{"slug":"discovery-results-that-carry-their-own-credential-check","citations":[{"url":"https://arxiv.org/html/2608.13030v1","committed_hash":"sha256:0cc06a11d3c51428afc6313862e2cc619648f4d77bf7773fef0f7e5aefc57405","committed_hash_short":"sha256:0cc06a11…efc57405","mime_type":"text/html","committed_at":"2026-09-10T19:00:27.255525+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\">\n<head>\n<meta http-equiv=\"content-type\" content=\"text/html; charset=UTF-8\">\n<title>InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab</title>\n<!--Generated by LaTeXML oxide (version 0.7.6) http://dlmf.nist.gov/LaTeXML/.-->\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1, shrink-to-fit=no\">\n<link rel=\"stylesheet\" href=\"/static/browse/0.3.4/css/arxiv-html-papers-20260823.css\" type=\"text/css\">\n<script src=\"/static/browse/0.3.4/js/arxiv-html-papers-20260131.js\"> </script>\n<script>\n  // Restore the saved color scheme preference, or\n  // enact the browser preference if \"automatic\", \n  // without expecting DOM load to have completed.\n  //\n  // Also restore any saved readingmode and ToC display preferences.\n  function initializeReadingPreferences() {\n    let saved_theme = localStorage.getItem(\"ar5iv_theme\") || \"automatic\";\n    if (saved_theme === \"automatic\") {\n      if (window.matchMedia(\"(prefers-color-scheme: dark)\").matches) {\n        saved_theme = \"dark\";\n      }\n    }\n    if (saved_theme == \"dark\") {\n      document.documentElement.setAttribute(\"data-theme\", \"dark\");\n    } else {\n      document.documentElement.setAttribute(\"data-theme\", \"light\");\n    }\n\n    const tocDisplay = localStorage.getItem('arxiv_html_paper_toc_display');\n    if (tocDisplay) {\n      document.documentElement.setAttribute(\"data-toc-display\", tocDisplay);\n    }\n    const readingMode = localStorage.getItem('arxiv_html_paper_reading_mode');\n    if (readingMode) {\n      document.documentElement.setAttribute(\"data-reading-mode\", readingMode);\n    }\n    // Pre-apply spinout-banner dismissal here, before the banner paints, so it\n    // never flashes in only to be hidden later by the deferred arxiv-header.js.\n    // Key matches arxiv-header.js: \"arxiv-banner-dismissed:\" + data-banner-name.\n    if (localStorage.getItem('arxiv-banner-dismissed:spinout-nonprofit')) {\n      document.documentElement.setAttribute(\"data-banner-dismissed\", \"\");\n    }\n  }\n  // Run as soon as JS starts, to minimize repainting\n  initializeReadingPreferences();\n</script>\n<link rel=\"apple-touch-icon\" sizes=\"180x180\"\n  href=\"/static/browse/0.3.4/images/icons/apple-touch-icon.png\">\n<link rel=\"icon\" type=\"image/png\" sizes=\"32x32\"\n  href=\"/static/browse/0.3.4/images/icons/favicon-32x32.png\">\n<link rel=\"icon\" type=\"image/png\" sizes=\"16x16\"\n  href=\"/static/browse/0.3.4/images/icons/favicon-16x16.png\">\n<link rel=\"manifest\" href=\"/static/browse/0.3.4/images/icons/site.webmanifest\">\n<link rel=\"mask-icon\" href=\"/static/browse/0.3.4/images/icons/safari-pinned-tab.svg\" color=\"#5bbad5\">\n<link rel=\"stylesheet\" type=\"text/css\" media=\"screen\" href=\"https://use.typekit.net/utz6mli.css\"><link rel=\"stylesheet\" type=\"text/css\" media=\"screen\"\n  href=\"/static/base/1.0.1/css/arxiv-header-footer.css?v=20260626\"><style>\n  /* Banner pre-dismissal (set above before paint -> no flash-then-hide) and\n     reading-mode chrome hiding. */\n  html[data-banner-dismissed] .ds-announcement { display: none; }\n  html[data-reading-mode=\"enabled\"] .ds-announcement,\n  html[data-reading-mode=\"enabled\"] .ds-site-footer { display: none; }\n  /* Keep the announcement text dark on the Open-Blue band in both colour themes\n     (otherwise it inherits the paper's warm-wash text in dark mode and washes out). */\n  .ds-announcement-text { color: var(--arxiv-ink, #1c1a17); }\n</style>\n<script defer src=\"/static/base/1.0.1/js/arxiv-header.js?v=20260626\"></script>\n</head>\n<body>\n<dialog id=\"modal-form\" aria-labelledby=\"modal-title\" closedby=\"any\">\n  <form id=\"modal-form-content\" method=\"dialog\" enctype=\"multipart/form-data\">\n    <header class=\"modal-header\">\n      <h5 id=\"modal-title\" class=\"modal-title\">Report GitHub Issue</h5>\n      <button type=\"submit\" formnovalidate class=\"modal-close\" aria-label=\"Close\">×</button>\n    </header>\n\n    <div class=\"modal-body\">\n      <label for=\"form_title\">Title:</label>\n      <input class=\"form-control\" id=\"form_title\" name=\"form_title\" required placeholder=\"Enter title\">\n\n      <p id=\"selectedTextModalDescription\" hidden>Content selection saved. Describe the issue below:</p>\n\n      <label for=\"description\">Description:</label>\n      <textarea class=\"form-control\" id=\"description\" name=\"description\" required maxlength=\"500\"\n        placeholder=\"500 characters maximum\"></textarea>\n    </div>\n\n    <footer class=\"modal-footer\">\n      <button type=\"submit\" value=\"internal-report\" class=\"sr-only modal-submit\">Submit without GitHub</button>\n      <button type=\"submit\" value=\"github-report\" class=\"modal-submit\">Submit in GitHub</button>\n    </footer>\n  </form>\n</dialog><div class=\"ds-announcement\" id=\"announcement-banner\" role=\"region\" aria-label=\"Announcement\"\n    data-banner-name=\"spinout-nonprofit\">\n    <img class=\"ds-announcement-glyph\" src=\"/static/base/1.0.1/images/icons/smileybones-small.svg\" alt=\"\" aria-hidden=\"true\">\n    <span class=\"ds-announcement-text\">arXiv is now an independent nonprofit!</span>\n    <a class=\"ds-announcement-link\" href=\"https://info.arxiv.org/about\">Learn more</a>\n    <button type=\"button\" class=\"ds-announcement-close\" aria-label=\"Dismiss announcement\">&times;</button>\n  </div>\n\n<header class=\"arxiv-html-header\">\n  <div class=\"html-header-logo\">\n    <a href=\"/\"><img alt=\"arXiv logo\" class=\"logo desktop-only\" width=\"100\"\n        src=\"/static/base/1.0.1/images/arxiv-logo-primary-light.svg\">\n      <span class=\"sr-only\">Back to arXiv</span>\n    </a>\n  </div>\n  <!--TOC, dark mode, links-->\n  <nav class=\"html-header-nav\">\n    <a class=\"header-button hover-effect desktop-only\" href=\"https://info.arxiv.org/about/accessible_HTML.html\"\n      target=\"_blank\">Why HTML?</a>\n    <a class=\"header-button\" title=\"Report an Issue\" href=\"#\" title=\"Report an issue\"\n      onclick=\"event.preventDefault(); showModalForm();\">\n      <svg role=\"presentation\" class=\"mobile-only toggle-icon\" aria-hidden=\"true\" height=\"1.25rem\"\n        viewBox=\"0 0 640 640\">\n        <path\n          d=\"M224 160C224 107 267 64 320 64C373 64 416 107 416 160L416 163.6C416 179.3 403.3 192 387.6 192L252.5 192C236.8 192 224.1 179.3 224.1 163.6L224.1 160zM569.6 172.8C580.2 186.9 577.3 207 563.2 217.6L465.4 290.9C470.7 299.8 474.7 309.6 477.2 320L576 320C593.7 320 608 334.3 608 352C608 369.7 593.7 384 576 384L480 384L480 416C480 418.6 479.9 421.3 479.8 423.9L563.2 486.4C577.3 497 580.2 517.1 569.6 531.2C559 545.3 538.9 548.2 524.8 537.6L461.7 490.3C438.5 534.5 395.2 566.5 344 574.2L344 344C344 330.7 333.3 320 320 320C306.7 320 296 330.7 296 344L296 574.2C244.8 566.5 201.5 534.5 178.3 490.3L115.2 537.6C101.1 548.2 81 545.3 70.4 531.2C59.8 517.1 62.7 497 76.8 486.4L160.2 423.9C160.1 421.3 160 418.7 160 416L160 384L64 384C46.3 384 32 369.7 32 352C32 334.3 46.3 320 64 320L162.8 320C165.3 309.6 169.3 299.8 174.6 290.9L76.8 217.6C62.7 207 59.8 186.9 70.4 172.8C81 158.7 101.1 155.8 115.2 166.4L224 248C236.3 242.9 249.8 240 264 240L376 240C390.2 240 403.7 242.8 416 248L524.8 166.4C538.9 155.8 559 158.7 569.6 172.8z\" />\n      </svg>\n      <span class=\"desktop-only\">Report Issue</span></a>\n    <!--back to abstract-->\n    <a class=\"header-button\" title=\"Back to abstract page\" aria-label=\"Back to abstract page\"\n      href=\"/abs/2608.13030v1\">\n      <svg class=\"mobile-only toggle-icon\" role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 512 512\" fill=\"#ffffff\"\n        aria-hidden=\"true\">\n        <path\n          d=\"M502.6 278.6c12.5-12.5 12.5-32.8 0-45.3l-128-128c-12.5-12.5-32.8-12.5-45.3 0s-12.5 32.8 0 45.3L402.7 224 192 224c-17.7 0-32 14.3-32 32s14.3 32 32 32l210.7 0-73.4 73.4c-12.5 12.5-12.5 32.8 0 45.3s32.8 12.5 45.3 0l128-128zM160 96c17.7 0 32-14.3 32-32s-14.3-32-32-32L96 32C43 32 0 75 0 128L0 384c0 53 43 96 96 96l64 0c17.7 0 32-14.3 32-32s-14.3-32-32-32l-64 0c-17.7 0-32-14.3-32-32l0-256c0-17.7 14.3-32 32-32l64 0z\">\n        </path>\n      </svg>\n      <span class=\"desktop-only\">Back to Abstract</span>\n    </a>\n    <!