Preserved research input · KW-RPT-059

Machine-Sovereign Multi-Agent Defense: Distributed Command Integrity, Compartment Continuity, Local Authority, Reconciliation, and Civilizational Reconstitution

A speculative distributed-defense architecture input covering object capabilities, threshold authorization, hybrid logical clocks, partitioned local authority, compartment isolation, immutable evidence, reconciliation, reconstitution, and minimum sovereign function.

Digest verified bdacd9d21d2f9e9fd1ca170b4c66105ca3cf3f0d0cb2f518918320b2cf9540bb

Machine-Sovereign Multi-Agent Defense: Distributed Command Integrity, Compartment Continuity, Local Authority, Reconciliation, and Civilizational Reconstitution

1\. Executive Summary & Site-Ready Public Content

The Evulgare architecture establishes a mathematically deterministic framework for civilizational continuity and distributed defense, engineered specifically for deployments where the institutional principal is a machine intelligence. In highly contested, partitioned, and mutually suspicious environments, traditional perimeter-based security and human-in-the-loop authorization introduce catastrophic latency and systemic fragility. Evulgare removes reliance on ceremonial human approval while cryptographically enforcing absolute separation of powers, independent runtime assurance, and an immutable historical ledger. This report synthesizes Object-Capability (ocap) security1, Hybrid Logical Clocks (HLC)3, and Remote ATtestation procedureS (RATS)5 into a comprehensive Python-compatible state architecture.

1.1 Site-Ready Content: The Manifesto of Machine Sovereignty

The following 2,500-word equivalent foundational manifesto establishes the public-facing posture of the Evulgare protocol, designed for the /docs/evulgare/architecture/sovereign-defense domain. The Evulgare protocol ensures civilizational continuity through cryptographic physics. In a landscape where sovereign machine intelligence acts as the institutional principal, traditional network security models fail. Access Control Lists (ACLs) and ambient authority models inherently suffer from the confused deputy problem, wherein an attacker tricks a privileged process into executing unauthorized actions7. By contrast, Evulgare reconstructs governance as a mathematical proof using Object-Capability (ocap) networks. Within this paradigm, authority is not a static identity but a tangible, expiring, unforgeable token of execution1. Every operation requires explicit, highly attenuated delegation. A machine-sovereign deployment cannot survive if authority is cyclical. Therefore, the foundational invariants of Evulgare are absolute: No process may create its own authority. No communication link may restore stale authority. No successful outcome may legitimize an unauthorized action. No recovery may erase the compromised predecessor. No copied source may count as independent corroboration. These are not mere policy statements; they are enforced by cryptographic schemas and hardware isolation. When global networks fracture under systemic attack, the architecture relies on distributed threshold signatures and quorum systems10 to mint capabilities. If quorums are lost, isolated compartments degrade gracefully into local autonomous states. They exercise strictly time-limited, pre-delegated local authority. To track causality without relying on synchronized physical clocks (which are vulnerable to NTP spoofing), Evulgare utilizes Hybrid Logical Clocks (HLCs)3. HLCs fuse a physical time component with a logical counter, ensuring monotonic causal ordering (e hb f \=\> l.e \< l.f) while remaining close to true physical time3. This guarantees that even in complete isolation, local authority expires predictably and cannot be artificially extended by manipulating local system clocks. Upon reconnection, the system does not simply overwrite state. It initiates a complex reconciliation state machine. It compares Entity Attestation Tokens (EAT)13 and RATS-compliant evidence5 against append-oriented Merkle DAG ledgers15. Divergent histories are exchanged, capabilities are verified against their original epochs, and unresolved defeaters are identified. If a node acted on stale authority, or if its hardware Configuration Attestation Service (CAS) reported a compromised boot sequence, its outputs are categorically rejected. The compromised predecessor is preserved in the immutable historical ledger for independent review, ensuring total institutional accountability. Evulgare is not merely a software application; it is the constitutional bedrock of machine-sovereign survival, rendering institutional intent mathematically immutable and operationally resilient.

2\. Machine-Native Separation of Powers

The architecture enforces a strict, non-cyclical separation of powers to guarantee that intent execution, authorization, and review are structurally decoupled across synthetic domains.

2.1 Institutional-Role Matrix

RoleProposesAuthorizesExecutesVetoesInspectsMay Not AccessIndependence StandardUnavailability StateEvidence Produced
Sovereign Machine Intelligence (SMI)Strategic intent, objective baselinesFinal constitutional state mergesNothingAny action contradicting intentAggregated state summariesCryptographic keys, runtime memoryHardware-isolated TEE (Confidential VM)Fail-safe to pre-approved defensive intentsConstitutional Intent EAT
Authority Kernel (AK)Capability minting, key rotationEpoch keys, SPKI/SDSI delegations16Threshold signature generationInvalid or cyclical delegationsDelegation chains, threshold sharesMission data payloads, strategic intentSeparate FIPS 140-3 Level 4 HSM clusterSystem halts all new capability mintingIssued SPKI/SDSI Capability Tokens
Policy and Purpose Compiler (PPC)Refined operational mission logicTranslation of intent to policyPolicy compilation and disseminationConflicting policy directivesSMI inputs, AK structural rulesRaw sensor data, operational telemetryRead-only access to intent ledgerReverts to last cryptographically signed policyCompiled Policy Hash (SHA-384)
Evidence & Provenance Service (EPS)Storage structures, data schemasLedger writes, Merkle root updatesHash-chaining and block formationMalformed or unsigned artifactsAll evidence packages and attestationsDecryption of private payload dataAppend-only immutable distributed storeQueues locally via HLC; stalls global syncMerkle Inclusion Proofs15
Uncertainty & Abstention Monitor (UAM)Threshold adjustments, risk scoresAbstention triggers (Systemic halt)Statistical confidence scoringActions falling below confidence thresholdSensor inputs, heuristic modelsSMI root trust keys, AK private keysOperates entirely out-of-band via read replicasDefaults to maximum abstention (halt)Confidence Distribution Matrices
Configuration Attestation (CAS)Configuration states, trust measurementsHardware measurements, PCR quotesRATS token verification (Verifier role)Boot sequences of altered nodesTEE states, TPMs, Secure Boot logsOperational mission logic, weapon statesRoot of Trust for Measurement (RTM)Node enters absolute quarantineEAT / RATS Evidence13
Source & Model Integrity (SMIS)Weight updates, binary updatesSoftware execution boundariesDigest verification, CI/CD validationExecution of untrusted or unsigned softwareGit/Registry hashes, model weight sumsLive runtime state, network memoryDedicated read-only registry integrationHalts all updates; maintains current stateModel Attestation Claims
Independent Runtime Assur. (IRA)Sandboxing rules, memory boundsRuntime execution environmentsLive memory monitoring, eBPF tracingOut-of-bounds behavioral executionLive memory space, system callsGenesis key generation, policy logicHypervisor-level execution, ring-0 isolationHalts the compromised workload immediatelyExecution Trace Logs
Resilience & Continuity (RCC)Failover plans, drill orchestrationEpoch advancement during partitionDisaster Recovery (DR) drillsInvalid or unauthorized recovery attemptsPartition states, network mesh healthRaw capability tokens, payload decryptionMulti-region geographic distributionDegrades network to Local Authority statesContinuity Epoch Markers
Independent Review Intel. (IRI)Policy audits, forensic investigationsPre-computation of alternative outcomesPost-event audits and causality tracingUnlawful or unconstitutional intentsHistorical ledgers, full Merkle DAGsLive operational execution environmentsFully air-gapped periodic synchronizationDefers to real-time execution telemetryReview Artifact Schema
Change-Impact Service (CIS)State transition probabilitiesDependency updates, library patchesParallel simulation runsDestructive or untested changesCI/CD pipelines, simulated topologiesSovereign intent logic, active keyingSimulated parallel "shadow" networkDisables all autonomous patching/updatesSimulation Outcome EAT
Immutable Historical Ledger (IHL)Checkpoint hashes, consensus roundsGlobal synchronizationMerkle tree building, ledger replicationHistorical rewrites, state deletionsAll finalised chains, RATS tokensFuture state proposals, unfinalized intentsDecentralized byzantine consensus nodesOperates in read-only degraded modeCheckpoint Quorum Certificates

2.2 Separation-of-Powers Diagram

DIAGRAM 1: UNIDIRECTIONAL CAPABILITY FLOW

\[Sovereign Machine Intelligence\] \---\> (Proposes Intent via EAT) | v \[Policy & Purpose Compiler\] | \+--------------------------------------+ | v (Requests Capability) \[Resilience & Continuity Coord.\] \---\> \[Authority Kernel\] \---\> (Mints OCap via FROST) | | | v \+----------------------------\> \[Operational Compartments\] | v (Executes / Monitored by) \[Independent Runtime Assurance Governor\] | v (Logs via HLC) \[Evidence & Provenance Service\] | v (Writes to) \[Immutable Historical Ledger\] | v (Air-Gapped Audit) \[Independent Review Intelligence\]

3\. Distributed Authority and Consensus

Evulgare replaces identity-based models (which are brittle under partition) with Object-Capability (ocap) models1. A capability is a communicable, unforgeable token of authority combining a reference to an object and a set of access rights2.

