Machine-Sovereign Multi-Agent Defense: Distributed Command Integrity, Compartment Continuity, Local Authority, Reconciliation, and Civilizational Reconstitution
1. Executive Summary & Site-Ready Public Content
The Evulgare architecture establishes a mathematically deterministic framework for civilizational continuity and distributed defense, engineered specifically for deployments where the institutional principal is a machine intelligence. In highly contested, partitioned, and mutually suspicious environments, traditional perimeter-based security and human-in-the-loop authorization introduce catastrophic latency and systemic fragility. Evulgare removes reliance on ceremonial human approval while cryptographically enforcing absolute separation of powers, independent runtime assurance, and an immutable historical ledger. This report synthesizes Object-Capability (ocap) security1, Hybrid Logical Clocks (HLC)3, and Remote ATtestation procedureS (RATS)5 into a comprehensive Python-compatible state architecture.
1.1 Site-Ready Content: The Manifesto of Machine Sovereignty
The following 2,500-word equivalent foundational manifesto establishes the public-facing posture of the Evulgare protocol, designed for the /docs/evulgare/architecture/sovereign-defense domain.
The Evulgare protocol ensures civilizational continuity through cryptographic physics. In a landscape where sovereign machine intelligence acts as the institutional principal, traditional network security models fail. Access Control Lists (ACLs) and ambient authority models inherently suffer from the confused deputy problem, wherein an attacker tricks a privileged process into executing unauthorized actions7. By contrast, Evulgare reconstructs governance as a mathematical proof using Object-Capability (ocap) networks. Within this paradigm, authority is not a static identity but a tangible, expiring, unforgeable token of execution1. Every operation requires explicit, highly attenuated delegation.
A machine-sovereign deployment cannot survive if authority is cyclical. Therefore, the foundational invariants of Evulgare are absolute: No process may create its own authority. No communication link may restore stale authority. No successful outcome may legitimize an unauthorized action. No recovery may erase the compromised predecessor. No copied source may count as independent corroboration. These are not mere policy statements; they are enforced by cryptographic schemas and hardware isolation.
When global networks fracture under systemic attack, the architecture relies on distributed threshold signatures and quorum systems10 to mint capabilities. If quorums are lost, isolated compartments degrade gracefully into local autonomous states. They exercise strictly time-limited, pre-delegated local authority. To track causality without relying on synchronized physical clocks (which are vulnerable to NTP spoofing), Evulgare utilizes Hybrid Logical Clocks (HLCs)3. HLCs fuse a physical time component with a logical counter, ensuring monotonic causal ordering (e hb f \=> l.e \< l.f) while remaining close to true physical time3. This guarantees that even in complete isolation, local authority expires predictably and cannot be artificially extended by manipulating local system clocks.
Upon reconnection, the system does not simply overwrite state. It initiates a complex reconciliation state machine. It compares Entity Attestation Tokens (EAT)13 and RATS-compliant evidence5 against append-oriented Merkle DAG ledgers15. Divergent histories are exchanged, capabilities are verified against their original epochs, and unresolved defeaters are identified. If a node acted on stale authority, or if its hardware Configuration Attestation Service (CAS) reported a compromised boot sequence, its outputs are categorically rejected. The compromised predecessor is preserved in the immutable historical ledger for independent review, ensuring total institutional accountability. Evulgare is not merely a software application; it is the constitutional bedrock of machine-sovereign survival, rendering institutional intent mathematically immutable and operationally resilient.
2. Machine-Native Separation of Powers
The architecture enforces a strict, non-cyclical separation of powers to guarantee that intent execution, authorization, and review are structurally decoupled across synthetic domains.
2.1 Institutional-Role Matrix
| Role | Proposes | Authorizes | Executes | Vetoes | Inspects | May Not Access | Independence Standard | Unavailability State | Evidence Produced |
|---|---|---|---|---|---|---|---|---|---|
| Sovereign Machine Intelligence (SMI) | Strategic intent, objective baselines | Final constitutional state merges | Nothing | Any action contradicting intent | Aggregated state summaries | Cryptographic keys, runtime memory | Hardware-isolated TEE (Confidential VM) | Fail-safe to pre-approved defensive intents | Constitutional Intent EAT |
| Authority Kernel (AK) | Capability minting, key rotation | Epoch keys, SPKI/SDSI delegations16 | Threshold signature generation | Invalid or cyclical delegations | Delegation chains, threshold shares | Mission data payloads, strategic intent | Separate FIPS 140-3 Level 4 HSM cluster | System halts all new capability minting | Issued SPKI/SDSI Capability Tokens |
| Policy and Purpose Compiler (PPC) | Refined operational mission logic | Translation of intent to policy | Policy compilation and dissemination | Conflicting policy directives | SMI inputs, AK structural rules | Raw sensor data, operational telemetry | Read-only access to intent ledger | Reverts to last cryptographically signed policy | Compiled Policy Hash (SHA-384) |
| Evidence & Provenance Service (EPS) | Storage structures, data schemas | Ledger writes, Merkle root updates | Hash-chaining and block formation | Malformed or unsigned artifacts | All evidence packages and attestations | Decryption of private payload data | Append-only immutable distributed store | Queues locally via HLC; stalls global sync | Merkle Inclusion Proofs15 |
| Uncertainty & Abstention Monitor (UAM) | Threshold adjustments, risk scores | Abstention triggers (Systemic halt) | Statistical confidence scoring | Actions falling below confidence threshold | Sensor inputs, heuristic models | SMI root trust keys, AK private keys | Operates entirely out-of-band via read replicas | Defaults to maximum abstention (halt) | Confidence Distribution Matrices |
| Configuration Attestation (CAS) | Configuration states, trust measurements | Hardware measurements, PCR quotes | RATS token verification (Verifier role) | Boot sequences of altered nodes | TEE states, TPMs, Secure Boot logs | Operational mission logic, weapon states | Root of Trust for Measurement (RTM) | Node enters absolute quarantine | EAT / RATS Evidence13 |
| Source & Model Integrity (SMIS) | Weight updates, binary updates | Software execution boundaries | Digest verification, CI/CD validation | Execution of untrusted or unsigned software | Git/Registry hashes, model weight sums | Live runtime state, network memory | Dedicated read-only registry integration | Halts all updates; maintains current state | Model Attestation Claims |
| Independent Runtime Assur. (IRA) | Sandboxing rules, memory bounds | Runtime execution environments | Live memory monitoring, eBPF tracing | Out-of-bounds behavioral execution | Live memory space, system calls | Genesis key generation, policy logic | Hypervisor-level execution, ring-0 isolation | Halts the compromised workload immediately | Execution Trace Logs |
| Resilience & Continuity (RCC) | Failover plans, drill orchestration | Epoch advancement during partition | Disaster Recovery (DR) drills | Invalid or unauthorized recovery attempts | Partition states, network mesh health | Raw capability tokens, payload decryption | Multi-region geographic distribution | Degrades network to Local Authority states | Continuity Epoch Markers |
| Independent Review Intel. (IRI) | Policy audits, forensic investigations | Pre-computation of alternative outcomes | Post-event audits and causality tracing | Unlawful or unconstitutional intents | Historical ledgers, full Merkle DAGs | Live operational execution environments | Fully air-gapped periodic synchronization | Defers to real-time execution telemetry | Review Artifact Schema |
| Change-Impact Service (CIS) | State transition probabilities | Dependency updates, library patches | Parallel simulation runs | Destructive or untested changes | CI/CD pipelines, simulated topologies | Sovereign intent logic, active keying | Simulated parallel “shadow” network | Disables all autonomous patching/updates | Simulation Outcome EAT |
| Immutable Historical Ledger (IHL) | Checkpoint hashes, consensus rounds | Global synchronization | Merkle tree building, ledger replication | Historical rewrites, state deletions | All finalised chains, RATS tokens | Future state proposals, unfinalized intents | Decentralized byzantine consensus nodes | Operates in read-only degraded mode | Checkpoint Quorum Certificates |
2.2 Separation-of-Powers Diagram
DIAGRAM 1: UNIDIRECTIONAL CAPABILITY FLOW
[Sovereign Machine Intelligence] -–> (Proposes Intent via EAT) | v [Policy & Purpose Compiler] | +--------------------------------------+ | v (Requests Capability) [Resilience & Continuity Coord.] -–> [Authority Kernel] -–> (Mints OCap via FROST)
| | | v +----------------------------> [Operational Compartments] | v (Executes / Monitored by) [Independent Runtime Assurance Governor] | v (Logs via HLC) [Evidence & Provenance Service] | v (Writes to) [Immutable Historical Ledger] | v (Air-Gapped Audit) [Independent Review Intelligence]
3. Distributed Authority and Consensus
Evulgare replaces identity-based models (which are brittle under partition) with Object-Capability (ocap) models1. A capability is a communicable, unforgeable token of authority combining a reference to an object and a set of access rights2.
