# WDY Evidence Model Specification v1.0

**WDY 存证证据模型规范 v1.0**

| Item | Value |
|---|---|
| Document ID | WDY-RULES-EVIDENCE-v1.0 |
| Language | English (the Chinese edition `evidence-model-v1.0-zh.md` is published separately; clause-by-clause equivalent) |
| Status | Current |
| Applies to | WDY provenance records (WDY-Certified), verify pages, delivery packs, provenance cards, public statements |
| Parent documents | WDY-Certified Rules v1.0; `wdy-manifest` v0.1 specification |

> **Nature of this document.** This specification publishes the **evidentiary structure and strength grading** of WDY records, so that anyone — clients, partner institutions, reviewers, courts, the public — can check it. It is not a product brochure and it is not legal advice. The strength of every link is graded as it stands, with no overstated claim.

---

## 1 Purpose and scope

1.1 The purpose of this specification is to let anyone **judge accurately** what each link of a WDY record does and does not prove.

1.2 It applies to every record WDY issues and to every public carrier of that record: verify page, manifest, delivery pack, provenance card, explanatory material.

1.3 This specification **does not constitute**: rights registration, a determination of ownership, judicial recognition, a substitute for notarisation, or copyright certification.

---

## 2 Terms

| Term | Definition |
|---|---|
| **Fingerprint** | The cryptographic hash computed over file content (WDY default: SHA-256) |
| **Anchor** | A registration of a fingerprint or record held by a third-party system independent of WDY, externally verifiable |
| **Anchoring** | The act of submitting a fingerprint to an anchor and obtaining a verifiable credential |
| **The five anchors** | The five evidentiary links defined in section 3 |
| **Physical anchor** | The evidentiary link formed by carrying the fingerprint on a physical object mailed as a registered item through the Designated Operator |
| **Delivery artefact** | A physical item, or its equivalent, delivered to the client; it evidences delivery only and creates no rights |
| **Joint resistance** | The property whereby, with multiple anchors present, forging or overturning the record requires defeating all of them at once (see 3.3) |
| **Self-issued record** | A record issued and self-signed by WDY. A self-assertion; it is **not an anchor** |

---

## 3 The five-anchor evidence model

### 3.1 Structure

```
File content
   └─(mathematics)─→ fingerprint SHA-256
        ├─(anchor 1)─→ domestic judicial chain (ZhiXinChain)
        ├─(anchor 2)─→ RFC 3161 timestamp
        ├─(anchor 3)─→ OpenTimestamps / Bitcoin
        ├─(anchor 4)─→ physical object (provenance card) + Designated Operator postmark
        └─(anchor 5)─→ archived postal tracking record (itself fixed by two public anchors)
```

### 3.2 Strength grading

| Link | Who vouches | What is vouched for | Grade |
|---|---|---|---|
| SHA-256 fingerprint | Mathematics | Content is unchanged | **Computational** |
| Anchor 1 — ZhiXinChain | Chain operator | The fingerprint existed at the listed block time | **Presumptive** (Online Litigation Rules §16) |
| Anchor 2 — RFC 3161 timestamp | Timestamping authority (CA) | The fingerprint existed at that instant | **Presumptive** |
| Anchor 3 — OpenTimestamps | Bitcoin network | The fingerprint existed at that block | **Presumptive** |
| Anchor 4 — physical object + postmark | Designated Operator | **This physical item** was accepted into the postal system on that day | **Third-party date credential** |
| Anchor 5 — postal tracking | Designated Operator | The item travelled the listed route (time to the minute) | **Third-party electronic record** |
| Self-issued record (signed manifest) | WDY | WDY's own statement only | **Self-asserted** |

### 3.3 Joint resistance

3.3.1 The failure conditions of the anchors **do not overlap**: chain shutdown / timestamping-authority shutdown / network unreachability / factors outside the postal system — four mutually independent causes. Common-mode failure does not hold.

3.3.2 Therefore, **if any single piece of infrastructure fails, the remaining anchors still independently prove the same fingerprint**.

3.3.3 It must also be stated plainly: **the significance of multiple anchors is that forging or overturning the record would require defeating several unrelated systems at once; it is not the sum of their individual strengths.** This table grades every link as it stands and does not inflate by aggregation.

---

## 4 Admission and failure conditions per anchor

| Anchor | Admission conditions | Known failure conditions | Precedent |
|---|---|---|---|
| ZhiXinChain | Chain account in good standing, valid credentials | Chain operator ceases service; account anomaly | — |
| RFC 3161 | Public endpoint of the authority issues | **CA ceases service or stops issuing timestamps** | **WIPO PROOF stopped issuing in Jan 2022** |
| OpenTimestamps | Calendar servers reachable | Calendar shuts down; Bitcoin network unreachable | — |
| Physical anchor | Dispatched via a **registered item (recorded-delivery mail)** | Not cancelled, item returned, recipient refuses | — |
| Archived tracking record | Archived within the query window | See the window constraint in 5.5 | — |

4.1 **Every anchor is conditional on "publish only what has happened"**: an anchor not actually obtained is never listed as obtained on a verify page, in a manifest, or in any material.

