0gAMEUCIF8MPd9iuxaiEfm28NinVb/5HASWzq8ADwri6kWmnaxhAiEA8XAgRjWL0enrzpbtc/sg0NHhSQfsUjhpJXiiyl7Zt28="
}
],
"signature_value": "MEUCIHxkexQrkp4E2aIHAQAg-OhGUwAe8b9Bpwlm8IvZTL0DAiEAoOvM7cAlKaQ8p0zfKFXV0coXQHpSWdaZFjFAlH6535w"
}
}5. JSON Schema
The normative JSON Schema for the KAP-KDM is provided by the accompanying file:
kap_kdm.schema.json
Conforming implementations SHALL validate KAP-KDM documents against this schema.
In case of discrepancies between this specification and the accompanying schema, this specification takes precedence.
6. Validation Rules
This chapter defines validation requirements specific to the KAP-KDM.
General validation requirements are defined by S0 – Knowledge Asset Package Architecture Specification.
Serialization validation rules are defined by SC0 – Common Serialization Rules.
Validation rules for common data types are defined by SC1 – Common Data Types.
The following additional validation rules apply:
- Exactly one kdm_id SHALL identify each KAP-KDM.
- Exactly one package_id SHALL identify the referenced Knowledge Asset Package.
- Every key_id SHALL identify a Key Identifier defined by the referenced Packing List.
- Every key_id SHALL appear at most once within the KAP-KDM.
- Every Key Entry SHALL contain exactly one Encrypted File Key.
- Every KAP-KDM SHALL identify exactly one recipient.
- Exactly one signature property SHALL be present in the KAP-KDM.
- The digital signature SHALL successfully validate the canonical representation of the KAP-KDM.
- The signature property SHALL conform to the Signature data type defined by SC1 – Common Data Types.
7. Conformance
7.1 General Conformance
An implementation claiming conformance with this specification SHALL conform to:
- S0 – Knowledge Asset Package Architecture Specification
- SC0 – Common Serialization Rules
- SC1 – Common Data Types
- the requirements defined by this specification.
7.2 Schema Conformance
KAP-KDM documents SHALL conform to the normative JSON Schema defined by this specification.
7.3 Interoperability
Conforming implementations SHALL preserve the semantic meaning of all KAP-KDM properties.
Conforming implementations SHALL interpret KAP-KDM documents consistently and independently of implementation technology.
Conforming implementations SHALL preserve
- the association between the referenced Knowledge Asset Package and the KAP-KDM,
- the association between recipients and Encrypted File Keys,
- the association between Key Identifiers and Encrypted File Keys,
- the integrity and authenticity of the KAP-KDM through its digital signature.