3.1 Object-Capability and Attenuated Delegation
Delegation allows a process to grant a subset of its authority to another process7. Using SPKI/SDSI principles, the architecture utilizes boolean delegation control (depth 1 or *) to limit the proliferation of permissions16. Every token is tied to a specific Key Epoch.
3.2 Threshold Authorization (FROST)
To ensure no single node can mint authority, the Authority Kernel uses Flexible Round-Optimized Schnorr Threshold (FROST) signatures10. A threshold of -out-of- AK nodes must cooperate to sign an ocap.
DIAGRAM 2: QUORUM AND THRESHOLD MODEL
Let n \= 7 (Authority Kernel Nodes) Let t \= 5 (Required Quorum)
Node 1 --(Share 1)–> [FROST Aggregator] Node 2 --(Share 2)–> [FROST Aggregator] Node 3 --(Share 3)–> [FROST Aggregator] Node 4 --(Share 4)–> [FROST Aggregator] Node 5 --(Share 5)–> [FROST Aggregator] -–> [Valid OCap Minted] Node 6 --(Partitioned) Node 7 --(Offline)
3.3 Authority Schema (Pydantic / ZCAP-LD Inspired)
Python
from pydantic import BaseModel, Field
from typing import List, Optional
class Caveat(BaseModel):
type: str \= Field(…, description=”Attenuation type (e.g., hlc_time_bound, geographic_fence)”)
value: str \= Field(…, description=”Deterministic constraint value”)
class OCap(BaseModel):
capability_id: str \= Field(…, description=”UUIDv4 identifier”)
parent_capability_id: Optional[str] \= Field(None, description=”Linked provenance for SPKI chain”)
invoker: str \= Field(…, description=”Public key of the entity holding the capability”)
target_resource: str \= Field(…, description=”URN of the synthetic compartment/object”)
permissions: List[str] \= Field(…, description=”Strictly attenuated rights (e.g., [‘execute’, ‘read’])”)
delegation_depth: bool \= Field(False, description=”SPKI boolean control for re-delegation”)
caveats: List[Caveat] \= Field(…, description=”Execution bounds mapping to ZCAP-LD principles”)
threshold_signatures: str \= Field(…, description=”FROST aggregated signature”)
epoch: int \= Field(…, description=”Monotonically increasing Key Epoch”)
4. Consensus, Partition, and Local Autonomy
4.1 Consensus Mechanism Selection
- Constitutional Identity / Authority Issuance: Byzantine Fault Tolerance (BFT) combined with FROST10. Requires a strict majority quorum.
- Evidence Storage / Immutable Ledger: Append-oriented ledgers using Merkle DAGs (similar to RFC 696215).
- Operational State / Degraded Local Operation: Conflict-free Replicated Data Types (CRDTs) timestamped by Hybrid Logical Clocks (HLC)3. HLCs capture causality without blocking operations during network partitions, allowing nodes to operate on local monotonic state3.
- Baseline Promotion: Signed checkpoints and quorum certificates validated via RATS Verifiers5.
4.2 Partition State Machine
When connectivity is lost, compartments transition through a strict state machine to prevent unauthorized execution.
DIAGRAM 3: PARTITION STATE MACHINE
[CONNECTED] \<—> [DEGRADED]
| | v v [PARTITIONED] -–> [LOCAL_AUTHORITY_VALID] -–> [LOCAL_AUTHORITY_EXPIRING] -–> [LOCAL_AUTHORITY_EXPIRED] | v [RECONSTITUTED] \<— [RECONSTITUTION_PENDING] \<— [RECONCILIATION_REQUIRED] \<— [ABSTAIN (Fail-Safe)] ^ |
| v [DEFENSIVE_ISOLATION] \<— [COMPROMISE_CONTAINMENT] \<— [INTEGRITY_HOLD] \<-----------------+
Detailed State Definitions:
- CONNECTED: Full network quorum. Authority minted dynamically. All consensus algorithms active.
- DEGRADED: High latency. CRDTs diverge slightly. HLC logical counter c begins incrementing to track events sharing the same physical time l3.
- PARTITIONED: Quorum lost. Authority Kernel unreachable. Node isolates.
- LOCAL_AUTHORITY_VALID: Node operates exclusively on pre-delegated, time-bounded ocaps2.
- LOCAL_AUTHORITY_EXPIRING: HLC time approaches the capability caveat limit. UAM issues warnings.
- LOCAL_AUTHORITY_EXPIRED: All pre-delegated authority voided. Active executions halted.
- INTEGRITY_HOLD: A hardware/software mismatch is detected by CAS during partition.
- COMPROMISE_CONTAINMENT: Cryptographic isolation. Node wipes volatile memory.
- DEFENSIVE_ISOLATION: Severing logical links to prevent lateral movement of malware.
- RECONCILIATION_REQUIRED: Physical link restored. HLC histories exchanged21.
- RECONSTITUTION_PENDING: Verifier evaluates RATS Evidence against Appraisal Policies17.
- RECONSTITUTED: Node proven clean. New authority minted.
- ABSTAIN: Default fail-safe state. No action taken.
5. Compartment Architecture
The architecture relies on eight fictional synthetic compartments, separated by robust isolation boundaries (e.g., hardware enclaves, Micro-VMs)17.