---

## 5 The physical anchor

### 5.1 Format

- Card size 165 × 102 mm; international items must fall within Universal Postal Union dimensions.
- International items must carry `PAR AVION / AIR MAIL` and the country name.
- **Two faces**:
  - **Provenance face** — record ID, fingerprint, verify-page address and QR code. In the co-branded edition the **partner artwork and the provenance information are fused onto the same face** (the artwork occupying one side in a half-concealed treatment, dissolving into the information area at its edge); with no partner artwork (base edition), the provenance information occupies the face in full.
  - **Postal face** — postal-anchor record block (see 5.3), stamp position, sender and recipient details, postcode boxes.

### 5.2 Fields that must be pre-printed

Only these three **must** be printed when the card is produced:

1. Record ID (`record_id`)
2. Fingerprint (SHA-256, single line, monospaced, never wrapped)
3. Verify-page address and QR code

### 5.3 Fields that must not be pre-printed (filled in after dispatch)

The following concern the physical dispatch itself; **pre-printing destroys their meaning**:

- Registered item number
- Acceptance time (to the **hour:minute**)
- Delivery time
- Tracking-archive reference

These four are placed as the "**postal anchor record block**" on the **postal face** (the side bearing the postmark), not on the provenance face.

### 5.4 Dispatch channel

5.4.1 A **registered item (recorded-delivery mail)** is **mandatory**. Grounds (references in Appendix A):

- Recorded-delivery mail is **receipted** by the operator at acceptance and **logged item by item** through internal handling and transit;
- Ordinary mail is not receipted, not logged, and **cannot be queried**.

5.4.2 After acceptance, retain: the original registration receipt, a photograph of the card together with the item number, and images of the acceptance and delivery postmarks.

### 5.5 Tracking archival (mandatory step)

5.5.1 **Time constraint.** The statutory right to query a recorded-delivery item runs **one year from acceptance for domestic mail and 180 days for international mail** (Postal Law §49). The statutory retention floor for the operator's electronic records is **no less than 2 years**, and the regulations **require periodic destruction**. The timescale on which disputes arise is normally far longer than this window.

5.5.2 **Therefore it must be done on the day of dispatch**: query the online tracking record → capture a screenshot/PDF → archive.

5.5.3 The archived record is fixed by two public anchors — an **RFC 3161 timestamp** and **OpenTimestamps** — and constitutes **anchor 5**.

### 5.6 Content the physical anchor must not carry

- The **title or body** of a client's unpublished material (medical, think-tank, contractual, etc.); only the record ID and fingerprint are printed, with the correspondence retained in the manifest.
- Any statement that states or implies that "the content has been certified".

---

## 6 Boundary of effect (statements of fact)

| Item | Conclusion |
|---|---|
| What the postmark proves | That **this physical item** was accepted by the Designated Operator on that day |
| What the postmark does **not** prove | The authenticity of the content attached to it, or of the electronic data it points to |
| Legal status of the item | The card **is not a public document**; public-document authentication (Apostille) procedures do not apply |
| Relationship to notarisation / expert examination | It **does not replace** notarisation, and **does not replace** forensic examination of document creation time |
| Relationship to rights | A provenance record **is not** a rights registration and creates no ownership effect |
| Carrier limitation | The card is an **open (unsealed) carrier**; it must not carry confidential content |
| Scope of service | WDY provides the **provenance and traceability layer**; the application of content labels and markings is the responsibility of producers, broadcasters and AI system providers |

---

## 7 Versioning and correction

7.1 This specification is versioned from the moment of publication; historical versions are not deleted.

7.2 Issued records are **not modified and not deleted**; errors are corrected by errata with a note, pointing from the affected verify pages.

7.3 Any textual change to this specification requires a new version number and an entry in the change log.

---

## Appendix A Index of citable law and standards

> Principle: **cite only provisions whose text has been verified**. For anything outside this index, verify the source text before citing.