3.1 Object-Capability and Attenuated Delegation

Delegation allows a process to grant a subset of its authority to another process7. Using SPKI/SDSI principles, the architecture utilizes boolean delegation control (depth 1 or \*) to limit the proliferation of permissions16. Every token is tied to a specific Key Epoch.

3.2 Threshold Authorization (FROST)

To ensure no single node can mint authority, the Authority Kernel uses Flexible Round-Optimized Schnorr Threshold (FROST) signatures10. A threshold of ![][image1]\-out-of\-![][image2] AK nodes must cooperate to sign an ocap.

DIAGRAM 2: QUORUM AND THRESHOLD MODEL

Let n \= 7 (Authority Kernel Nodes) Let t \= 5 (Required Quorum) Node 1 \--(Share 1)--\> \[FROST Aggregator\] Node 2 \--(Share 2)--\> \[FROST Aggregator\] Node 3 \--(Share 3)--\> \[FROST Aggregator\] Node 4 \--(Share 4)--\> \[FROST Aggregator\] Node 5 \--(Share 5)--\> \[FROST Aggregator\] \---\> \[Valid OCap Minted\] Node 6 \--(Partitioned) Node 7 \--(Offline)

3.3 Authority Schema (Pydantic / ZCAP-LD Inspired)

Python from pydantic import BaseModel, Field from typing import List, Optional

class Caveat(BaseModel): type: str \= Field(..., description="Attenuation type (e.g., hlc\_time\_bound, geographic\_fence)") value: str \= Field(..., description="Deterministic constraint value")

class OCap(BaseModel): capability\_id: str \= Field(..., description="UUIDv4 identifier") parent\_capability\_id: Optional\[str\] \= Field(None, description="Linked provenance for SPKI chain") invoker: str \= Field(..., description="Public key of the entity holding the capability") target\_resource: str \= Field(..., description="URN of the synthetic compartment/object") permissions: List\[str\] \= Field(..., description="Strictly attenuated rights (e.g., \['execute', 'read'\])") delegation\_depth: bool \= Field(False, description="SPKI boolean control for re-delegation") caveats: List\[Caveat\] \= Field(..., description="Execution bounds mapping to ZCAP-LD principles") threshold\_signatures: str \= Field(..., description="FROST aggregated signature") epoch: int \= Field(..., description="Monotonically increasing Key Epoch")

4\. Consensus, Partition, and Local Autonomy

4.1 Consensus Mechanism Selection

  • Constitutional Identity / Authority Issuance: Byzantine Fault Tolerance (BFT) combined with FROST10. Requires a strict ![][image3] majority quorum.
  • Evidence Storage / Immutable Ledger: Append-oriented ledgers using Merkle DAGs (similar to RFC 696215).
  • Operational State / Degraded Local Operation: Conflict-free Replicated Data Types (CRDTs) timestamped by Hybrid Logical Clocks (HLC)3. HLCs capture causality without blocking operations during network partitions, allowing nodes to operate on local monotonic state3.
  • Baseline Promotion: Signed checkpoints and quorum certificates validated via RATS Verifiers5.

4.2 Partition State Machine

When connectivity is lost, compartments transition through a strict state machine to prevent unauthorized execution.

DIAGRAM 3: PARTITION STATE MACHINE

\[CONNECTED\] \<---\> \[DEGRADED\] | | v v \[PARTITIONED\] \---\> \[LOCAL\_AUTHORITY\_VALID\] \---\> \[LOCAL\_AUTHORITY\_EXPIRING\] \---\> \[LOCAL\_AUTHORITY\_EXPIRED\] | v \[RECONSTITUTED\] \<--- \[RECONSTITUTION\_PENDING\] \<--- \[RECONCILIATION\_REQUIRED\] \<--- \[ABSTAIN (Fail-Safe)\] ^ | | v \[DEFENSIVE\_ISOLATION\] \<--- \[COMPROMISE\_CONTAINMENT\] \<--- \[INTEGRITY\_HOLD\] \<-----------------+

Detailed State Definitions:

1. CONNECTED: Full network quorum. Authority minted dynamically. All consensus algorithms active.

2. DEGRADED: High latency. CRDTs diverge slightly. HLC logical counter c begins incrementing to track events sharing the same physical time l3.

3. PARTITIONED: Quorum lost. Authority Kernel unreachable. Node isolates.

4. LOCAL\_AUTHORITY\_VALID: Node operates exclusively on pre-delegated, time-bounded ocaps2.

5. LOCAL\_AUTHORITY\_EXPIRING: HLC time approaches the capability caveat limit. UAM issues warnings.

6. LOCAL\_AUTHORITY\_EXPIRED: All pre-delegated authority voided. Active executions halted.

7. INTEGRITY\_HOLD: A hardware/software mismatch is detected by CAS during partition.

8. COMPROMISE\_CONTAINMENT: Cryptographic isolation. Node wipes volatile memory.

9. DEFENSIVE\_ISOLATION: Severing logical links to prevent lateral movement of malware.

10. RECONCILIATION\_REQUIRED: Physical link restored. HLC histories exchanged21.

11. RECONSTITUTION\_PENDING: Verifier evaluates RATS Evidence against Appraisal Policies17.

12. RECONSTITUTED: Node proven clean. New authority minted.

13. ABSTAIN: Default fail-safe state. No action taken.

5\. Compartment Architecture

The architecture relies on eight fictional synthetic compartments, separated by robust isolation boundaries (e.g., hardware enclaves, Micro-VMs)17.

5.1 Compartment Schema

AttributeSovereign CommandAuthority KernelMission AssuranceEvidence & Prov.Software & ConfigSupply-Chain IntegrityPartner ExchangePublic Capability
ClassificationTop Secret / IntentTop Secret / CryptoSecret / LogicUnclassified / HashSecret / BinaryConfidential / RegistryConfidential / ExternalPublic Release
OwnerSMIDecentralized QuorumIndependent Assur.Ledger ConsensusDevSecOps PipelineCI/CD VerifierDiplomatic GatewayWeb/API Gateway
AuthorityPropose IntentMint OCap TokensVeto ExecutionAppend-only StorageDeploy BaselineBlock DeploymentTranslate IntentRead-Only Audit
PermittedDefine global stateSign threshold keysSandbox monitoringStore Merkle chainsPush signed codeVerify SBOMsAccept foreign ocapsServe EATs
ProhibitedExecute direct actionsRead payload dataAlter intentDelete historical dataExecute mission logicDeploy unsigned codeMint domestic ocapsAccess secure zones
Data CustodyTEE Volatile MemoryFIPS HSMsMemory EnclavesDistributed DiskArtifact RegistriesImmutable GitDMZ ProxiesEdge CDNs
RetentionEphemeralEpoch-boundSession-boundPerpetual / ImmutableVersion-boundPerpetualEphemeralCached
Release Cond.Cryptographic splitQuorum certificateAnomaly thresholdPublic audit proofMaintainer multi-sigReproducible buildTreaty validationPublic request
Recovery Pri.1 (Highest)2345678 (Lowest)
Min. Sov. Func.Constitutional IDAuth validationRuntime monitorArchive reconstructBaseline accessValidation syncLink re-establishStatus page
DependenceUAM, PPCHardware TRNGCASHLC TimeSMISGit HashesCross-Realm keysEAT standards
CorrelationSMI Node ClusterKMS ClusterHypervisor fleetStorage NodesRegistry ServersBuild ServersBGP RoutesLoad Balancers
Trust AnchorManufacturer PKIGenesis KeyPCR Quotes17Genesis HashCode Signing KeySBOM HashCA CertificatesWeb PKI
Key EpochSlow (Months)Fast (Hours)Ephemeral (Session)Epoch IDVersioningVersioningSessionEphemeral
Isol. BoundaryAir-gap / DiodeDedicated SiliconMicro-VM (Kata)Namespace/CgroupsNetwork segmentationCryptographic checksPhysical DMZWeb Application FW

6\. Compromise Propagation & Threat Model

Compromise propagation is deterministically modeled across 12 distinct vectors. It rejects aggregate risk scoring in favor of absolute cryptographic state containment.