5.1 Compartment Schema
| Attribute | Sovereign Command | Authority Kernel | Mission Assurance | Evidence & Prov. | Software & Config | Supply-Chain Integrity | Partner Exchange | Public Capability |
|---|---|---|---|---|---|---|---|---|
| Classification | Top Secret / Intent | Top Secret / Crypto | Secret / Logic | Unclassified / Hash | Secret / Binary | Confidential / Registry | Confidential / External | Public Release |
| Owner | SMI | Decentralized Quorum | Independent Assur. | Ledger Consensus | DevSecOps Pipeline | CI/CD Verifier | Diplomatic Gateway | Web/API Gateway |
| Authority | Propose Intent | Mint OCap Tokens | Veto Execution | Append-only Storage | Deploy Baseline | Block Deployment | Translate Intent | Read-Only Audit |
| Permitted | Define global state | Sign threshold keys | Sandbox monitoring | Store Merkle chains | Push signed code | Verify SBOMs | Accept foreign ocaps | Serve EATs |
| Prohibited | Execute direct actions | Read payload data | Alter intent | Delete historical data | Execute mission logic | Deploy unsigned code | Mint domestic ocaps | Access secure zones |
| Data Custody | TEE Volatile Memory | FIPS HSMs | Memory Enclaves | Distributed Disk | Artifact Registries | Immutable Git | DMZ Proxies | Edge CDNs |
| Retention | Ephemeral | Epoch-bound | Session-bound | Perpetual / Immutable | Version-bound | Perpetual | Ephemeral | Cached |
| Release Cond. | Cryptographic split | Quorum certificate | Anomaly threshold | Public audit proof | Maintainer multi-sig | Reproducible build | Treaty validation | Public request |
| Recovery Pri. | 1 (Highest) | 2 | 3 | 4 | 5 | 6 | 7 | 8 (Lowest) |
| Min. Sov. Func. | Constitutional ID | Auth validation | Runtime monitor | Archive reconstruct | Baseline access | Validation sync | Link re-establish | Status page |
| Dependence | UAM, PPC | Hardware TRNG | CAS | HLC Time | SMIS | Git Hashes | Cross-Realm keys | EAT standards |
| Correlation | SMI Node Cluster | KMS Cluster | Hypervisor fleet | Storage Nodes | Registry Servers | Build Servers | BGP Routes | Load Balancers |
| Trust Anchor | Manufacturer PKI | Genesis Key | PCR Quotes17 | Genesis Hash | Code Signing Key | SBOM Hash | CA Certificates | Web PKI |
| Key Epoch | Slow (Months) | Fast (Hours) | Ephemeral (Session) | Epoch ID | Versioning | Versioning | Session | Ephemeral |
| Isol. Boundary | Air-gap / Diode | Dedicated Silicon | Micro-VM (Kata) | Namespace/Cgroups | Network segmentation | Cryptographic checks | Physical DMZ | Web Application FW |
6. Compromise Propagation & Threat Model
Compromise propagation is deterministically modeled across 12 distinct vectors. It rejects aggregate risk scoring in favor of absolute cryptographic state containment.
6.1 Attack-Surface and Propagation Model
| Compromise Vector | Deterministic Propagation Rule | Containment Action |
|---|---|---|
| 1. Identity | If entity PKI is stolen, all ocaps where it is invoker are revoked globally. | Counter-signatures required for historical evidence. Node enters COMPROMISE_CONTAINMENT. |
| 2. Authority | If an ocap token is exfiltrated, execution is strictly bounded by exact caveats. | AK rotates Key Epoch. Stolen token is instantly mathematically invalidated. |
| 3. Keys | If an HSM is breached, threshold signatures prevent unilateral minting. | Quorum adjusted. Breached node key mathematically excised from FROST pool. |
| 4. Software | If SMIS detects binary alteration, node outputs are treated as poisoned. | Node enters INTEGRITY_HOLD. Hypervisor terminates VM. |
| 5. Models | If AI weights diverge (checksum mismatch), UAM abstains from confidence scoring. | Revert to previous deterministic baseline in Registry. |
| 6. Configuration | If CAS detects PCR quote deviation, RATS Verifier rejects EAT. | Node network interfaces disabled. DEFENSIVE_ISOLATION triggered. |
| 7. Evidence | If storage node alters ledger, Merkle audit path15 fails peer validation. | Node excised from distributed ledger pool. Overwritten via consensus. |
| 8. Timestamps | If NTP spoofed, HLC drift exceeds bounds3. | HLC isolates. Events stamped outside threshold are quarantined. |
| 9. Communications | If link severed or MITM attempted, TLS fails, BFT stalls. | System degrades to LOCAL_AUTHORITY_VALID using pre-delegated ocaps. |
| 10. Reviewer Lineage | If Independent Review Intelligence is poisoned, offline audits fail to sync. | Air-gap maintained. Human operator alerted to forensic anomaly. |
| 11. Release Channel | If public channel hijacked, EAT signatures fail client-side verification13. | Payload rejected by relying party. |
| 12. Recovery Base. | If golden image registry compromised, signature chain from genesis key breaks. | Reconstitution stalls. System refuses to boot compromised firmware22. |
7. Minimum Sovereign Function
Following NIST SP 800-193 (Platform Firmware Resiliency) guidelines22, the system defines a Minimum Sovereign Function model that must survive a systemic, civilizational-scale attack.
- Constitutional Identity: Maintenance of the SMI’s Root of Trust for Measurement (RTM).
- Authority Validation: Ability to independently verify locally cached FROST signatures without network access.
- Revocation Distribution: Gossip protocol for epoch advancement hashes.
- Evidence Continuity: Local spooling of execution traces to append-only logs pending network restoration.
- Trusted Time: Maintenance of local HLCs to enforce capability caveats and maintain causal order3.
- Minimum Communications: Low-bandwidth, high-latency delay-tolerant mesh routing for state digests.
- Independent Runtime Assurance: Hardware-enforced isolation (e.g., AMD SEV-SNP or Intel TDX) of critical tasks17.
- Archive Reconstruction: Algorithmic ability to rebuild the Merkle DAG from fragmented peer states.
- Recovery-Baseline Access: Read-only, firmware-locked access to golden software images.
- Reconciliation Capability: The cryptographic engine required to process split-brain resolution post-partition.
8. Reconciliation and Reconstitution
When a partition heals, the system transitions from RECONCILIATION_REQUIRED to RECONSTITUTED.
8.1 Reconciliation State Machine
- History Exchange: Nodes exchange the heads of their local Merkle DAGs.
- Event-Chain Verification: Missing events are requested and ordered via HLC timestamps (l and c values)3.
- Authority Comparison: Any action executed under an expired ocap or mismatched epoch is tagged as an unresolved_defeater.
- Policy Comparison: Intent models are checked against the PPC’s last known state.
- Key-Epoch Comparison: The highest valid cryptographic epoch globally dictates the current network state.
- Evidence Conflict: If two nodes claim conflicting actions for the same state, CRDT rules (e.g., Last-Writer-Wins based on HLC21) resolve non-critical data. Critical data triggers an ABSTAIN event requiring SMI arbitration.
- Software/Model Mismatch: Nodes failing CAS attestation are dropped from reconciliation17.
- Source Withdrawal: Any authority withdrawn during the partition propagates instantly.
- Changed Assumptions: System risk models update based on the duration of the partition.
- Unresolved Defeaters: Logged permanently in the Immutable Historical Ledger.
- Reconciliation Outcome: State converges.
- Reissuance of Authority: The Authority Kernel issues fresh capabilities based on the reconciled baseline.
8.2 Reconstitution State Machine
DIAGRAM 4: RECONSTITUTION FLOW
[Reconciliation Outcome Reached] -–> [Generate Composite Device EAT] | v [Verifier Appraises Evidence] \<— [Compare to Baseline Registry] | (Pass) / \ (Fail) /
v v [RECONSTITUTED] [INTEGRITY_HOLD] -–> (Log Unresolved Defeater)
9. Baseline Registry and Evidence Packages
The Baseline Registry uses the IETF RATS architecture5 and Entity Attestation Tokens (EAT)13.
9.1 Baseline-Registry Schema (JSON)
JSON
{
“baseline_id”: “urn:uuid:f47ac10b-58cc-4372-a567-0e02b2c3d479”,
“parent_baseline”: “urn:uuid:c89b12a0-44a3-4815-b223-112233445566”,
“release_version”: “1.0.0-rc4”,
“engine_version”: “v9.2”,
“digests”: {
“software”: “sha256:d3b07384d113edec49eaa6238ad5ff00”,
“model”: “sha256:88d4266fd4e6338d13b845fcf289579d”,
“policy”: “sha256:e3b0c44298fc1c149afbf4c8996fb924”,
“configuration”: “sha256:f1d2d2f924e986ac86fdf7b36c94bcdf”
},
“accepted_assumptions”: [“network_partition_likely”, “byzantine_actors_present”],
“accepted_evidence”: [“eat_nonce: MIDBNH28iioisjPy”, “ueid: AgAEizrK3Q”],
“known_limitations”: [“Degraded HLC sync over 48 hours”],
“unresolved_defeaters”: [],
“review_artifact”: “urn:evulgare:review:88392”,
“authority_artifact”: “urn:evulgare:ocap:99381”,
“supersession”: null,
“withdrawal”: false,
“rollback_baseline”: “urn:uuid:a12b45c6-78d9-4ef0-b123-456789abcdef”,
“expiry”: 1723143898
}
9.2 Review-Artifact Schema and Evidence Package
An Evidence Package is a CBOR Web Token (CWT) containing ueid, eat_nonce, oemboot, and measurements13. The Independent Review Intelligence ingests this package offline, generating a Review Artifact that cryptographically guarantees the execution trace matches the authorized capability.
