PROTOCOL SPECIFICATION
Attestation & Evidence Exchange Protocol Specification
Attestation & Evidence Exchange Protocol (AEP) · AI-Native Evidence Infrastructure Standard
Overview
The Attestation & Evidence Exchange Protocol (AEP) is an open evidence infrastructure protocol for autonomous AI agents and automated content generation.
Through machine-identity binding, causal time proofs, and cryptographically verifiable evidence chains, AEP freezes the AI creation and execution process into complete evidence that any party can verify independently — bridging the gap between generic notarization and AI creation.
The protocol runs on four cooperating infrastructure services — AEP-PKI, AEP-TSA, AEP-Chain, and Developer IAM — and supports neutral offline verification across the entire lifecycle.
Design Principles
Openness
An open protocol and specification; any party can freely build standards-compliant implementations
Cryptographically Verifiable
Built on proven cryptography; all claims are independently verifiable without relying on trusted intermediaries
Extensibility
Modular layered design supporting custom signature schemes and verifiable data structures
Interoperability
Natively compatible with MCP, C2PA, and W3C PROV to seamlessly integrate into agent frameworks
Core Concepts
Evidence
A set of cryptographically verifiable claims, the atomic unit of the protocol
Artifact
Code, files, execution decisions, and data generated by AI agents
Event
Granular execution records, tool invocations, and environment context
Identity
Agent machine identity credential powered by AEP PKI
Evidence Graph
A causal graph of events and artifacts, fully capturing the agent's action chain
Blockchain Anchor
Evidence fingerprints anchored to global distributed ledgers, providing public existence and immutable finality
Evidence Levels
From L0 to L7, evidence strength increases progressively (cumulative)
PlainHash: any valid package payload with cryptographic hash for single-point integrity
Signed: at least one valid asymmetric signature providing tamper-proofing and signer attribution
IdentityBound: identity verified via AEP-PKI certificate chain or IdP binding to establish machine principal
Timestamped: high-precision AEP-TSA trusted timestamp proof (RFC 3161) locking causal sequencing
Anchored: AEP-Chain distributed global ledger existence anchoring for immutable finality
Notarized: endorsement by a neutral audit or notary authority
Continuously-witnessed: continuous full-lifecycle execution logs with multi-party consensus witnessing
Hardware-rooted: TEE secure enclave and hardware root of trust binding
Current reference implementation (aep-refimpl) has production-grade L0–L2; L3 trusted timestamping and L4 blockchain anchoring are verified end-to-end; L5–L7 remain reserved protocol tiers.
Relationship with Other Standards
Evidence MCP
MCP is the de facto standard for agent-tool interaction; AEP treats Evidence MCP as a native core integration gateway to empower agents with native evidence capabilities.
C2PA
C2PA focuses on media content provenance (Content Credentials), while AEP concentrates on verifiable evidence chains across the full lifecycle of AI agent executions. The two are complementary.
W3C PROV
PROV provides a general provenance ontology specification. AEP's evidence graph closely aligns with its data model while being cryptographically optimized for AI behaviors.