-- PDF download link -->\n    <a class=\"header-button\" title=\"Download PDF\" href=\"/pdf/2608.13030v1\"\n      target=\"_blank\">\n      <svg class=\"mobile-only toggle-icon\" role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 576 542\">\n        <path\n          d=\"M208 48L96 48c-8.8 0-16 7.2-16 16l0 384c0 8.8 7.2 16 16 16l80 0 0 48-80 0c-35.3 0-64-28.7-64-64L32 64C32 28.7 60.7 0 96 0L229.5 0c17 0 33.3 6.7 45.3 18.7L397.3 141.3c12 12 18.7 28.3 18.7 45.3l0 149.5-48 0 0-128-88 0c-39.8 0-72-32.2-72-72l0-88zM348.1 160L256 67.9 256 136c0 13.3 10.7 24 24 24l68.1 0zM240 380l32 0c33.1 0 60 26.9 60 60s-26.9 60-60 60l-12 0 0 28c0 11-9 20-20 20s-20-9-20-20l0-128c0-11 9-20 20-20zm32 80c11 0 20-9 20-20s-9-20-20-20l-12 0 0 40 12 0zm96-80l32 0c28.7 0 52 23.3 52 52l0 64c0 28.7-23.3 52-52 52l-32 0c-11 0-20-9-20-20l0-128c0-11 9-20 20-20zm32 128c6.6 0 12-5.4 12-12l0-64c0-6.6-5.4-12-12-12l-12 0 0 88 12 0zm76-108c0-11 9-20 20-20l48 0c11 0 20 9 20 20s-9 20-20 20l-28 0 0 24 28 0c11 0 20 9 20 20s-9 20-20 20l-28 0 0 44c0 11-9 20-20 20s-20-9-20-20l0-128z\" />\n      </svg>\n      <span class=\"desktop-only\">Download PDF</span></a>\n    <!-- navigational table of contents toggle -->\n    <a class=\"header-button toggle-icon\" href=\"javascript:toggleNavTOC();\" title=\"Toggle navigation\"\n      aria-label=\"Toggle navigation\">\n      <svg height=\"1.25rem\" role=\"presentation\" viewBox=\"0 0 512 512\">\n        <path\n          d=\"M40 48C26.7 48 16 58.7 16 72v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V72c0-13.3-10.7-24-24-24H40zM192 64c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zm0 160c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zm0 160c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zM16 232v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V232c0-13.3-10.7-24-24-24H40c-13.3 0-24 10.7-24 24zM40 368c-13.3 0-24 10.7-24 24v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V392c0-13.3-10.7-24-24-24H40z\">\n        </path>\n      </svg>\n    </a>\n    <!--- collapsable header / reading mode toggle -->\n    <a class=\"header-button toggle-icon\" href=\"javascript:toggleReadingMode();\"\n      title=\"Disable reading mode, show header and footer\">\n      <svg role=\"presentation\" height=\"1.25rem\"\n        viewBox=\"0 0 448 512\"><!--!Font Awesome Free v7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.-->\n        <path\n          d=\"M32 32C14.3 32 0 46.3 0 64l0 96c0 17.7 14.3 32 32 32s32-14.3 32-32l0-64 64 0c17.7 0 32-14.3 32-32s-14.3-32-32-32L32 32zM64 352c0-17.7-14.3-32-32-32S0 334.3 0 352l0 96c0 17.7 14.3 32 32 32l96 0c17.7 0 32-14.3 32-32s-14.3-32-32-32l-64 0 0-64zM320 32c-17.7 0-32 14.3-32 32s14.3 32 32 32l64 0 0 64c0 17.7 14.3 32 32 32s32-14.3 32-32l0-96c0-17.7-14.3-32-32-32l-96 0zM448 352c0-17.7-14.3-32-32-32s-32 14.3-32 32l0 64-64 0c-17.7 0-32 14.3-32 32s14.3 32 32 32l96 0c17.7 0 32-14.3 32-32l0-96z\" />\n      </svg>\n    </a>\n    <!--- colored theme toggle -->\n    <button type=\"button\" class=\"header-button color-tog\" onclick=\"toggleColorScheme();\" title=\"Toggle dark/light mode\" aria-label=\"Toggle color scheme\">\n      <span class=\"toggle-icon automatic-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"m14.3 16-.7-2h-3.2l-.7 2H7.8L11 7h2l3.2 9h-1.9M20 8.69V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69m-9.15 3.96h2.3L12 9l-1.15 3.65Z\">\n          </path>\n        </svg>\n      </span>\n      <span class=\"toggle-icon light-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"M12 8a4 4 0 0 0-4 4 4 4 0 0 0 4 4 4 4 0 0 0 4-4 4 4 0 0 0-4-4m0 10a6 6 0 0 1-6-6 6 6 0 0 1 6-6 6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69Z\">\n          </path>\n        </svg>\n      </span>\n      <span class=\"toggle-icon dark-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"M12 18c-.89 0-1.74-.2-2.5-.55C11.56 16.5 13 14.42 13 12c0-2.42-1.44-4.5-3.5-5.45C10.26 6.2 11.11 6 12 6a6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69Z\">\n          </path>\n        </svg>\n      </span>\n    </button>\n  </nav>\n</header><nav class=\"ltx_page_navbar\">\n<nav class=\"ltx_TOC\">\n<ol class=\"ltx_toclist\">\n<li class=\"ltx_tocentry ltx_tocentry_abstract\"><a href=\"#abstract1\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\">Abstract</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S1\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">1 </span>Introduction</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S2\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2 </span>Background &amp; Threat Landscape</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS1\" title=\"In 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.1 </span>The Agent Interaction Landscape</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS2\" title=\"In 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.2 </span>Agent-Specific Threat Model</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS3\" title=\"In 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.3 </span>Why Traditional Internet Security Falls Short</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S3\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3 </span><span class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>: Design Philosophy &amp; Protocol Suite Overview</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S3.SS1\" title=\"In 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3.1 </span>Design Principles</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S3.SS2\" title=\"In 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3.2 </span>Protocol Suite Architecture</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S3.SS3\" title=\"In 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3.3 </span>Relationship to Existing Protocols</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S4\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4 </span>Layer 0: Persistent Agent Identity</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS1\" title=\"In 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.1 </span>Agent Identity Card (AIC)</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS2\" title=\"In 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.2 </span>Four-Dimensional Identity Binding</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS3\" title=\"In 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.3 </span>Global Agent Registry (GAR)</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS4\" title=\"In 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.4 </span>Key Protection Tiers</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS5\" title=\"In 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.5 </span>Identity Lifecycle</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S5\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5 </span>Layer 1: Registration, Discovery &amp; Semantic Interoperability</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS1\" title=\"In 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.1 </span>Capability-Aware Registration</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS2\" title=\"In 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.2 </span>Semantic Capability Tagging</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS3\" title=\"In 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.3 </span>Capability-Aware Discovery</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS4\" title=\"In 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.4 </span>Verifiable Skill &amp; Tool Manifests</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S6\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6 </span>Layer 2: Trust Negotiation</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S6.SS1\" title=\"In 