AEP

SYSTEM ARCHITECTURE

System Architecture

Attestation & Evidence Exchange Protocol (AEP) · Five-Layer Technical Stack and Infrastructure Matrix

Architecture Overview

The Attestation & Evidence Exchange Protocol (AEP) is engineered on a decoupled, layered design to provide standardized and cryptographically verifiable evidence chains for AI Agent executions and automated assets.

Addressing core pain points such as tamper-prone text logs and post-hoc snapshots that lose causal context, AEP defines a five-layer stack: Evidence MCP captures behaviors and events, which are then combined with Merkle proofs, asymmetric signatures, and timestamps, and packaged into standard .aep evidence packages.

At the infrastructure tier, AEP integrates AEP-PKI, AEP-TSA, AEP-Chain, and Developer IAM as four complementary infrastructure services, covering machine identity issuance, causal ordering, and immutable state anchoring.

Five-Layer Architecture System

AI Application Layer Application layer: autonomous agents, multi-agent workflows, and tool platforms Evidence Capture Layer Capture layer: Evidence MCP, SDK interceptors, and runtime environment probes Evidence Model Layer Model layer: structured evidence, causal events, and machine identity models Cryptographic Layer Cryptographic layer: asymmetric signatures, hash digests, Merkle trees, RFC 3161 timestamps Verification Layer Verification layer: neutral verifiers, offline verification tools, and objective audit reports

Evidence Graph Structure

The evidence graph uses a directed acyclic graph (DAG) to accurately capture the agent execution trail: Events link Artifacts and Identities via generatedBy/used semantics, while precededBy locks causal sequencing.

generatedBy precededBy used used Event 1 Artifact Event 2 Identity

Data Flow

Complete closed loop from action capture to independent verification

  1. AI Agent executes mission-critical tasks and triggers action capture

  2. Evidence MCP captures and standardizes Artifacts and Events

  3. Compute cryptographic hash digests of artifacts and events

  4. Generate asymmetric digital signatures using agent private key

  5. Build causal graphs and construct Merkle integrity proofs

  6. Seal and package into standardized .aep evidence container

  7. Any third party verifies independently offline or online

Evidence Package Container Format

The .aep evidence package is a standardized, out-of-the-box container that bundles manifest specifications, identity metadata, artifact digests, causal event chains, Merkle proofs, and digital signatures.

evidence.aep/
├── manifest.json
├── metadata/
│   └── identity/
├── artifacts/
├── events/
├── evidence_graph/
├── merkle/
└── signature/
    ├── signature.json
    └── signature.pub

Infrastructure Network

AEP-PKI, AEP-TSA, AEP-Chain, and Developer IAM operate together as the verifiable evidence foundation for AI actions and creative processes

AEP-PKI

ca.aep.org.cn

Role

Certificate and identity service: issues machine identity certificates to agents and developers, establishing a cryptographic principal.

AEP-TSA

tsa.aep.org.cn

Role

Trusted timestamp service: issues timestamp receipts for evidence, locking an irreversible causal ordering.

AEP-Chain

chain.aep.org.cn

Role

On-chain anchoring service: anchors evidence root digests publicly to provide an independently verifiable proof of existence.

Developer IAM

iam.aep.org.cn

Role

Developer identity and access management: unified developer onboarding, authentication, and permission governance.