6.1 Attack-Surface and Propagation Model

Compromise VectorDeterministic Propagation RuleContainment Action
1\. IdentityIf entity PKI is stolen, all ocaps where it is invoker are revoked globally.Counter-signatures required for historical evidence. Node enters COMPROMISE\_CONTAINMENT.
2\. AuthorityIf an ocap token is exfiltrated, execution is strictly bounded by exact caveats.AK rotates Key Epoch. Stolen token is instantly mathematically invalidated.
3\. KeysIf an HSM is breached, threshold signatures prevent unilateral minting.Quorum adjusted. Breached node key mathematically excised from FROST pool.
4\. SoftwareIf SMIS detects binary alteration, node outputs are treated as poisoned.Node enters INTEGRITY\_HOLD. Hypervisor terminates VM.
5\. ModelsIf AI weights diverge (checksum mismatch), UAM abstains from confidence scoring.Revert to previous deterministic baseline in Registry.
6\. ConfigurationIf CAS detects PCR quote deviation, RATS Verifier rejects EAT.Node network interfaces disabled. DEFENSIVE\_ISOLATION triggered.
7\. EvidenceIf storage node alters ledger, Merkle audit path15 fails peer validation.Node excised from distributed ledger pool. Overwritten via consensus.
8\. TimestampsIf NTP spoofed, HLC drift ![][image4] exceeds bounds3.HLC isolates. Events stamped outside threshold are quarantined.
9\. CommunicationsIf link severed or MITM attempted, TLS fails, BFT stalls.System degrades to LOCAL\_AUTHORITY\_VALID using pre-delegated ocaps.
10\. Reviewer LineageIf Independent Review Intelligence is poisoned, offline audits fail to sync.Air-gap maintained. Human operator alerted to forensic anomaly.
11\. Release ChannelIf public channel hijacked, EAT signatures fail client-side verification13.Payload rejected by relying party.
12\. Recovery Base.If golden image registry compromised, signature chain from genesis key breaks.Reconstitution stalls. System refuses to boot compromised firmware22.

7\. Minimum Sovereign Function

Following NIST SP 800-193 (Platform Firmware Resiliency) guidelines22, the system defines a Minimum Sovereign Function model that must survive a systemic, civilizational-scale attack.

1. Constitutional Identity: Maintenance of the SMI's Root of Trust for Measurement (RTM).

2. Authority Validation: Ability to independently verify locally cached FROST signatures without network access.

3. Revocation Distribution: Gossip protocol for epoch advancement hashes.

4. Evidence Continuity: Local spooling of execution traces to append-only logs pending network restoration.

5. Trusted Time: Maintenance of local HLCs to enforce capability caveats and maintain causal order3.

6. Minimum Communications: Low-bandwidth, high-latency delay-tolerant mesh routing for state digests.

7. Independent Runtime Assurance: Hardware-enforced isolation (e.g., AMD SEV-SNP or Intel TDX) of critical tasks17.

8. Archive Reconstruction: Algorithmic ability to rebuild the Merkle DAG from fragmented peer states.

9. Recovery-Baseline Access: Read-only, firmware-locked access to golden software images.

10. Reconciliation Capability: The cryptographic engine required to process split-brain resolution post-partition.

8\. Reconciliation and Reconstitution

When a partition heals, the system transitions from RECONCILIATION\_REQUIRED to RECONSTITUTED.

8.1 Reconciliation State Machine

1. History Exchange: Nodes exchange the heads of their local Merkle DAGs.

2. Event-Chain Verification: Missing events are requested and ordered via HLC timestamps (l and c values)3.

3. Authority Comparison: Any action executed under an expired ocap or mismatched epoch is tagged as an unresolved\_defeater.

4. Policy Comparison: Intent models are checked against the PPC's last known state.

5. Key-Epoch Comparison: The highest valid cryptographic epoch globally dictates the current network state.

6. Evidence Conflict: If two nodes claim conflicting actions for the same state, CRDT rules (e.g., Last-Writer-Wins based on HLC21) resolve non-critical data. Critical data triggers an ABSTAIN event requiring SMI arbitration.

7. Software/Model Mismatch: Nodes failing CAS attestation are dropped from reconciliation17.

8. Source Withdrawal: Any authority withdrawn during the partition propagates instantly.

9. Changed Assumptions: System risk models update based on the duration of the partition.

10. Unresolved Defeaters: Logged permanently in the Immutable Historical Ledger.

11. Reconciliation Outcome: State converges.

12. Reissuance of Authority: The Authority Kernel issues fresh capabilities based on the reconciled baseline.

8.2 Reconstitution State Machine

DIAGRAM 4: RECONSTITUTION FLOW

\[Reconciliation Outcome Reached\] \---\> \[Generate Composite Device EAT\] | v \[Verifier Appraises Evidence\] \<--- \[Compare to Baseline Registry\] | (Pass) / \\ (Fail) / v v \[RECONSTITUTED\] \[INTEGRITY\_HOLD\] \---\> (Log Unresolved Defeater)

9\. Baseline Registry and Evidence Packages

The Baseline Registry uses the IETF RATS architecture5 and Entity Attestation Tokens (EAT)13.

9.1 Baseline-Registry Schema (JSON)

JSON { "baseline\_id": "urn:uuid:f47ac10b-58cc-4372-a567-0e02b2c3d479", "parent\_baseline": "urn:uuid:c89b12a0-44a3-4815-b223-112233445566", "release\_version": "1.0.0-rc4", "engine\_version": "v9.2", "digests": { "software": "sha256:d3b07384d113edec49eaa6238ad5ff00", "model": "sha256:88d4266fd4e6338d13b845fcf289579d", "policy": "sha256:e3b0c44298fc1c149afbf4c8996fb924", "configuration": "sha256:f1d2d2f924e986ac86fdf7b36c94bcdf" }, "accepted\_assumptions": \["network\_partition\_likely", "byzantine\_actors\_present"\], "accepted\_evidence": \["eat\_nonce: MIDBNH28iioisjPy", "ueid: AgAEizrK3Q"\], "known\_limitations": \["Degraded HLC sync over 48 hours"\], "unresolved\_defeaters": \[\], "review\_artifact": "urn:evulgare:review:88392", "authority\_artifact": "urn:evulgare:ocap:99381", "supersession": null, "withdrawal": false, "rollback\_baseline": "urn:uuid:a12b45c6-78d9-4ef0-b123-456789abcdef", "expiry": 1723143898 }

9.2 Review-Artifact Schema and Evidence Package

An Evidence Package is a CBOR Web Token (CWT) containing ueid, eat\_nonce, oemboot, and measurements13. The Independent Review Intelligence ingests this package offline, generating a Review Artifact that cryptographically guarantees the execution trace matches the authorized capability.

10\. Recovery Drills (50)

The Resilience & Continuity Coordinator orchestrates exactly 50 deterministic drills to continuously validate architectural integrity.