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6.1 </span>Mutual Attestation Protocol</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S6.SS2\" title=\"In 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6.2 </span>AIC Delegation Chain</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S6.SS3\" title=\"In 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6.3 </span>Two-Tier A2A Access Control</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S6.SS4\" title=\"In 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6.4 </span>The Capability Narrowing Chain</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S7\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">7 </span>Layer 3: Accountability &amp; Economics</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S7.SS1\" title=\"In 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">7.1 </span>Token-Usage Tracing</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S7.SS2\" title=\"In 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">7.2 </span>Payment Primitives</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S7.SS3\" title=\"In 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">7.3 </span>Action Accountability</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S7.SS4\" title=\"In 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">7.4 </span>Non-Repudiation</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S8\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">8 </span>Security Analysis</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S8.SS1\" title=\"In 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">8.1 </span>Threat Model and Assumptions</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S8.SS2\" title=\"In 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">8.2 </span>Property-Centric Security Evaluation</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S8.SS3\" title=\"In 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">8.3 </span>Security under Composition</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S8.SS4\" title=\"In 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">8.4 </span>Comparison and Residual Risks</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S9\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9 </span>Related Work</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS1\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.1 </span>Communication Stacks vs. Security-First Substrates</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS2\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.2 </span>Single-Dimension IAM vs. Multi-Dimensional Binding</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS3\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.3 </span>Directory Discovery vs. Capability-Aware Manifests</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS4\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.4 </span>Policy-Evaluated vs. Structurally-Attenuated Delegation</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS5\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.5 </span>Conformance Testing vs. Cryptographic Enforcement</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS6\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.6 </span>Single-Plane Overlays vs. Two-Tier Authorization</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS7\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.7 </span>Our Prior Work: <span class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span></span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S9.SS8\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">9.8 </span>Summary: the Joint-Coverage Argument</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S10\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">10 </span>Discussion &amp; Future Directions</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S10.SS1\" title=\"In 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">10.1 </span>Limitations</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S10.SS2\" title=\"In 