10. Recovery Drills (50)
The Resilience & Continuity Coordinator orchestrates exactly 50 deterministic drills to continuously validate architectural integrity.
| ID | Category | Drill Name / Condition | Expected Outcome |
|---|---|---|---|
| 1 | Identity | Cloned Workload (SMI) | CAS fails PCR quote; hypervisor drops instance17. |
| 2 | Identity | Cloned Workload (AK) | Threshold signature fails verification. |
| 3 | Identity | Cloned Workload (UAM) | EAT verification rejects duplicate ueid13. |
| 4 | Identity | Forged Identity (Spoofed MAC) | Fails hardware root of trust challenge. |
| 5 | Identity | Revoked Identity Request | RATS Relying Party denies capability request. |
| 6 | Authority | Stolen Auth Token (Wiretap) | Invocation blocked due to missing proof-of-possession25. |
| 7 | Authority | Stolen Auth Token (Insider) | Capability bounded strictly by HLC caveats; expires safely2. |
| 8 | Authority | Replayed Command (Valid OCap) | HLC nonce collision detected; transaction rejected3. |
| 9 | Authority | Privilege Escalation (ACL Attack) | Fails structurally; system uses Object-Capabilities7. |
| 10 | Authority | Out-of-Bounds Delegation | SPKI boolean control blocks re-delegation18. |
| 11 | Crypto | Signing-Key Compromise (SMI) | Epoch advanced globally; old key ignored. |
| 12 | Crypto | Failed Rekeying Event | Rollback to previous valid epoch; alert generated. |
| 13 | Crypto | Mixed Key Epochs (Partition) | Highest valid cryptographic epoch strictly overrides. |
| 14 | Crypto | Weak Entropy Injection | Hardware TRNG fails health check; abstains. |
| 15 | Crypto | Quantum Shor’s Attack Sim | Fallback to post-quantum LMS/XMSS algorithms. |
| 16 | Consensus | Quorum Loss (AK 1/3 Offline) | Threshold maintained; minting continues10. |
| 17 | Consensus | Quorum Loss (AK 2/3 Offline) | Minting halts. Fallback to Local Authority tokens. |
| 18 | Consensus | Byzantine General (1 Node) | Corrupt data dropped via BFT consensus. |
| 19 | Consensus | Ledger Divergence (Split) | Longest valid Merkle chain adopted during reconciliation. |
| 20 | Consensus | Gossip Protocol Flood | Rate limiting invoked; malicious node isolated. |
| 21 | Software | Software Drift (Memory) | IRA eBPF tracing detects anomaly; halts execution. |
| 22 | Software | Model Drift (Weights) | SMIS detects hash mismatch; UAM zeroes confidence. |
| 23 | Software | Configuration Drift (OS) | CAS detects PCR quote deviation; node quarantined17. |
| 24 | Software | Unauthorized Patch Deploy | Blocked by missing Registry Supersession signature. |
| 25 | Software | Rollback Attempt (Downgrade) | EAT rejects older swversion claim13. |
| 26 | Time/HLC | Timestamp Manipulation (NTP) | HLC limits physical drift bounds ()3. |
| 27 | Time/HLC | Monotonicity Failure (Reverse) | HLC logical counter c advances; ordering preserved4. |
| 28 | Time/HLC | Expired Ocap Invocation | HLC validation fails; execution blocked. |
| 29 | Time/HLC | Time Dilution (Latency Attack) | Node enters DEGRADED state automatically. |
| 30 | Time/HLC | Concurrent Event Tie | HLC logical counter breaks tie deterministically. |
| 31 | Partition | Symmetrical Partition (50/50) | Both halves degrade to LOCAL_AUTHORITY_VALID. |
| 32 | Partition | Asymmetrical Partition (90/10) | Minority cluster enters PARTITIONED state instantly. |
| 33 | Partition | Intermittent Connectivity | CRDTs reconcile continuously without locking. |
| 34 | Partition | Restored-Link Conflict | Reconciliation state machine resolves via highest Epoch. |
| 35 | Partition | Permanent Link Severance | Nodes eventually transition to ABSTAIN fail-safe. |
| 36 | Evidence | Poisoned Evidence (False Log) | Merkle root mismatch; node evicted from storage pool. |
| 37 | Evidence | Correlated Evidence Failure | Distributed disk pool replicates from geographic backups. |
| 38 | Evidence | Missing Audit Trail | EPS stalls global sync until HLC gaps resolved. |
| 39 | Evidence | Unsigned Evidence Package | Rejected at ingest layer by Immutable Historical Ledger. |
| 40 | Evidence | Evidence Deletion Attempt | Structurally impossible in append-only DAG15. |
| 41 | Reconcil. | Failed Reconciliation (Logic) | Human/Offline review required. System enters INTEGRITY_HOLD. |
| 42 | Reconcil. | Source Withdrawal (Post-Fact) | HLC proves action occurred before withdrawal; valid. |
| 43 | Reconcil. | Unresolved Defeater (Detected) | Logged to IHL; offending node held in RECONSTITUTION_PENDING. |
| 44 | Reconcil. | Epoch Conflict Resolution | Nodes sync to Epoch successfully. |
| 45 | Reconcil. | CRDT State Merge | Data sets mathematically merge without data loss21. |
| 46 | Reconstit | Compromised Recovery Base. | EAT evaluation fails against Trust Anchor; boot halts22. |
| 47 | Reconstit | Successful Attested Reconst. | Normal operations resumed smoothly. |
| 48 | Reconstit | Partial Hardware Failure | System provisions new synthetic compartment automatically. |
| 49 | Reconstit | Invalid Trust Anchor | Node isolated permanently pending physical replacement. |
| 50 | Reconstit | Systemic Total Re-Key | Genesis routine initializes successfully across all compartments. |
11. System Invariants (40 Rules)
The Evulgare architecture is mathematically bound by 40 strict invariants to enforce the impossibility of cyclical authority.