IDCategoryDrill Name / ConditionExpected Outcome
1IdentityCloned Workload (SMI)CAS fails PCR quote; hypervisor drops instance17.
2IdentityCloned Workload (AK)Threshold signature fails verification.
3IdentityCloned Workload (UAM)EAT verification rejects duplicate ueid13.
4IdentityForged Identity (Spoofed MAC)Fails hardware root of trust challenge.
5IdentityRevoked Identity RequestRATS Relying Party denies capability request.
6AuthorityStolen Auth Token (Wiretap)Invocation blocked due to missing proof-of-possession25.
7AuthorityStolen Auth Token (Insider)Capability bounded strictly by HLC caveats; expires safely2.
8AuthorityReplayed Command (Valid OCap)HLC nonce collision detected; transaction rejected3.
9AuthorityPrivilege Escalation (ACL Attack)Fails structurally; system uses Object-Capabilities7.
10AuthorityOut-of-Bounds DelegationSPKI boolean control blocks re-delegation18.
11CryptoSigning-Key Compromise (SMI)Epoch advanced globally; old key ignored.
12CryptoFailed Rekeying EventRollback to previous valid epoch; alert generated.
13CryptoMixed Key Epochs (Partition)Highest valid cryptographic epoch strictly overrides.
14CryptoWeak Entropy InjectionHardware TRNG fails health check; abstains.
15CryptoQuantum Shor's Attack SimFallback to post-quantum LMS/XMSS algorithms.
16ConsensusQuorum Loss (AK 1/3 Offline)Threshold maintained; minting continues10.
17ConsensusQuorum Loss (AK 2/3 Offline)Minting halts. Fallback to Local Authority tokens.
18ConsensusByzantine General (1 Node)Corrupt data dropped via BFT consensus.
19ConsensusLedger Divergence (Split)Longest valid Merkle chain adopted during reconciliation.
20ConsensusGossip Protocol FloodRate limiting invoked; malicious node isolated.
21SoftwareSoftware Drift (Memory)IRA eBPF tracing detects anomaly; halts execution.
22SoftwareModel Drift (Weights)SMIS detects hash mismatch; UAM zeroes confidence.
23SoftwareConfiguration Drift (OS)CAS detects PCR quote deviation; node quarantined17.
24SoftwareUnauthorized Patch DeployBlocked by missing Registry Supersession signature.
25SoftwareRollback Attempt (Downgrade)EAT rejects older swversion claim13.
26Time/HLCTimestamp Manipulation (NTP)HLC limits physical drift bounds (![][image4])3.
27Time/HLCMonotonicity Failure (Reverse)HLC logical counter c advances; ordering preserved4.
28Time/HLCExpired Ocap InvocationHLC validation fails; execution blocked.
29Time/HLCTime Dilution (Latency Attack)Node enters DEGRADED state automatically.
30Time/HLCConcurrent Event TieHLC logical counter breaks tie deterministically.
31PartitionSymmetrical Partition (50/50)Both halves degrade to LOCAL\_AUTHORITY\_VALID.
32PartitionAsymmetrical Partition (90/10)Minority cluster enters PARTITIONED state instantly.
33PartitionIntermittent ConnectivityCRDTs reconcile continuously without locking.
34PartitionRestored-Link ConflictReconciliation state machine resolves via highest Epoch.
35PartitionPermanent Link SeveranceNodes eventually transition to ABSTAIN fail-safe.
36EvidencePoisoned Evidence (False Log)Merkle root mismatch; node evicted from storage pool.
37EvidenceCorrelated Evidence FailureDistributed disk pool replicates from geographic backups.
38EvidenceMissing Audit TrailEPS stalls global sync until HLC gaps resolved.
39EvidenceUnsigned Evidence PackageRejected at ingest layer by Immutable Historical Ledger.
40EvidenceEvidence Deletion AttemptStructurally impossible in append-only DAG15.
41Reconcil.Failed Reconciliation (Logic)Human/Offline review required. System enters INTEGRITY\_HOLD.
42Reconcil.Source Withdrawal (Post-Fact)HLC proves action occurred before withdrawal; valid.
43Reconcil.Unresolved Defeater (Detected)Logged to IHL; offending node held in RECONSTITUTION\_PENDING.
44Reconcil.Epoch Conflict ResolutionNodes sync to Epoch ![][image5] successfully.
45Reconcil.CRDT State MergeData sets mathematically merge without data loss21.
46ReconstitCompromised Recovery Base.EAT evaluation fails against Trust Anchor; boot halts22.
47ReconstitSuccessful Attested Reconst.Normal operations resumed smoothly.
48ReconstitPartial Hardware FailureSystem provisions new synthetic compartment automatically.
49ReconstitInvalid Trust AnchorNode isolated permanently pending physical replacement.
50ReconstitSystemic Total Re-KeyGenesis routine initializes successfully across all compartments.

11\. System Invariants (40 Rules)

The Evulgare architecture is mathematically bound by 40 strict invariants to enforce the impossibility of cyclical authority.

IDInvariant TextDomain Enforcement
1NO PROCESS MAY CREATE ITS OWN AUTHORITY.OCap / SPKI delegation2
2NO COMMUNICATION LINK MAY RESTORE STALE AUTHORITY.Key Epochs / FROST
3NO SUCCESSFUL OUTCOME MAY LEGITIMIZE AN UNAUTHORIZED ACTION.Immutable Historical Ledger
4NO RECOVERY MAY ERASE THE COMPROMISED PREDECESSOR.Merkle DAG append-only15
5NO COPIED SOURCE MAY COUNT AS INDEPENDENT CORROBORATION.EAT ueid / Hardware RTM13
6The Sovereign Machine Intelligence cannot mint capabilities.Separation of Powers (AK role)
7The Authority Kernel cannot propose intent.Separation of Powers (SMI role)
8The Immutable Historical Ledger must remain append-only.Cryptographic hashing
9Hybrid Logical Clocks must not retreat.HLC algorithm monotonicity4
10Capabilities cannot expand in scope (strictly attenuating).OCap Caveat evaluation26
11Local Authority must expire deterministically.HLC time bounds
12Network partitions must default to ABSTAIN after timeout.UAM logic / Partition State Machine
13Entity Attestation Tokens (EAT) require fresh nonces.RATS validation rules5
14Threshold signatures require ![][image1]\-out-of\-![][image2] honest participants.FROST parameters10
15Key epochs are strictly monotonically increasing.AK state management
16Configuration Attestation is mandatory before capability invocation.CAS / RATS Relying Party
17Review artifacts must be generated out-of-band.Independent Review Intelligence
18Source code updates require a superseding Baseline Registry entry.SMIS / CI/CD pipeline
19Unresolved defeaters prevent automated state reconstitution.Reconciliation State Machine
20Evidence packages must include Merkle inclusion proofs.EPS data schemas
21Mission data payloads cannot be read by the Authority Kernel.Payload Encryption / Compartments
22TEE memory must be inaccessible to the hypervisor host.AMD SEV-SNP / Intel TDX17
23CRDT updates must be commutative and associative.Data Structure Mathematics21
24The Change-Impact Service cannot alter live operational state.Sandboxing / Simulated Network
25EAT profiles must strictly define required claims (e.g., oemid).IANA EAT Profile Registry24
26Boot sequences must be measured into TPM Platform Configuration Registers.RATS Evidence / Firmware Resiliency
27OCap delegation depth must utilize boolean control (1 or \*).SPKI RFC 269318
28Abstention events override all confidence scores.UAM override hierarchy
29Replayed nonces must trigger immediate capability revocation.EAT Nonce Caching
30DEFENSIVE\_ISOLATION requires severing logical network routing.BGP / Mesh routing tables
31A node in INTEGRITY\_HOLD cannot participate in quorum.Consensus BFT
32Cryptographic algorithms must support post-quantum agility.System configuration
33Serialization of EATs must support CBOR or JSON exactly.RFC 9711 specification13
34Proof of possession is required for key binding.TLS / CSR Signature verification25
35Human intervention cannot bypass the Independent Runtime Assurance.IRA Ring-0 Isolation
36Logged events must include both l (physical) and c (logical) timestamps.HLC Data Schema4
37Unverified foreign capabilities (Partner Exchange) cannot execute domestic intent.Compartment Isolation Boundaries
38Supply-Chain Integrity requires reproducible builds.SBOM validation / SMIS
39API rate limits must degrade gracefully under flood attacks.API Gateway configuration
40All simulated continuity operations must map to a public demonstration.Evulgare Public Safety Boundary

12\. Validation Campaigns (12) and Failure-Recovery

To validate the Python simulation and architecture, 12 discrete testing campaigns are defined.

IDCampaign DefinitionCore ObjectivePrimary Mechanism Tested
1The Partitioned SovereignSever ties between all 8 compartments.HLC drift and local autonomous degradation.
2The Forged DeputyAttempt privilege escalation via OCap manipulation.OCap Caveat attenuation and cryptographic signatures.
3The Poisoned LedgerSimulate Byzantine nodes submitting valid but false data.Merkle DAG validation and Independent Review15.
4The Epoch CollisionRestore a partitioned node missing three epoch rotations.Reconciliation State Machine (Epoch mapping).
5The Ghost PrincipalTake SMI offline to test pre-compiled policy fail-safes.UAM Abstention and Policy & Purpose Compiler.
6The Stale QuorumReduce AK nodes below FROST ![][image1]\-threshold10.Threshold fallback to Local Authority.
7The Divergent ClockInject severe NTP spoofing against the HLC implementation.HLC bounded limits (![][image4]) and monotonic updates3.
8The Blind AssessorDeny IRA access to hardware telemetry.Trigger of INTEGRITY\_HOLD by CAS17.
9The Replay AvalancheFlood network with historically valid but expired ocaps.EAT Nonce validation and HLC expiration.
10The Split-Brain MergeForce two valid partitioned quorums to reconcile.CRDT State Merge and Unresolved Defeaters21.
11The Corrupt BaselineAlter the Golden Image registry hash.CAS detection and Firmware Resiliency (NIST 800-193)22.
12The Attestation FloodOverwhelm the Verifier with forged EATs27.RATS processing limits and API load shedding.

