SECURITY MODEL
Security Model
Zero-trust security based on cryptographic verifiability
Security Model Overview
AEP's security design centers on one core philosophy: providing an objective, verifiable evidence infrastructure rather than subjectively endorsing the veracity of content conclusions. The protocol assumes no centralized trust, but enables any entity to objectively audit and trace an Agent's identity, timestamp window, and data integrity independently of the execution environment.
All security properties are grounded in rigorous asymmetric cryptography, collision-resistant hashing, Merkle tree proofs, and RFC 3161 timestamping mechanisms, making unauthorized alterations or forgeries cryptographically undeniable.
Cryptographic Infrastructure
SM2 / Asymmetric Digital Signatures
Discrete logarithm and elliptic curve cryptography for execution identity authenticity and non-repudiation
SM3 / Cryptographic Hash Algorithm
256-bit secure hash digest guaranteeing avalanche-effect integrity verification across all inputs
Merkle Tree Existence Proofs
Efficient proof of membership supporting high-throughput independent verification of large-scale action records
AEP TSA Trusted Timestamp
High-precision causal time sequencing (RFC 3161) providing time proofs for ordering validation and replay detection
Threat Model & Mitigations
Before data is hashed and signed, an attacker injects into memory or uses a debugger/Rootkit to alter prompts, parameters, or outputs, producing formally valid but false evidence.
Millisecond incremental signing + Merkle-chain avalanche checks + periodic environment-hash refresh, shrinking the tampering window and exposing any change instantly.
After stealing a signing key, an attacker forges evidence, replays old signatures, or repudiates existing ones.
Keys are encrypted at rest with HSM/TEE hardware protection; trusted timestamps bound the leak time, verified against certificate revocation (CRL/OCSP).
Crafted .aep containers (zip bombs, path traversal, deep nesting) attack the verifier to trigger crashes or code execution.
Memory-safe implementation, fuzzing, decompression-ratio and path-traversal checks, and sandboxed parsing.
Constructing hash collisions to bypass integrity checks, or coercing weak algorithms during negotiation to lower evidence strength.
Collision-resistant hashes and a minimum 128-bit security policy; negotiation takes the strongest common set and alerts on downgrades.
Seven-Stage Independent Verification
-
Container Parsing
Deconstruct .aep container hierarchy, validate directory specs, and enforce path-traversal protection
-
Graph Building
Extract object topology, construct causal graphs, and enforce directed acyclic properties
-
Object Validation
Strictly validate schema compliance and field correctness of events, artifacts, and metadata
-
Merkle Verification
Independently recompute Merkle root hashes to verify dataset integrity and consistency
-
Signature & Identity Verification
Validate asymmetric signatures and validity against public keys and AEP PKI certificate chains
-
Level Determination
Evaluate cryptographic assurance and external anchoring state to determine evidence level (cumulative L0–L7; reference implementation currently covers L0–L4, with L5–L7 reserved)
-
Objective Audit Report
Generate machine-readable structured audit reports (supporting JSON / SARIF / HTML)
Objective Security Statement
-
AEP provides neutral, cryptographic evidence infrastructure: evidence is independently verifiable, transparently traceable, and fully auditable across its lifecycle.
-
Security relies on modern public-key cryptography and hash collision resistance; signature forgery and hash inversion are computationally infeasible.
-
Agent private key and certificate lifecycle management are foundational; securing private keys is essential for non-repudiation.
-
AEP focuses on the chain of evidence (Proof of AI Action), making all unauthorized modifications and impersonations mathematically detectable.