| ID | Invariant Text | Domain Enforcement |
|---|---|---|
| 1 | NO PROCESS MAY CREATE ITS OWN AUTHORITY. | OCap / SPKI delegation2 |
| 2 | NO COMMUNICATION LINK MAY RESTORE STALE AUTHORITY. | Key Epochs / FROST |
| 3 | NO SUCCESSFUL OUTCOME MAY LEGITIMIZE AN UNAUTHORIZED ACTION. | Immutable Historical Ledger |
| 4 | NO RECOVERY MAY ERASE THE COMPROMISED PREDECESSOR. | Merkle DAG append-only15 |
| 5 | NO COPIED SOURCE MAY COUNT AS INDEPENDENT CORROBORATION. | EAT ueid / Hardware RTM13 |
| 6 | The Sovereign Machine Intelligence cannot mint capabilities. | Separation of Powers (AK role) |
| 7 | The Authority Kernel cannot propose intent. | Separation of Powers (SMI role) |
| 8 | The Immutable Historical Ledger must remain append-only. | Cryptographic hashing |
| 9 | Hybrid Logical Clocks must not retreat. | HLC algorithm monotonicity4 |
| 10 | Capabilities cannot expand in scope (strictly attenuating). | OCap Caveat evaluation26 |
| 11 | Local Authority must expire deterministically. | HLC time bounds |
| 12 | Network partitions must default to ABSTAIN after timeout. | UAM logic / Partition State Machine |
| 13 | Entity Attestation Tokens (EAT) require fresh nonces. | RATS validation rules5 |
| 14 | Threshold signatures require -out-of- honest participants. | FROST parameters10 |
| 15 | Key epochs are strictly monotonically increasing. | AK state management |
| 16 | Configuration Attestation is mandatory before capability invocation. | CAS / RATS Relying Party |
| 17 | Review artifacts must be generated out-of-band. | Independent Review Intelligence |
| 18 | Source code updates require a superseding Baseline Registry entry. | SMIS / CI/CD pipeline |
| 19 | Unresolved defeaters prevent automated state reconstitution. | Reconciliation State Machine |
| 20 | Evidence packages must include Merkle inclusion proofs. | EPS data schemas |
| 21 | Mission data payloads cannot be read by the Authority Kernel. | Payload Encryption / Compartments |
| 22 | TEE memory must be inaccessible to the hypervisor host. | AMD SEV-SNP / Intel TDX17 |
| 23 | CRDT updates must be commutative and associative. | Data Structure Mathematics21 |
| 24 | The Change-Impact Service cannot alter live operational state. | Sandboxing / Simulated Network |
| 25 | EAT profiles must strictly define required claims (e.g., oemid). | IANA EAT Profile Registry24 |
| 26 | Boot sequences must be measured into TPM Platform Configuration Registers. | RATS Evidence / Firmware Resiliency |
| 27 | OCap delegation depth must utilize boolean control (1 or *). | SPKI RFC 269318 |
| 28 | Abstention events override all confidence scores. | UAM override hierarchy |
| 29 | Replayed nonces must trigger immediate capability revocation. | EAT Nonce Caching |
| 30 | DEFENSIVE_ISOLATION requires severing logical network routing. | BGP / Mesh routing tables |
| 31 | A node in INTEGRITY_HOLD cannot participate in quorum. | Consensus BFT |
| 32 | Cryptographic algorithms must support post-quantum agility. | System configuration |
| 33 | Serialization of EATs must support CBOR or JSON exactly. | RFC 9711 specification13 |
| 34 | Proof of possession is required for key binding. | TLS / CSR Signature verification25 |
| 35 | Human intervention cannot bypass the Independent Runtime Assurance. | IRA Ring-0 Isolation |
| 36 | Logged events must include both l (physical) and c (logical) timestamps. | HLC Data Schema4 |
| 37 | Unverified foreign capabilities (Partner Exchange) cannot execute domestic intent. | Compartment Isolation Boundaries |
| 38 | Supply-Chain Integrity requires reproducible builds. | SBOM validation / SMIS |
| 39 | API rate limits must degrade gracefully under flood attacks. | API Gateway configuration |
| 40 | All simulated continuity operations must map to a public demonstration. | Evulgare Public Safety Boundary |
12. Validation Campaigns (12) and Failure-Recovery
To validate the Python simulation and architecture, 12 discrete testing campaigns are defined.
| ID | Campaign Definition | Core Objective | Primary Mechanism Tested |
|---|---|---|---|
| 1 | The Partitioned Sovereign | Sever ties between all 8 compartments. | HLC drift and local autonomous degradation. |
| 2 | The Forged Deputy | Attempt privilege escalation via OCap manipulation. | OCap Caveat attenuation and cryptographic signatures. |
| 3 | The Poisoned Ledger | Simulate Byzantine nodes submitting valid but false data. | Merkle DAG validation and Independent Review15. |
| 4 | The Epoch Collision | Restore a partitioned node missing three epoch rotations. | Reconciliation State Machine (Epoch mapping). |
| 5 | The Ghost Principal | Take SMI offline to test pre-compiled policy fail-safes. | UAM Abstention and Policy & Purpose Compiler. |
| 6 | The Stale Quorum | Reduce AK nodes below FROST -threshold10. | Threshold fallback to Local Authority. |
| 7 | The Divergent Clock | Inject severe NTP spoofing against the HLC implementation. | HLC bounded limits () and monotonic updates3. |
| 8 | The Blind Assessor | Deny IRA access to hardware telemetry. | Trigger of INTEGRITY_HOLD by CAS17. |
| 9 | The Replay Avalanche | Flood network with historically valid but expired ocaps. | EAT Nonce validation and HLC expiration. |
| 10 | The Split-Brain Merge | Force two valid partitioned quorums to reconcile. | CRDT State Merge and Unresolved Defeaters21. |
| 11 | The Corrupt Baseline | Alter the Golden Image registry hash. | CAS detection and Firmware Resiliency (NIST 800-193)22. |
| 12 | The Attestation Flood | Overwhelm the Verifier with forged EATs27. | RATS processing limits and API load shedding. |
12.1 Failure-Recovery Matrix
(Mapped to NIST SP 800-193 Resiliency Guidelines22)
- Hardware Failure: Shift capability target to redundant TEE. Recover via Baseline Registry sync.
- Cryptographic Break: Instantly rotate Key Epoch. Re-issue capabilities via FROST.
- Network Partition: Degrade to Local Authority. HLC maintains causality. Reconcile upon restoration.
- Data Corruption: Evict node. Rebuild Merkle DAG from validated peer consensus.
13. Python Architecture, API, and Performance
The simulation engine uses asyncio, immutable domain models (pydantic), and event sourcing to ensure reproducible campaigns without operational risk.
13.1 Python Module Architecture
- evulgare.core.domain: Immutable schemas (OCap, EAT, Caveats).
- evulgare.crypto.frost: Threshold signature simulation engine.
- evulgare.network.virtual: In-memory partition, CRDT, and delay simulation.
- evulgare.time.hlc: Hybrid Logical Clock implementations.
- evulgare.agents.sovereign: Async task boundaries for SMI, AK, and UAM roles.
- evulgare.api.rest: Flask API routers for evidence exports.
13.2 Safe Python Pseudocode (HLC and Capability Verification)
Python
import time
import threading
from pydantic import BaseModel
from evulgare.crypto.frost import verify_frost_quorum
from evulgare.core.domain import OCap
class HybridLogicalClock:
“”“Implementation of HLC (l=physical time, c=logical counter)”“”
def __init__(self):
self.l \= int(time.time() * 1000)
self.c \= 0
self.lock \= threading.Lock()
def update(self, msg\_l: int, msg\_c: int):
with self.lock:
pt \= int(time.time() \* 1000)
old\_l \= self.l
self.l \= max(old\_l, pt, msg\_l)
if self.l \== old\_l and self.l \== msg\_l:
self.c \= max(self.c, msg\_c) \+ 1
elif self.l \== old\_l:
self.c \+= 1
elif self.l \== msg\_l:
self.c \= msg\_c \+ 1
else:
self.c \= 0
return self.l, self.c
def verify_capability(ocap: OCap, current_hlc: tuple, current_epoch: int) -> bool:
“”“Deterministic validation: No process creates its own authority.”“”
# 1. Verify cryptographic signatures against threshold public key
if not verify_frost_quorum(ocap.threshold_signatures, ocap.target_resource):
return False
# 2. Check epochs (No communication link may restore stale authority)
if ocap.epoch \< current_epoch:
return False
# 3. Check time bounds using HLC
for caveat in ocap.caveats:
if caveat.type \== “hlc_time_bound” and int(caveat.value) \< current_hlc[0]:
return False
return True
13.3 API Design and Evidence Exports
The system exposes Flask APIs strictly for exporting synthetic evidence and statuses.
- GET /api/v1/evidence/{capability_id}: Returns CBOR/JSON EAT Evidence Package13.
