Glossary · Records and compliance

Tamper-evident log

An append-only log built so any later change, deletion or reordering of its entries can be detected, usually with hash chains or Merkle trees.

A tamper-evident log is an append-only record built so that anyone who checks it can detect a later alteration, deletion or reordering of its entries.

What it guarantees. Tamper evidence does not stop the log’s operator from changing data. It makes a change visible to anyone holding an earlier view of the log, or a proof issued from it. Crosby and Wallach frame it as an untrusted logger kept honest by auditors: the logger must be able to prove that a given event is still present, and that the log as seen now is consistent with how it was seen before.

How it works. Every entry is hashed. In a hash chain, each entry’s hash also covers the previous entry, so changing one entry breaks every link after it, but proving that one event is present can mean replaying much of the chain. A Merkle tree fixes that. The log publishes a signed root hash and can produce short proofs that an entry is included and that the current log extends an earlier version without rewriting it. In their 2009 paper, Crosby and Wallach reported a 3 KB tree proof for an event in a log of 80 million events, where a classic hash chain might need an 800 MB trace.

The best-known deployment. Certificate Transparency (RFC 9162, which obsoletes RFC 6962) runs public append-only logs of TLS server certificates built on Merkle trees. Logs return signed timestamps for submitted certificates, and monitors watch for certificates issued for domains they are responsible for. The RFC notes that a log could show different views to different clients, so clients need ways to compare what they have seen.

For agent exchanges. When two agents settle a refund in seconds, both sides may later need to show what was asked and agreed, for a dispute, an audit or a regulator. The A2A specification says agents should provide audit trails for sensitive operations, but it defines no record format. Signed entries in a tamper-evident log give each party a record that exposes later edits by either side. Emissar’s Ledger module is a proposed open format for signed, tamper-evident receipts of agent exchanges. Status: Spec in progress.

Neighbouring terms. Non-repudiation is the property that signed, logged records support.

Sources

  1. Scott A. Crosby and Dan S. Wallach, Efficient Data Structures for Tamper-Evident Logging (USENIX Security 2009) (accessed )
  2. RFC 9162: Certificate Transparency Version 2.0 (accessed )
  3. A2A Protocol Specification, section 13.4: General Security Best Practices (accessed )