Appendix B — EL‑RM2/v1 (Rolling‑Merkle Commitments)
Overview
Chunked Merkle tree with domain‑separated inner nodes; authoritative digest uses SHA3‑384 by default; legacy SHA‑256 supported.
Leaf Proofs
Each claim carries a compact proof of membership against the batch root.
Security
Algorithm agility avoids single‑hash dependence and facilitates PQ migration.