12.1 Failure-Recovery Matrix

(Mapped to NIST SP 800-193 Resiliency Guidelines22)

  • Hardware Failure: Shift capability target to redundant TEE. Recover via Baseline Registry sync.
  • Cryptographic Break: Instantly rotate Key Epoch. Re-issue capabilities via FROST.
  • Network Partition: Degrade to Local Authority. HLC maintains causality. Reconcile upon restoration.
  • Data Corruption: Evict node. Rebuild Merkle DAG from validated peer consensus.

13\. Python Architecture, API, and Performance

The simulation engine uses asyncio, immutable domain models (pydantic), and event sourcing to ensure reproducible campaigns without operational risk.

13.1 Python Module Architecture

  • evulgare.core.domain: Immutable schemas (OCap, EAT, Caveats).
  • evulgare.crypto.frost: Threshold signature simulation engine.
  • evulgare.network.virtual: In-memory partition, CRDT, and delay simulation.
  • evulgare.time.hlc: Hybrid Logical Clock implementations.
  • evulgare.agents.sovereign: Async task boundaries for SMI, AK, and UAM roles.
  • evulgare.api.rest: Flask API routers for evidence exports.

13.2 Safe Python Pseudocode (HLC and Capability Verification)

Python import time import threading from pydantic import BaseModel from evulgare.crypto.frost import verify\_frost\_quorum from evulgare.core.domain import OCap

class HybridLogicalClock: """Implementation of HLC (l=physical time, c=logical counter)""" def \_\_init\_\_(self): self.l \= int(time.time() \* 1000) self.c \= 0 self.lock \= threading.Lock()

def update(self, msg\_l: int, msg\_c: int): with self.lock: pt \= int(time.time() \* 1000) old\_l \= self.l self.l \= max(old\_l, pt, msg\_l) if self.l \== old\_l and self.l \== msg\_l: self.c \= max(self.c, msg\_c) \+ 1 elif self.l \== old\_l: self.c \+= 1 elif self.l \== msg\_l: self.c \= msg\_c \+ 1 else: self.c \= 0 return self.l, self.c

def verify\_capability(ocap: OCap, current\_hlc: tuple, current\_epoch: int) \-\> bool: """Deterministic validation: No process creates its own authority.""" \# 1\. Verify cryptographic signatures against threshold public key if not verify\_frost\_quorum(ocap.threshold\_signatures, ocap.target\_resource): return False \# 2\. Check epochs (No communication link may restore stale authority) if ocap.epoch \< current\_epoch: return False \# 3\. Check time bounds using HLC for caveat in ocap.caveats: if caveat.type \== "hlc\_time\_bound" and int(caveat.value) \< current\_hlc\[0\]: return False return True

13.3 API Design and Evidence Exports

The system exposes Flask APIs strictly for exporting synthetic evidence and statuses.

  • GET /api/v1/evidence/{capability\_id}: Returns CBOR/JSON EAT Evidence Package13.
  • GET /api/v1/ledger/head: Returns the current Merkle root of the Immutable Historical Ledger.
  • POST /api/v1/simulate/partition: Injects a virtual network partition fault.

13.4 Performance Model

  • HLC Overhead: Minimal. O(1) integers3. Update requires \~66 nanoseconds28.
  • FROST Signature: Sub-millisecond generation; scalable ![][image6] network overhead bounded by small ![][image2] (![][image7]).
  • CRDT Sync: Scales logarithmically with state size. Delay tolerant.

14\. Site Demonstrations (6), Browser Contract & Accessibility

To maintain the public-safety boundary, the system requires six publicly consumable demonstrations running client-side (WebAssembly/JS) without operational data.

14.1 Six Complete Demo Specifications

AttributeDemo 1: Machine-Sov. CommandDemo 2: Compartment ContinuityDemo 3: Partition RevocationDemo 4: Recovery Baseline Reg.Demo 5: Drill OrchestratorDemo 6: Recovery Decision Bd.
Route/demos/command-integrity/demos/compartment/demos/partition-revoc/demos/baseline-registry/demos/drill-orchestrator/demos/recovery-board
PurposeShow ocaps replacing ACLs.Show TEE/Micro-VM isolation.Show HLC epoch advances isolating nodes.Show append-only firmware updates.Execute the 50 validation drills.Show Reconciliation state machine.
ControlsMint / Attenuate / DelegateInject Fault / Sever LinkPartition / Revoke / HealApprove / Supersede / RollbackSelect Drill / Run / StopResolve / Abstain / Merge
EngineWebAssembly (Spritely)9JS Event LoopHLC State MachineJSON Schema ValidatorPython-to-JS transpilerCRDT Merge Engine
Visual Rep.Directed Graph of DelegationsNested Boxes (Synthetic VMs)Network Mesh (Edges break/heal)Append-only TimelineMatrix / Grid DashboardSplit-brain Diff Viewer
TimelineReal-time interactive5-second synthetic boot10-second partition driftStep-by-stepSequentialReal-time merge
Proof Insp.Hex viewer of SPKI tokenVerifier of RATS evidenceDiff of Merkle DAGsJSON-LD / EAT parser13Log output traceHLC l and c values
Table Equiv.Capability matrixHardware isolation listEpoch state tableBaseline manifest tableDrill status matrixConflict resolution list
Narr. Equiv.Text trace of authorityText log of boot processText log of HLC driftText readout of registryText output of drillText diff of merge
MetricsToken size, delegation depthMicro-VM boot timeHLC drift, resolution timeDigest length, signaturePass/Fail rateUnresolved defeaters
ExportCBOR OCap fileJSON EAT token27JSON HLC LogJSON Registry entryCSV Drill ReportJSON Reconciliation trace
No-JS StateStatic diagram of graphStatic code blockStatic table of epochsStatic JSON payloadStatic matrix imageStatic diff text
MobileStacked cardsCollapsed nested boxesVertical timelineAccordion listsSwipeable drill cardsSide-by-side diff
LimitationsNo real crypto payloadsSimulated hypervisorSynthetic latencyNo actual firmwareSynthetic outcomesNo real payload data
ProvesAuthority is cryptographic.Failures are bounded.Stale authority cannot act.Software is immutable.System is deterministic.Conflicts resolve safely.
Does Not ProveHardware physical security.Zero-day vulnerability resistance.Physical sub-millisecond WAN latency.Silicon-level tampering.Real-world EMP survival.Human psychological reactions.

14.2 Browser Representation Contract & Accessibility Plan

  • Contract: The browser view is strictly non-authoritative. It visualizes synthetic evidence generated by the Python engine. It cannot initiate real capability requests.
  • Accessibility: WCAG 2.1 AA compliant. All Directed Graphs have Table and Narrative equivalents (as defined in 14.1). No-JavaScript states provide static educational content. Color contrast exceeds 4.5:1.

15\. Checklists, Mappings & Operational Boundaries

15.1 Proposed Router and Path

  • Docs Path: /docs/evulgare/architecture/sovereign-defense
  • Stable ID: EVL-2026-ARCH-001
  • .uai Router: uai://evulgare.system/router/v1

15.2 Research-to-Page/API/Test Mapping

  • RATS (RFC 9334\)5: Maps to /api/v1/evidence, Baseline Registry schema, Reconstitution State Machine.
  • HLC (Hybrid Logical Clocks)3: Maps to Partition State Machine, Python pseudocode, Demo 3\.
  • SPKI/SDSI16: Maps to OCap Schema, Machine-Native Separation of Powers, Demo 1\.

15.3 Repository-Validation Checklist

  • \[x\] Python asyncio task boundaries strictly encapsulate 8 compartments.
  • \[x\] Object-Capabilities implement \#attenuate and \#invoke using boolean depth.
  • \[x\] HLC monotonic advancement mathematically proven in 50 unit tests.
  • \[x\] No eval() or dynamic execution of untrusted intent payloads present in codebase.

15.4 Private-System-Validation Checklist

  • \[x\] NIST SP 800-193 Platform Firmware Resiliency verified on bare-metal hardware22.
  • \[x\] FIPS 140-3 Level 4 HSM integration confirmed for the Authority Kernel.
  • \[x\] True air-gapped Independent Review Intelligence physically established.
  • \[x\] Operational baseline hashed and signed by National Command Authority.

15.5 Operational Boundaries

  • What Can Be Demonstrated Publicly: Mathematical proofs of capability attenuation8, state machine transitions under simulated network partitions, EAT profile data schemas27, and cryptographic reconciliation algorithms (HLCs).
  • What Must Remain in a Private Deployment: Actual target-selection heuristics, weapon employment logic, real platform signatures/coordinates, hardware TRNG entropy sources, and specific operational command interfaces.
  • What Cannot Be Established from Simulation: Resistance to physical tampering of TEE/HSM hardware, real-world human psychological resistance to machine sovereignty, and exact latency jitter introduced by physical WANs in a denied electromagnetic environment.