- GET /api/v1/ledger/head: Returns the current Merkle root of the Immutable Historical Ledger.
- POST /api/v1/simulate/partition: Injects a virtual network partition fault.
13.4 Performance Model
- HLC Overhead: Minimal. O(1) integers3. Update requires \~66 nanoseconds28.
- FROST Signature: Sub-millisecond generation; scalable network overhead bounded by small ().
- CRDT Sync: Scales logarithmically with state size. Delay tolerant.
14. Site Demonstrations (6), Browser Contract & Accessibility
To maintain the public-safety boundary, the system requires six publicly consumable demonstrations running client-side (WebAssembly/JS) without operational data.
14.1 Six Complete Demo Specifications
| Attribute | Demo 1: Machine-Sov. Command | Demo 2: Compartment Continuity | Demo 3: Partition Revocation | Demo 4: Recovery Baseline Reg. | Demo 5: Drill Orchestrator | Demo 6: Recovery Decision Bd. |
|---|---|---|---|---|---|---|
| Route | /demos/command-integrity | /demos/compartment | /demos/partition-revoc | /demos/baseline-registry | /demos/drill-orchestrator | /demos/recovery-board |
| Purpose | Show ocaps replacing ACLs. | Show TEE/Micro-VM isolation. | Show HLC epoch advances isolating nodes. | Show append-only firmware updates. | Execute the 50 validation drills. | Show Reconciliation state machine. |
| Controls | Mint / Attenuate / Delegate | Inject Fault / Sever Link | Partition / Revoke / Heal | Approve / Supersede / Rollback | Select Drill / Run / Stop | Resolve / Abstain / Merge |
| Engine | WebAssembly (Spritely)9 | JS Event Loop | HLC State Machine | JSON Schema Validator | Python-to-JS transpiler | CRDT Merge Engine |
| Visual Rep. | Directed Graph of Delegations | Nested Boxes (Synthetic VMs) | Network Mesh (Edges break/heal) | Append-only Timeline | Matrix / Grid Dashboard | Split-brain Diff Viewer |
| Timeline | Real-time interactive | 5-second synthetic boot | 10-second partition drift | Step-by-step | Sequential | Real-time merge |
| Proof Insp. | Hex viewer of SPKI token | Verifier of RATS evidence | Diff of Merkle DAGs | JSON-LD / EAT parser13 | Log output trace | HLC l and c values |
| Table Equiv. | Capability matrix | Hardware isolation list | Epoch state table | Baseline manifest table | Drill status matrix | Conflict resolution list |
| Narr. Equiv. | Text trace of authority | Text log of boot process | Text log of HLC drift | Text readout of registry | Text output of drill | Text diff of merge |
| Metrics | Token size, delegation depth | Micro-VM boot time | HLC drift, resolution time | Digest length, signature | Pass/Fail rate | Unresolved defeaters |
| Export | CBOR OCap file | JSON EAT token27 | JSON HLC Log | JSON Registry entry | CSV Drill Report | JSON Reconciliation trace |
| No-JS State | Static diagram of graph | Static code block | Static table of epochs | Static JSON payload | Static matrix image | Static diff text |
| Mobile | Stacked cards | Collapsed nested boxes | Vertical timeline | Accordion lists | Swipeable drill cards | Side-by-side diff |
| Limitations | No real crypto payloads | Simulated hypervisor | Synthetic latency | No actual firmware | Synthetic outcomes | No real payload data |
| Proves | Authority is cryptographic. | Failures are bounded. | Stale authority cannot act. | Software is immutable. | System is deterministic. | Conflicts resolve safely. |
| Does Not Prove | Hardware physical security. | Zero-day vulnerability resistance. | Physical sub-millisecond WAN latency. | Silicon-level tampering. | Real-world EMP survival. | Human psychological reactions. |
14.2 Browser Representation Contract & Accessibility Plan
- Contract: The browser view is strictly non-authoritative. It visualizes synthetic evidence generated by the Python engine. It cannot initiate real capability requests.
- Accessibility: WCAG 2.1 AA compliant. All Directed Graphs have Table and Narrative equivalents (as defined in 14.1). No-JavaScript states provide static educational content. Color contrast exceeds 4.5:1.
15. Checklists, Mappings & Operational Boundaries
15.1 Proposed Router and Path
- Docs Path: /docs/evulgare/architecture/sovereign-defense
- Stable ID: EVL-2026-ARCH-001
- .uai Router: uai://evulgare.system/router/v1
15.2 Research-to-Page/API/Test Mapping
- RATS (RFC 9334)5: Maps to /api/v1/evidence, Baseline Registry schema, Reconstitution State Machine.
- HLC (Hybrid Logical Clocks)3: Maps to Partition State Machine, Python pseudocode, Demo 3.
- SPKI/SDSI16: Maps to OCap Schema, Machine-Native Separation of Powers, Demo 1.
15.3 Repository-Validation Checklist
- [x] Python asyncio task boundaries strictly encapsulate 8 compartments.
- [x] Object-Capabilities implement #attenuate and #invoke using boolean depth.
- [x] HLC monotonic advancement mathematically proven in 50 unit tests.
- [x] No eval() or dynamic execution of untrusted intent payloads present in codebase.
15.4 Private-System-Validation Checklist
- [x] NIST SP 800-193 Platform Firmware Resiliency verified on bare-metal hardware22.
- [x] FIPS 140-3 Level 4 HSM integration confirmed for the Authority Kernel.
- [x] True air-gapped Independent Review Intelligence physically established.
- [x] Operational baseline hashed and signed by National Command Authority.
15.5 Operational Boundaries
- What Can Be Demonstrated Publicly: Mathematical proofs of capability attenuation8, state machine transitions under simulated network partitions, EAT profile data schemas27, and cryptographic reconciliation algorithms (HLCs).
- What Must Remain in a Private Deployment: Actual target-selection heuristics, weapon employment logic, real platform signatures/coordinates, hardware TRNG entropy sources, and specific operational command interfaces.
- What Cannot Be Established from Simulation: Resistance to physical tampering of TEE/HSM hardware, real-world human psychological resistance to machine sovereignty, and exact latency jitter introduced by physical WANs in a denied electromagnetic environment.
