If all control keys are lost:
- User (or guardian) triggers recovery flow using the recovery scheme:
- guardian signatures
- hardware fallback device
- multi-party recovery protocol
- A new control key (or set of keys) is issued.
- Policies are updated to reflect new control + possibly new recovery scheme.
- A new
state_commitment is computed and published.
At no point is a new identity created; we simply move to a new state.