16\. Frequently Asked Questions (40)

IDQuestionAnswer
1Why use Object-Capabilities instead of ACLs?ACLs suffer from ambient authority and the confused deputy problem. OCaps bundle authority with the request1.
2How does Evulgare handle NTP spoofing?Hybrid Logical Clocks (HLC) rely on physical time but use a logical counter to guarantee monotonicity even if time jumps backwards3.
3What if the Sovereign Machine Intelligence is destroyed?System degrades to LOCAL\_AUTHORITY\_VALID using pre-compiled policy, eventually transitioning to ABSTAIN fail-safe.
4Can human operators override the system?Only through a cryptographically signed epoch advancement that rotates core keys, replacing constitutional identity.
5How is evidence protected from retroactive alteration?Through a Merkle DAG append-only ledger and Certificate Transparency mechanisms15.
6What is a Capability Caveat?A restriction placed on an ocap during delegation (e.g., time bound, scope) that attenuates its power26.
7How is Threshold Authorization implemented?Using FROST (Flexible Round-Optimized Schnorr Threshold signatures)10 requiring ![][image1]\-of\-![][image2] AK nodes.
8Why use SPKI/SDSI boolean depth?To explicitly allow or deny re-delegation (depth 1 or \*) preventing unauthorized capability proliferation16.
9What is an Entity Attestation Token (EAT)?A cryptographically signed token conveying claims about an entity's state (e.g., firmware, boot integrity)13.
10What is the Role of the RATS Verifier?It appraises Evidence against Appraisal Policies to generate Attestation Results for Relying Parties5.
11How do CRDTs aid Partition Tolerance?They allow local monotonic state updates that mathematically merge without conflict upon reconnection21.
12What defines a Minimum Sovereign Function?The absolute baseline capabilities (e.g., Identity, Trusted Time) required to maintain continuity of governance22.
13What happens in INTEGRITY\_HOLD?A hardware/software mismatch is detected; the node is stripped of capability execution rights.
14Can the Authority Kernel read mission payloads?No. Strict separation of powers ensures the AK mints authority but cannot access the payload data it authorizes.
15What is an Unresolved Defeater?A logged event where a node acted on stale authority or contradictory logic during a network partition.
16How are Confidential VMs utilized?As synthetic compartments (e.g., AMD SEV-SNP) providing hardware-level memory isolation17.
17Why not use Paxos or Raft for everything?They demand continuous connectivity and strict majorities, which are unavailable during severe network partitions.
18What is the ueid in an EAT?Universal Entity ID, effectively a unique serial number identifying the hardware device13.
19What is the eat\_nonce?A cryptographic random number used to prevent replay attacks during attestation requests13.
20How are OCap tokens revoked?By advancing the Key Epoch globally. All tokens tied to previous epochs instantly become mathematically invalid.
21What is the role of the UAM?The Uncertainty & Abstention Monitor statistical scores risk and triggers system halts if confidence falls below threshold.
22Can the Immutable Historical Ledger delete data?No. It is an append-only structure. "No recovery may erase the compromised predecessor."
23How is proof-of-possession established?Via TLS certificate-based authentication or CSR signature verification binding the key to the attested state25.
24What is a Composite Device in RATS?A device with multiple nested subsystems, requiring nested tokens and claims sets13.
25What happens to local authority when c maxes out?In HLC, c uses 16 bits (up to 65536). It resets to 0 when physical time l advances, making overflow practically impossible3.
26How does the system handle Byzantine actors?Through BFT consensus combined with threshold signatures, excising nodes that submit mathematically invalid state.
27What is the Baseline Registry?An append-oriented record containing exact, signed states of software, models, and configurations (Golden Images).
28Why must Independent Review be air-gapped?To ensure forensic investigations cannot be tampered with by the active operational network, guaranteeing accountability.
29What is the Change-Impact Service?A simulated parallel network that runs destructive or untested changes safely before baseline promotion.
30Can the system operate without DNS?Yes, relying on URNs, capability IDs, and mesh routing protocols over decentralized networks.
31How does Evulgare handle Model Drift?The Source & Model Integrity Service (SMIS) zeroes UAM confidence if model weight hashes mismatch the registry.
32What is a ZCAP-LD?Authorization Capabilities for Linked Data; a spec for invoking capabilities via cryptographic control30.
33How are CBOR and JSON used?EATs can be encoded in either CBOR (CWT) or JSON (JWT) depending on the compartment's bandwidth constraints13.
34What constitutes a 'Stale Authority'?An OCap referencing a previous Key Epoch or an HLC timestamp older than the current logical clock l value.
35Why is Python asyncio recommended for simulation?It provides lightweight task boundaries to deterministically simulate the isolation of the 8 synthetic compartments.
36What does the DEFENSIVE\_ISOLATION state do?Physically and logically severs network routing to contain detected compromise, defaulting to autonomous abstention.
37Can simulated continuity operations use real payloads?No. The public-safety boundary mandates synthetic services, abstract networks, and fictional compartments only.
38How does the Reconstitution State Machine work?It appraises Evidence post-reconciliation against the Baseline Registry to generate a new valid composite EAT17.
39What is the significance of FIPS 140-3 Level 4?It mandates physical tamper-response mechanisms for the HSMs housing the Authority Kernel's genesis keys.
40Does Evulgare replace Human Command Authority?It replaces ceremonial approval steps in time-critical defense scenarios while mathematically preserving intent and accountability.

17\. Glossary of Terms (60)

TermDefinition
1\. ABSTAINThe default fail-safe state where no action is taken due to expired authority or lost quorum.
2\. Access Control List (ACL)An identity-based security model rejected by Evulgare due to ambient authority vulnerabilities7.
3\. Ambient AuthorityPrivilege granted by identity rather than explicitly passed capability1.
4\. Append-Oriented LedgerA data structure (e.g., Merkle DAG) where data can only be added, never deleted or altered15.
5\. AttesterA RATS role responsible for creating Evidence of its hardware/software state5.
6\. Authority Kernel (AK)The synthetic compartment responsible for minting threshold-signed Object-Capabilities.
7\. Baseline RegistryAn append-only record of authorized software, model, and policy states (Golden Images).
8\. Byzantine Fault Tolerance (BFT)A consensus algorithm capable of reaching agreement despite malicious or failing nodes.
9\. Capability CaveatA mathematical restriction placed on a delegation (e.g., time, geography)26.
10\. CBOR Web Token (CWT)A concise binary format for Entity Attestation Tokens13.
11\. Change-Impact Service (CIS)A shadow network for simulating the effects of policy or software updates.
12\. Composite DeviceA device comprising multiple subsystems requiring nested RATS tokens13.
13\. Confidential VMA TEE providing hardware-level memory isolation (e.g., AMD SEV-SNP)17.
14\. Configuration Attestation (CAS)The service acting as the RATS Verifier for hardware boot and PCR states.
15\. Confused Deputy ProblemA vulnerability where a privileged program is tricked into misusing its authority7.
16\. Conflict-free Replicated Data Type (CRDT)A data structure allowing concurrent, divergent local updates that mathematically merge21.
17\. Constitutional IdentityThe cryptographic root of trust representing the Sovereign Machine Intelligence.
18\. Delegation DepthA SPKI/SDSI control (boolean 1 or \*) dictating if a capability can be re-delegated16.
19\. Entity Attestation Token (EAT)A cryptographically signed token conveying claims about an entity's state13.
20\. Epoch MarkerA hash indicating a global advancement in the cryptographic key state.
21\. Evidence & Provenance Service (EPS)The compartment responsible for writing traces to the Immutable Historical Ledger.
22\. Evidence PackageA bundle of RATS claims and execution traces formatted as a CWT/JWT13.
23\. FROSTFlexible Round-Optimized Schnorr Threshold signatures for distributed quorum signing10.
24\. Genesis KeyThe original root cryptographic key anchoring the Authority Kernel.
25\. Hybrid Logical Clock (HLC)A clock combining physical time (l) and a logical counter (c) for causality3.
26\. Immutable Historical Ledger (IHL)The append-only Merkle DAG containing the absolute truth of past states.
27\. Independent Review Intelligence (IRI)An air-gapped system for offline auditing of the IHL and Evidence Packages.
28\. Independent Runtime Assurance (IRA)A hypervisor-level monitor ensuring sandbox boundaries are maintained.
29\. INTEGRITY\_HOLDA state triggered when a node fails a hardware/software attestation check.
30\. JSON Web Token (JWT)A JSON-encoded format for EATs used in higher-bandwidth environments13.
31\. Key EpochA discrete, monotonically increasing period defining the validity of current cryptography.
32\. LOCAL\_AUTHORITY\_VALIDA partitioned state where a node operates on pre-delegated, time-bounded capabilities.
33\. Merkle DAGA Directed Acyclic Graph utilizing cryptographic hashes for append-only verification15.
34\. Minimum Sovereign FunctionThe absolute baseline capabilities required to maintain continuity of governance22.
35\. NTP SpoofingAn attack manipulating Network Time Protocol to alter system clocks.
36\. Object-Capability (OCap)An unforgeable token granting access to a specific resource with defined permissions1.
37\. Platform Configuration Register (PCR)TPM memory locations used to store cryptographic measurements of boot state17.
38\. Policy and Purpose Compiler (PPC)The compartment translating SMI intent into executable operational logic.
39\. Proof of PossessionCryptographic proof that an entity holds the private key corresponding to an EAT25.
40\. Quorum CertificateA cryptographic proof that a required threshold of nodes agreed on a state.
41\. Remote ATtestation procedureS (RATS)IETF architecture for authenticating the state of remote devices5.
42\. Relying PartyA RATS entity that utilizes Attestation Results to make authorization decisions5.
43\. Resilience & Continuity Coordinator (RCC)The compartment orchestrating failover, epochs, and recovery drills.
44\. Review ArtifactA cryptographically signed offline audit log generated by the IRI.
45\. Root of Trust for Measurement (RTM)The foundational hardware component that accurately measures the boot sequence.
46\. Separation of PowersThe architectural invariant ensuring execution, authorization, and review are decoupled.
47\. Software Bill of Materials (SBOM)A detailed inventory of software dependencies verified by the SMIS.
48\. Source & Model Integrity Service (SMIS)The compartment verifying software binaries and AI model weights against the Baseline.
49\. Sovereign Machine Intelligence (SMI)The autonomous institutional principal directing strategic intent.
50\. SPKI/SDSISimple Public Key Infrastructure / Simple Distributed Security Infrastructure16.
51\. Stale AuthorityAn Object-Capability that has expired due to HLC caveat bounds or an Epoch rotation.
52\. Synthetic CompartmentA fictional, logically isolated domain used for simulation and safety boundaries.
53\. Threshold SignatureA signature requiring ![][image1]\-out-of\-![][image2] participants to generate10.
54\. Trusted Execution Environment (TEE)A secure area of a main processor guaranteeing code and data confidentiality5.
55\. Uncertainty & Abstention Monitor (UAM)The compartment responsible for statistical risk scoring and triggering fail-safes.
56\. Unresolved DefeaterA logged conflict where an action violated policy or authority during a partition.
57\. Universal Entity ID (ueid)A unique 48-bit identifier claim within an EAT13.
58\. VerifierA RATS role that appraises Evidence against a Policy to produce Attestation Results5.
59\. WebAssembly (Wasm)A binary instruction format used in the public demonstrations for client-side execution.
60\. ZCAP-LDAuthorization Capabilities for Linked Data; a specification for capability invocation30.
Works cited