### A.1 China

| Instrument | Point cited |
|---|---|
| Online Litigation Rules of the People's Courts (Fa Shi [2021] No. 12, in force 2021-08-01) §16 | Blockchain-preserved evidence: where technical verification is consistent, the data may be found **unaltered after being written to the chain** (rebuttable presumption) |
| Ibid. §17 | Factors on challenge to authenticity **after** writing to the chain (platform compliance, interested-party relationship, cleanliness/security/reliability/availability, technical-process compliance) |
| Ibid. §18 | Authenticity **before** writing to the chain: to be judged together with the data's specific source, generation mechanism, storage process, notarisation, **third-party witnessing** and **corroborating data** |
| Postal Law of the PRC §49 | Recorded-delivery mail: query against the receipt within **1 year** domestically, **180 days** internationally |
| Ibid., definitions | "Letter" includes correspondence and postcards; "recorded-delivery mail" is receipted at acceptance and signed for on delivery; "ordinary mail" is not receipted |
| Universal Postal Service Standard 7.6.4 | Query period (as above); 7.6.5 response times |
| Express Business Operating Guidelines (State Post Bureau) §36 | Electronic archive retention for query information **not less than 2 years** |
| Ibid. §12 | Acceptance records retained not less than 1 year |
| Interim Regulations on Express Delivery §34 | Maintain a waybill and electronic-data management system; **periodically destroy** waybills |
| National court rules on service by post | Where documents are returned, the date of service is determined by the **postmark date** on the postal return slip |
| SPC Provisions on Internet Courts (Fa Shi [2018] No. 16) §11 | Factors for examining the authenticity of electronic data |
| Administrative Provisions on Blockchain Information Services (CAC, 2019) | Compliance requirements for provenance platforms |
| Measures for the Identification of AI-Generated Synthetic Content (issued 2025-03, **in force 2025-09-01**) | Dual-track duty: explicit labels + implicit labels (provider name, content ID, generation time, etc.) |
| GB 45438-2025, *Cybersecurity technology — Labeling method for content generated by artificial intelligence* | **Mandatory** national standard, in force with the Measures |
| Measures for the Administration of the Development of Micro-Drama (**NRTA Order No. 16**, published 2026-07-31, **in force 2026-09-01**) §34 | Micro-drama generated or produced using AI technology: producers and broadcasters shall, in accordance with relevant provisions, **add a notice at a conspicuous position in every episode** |

**Verify before citing.** Any standard number and title must be checked against the issuing body's published text before it is cited; where number and title do not correspond, it must not be cited.

### A.2 Outside China

| Instrument | Point cited | Limits on use |
|---|---|---|
| Regulation (EU) 2024/1689 (EU AI Act) Art. 50 | Transparency duties: outputs of generative systems must be marked in a **machine-readable** format; applicable from 2026-08-02, with the machine-readable marking transition for legacy systems running to **2026-12-02** | The duty-bearers are providers and deployers of AI systems; WDY is a **service provider**, not a duty-bearer |
| Code of Practice on Transparency of AI-generated Content, Sub-measure 1.1.1 | Requires **digitally signed metadata**, **time-stamped in a secure, tamper-evident manner** | The code of practice is **voluntary** to sign; non-signatories must demonstrate compliance by equivalently adequate means |
| Regulation (EU) 910/2014 (eIDAS) Art. 41 | An electronic timestamp may not be denied evidentiary effect or admissibility solely because of its form | **Public TSAs such as DigiCert are not eIDAS qualified**; no presumption of validity may be claimed |
| Regulation (EU) 2024/1183 (eIDAS 2.0) | Member States must make at least one EUDI Wallet available by **2026-12-24**; acceptance duty for regulated relying parties by 2027-12-24 | WDY is neither a QTSP nor a wallet provider; background only |
| US Federal Rules of Evidence, FRE 901(b)(4) | Distinctive characteristics (appearance, contents, substance, internal patterns) as a method of authentication | — |
| Ibid., FRE 902(13)–(14) | Electronic data may be **self-authenticating** through a certification record by a qualified person | — |
| USPS Certificate of Mailing (PS Form 3811) | Comparable practice accepted in court as proof of mailing | Practice outside China; not a Chinese source of law |
| Universal Postal Union (UPU) registered-item regime | Registered items are traceable across borders | — |
| California AI Transparency Act (SB 942, as amended by AB 853) | Large online platforms must detect provenance data and offer a disclosure interface from **2027-01-01** | US state law, not federal |

## Appendix B Term mapping

| Chinese | English |
|---|---|
| 锚 / 锚定 | anchor / anchoring |
| 指纹 | fingerprint |
| 自有记录 | self-issued record |
| 联合阻抗 | joint resistance |
| 交付凭证 | delivery artefact |
| 实物锚 | physical anchor |
| 存证卡 | provenance card |
| 指定邮政经营者 | Designated Operator (UPU) |

> **Internationalisation convention.** In this English edition and in every outward-facing version on the `.org` site, the postal link is expressed as
> **"the Designated Operator (per UPU terminology)"**, and no country-specific entity name appears.
> Country-specific entity names appear only on the `.org.cn` site and in the corresponding positions of the Chinese edition.

---

## Change log

| Version | Date | Change |
|---|---|---|
| v1.0 | 2026-09-12 | First publication. Establishes the five-anchor model, strength grading, physical-anchor specification and boundary of effect. |

