<-Basic API Go to ToC Workflow Description ->

1 Reference Model

Figure 1 depicts the Reference Model of the MPAI Store.

Figure 1 - Reference Model of the MPAI Store

Figure 1 – Reference Model of the MPAI Store

The MPAI Store is a repository of approved Metadata and of the Implementations it names. It is the guarantor of the infrastructure: it approves AIM Instance Metadata – what an AIM is, what it takes and produces, where its Implementation is – and verifies that an Implementation is the one its Implementer submitted. It never runs an AIM, and is not addressed by a User Agent at run time.

Implementers submit AIM Instance Metadata and Implementations. Controllers obtain the approved Metadata they need and the Implementations it names, and ask the Store to verify them. A Service of MPAI-MAS builds its own business on approved Metadata: its Applications, their Workflows and their descriptors are its own.

2 Functions

Table 1 – Functions of the MPAI Store

Function Description
Approval Validates submitted AIM Instance Metadata against the AIM Metadata Schema and checks that it is an instance of the AIM Metadata its Header names (Metadata). For a Composite AIM, checks that the AIM Instance Metadata of each Sub-AIM is in the submission or in the Store, since without it the Composite AIM could not be built.
Versions Keeps every published version. Published Metadata is never overwritten: a resubmission is a new version.
Findings Records, with each version, what it found in the submission – for example, a package the Metadata names that could not be inspected. A finding is signalled; it does not refuse the submission.
Fingerprints Records the fingerprint (SHA-256) of each Implementation the AIM Instance Metadata names, as submitted and approved.
Verification Confirms, on request, that an Implementation is the one approved for that AIM Instance Metadata.

3 Submission

An Implementer submits the AIM Instance Metadata of an Implementation, with the Implementations it names. The Store refuses a submission, and says why, where:

  1. it is not a valid JSON instance of the AIM Metadata Schema;
  2. it does not identify the AIM Instance it describes;
  3. its Topology cannot be resolved into Data Types and Port Numbers;
  4. it is not an instance of the AIM Metadata its Header names;
  5. a Sub-AIM it names can be found neither in the submission nor in the Store.

Otherwise the Store publishes it as a new version, with its findings.

4 Verification

A Controller runs only code it has verified (Controller). Before an AIM is built, the Controller – or the AIM host of a remote AIM – measures its Implementation and the models it needs, and compares them with the fingerprints the Store approved and the hashes the settings of the AIM state. Where they differ, the Controller refuses the Module with MPAI_AIF_NOT_TRUSTED. An AIM host proves, when it connects, which Implementation it runs (Zero Trust and Profiles).

All archives obtained from the Store shall not leave the Trusted Zone where the API Profile is Basic, and shall not leave Secure Storage where the API Profile is Secure.

5 Store API

All communication with the Store is over HTTPS. The functions of the Store API follow the conventions of the Basic API.

5.1 Called by an Implementer

5.1.1 MPAI_AIFS_SubmitAIM

error_t MPAI_AIFS_SubmitAIM(const char* AIMInstanceMetadata)

Submits the AIM Instance Metadata of an Implementation to the MPAI Store for approval and subsequent availability. The Metadata contains the information about the submitter and the submitted AIM, including its Implementations and its resources. Returns the reasons of a refusal (3), or the version published and its findings.

5.2 Called by a Controller

5.2.1 MPAI_AIFS_RequestAIM

error_t MPAI_AIFS_RequestAIM(const char* AIM_ID)

Requests the list of approved AIM Instance Metadata whose AIM type is AIM_ID – for example, every Implementation of MMC-EDP-V2.5.

5.2.2 MPAI_AIFS_GetAIMMetadata

error_t MPAI_AIFS_GetAIMMetadata(const char* AIM_ID, AIMMetadata_t* metadata)

Retrieves the approved AIM Instance Metadata AIM_ID, used for the selection of an Implementation, the evaluation of resources and the deployment.

5.2.3 MPAI_AIFS_VerifyImplementation

error_t MPAI_AIFS_VerifyImplementation(const char* ImplementationID,
                                       const char* Fingerprint, int* Result)

Verifies an Implementation obtained elsewhere against the fingerprint the Store recorded when it approved it.

5.2.4 MPAI_AIFS_GetAndParseArchive

error_t MPAI_AIFS_GetAndParseArchive(const char* filename)

Obtains and parses an archive from the Store. The default format is tar.gz; the options are tar.gz, tar.bz2, tbz, tbz2, tb2, bz2, tar and zip. An archive includes one AIM Instance Metadata file and one or more binary files. The parsing of the JSON Metadata, and the creation of the corresponding data structure, are left to the Implementer.

The MPAI Store exposes these functions over HTTPS under the path /MPAI/Store:

  • POST /MPAI/Store/L3 submits AIM Instance Metadata. The Store publishes it with a new version only if it is an instance of its AIM Metadata and every Sub-AIM it names is in the submission or in the Store; otherwise it refuses it, stating the nonconformities found.
  • GET /MPAI/Store/L3?name= returns the latest approved AIM Instance Metadata of an AIM.
  • GET /MPAI/Store/L3/{id}[?version=n] returns one AIM Instance Metadata, its version in the response header MPAI-Store-Version.
  • GET /MPAI/Store/L3/{id}/versions returns its versions, and GET /MPAI/Store/L3/{id}/findings what the Store found in it.

A Controller obtains the AIM Instance Metadata of a Module and of all its Sub-AIMs through these routes, and may use a copy it keeps when the Store cannot be reached. AIM Implementations are obtained from the location their AIM Instance Metadata states, and verified against the fingerprints the Store approved.

6 Requirements

Table 2 – Requirements of the MPAI Store

# Requirement
STR-1 The MPAI Store shall refuse AIM Instance Metadata that does not validate against the AIM Metadata Schema or is not an instance of the AIM Metadata its Header names.
STR-2 The MPAI Store shall never overwrite published Metadata.
STR-3 The MPAI Store shall record the fingerprint of each Implementation it approves, and verify an Implementation against it on request.
STR-4 The MPAI Store shall authenticate the submitter of Metadata.
STR-5 The MPAI Store shall not run an AIM.

<-Basic API Go to ToC Workflow Description ->