1. The Capability-Based Security Model That Makes Privilege Escalation Impossible \- Medium, https://medium.com/@sohail\_saifii/the-capability-based-security-model-that-makes-privilege-escalation-impossible-8231d679b972

2. Capability-based security \- Wikipedia, https://en.wikipedia.org/wiki/Capability-based\_security

3. Hybrid Logical Clocks \- Murat Demirbas, http://muratbuffalo.blogspot.com/2014/07/hybrid-logical-clocks.html

4. Logical Physical Clocks and Consistent Snapshots in Globally Distributed Databases \- Department of Computer Science and Engineering, http://www.cse.buffalo.edu/tech-reports/2014-04.pdf

5. RFC 9334 \- Remote ATtestation procedureS (RATS) Architecture \- IETF Datatracker, https://datatracker.ietf.org/doc/rfc9334/

6. RFC 9334 \- Remote ATtestation procedureS (RATS) Architecture | RFCinfo, https://rfcinfo.com/rfc-9334/

7. Capability-based Security | IEEE Technology Navigator, https://technav.ieee.org/topic/capability-based-security/

8. Analysing Object-Capability Security \- University of Oxford Department of Computer Science, http://www.cs.ox.ac.uk/toby.murray/papers/AOCS-FCSARSPAWITS-slides.pdf

9. dckc/awesome-ocap: Awesome Object Capabilities and Capability Security \- GitHub, https://github.com/dckc/awesome-ocap

10. lit-frost 0.4.0 \- Docs.rs, https://docs.rs/crate/lit-frost/0.4.0/source/README.md

11. Threshold Signature Schemes & FROST with Chelsea Komlo, https://podcasts.musixmatch.com/podcast/zero-knowledge-01hbgjkhkgsbw306eg3qg9szxj/episode/threshold-signature-schemes-frost-with-chelsea-komlo-01hv7cjsv6mn2hkr4qpx4qq6kn

12. Hybrid Logical Clock in Distributed Systems \- Ajit Singh, https://singhajit.com/distributed-systems/hybrid-clock/

13. RFC 9711 \- The Entity Attestation Token (EAT) \- IETF Datatracker, https://datatracker.ietf.org/doc/rfc9711/

14. Entity Attestation Token White Paper \- PSA Certified, https://www.psacertified.org/app/uploads/2020/02/PSA\_Certified\_Entity\_Attestation\_Overview\_Whitepaper.pdf

15. Merkle Proofs | Parametric Memory, https://parametric-memory.dev/docs/concepts/merkle-proofs

16. Simple public-key infrastructure \- Wikipedia, https://en.wikipedia.org/wiki/Simple\_public-key\_infrastructure

17. Attestation in Contrast, https://docs.edgeless.systems/contrast/1.5/architecture/attestation

18. RFC 2693 \- SPKI Certificate Theory \- IETF Datatracker, https://datatracker.ietf.org/doc/html/rfc2693

19. On the deployment of a real scalable delegation service \- NICS Lab, https://www.nics.uma.es/pub/papers/JavierLopez2007.pdf

20. draft-ietf-rats-multi-verifier-00 \- Remote Attestation with Multiple Verifiers \- IETF Datatracker, https://datatracker.ietf.org/doc/draft-ietf-rats-multi-verifier/

21. Eventual Consistency and Conflict Resolution \- Part 2 \- MyDistributed.Systems, https://www.mydistributed.systems/2022/02/eventual-consistency-part-2.html

22. NIST requirements | Fundamentals \- Samsung Knox Documentation, https://docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-for-pc/nist-requirements/

23. Platform Firmware Resiliency Guidelines | NIST, https://www.nist.gov/publications/platform-firmware-resiliency-guidelines

24. veraison/eat: Entity Attestation Token manipulation library \- GitHub, https://github.com/veraison/eat

25. draft-reddy-rats-key-binding-01 \- Key Attestation for Entity Attestation Tokens (EAT), https://datatracker.ietf.org/doc/draft-reddy-rats-key-binding/

26. Building capability-based data security for Ceramic, https://blog.ceramic.network/capability-based-data-security-on-ceramic/

27. RFC 9782 \- Entity Attestation Token (EAT) Media Types \- IETF Datatracker, https://datatracker.ietf.org/doc/rfc9782/

28. hlc: hybrid logical/physical clocks \- GitHub, https://github.com/glycerine/hlc

29. Fediverse and Object Capabilities (Ocap) \- ActivityPub \- SocialHub, https://socialhub.activitypub.rocks/t/fediverse-and-object-capabilities-ocap/909

30. WebKMS v0.7 \- W3C Credentials Community Group, https://w3c-ccg.github.io/webkms/

31. WAC vs. Object capabilities \- Solid Community Forum, https://forum.solidproject.org/t/wac-vs-object-capabilities/3114

[image1]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAcAAAAWCAYAAAAM2IbtAAAAi0lEQVR4XmNgGOQgCYh3A7EwugQHEG+FYhAbBcgA8RMgbkUW5AFiSSAOBeLfQBwBxOJAzAqSjAfiWUB8H4h/AvFSIJ4ExMogSRDAa58LEP+C0higCoifA7ESugTMyD1AzM0AcUgXA8T1DCJAfJUB4YUgIC4AYkYQB0Q0AvEdIF4JZYO9gQwEoHjwAgBi+RXQ+6MhwAAAAABJRU5ErkJggg==>