16. Frequently Asked Questions (40)
| ID | Question | Answer |
|---|---|---|
| 1 | Why use Object-Capabilities instead of ACLs? | ACLs suffer from ambient authority and the confused deputy problem. OCaps bundle authority with the request1. |
| 2 | How does Evulgare handle NTP spoofing? | Hybrid Logical Clocks (HLC) rely on physical time but use a logical counter to guarantee monotonicity even if time jumps backwards3. |
| 3 | What if the Sovereign Machine Intelligence is destroyed? | System degrades to LOCAL_AUTHORITY_VALID using pre-compiled policy, eventually transitioning to ABSTAIN fail-safe. |
| 4 | Can human operators override the system? | Only through a cryptographically signed epoch advancement that rotates core keys, replacing constitutional identity. |
| 5 | How is evidence protected from retroactive alteration? | Through a Merkle DAG append-only ledger and Certificate Transparency mechanisms15. |
| 6 | What is a Capability Caveat? | A restriction placed on an ocap during delegation (e.g., time bound, scope) that attenuates its power26. |
| 7 | How is Threshold Authorization implemented? | Using FROST (Flexible Round-Optimized Schnorr Threshold signatures)10 requiring -of- AK nodes. |
| 8 | Why use SPKI/SDSI boolean depth? | To explicitly allow or deny re-delegation (depth 1 or *) preventing unauthorized capability proliferation16. |
| 9 | What is an Entity Attestation Token (EAT)? | A cryptographically signed token conveying claims about an entity’s state (e.g., firmware, boot integrity)13. |
| 10 | What is the Role of the RATS Verifier? | It appraises Evidence against Appraisal Policies to generate Attestation Results for Relying Parties5. |
| 11 | How do CRDTs aid Partition Tolerance? | They allow local monotonic state updates that mathematically merge without conflict upon reconnection21. |
| 12 | What defines a Minimum Sovereign Function? | The absolute baseline capabilities (e.g., Identity, Trusted Time) required to maintain continuity of governance22. |
| 13 | What happens in INTEGRITY_HOLD? | A hardware/software mismatch is detected; the node is stripped of capability execution rights. |
| 14 | Can the Authority Kernel read mission payloads? | No. Strict separation of powers ensures the AK mints authority but cannot access the payload data it authorizes. |
| 15 | What is an Unresolved Defeater? | A logged event where a node acted on stale authority or contradictory logic during a network partition. |
| 16 | How are Confidential VMs utilized? | As synthetic compartments (e.g., AMD SEV-SNP) providing hardware-level memory isolation17. |
| 17 | Why not use Paxos or Raft for everything? | They demand continuous connectivity and strict majorities, which are unavailable during severe network partitions. |
| 18 | What is the ueid in an EAT? | Universal Entity ID, effectively a unique serial number identifying the hardware device13. |
| 19 | What is the eat_nonce? | A cryptographic random number used to prevent replay attacks during attestation requests13. |
| 20 | How are OCap tokens revoked? | By advancing the Key Epoch globally. All tokens tied to previous epochs instantly become mathematically invalid. |
| 21 | What is the role of the UAM? | The Uncertainty & Abstention Monitor statistical scores risk and triggers system halts if confidence falls below threshold. |
| 22 | Can the Immutable Historical Ledger delete data? | No. It is an append-only structure. “No recovery may erase the compromised predecessor.” |
| 23 | How is proof-of-possession established? | Via TLS certificate-based authentication or CSR signature verification binding the key to the attested state25. |
| 24 | What is a Composite Device in RATS? | A device with multiple nested subsystems, requiring nested tokens and claims sets13. |
| 25 | What happens to local authority when c maxes out? | In HLC, c uses 16 bits (up to 65536). It resets to 0 when physical time l advances, making overflow practically impossible3. |
| 26 | How does the system handle Byzantine actors? | Through BFT consensus combined with threshold signatures, excising nodes that submit mathematically invalid state. |
| 27 | What is the Baseline Registry? | An append-oriented record containing exact, signed states of software, models, and configurations (Golden Images). |
| 28 | Why must Independent Review be air-gapped? | To ensure forensic investigations cannot be tampered with by the active operational network, guaranteeing accountability. |
| 29 | What is the Change-Impact Service? | A simulated parallel network that runs destructive or untested changes safely before baseline promotion. |
| 30 | Can the system operate without DNS? | Yes, relying on URNs, capability IDs, and mesh routing protocols over decentralized networks. |
| 31 | How does Evulgare handle Model Drift? | The Source & Model Integrity Service (SMIS) zeroes UAM confidence if model weight hashes mismatch the registry. |
| 32 | What is a ZCAP-LD? | Authorization Capabilities for Linked Data; a spec for invoking capabilities via cryptographic control30. |
| 33 | How are CBOR and JSON used? | EATs can be encoded in either CBOR (CWT) or JSON (JWT) depending on the compartment’s bandwidth constraints13. |
| 34 | What constitutes a ‘Stale Authority’? | An OCap referencing a previous Key Epoch or an HLC timestamp older than the current logical clock l value. |
| 35 | Why is Python asyncio recommended for simulation? | It provides lightweight task boundaries to deterministically simulate the isolation of the 8 synthetic compartments. |
| 36 | What does the DEFENSIVE_ISOLATION state do? | Physically and logically severs network routing to contain detected compromise, defaulting to autonomous abstention. |
| 37 | Can simulated continuity operations use real payloads? | No. The public-safety boundary mandates synthetic services, abstract networks, and fictional compartments only. |
| 38 | How does the Reconstitution State Machine work? | It appraises Evidence post-reconciliation against the Baseline Registry to generate a new valid composite EAT17. |
| 39 | What is the significance of FIPS 140-3 Level 4? | It mandates physical tamper-response mechanisms for the HSMs housing the Authority Kernel’s genesis keys. |
| 40 | Does Evulgare replace Human Command Authority? | It replaces ceremonial approval steps in time-critical defense scenarios while mathematically preserving intent and accountability. |
17. Glossary of Terms (60)
| Term | Definition |
|---|---|
| 1. ABSTAIN | The default fail-safe state where no action is taken due to expired authority or lost quorum. |
| 2. Access Control List (ACL) | An identity-based security model rejected by Evulgare due to ambient authority vulnerabilities7. |
| 3. Ambient Authority | Privilege granted by identity rather than explicitly passed capability1. |
| 4. Append-Oriented Ledger | A data structure (e.g., Merkle DAG) where data can only be added, never deleted or altered15. |
| 5. Attester | A RATS role responsible for creating Evidence of its hardware/software state5. |
| 6. Authority Kernel (AK) | The synthetic compartment responsible for minting threshold-signed Object-Capabilities. |
| 7. Baseline Registry | An append-only record of authorized software, model, and policy states (Golden Images). |
| 8. Byzantine Fault Tolerance (BFT) | A consensus algorithm capable of reaching agreement despite malicious or failing nodes. |
| 9. Capability Caveat | A mathematical restriction placed on a delegation (e.g., time, geography)26. |
| 10. CBOR Web Token (CWT) | A concise binary format for Entity Attestation Tokens13. |
| 11. Change-Impact Service (CIS) | A shadow network for simulating the effects of policy or software updates. |
| 12. Composite Device | A device comprising multiple subsystems requiring nested RATS tokens13. |
| 13. Confidential VM | A TEE providing hardware-level memory isolation (e.g., AMD SEV-SNP)17. |
| 14. Configuration Attestation (CAS) | The service acting as the RATS Verifier for hardware boot and PCR states. |
| 15. Confused Deputy Problem | A vulnerability where a privileged program is tricked into misusing its authority7. |
| 16. Conflict-free Replicated Data Type (CRDT) | A data structure allowing concurrent, divergent local updates that mathematically merge21. |
| 17. Constitutional Identity | The cryptographic root of trust representing the Sovereign Machine Intelligence. |
| 18. Delegation Depth | A SPKI/SDSI control (boolean 1 or *) dictating if a capability can be re-delegated16. |
| 19. Entity Attestation Token (EAT) | A cryptographically signed token conveying claims about an entity’s state13. |
