AEP

PROTOCOL SPECIFICATION

Attestation & Evidence Exchange Protocol Specification

Attestation & Evidence Exchange Protocol (AEP) · AI-Native Evidence Infrastructure Standard

Overview

The Attestation & Evidence Exchange Protocol (AEP) is an open evidence infrastructure protocol for autonomous AI agents and automated content generation.

Through machine-identity binding, causal time proofs, and cryptographically verifiable evidence chains, AEP freezes the AI creation and execution process into complete evidence that any party can verify independently — bridging the gap between generic notarization and AI creation.

The protocol runs on four cooperating infrastructure services — AEP-PKI, AEP-TSA, AEP-Chain, and Developer IAM — and supports neutral offline verification across the entire lifecycle.

Design Principles

Openness

An open protocol and specification; any party can freely build standards-compliant implementations

Cryptographically Verifiable

Built on proven cryptography; all claims are independently verifiable without relying on trusted intermediaries

Extensibility

Modular layered design supporting custom signature schemes and verifiable data structures

Interoperability

Natively compatible with MCP, C2PA, and W3C PROV to seamlessly integrate into agent frameworks

Core Concepts

Evidence

A set of cryptographically verifiable claims, the atomic unit of the protocol

Artifact

Code, files, execution decisions, and data generated by AI agents

Event

Granular execution records, tool invocations, and environment context

Identity

Agent machine identity credential powered by AEP PKI

Evidence Graph

A causal graph of events and artifacts, fully capturing the agent's action chain

Blockchain Anchor

Evidence fingerprints anchored to global distributed ledgers, providing public existence and immutable finality

Evidence Levels

From L0 to L7, evidence strength increases progressively (cumulative)

L0 Implemented

PlainHash: any valid package payload with cryptographic hash for single-point integrity

L1 Implemented

Signed: at least one valid asymmetric signature providing tamper-proofing and signer attribution

L2 Implemented

IdentityBound: identity verified via AEP-PKI certificate chain or IdP binding to establish machine principal

L3 Implemented

Timestamped: high-precision AEP-TSA trusted timestamp proof (RFC 3161) locking causal sequencing

L4 Implemented

Anchored: AEP-Chain distributed global ledger existence anchoring for immutable finality

L5 Reserved

Notarized: endorsement by a neutral audit or notary authority

L6 Reserved

Continuously-witnessed: continuous full-lifecycle execution logs with multi-party consensus witnessing

L7 Reserved

Hardware-rooted: TEE secure enclave and hardware root of trust binding

Current reference implementation (aep-refimpl) has production-grade L0–L2; L3 trusted timestamping and L4 blockchain anchoring are verified end-to-end; L5–L7 remain reserved protocol tiers.

Relationship with Other Standards

Evidence MCP

MCP is the de facto standard for agent-tool interaction; AEP treats Evidence MCP as a native core integration gateway to empower agents with native evidence capabilities.

C2PA

C2PA focuses on media content provenance (Content Credentials), while AEP concentrates on verifiable evidence chains across the full lifecycle of AI agent executions. The two are complementary.

W3C PROV

PROV provides a general provenance ontology specification. AEP's evidence graph closely aligns with its data model while being cryptographically optimized for AI behaviors.