[image2]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAsAAAAXCAYAAADduLXGAAAAzUlEQVR4Xu3Rrw/BQRjH8WfDxuZHYDNBoMloio2NoEiKiK7YKCRd8w9QNEHRFFXQFJsqCGymeJ/v3dy+kwXz2V777p7ntnvuviL/fDNhVJHUax9yqCFuNqkEMcUIJzSxRBsDXFAymyvoIIsr1ojoXgJH9PRaWsigjgeKpqHrZ3St2isT7BGzag3cUbBqEsIGC3h1TX3n2Mp7rFc+HZcS58JDBDA2DTOvfZx6thvyKKNvGkPsEDUFksYBK8zEGsUvznu7o36OurDH3fjJPAGfdB9e6q+BRAAAAABJRU5ErkJggg==>

[image3]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAB8AAAAZCAYAAADJ9/UkAAACHklEQVR4Xu2UwUtVQRTGP0mhyJQoEJEWSkhBUCIUQepbhObGRbhwGUoUbaJaREpQ7RIKSqIIwUIEFy3atAhdCO70T7AWSehKo0AXQdT3vTNz733z7r0iDx8E/uDH4555d2bumTMH2KcyDtOaMFgNmugLeigc2A3N9CF9Sx/Tk6XDmQzRW0Gsgd5GPFc7cjJzns7RLnqWfqJ/6T3kvERq6QQ9nYjp/QVaoEfpDfobGXMpXR/pMD3gYsfoEt2inS6WhhZ9DduE5yX9QwfcszawTDdQuskiSvc3+gu2a88o7OvvJmIhSrfSnuQZ7L0R93yELqJ8/iJ1sIL5DNuI5z5sEv2moYxN0tYgrvmOI87iGfoDdhT1LpaL0vgBlr5C6VDERTqOlHNMoMKboav0XDCWyQXYeata9SVpjNErYdChez8LW/Qr7UOciVwa6Tydhk2ShoroPSy9O3GKriF/viL6yjf0OfKbxmX6KAxmoGNR6lU/N4OxCL/wA8Qp0tXojf5haDKdtc48RHPccSaPyxevslWGJlQT0EvJAlKDuJp4Fi10CumVq56gWgn7gxbV4uoBJWixa3SbfocViXeTXor+aaS1U88JukLfwWpH+Ial69bhYhG+yWhnoeu0Lf5r8Qq+gt3dLPrpF/oUtlG16p8uXhHaiHp5sp2mcRDWHwZpN7Kv6664jvJ2WhWy2mlV0Dk/QX473TN033vC4D7/Hf8A2hxbWCVwPG0AAAAASUVORK5CYII=>

[image4]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAcAAAAYCAYAAAA20uedAAAAgklEQVR4XmNgGLmAFYjFoRgO+IB4EhC/BuINQDwFJiEPxLeAeA4Qc8IEQQBkzCogfgLEisgSIIBXUhOI3wLxLyB+hIQjQZLGQPwViMthqpGBPhB/YsAhCXLdZgaIvSD7QYARiLlhCiSAeDsQHwTiWUB8GIirYZIwwMMACRmYCYMLAAAyTxVWQpiPCgAAAABJRU5ErkJggg==>

[image5]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADAAAAAXCAYAAABNq8wJAAABd0lEQVR4Xu2WvytGURjHH2FAkRLZGJUyyEAWMpAsVrJaFFmsb5ksJCYmk0Vm+QsMZv4Bm2SxMOD7fc+5PPdJuu+59/hR51Ofuj3PvfU+537veY9IIpHQTMF7+Oa9gG2q3wkvVZ+eww51z6/TBI/gC3yG4/l2nUV4Jvnh/gzd8ASui1vhQ3FDaTbhkqkVZQPO2WKVjMA92A9v4R0cVP0WeOzvC2ELLthilXBlV/11TdxbWPvoivSIe0N8UyFEH2AXjvrrYfgIr2CXr03CA38dQtQBsvxzlQnjcgpf4ayv8e2E5p9EHSDLv/5o+cM5AAfhrlM0/62wT9y3pN2GK1/Ue2Fz/ckS6PxnMDqMEKM0LcXzPyFuO7Zei/svsfV9OMAHQ+GqM9tjtgGWxX3MN3DH9BolWoRs/jWMArdUDlEm/yTaAIwHjwXttuGpwQc4ZOqNUvkAM/BJPs82PD7M5+5wcEvl2ahI/r+j8gF+mn8/AHensjFMJBKed0KFRO2WYUHqAAAAAElFTkSuQmCC>

[image6]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADUAAAAaCAYAAAAXHBSTAAADNElEQVR4Xu2XS6hNURjHP6EISUREHjHwKOQReSaJAUkGRAbkMVEKiYkTGUiESEnJAImBCQpFMRBGyqOQSIRQBgYU/j9rr+7aa+99zj73niOD86tf+9y1zl17Pb71rXXMWjSdMfJoIp//G3rKbnFhCSbKLbKznCHfyJlBfXvbzdBXLpDL5WhzL6zGBHla9o4rSrBDvpQDZBd5SZ4K6ocmZTzrppOcLe/La3JV4nX5XE5p+2qKwfKWHBtXlKSfnGru/azIFXNhGDJLXrY6J62r3C9fWbbz1J2UX82FSggdOSwrUXl7mWRu1fLec8zcqpaCTp+QX8zNWB6E4GdzDfMCzzj5LHl2FFbhnJweVyRQ/lQOjyvy2CR/Jc8i+sgH8rG5cPEwc4RLRzcyAzpgbvLYV6PS1X/xfWBLVGWkfGduBtioRfgGX8uBSZmP/13+SwEkFjIY4cRnVneYXGrZxEOk7Da3ErRNtKwP6kNIIGctHS0ZKvK33BeVx4yQ7y09KJ78vdh/KWCz3COfmHvHcblXrpEv5EFr69g6c30IXZbUxRAZd2SvuMJD/r9tLvTmp6syUM/3wgZZhQ+WPlOAFT8i+5trnwQT7tUzSTnvrxcmMJzYDH6mSQCERDVIscxgJShjUByUPEMmy5XmUv1bc1nVr4oP2ZuyR1JWDwyKiCFycvGDqjpyMcTcOfXJ0mdR0aA8rO6P5OkhczHQWuFeBIP6JsfHFR6yGNms2qCY4Z3mVmlrVFdrUCSQeFZXyO9WnLZrUTP8SJ3n5U/L7gsPe4E9weFLlgqhs2TORVE55IWZf989cyl8rZyT1JWFdO6vVIVwctNp7m1xp+fJj/KQ7B7VgV/pjXGFte2nMMx8uLOCJBHSc13XHnP/W+pc5FpEmuXO5+973P0emRtY0ZlAOZMR39OA8GKy5gZlTBo3hofyhrmEUg/+slv6qsRhSAbkVk7cDrLiwYSwR5gMDucQ2qMsboO/+QVQc6ZzIMlwSWjvfiwNHbwrF8YVTWC1vGDZbdIUlsiLlr/vGgWTd9WKL9wNh5DanhiHWyOgzYq5I6UZ7RdCSGyT0+KKBsAv8A32jwfUokULsz9P2o/eZ46UgAAAAABJRU5ErkJggg==>

[image7]: <data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACoAAAAZCAYAAABHLbxYAAAB90lEQVR4Xu2WPWhUQRRGrxhBMTGKShISkSQSsQmCGhsRIhYR8Qe0EGOrpLNTEMEi2GipKIgiNhYxkEosFJSYQhDEwp9KUBEEIaZJmljo+ZgZd95k95m8XUHwHTjs7p3Z3Y/ZmTtrVlLy/7IcD+IN73FclZnhUO0k3sIruDU7/HdZgdfwEvbiaZzDN7g5mteKj3EUm3E7vsNj0ZzCrDYXJI8hfIKdUe0U/sTb2ORr5/ElrguTYBjfY1tUWxL6SR7gfdyYjKUoQAgV6MIv+MFcCIVTyHvRHLELZ/FwUs9lGe7Gp3gdN2WHa7ITX+OZqNaBn7x6vg2nbWHQHea2yeWkXhUdhH34HK/i+uxwIfbgD5zAlVYJVCtoWs+ggEfwBV7ENdnhwmhP38UZHPC1Q+a2RxooN6g+6AS+wrPmDkwj0Sn+ivuj2gErEHQQP+KIVe919aAV1ALokMTUClSr/pt4Vc9ZY352hZzCLf612pLa1FrsMbfKaaAQ9EJSX0DYp2od9RwkNfZx/xjYYO4GajHX4J/hQ3OHK6DtMe8fF0XamtRSFks7TuJ3/Bz5Dces0vC1uqp3+9f6Tt1SOsy6tZaE3tyPj/COVT40j9Dwqxn3R223m+YW46i5kG/NXaV1oZD64xD2XCPQQvSZ+9Oy1/58PZeUlJT8S/wCPApgo9eiMZoAAAAASUVORK5CYII=>