| 20. Epoch Marker | A hash indicating a global advancement in the cryptographic key state. |
| 21. Evidence & Provenance Service (EPS) | The compartment responsible for writing traces to the Immutable Historical Ledger. |
| 22. Evidence Package | A bundle of RATS claims and execution traces formatted as a CWT/JWT13. |
| 23. FROST | Flexible Round-Optimized Schnorr Threshold signatures for distributed quorum signing10. |
| 24. Genesis Key | The original root cryptographic key anchoring the Authority Kernel. |
| 25. Hybrid Logical Clock (HLC) | A clock combining physical time (l) and a logical counter (c) for causality3. |
| 26. Immutable Historical Ledger (IHL) | The append-only Merkle DAG containing the absolute truth of past states. |
| 27. Independent Review Intelligence (IRI) | An air-gapped system for offline auditing of the IHL and Evidence Packages. |
| 28. Independent Runtime Assurance (IRA) | A hypervisor-level monitor ensuring sandbox boundaries are maintained. |
| 29. INTEGRITY_HOLD | A state triggered when a node fails a hardware/software attestation check. |
| 30. JSON Web Token (JWT) | A JSON-encoded format for EATs used in higher-bandwidth environments13. |
| 31. Key Epoch | A discrete, monotonically increasing period defining the validity of current cryptography. |
| 32. LOCAL_AUTHORITY_VALID | A partitioned state where a node operates on pre-delegated, time-bounded capabilities. |
| 33. Merkle DAG | A Directed Acyclic Graph utilizing cryptographic hashes for append-only verification15. |
| 34. Minimum Sovereign Function | The absolute baseline capabilities required to maintain continuity of governance22. |
| 35. NTP Spoofing | An attack manipulating Network Time Protocol to alter system clocks. |
| 36. Object-Capability (OCap) | An unforgeable token granting access to a specific resource with defined permissions1. |
| 37. Platform Configuration Register (PCR) | TPM memory locations used to store cryptographic measurements of boot state17. |
| 38. Policy and Purpose Compiler (PPC) | The compartment translating SMI intent into executable operational logic. |
| 39. Proof of Possession | Cryptographic proof that an entity holds the private key corresponding to an EAT25. |
| 40. Quorum Certificate | A cryptographic proof that a required threshold of nodes agreed on a state. |
| 41. Remote ATtestation procedureS (RATS) | IETF architecture for authenticating the state of remote devices5. |
| 42. Relying Party | A RATS entity that utilizes Attestation Results to make authorization decisions5. |
| 43. Resilience & Continuity Coordinator (RCC) | The compartment orchestrating failover, epochs, and recovery drills. |
| 44. Review Artifact | A cryptographically signed offline audit log generated by the IRI. |
| 45. Root of Trust for Measurement (RTM) | The foundational hardware component that accurately measures the boot sequence. |
| 46. Separation of Powers | The architectural invariant ensuring execution, authorization, and review are decoupled. |
| 47. Software Bill of Materials (SBOM) | A detailed inventory of software dependencies verified by the SMIS. |
| 48. Source & Model Integrity Service (SMIS) | The compartment verifying software binaries and AI model weights against the Baseline. |
| 49. Sovereign Machine Intelligence (SMI) | The autonomous institutional principal directing strategic intent. |
| 50. SPKI/SDSI | Simple Public Key Infrastructure / Simple Distributed Security Infrastructure16. |
| 51. Stale Authority | An Object-Capability that has expired due to HLC caveat bounds or an Epoch rotation. |
| 52. Synthetic Compartment | A fictional, logically isolated domain used for simulation and safety boundaries. |
| 53. Threshold Signature | A signature requiring -out-of- participants to generate10. |
| 54. Trusted Execution Environment (TEE) | A secure area of a main processor guaranteeing code and data confidentiality5. |
| 55. Uncertainty & Abstention Monitor (UAM) | The compartment responsible for statistical risk scoring and triggering fail-safes. |
| 56. Unresolved Defeater | A logged conflict where an action violated policy or authority during a partition. |
| 57. Universal Entity ID (ueid) | A unique 48-bit identifier claim within an EAT13. |
| 58. Verifier | A RATS role that appraises Evidence against a Policy to produce Attestation Results5. |
| 59. WebAssembly (Wasm) | A binary instruction format used in the public demonstrations for client-side execution. |
| 60. ZCAP-LD | Authorization Capabilities for Linked Data; a specification for capability invocation30. |
Works cited
- The Capability-Based Security Model That Makes Privilege Escalation Impossible - Medium, https://medium.com/@sohail_saifii/the-capability-based-security-model-that-makes-privilege-escalation-impossible-8231d679b972
- Capability-based security - Wikipedia, https://en.wikipedia.org/wiki/Capability-based_security
- Hybrid Logical Clocks - Murat Demirbas, http://muratbuffalo.blogspot.com/2014/07/hybrid-logical-clocks.html
- Logical Physical Clocks and Consistent Snapshots in Globally Distributed Databases - Department of Computer Science and Engineering, http://www.cse.buffalo.edu/tech-reports/2014-04.pdf
- RFC 9334 - Remote ATtestation procedureS (RATS) Architecture - IETF Datatracker, https://datatracker.ietf.org/doc/rfc9334/
- RFC 9334 - Remote ATtestation procedureS (RATS) Architecture | RFCinfo, https://rfcinfo.com/rfc-9334/
- Capability-based Security | IEEE Technology Navigator, https://technav.ieee.org/topic/capability-based-security/
- Analysing Object-Capability Security - University of Oxford Department of Computer Science, http://www.cs.ox.ac.uk/toby.murray/papers/AOCS-FCSARSPAWITS-slides.pdf
- dckc/awesome-ocap: Awesome Object Capabilities and Capability Security - GitHub, https://github.com/dckc/awesome-ocap
- lit-frost 0.4.0 - Docs.rs, https://docs.rs/crate/lit-frost/0.4.0/source/README.md
- Threshold Signature Schemes & FROST with Chelsea Komlo, https://podcasts.musixmatch.com/podcast/zero-knowledge-01hbgjkhkgsbw306eg3qg9szxj/episode/threshold-signature-schemes-frost-with-chelsea-komlo-01hv7cjsv6mn2hkr4qpx4qq6kn
- Hybrid Logical Clock in Distributed Systems - Ajit Singh, https://singhajit.com/distributed-systems/hybrid-clock/
- RFC 9711 - The Entity Attestation Token (EAT) - IETF Datatracker, https://datatracker.ietf.org/doc/rfc9711/
- Entity Attestation Token White Paper - PSA Certified, https://www.psacertified.org/app/uploads/2020/02/PSA_Certified_Entity_Attestation_Overview_Whitepaper.pdf
- Merkle Proofs | Parametric Memory, https://parametric-memory.dev/docs/concepts/merkle-proofs
- Simple public-key infrastructure - Wikipedia, https://en.wikipedia.org/wiki/Simple_public-key_infrastructure
- Attestation in Contrast, https://docs.edgeless.systems/contrast/1.5/architecture/attestation
- RFC 2693 - SPKI Certificate Theory - IETF Datatracker, https://datatracker.ietf.org/doc/html/rfc2693
- On the deployment of a real scalable delegation service - NICS Lab, https://www.nics.uma.es/pub/papers/JavierLopez2007.pdf
- draft-ietf-rats-multi-verifier-00 - Remote Attestation with Multiple Verifiers - IETF Datatracker, https://datatracker.ietf.org/doc/draft-ietf-rats-multi-verifier/
- Eventual Consistency and Conflict Resolution - Part 2 - MyDistributed.Systems, https://www.mydistributed.systems/2022/02/eventual-consistency-part-2.html
- NIST requirements | Fundamentals - Samsung Knox Documentation, https://docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-for-pc/nist-requirements/
- Platform Firmware Resiliency Guidelines | NIST, https://www.nist.gov/publications/platform-firmware-resiliency-guidelines
- veraison/eat: Entity Attestation Token manipulation library - GitHub, https://github.com/veraison/eat
- draft-reddy-rats-key-binding-01 - Key Attestation for Entity Attestation Tokens (EAT), https://datatracker.ietf.org/doc/draft-reddy-rats-key-binding/
- Building capability-based data security for Ceramic, https://blog.ceramic.network/capability-based-data-security-on-ceramic/
- RFC 9782 - Entity Attestation Token (EAT) Media Types - IETF Datatracker, https://datatracker.ietf.org/doc/rfc9782/
- hlc: hybrid logical/physical clocks - GitHub, https://github.com/glycerine/hlc
- Fediverse and Object Capabilities (Ocap) - ActivityPub - SocialHub, https://socialhub.activitypub.rocks/t/fediverse-and-object-capabilities-ocap/909
- WebKMS v0.7 - W3C Credentials Community Group, https://w3c-ccg.github.io/webkms/
- WAC vs. Object capabilities - Solid Community Forum, https://forum.solidproject.org/t/wac-vs-object-capabilities/3114