AEP

SECURITY MODEL

Security Model

Zero-trust security based on cryptographic verifiability

Security Model Overview

AEP's security design centers on one core philosophy: providing an objective, verifiable evidence infrastructure rather than subjectively endorsing the veracity of content conclusions. The protocol assumes no centralized trust, but enables any entity to objectively audit and trace an Agent's identity, timestamp window, and data integrity independently of the execution environment.

All security properties are grounded in rigorous asymmetric cryptography, collision-resistant hashing, Merkle tree proofs, and RFC 3161 timestamping mechanisms, making unauthorized alterations or forgeries cryptographically undeniable.

Cryptographic Infrastructure

SM2 / Asymmetric Digital Signatures

Discrete logarithm and elliptic curve cryptography for execution identity authenticity and non-repudiation

SM3 / Cryptographic Hash Algorithm

256-bit secure hash digest guaranteeing avalanche-effect integrity verification across all inputs

Merkle Tree Existence Proofs

Efficient proof of membership supporting high-throughput independent verification of large-scale action records

AEP TSA Trusted Timestamp

High-precision causal time sequencing (RFC 3161) providing time proofs for ordering validation and replay detection

Threat Model & Mitigations

Generation-Phase Data Tampering

Before data is hashed and signed, an attacker injects into memory or uses a debugger/Rootkit to alter prompts, parameters, or outputs, producing formally valid but false evidence.

Mitigation

Millisecond incremental signing + Merkle-chain avalanche checks + periodic environment-hash refresh, shrinking the tampering window and exposing any change instantly.

Key Theft & Forgery

After stealing a signing key, an attacker forges evidence, replays old signatures, or repudiates existing ones.

Mitigation

Keys are encrypted at rest with HSM/TEE hardware protection; trusted timestamps bound the leak time, verified against certificate revocation (CRL/OCSP).

Evidence Package Parsing Attacks

Crafted .aep containers (zip bombs, path traversal, deep nesting) attack the verifier to trigger crashes or code execution.

Mitigation

Memory-safe implementation, fuzzing, decompression-ratio and path-traversal checks, and sandboxed parsing.

Hash Collision & Algorithm Downgrade

Constructing hash collisions to bypass integrity checks, or coercing weak algorithms during negotiation to lower evidence strength.

Mitigation

Collision-resistant hashes and a minimum 128-bit security policy; negotiation takes the strongest common set and alerts on downgrades.

Seven-Stage Independent Verification

  1. Container Parsing

    Deconstruct .aep container hierarchy, validate directory specs, and enforce path-traversal protection

  2. Graph Building

    Extract object topology, construct causal graphs, and enforce directed acyclic properties

  3. Object Validation

    Strictly validate schema compliance and field correctness of events, artifacts, and metadata

  4. Merkle Verification

    Independently recompute Merkle root hashes to verify dataset integrity and consistency

  5. Signature & Identity Verification

    Validate asymmetric signatures and validity against public keys and AEP PKI certificate chains

  6. Level Determination

    Evaluate cryptographic assurance and external anchoring state to determine evidence level (cumulative L0–L7; reference implementation currently covers L0–L4, with L5–L7 reserved)

  7. Objective Audit Report

    Generate machine-readable structured audit reports (supporting JSON / SARIF / HTML)

Objective Security Statement

  • AEP provides neutral, cryptographic evidence infrastructure: evidence is independently verifiable, transparently traceable, and fully auditable across its lifecycle.

  • Security relies on modern public-key cryptography and hash collision resistance; signature forgery and hash inversion are computationally infeasible.

  • Agent private key and certificate lifecycle management are foundational; securing private keys is essential for non-repudiation.

  • AEP focuses on the chain of evidence (Proof of AI Action), making all unauthorized modifications and impersonations mathematically detectable.