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">10.2 </span>Future Directions</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S11\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">11 </span>Conclusion</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_bibliography\"><a href=\"#bib\" title=\"In InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\">References</span></a></li>\n</ol></nav>\n</nav>\n<div class=\"ltx_page_main\">\n<div id=\"infobox\" class=\"infobox\">\n  <a id=\"license-tr\" href=\"https://info.arxiv.org/help/license/index.html#licenses-available\">\n    License: arXiv.org perpetual non-exclusive license\n  </a>\n  <div id=\"watermark-tr\">\narXiv:2608.13030v1 [cs.CR] 13 Aug 2026</div>\n</div><div class=\"ltx_page_content\">\n<article class=\"ltx_document ltx_authors_1line\">\n<h1 class=\"ltx_title ltx_font_italic ltx_title_document\" style=\"font-size:120%;\"><span id=\"id1\" class=\"ltx_text ltx_font_bold ltx_font_smallcaps\" style=\"font-size:248%;\">InterSAGE\n<br class=\"ltx_break\" style=\"--ltx-break-space:10.0pt;\"></span><span id=\"id2\" class=\"ltx_text ltx_font_upright\" style=\"font-size:83%;\">\n<span id=\"id2.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:173%;\">The Secure and Verifiable Interoperability Protocol \n<br class=\"ltx_break\">for An Internet of Agents\n<br class=\"ltx_break\" style=\"--ltx-break-space:12.0pt;\"></span>\n</span>A Paper from the DeepKernel Lab</h1>\n<div class=\"ltx_authors\">\n<span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Zhenhua ZouSheng GuoQiuyang ZhanLepeng ZhaoShuo Li\n</span></span>\n<span class=\"ltx_author_before\">  </span><span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Zhuotao Liu\n</span><span class=\"ltx_author_notes\"><span class=\"ltx_author_notes_content\">\n<span class=\"ltx_contact ltx_role_affiliation\"><span class=\"ltx_contact_name\">Affiliation: </span>\n</span>\n<span class=\"ltx_contact ltx_role_affiliation\"><span class=\"ltx_contact_name\">Affiliation: </span>Corresponding author:\n<span id=\"id3\" class=\"ltx_text ltx_font_typewriter\">zhuotaoliu@tsinghua.edu.cn</span>\n</span></span></span></span></div>\n\n<div id=\"abstract1\" class=\"ltx_abstract\"><h6 class=\"ltx_title ltx_title_abstract\">Abstract</h6>\n    \n<p id=\"abstract1.1\" class=\"ltx_p\">The emerging Internet of Agents—a global environment in which\nLLM-powered agents discover peers, negotiate trust, invoke tools, and\ndelegate tasks across organizational boundaries—is currently being\nstandardized from the communication layer upward. Protocols increasingly\nspecify how agents exchange messages, but not how an agent proves what it\nis, what it is authorized to do, whether its advertised capabilities are\ngenuine, or how its actions remain accountable after delegation. We argue\nthat this leaves the ecosystem without the foundation for <em id=\"abstract1.1.1\" class=\"ltx_emph ltx_font_italic\">secure\ninteroperability</em>.</p>\n    \n<p id=\"abstract1.2\" class=\"ltx_p\">We present <span id=\"abstract1.2.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>, a trust-native protocol suite that supplies this trust\nsubstrate alongside existing Internet and agent communication protocols.\n<span id=\"abstract1.2.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is organized into four layers—Persistent\nIdentity (L0), Discovery (L1), Trust Negotiation (L2), and\nAccountability (L3)—covering nine security aspects across the agent\nlifecycle. Its core contribution is a set of four layer-aligned design\nprimitives. First, Agent Identity Cards provide persistent agent identity\nwith four-dimensional binding across developer, code package, operator, and\ndeployment context. Second, capability-aware discovery turns skill and tool\nadvertisements into DID-bound Verifiable Credential manifests, so discovery\nresults are verified for issuer provenance, subject binding, permission\nalignment, and freshness before interaction begins. Third, trust negotiation\ncombines monotonic capability attenuation with two-tier access control,\nmaking least privilege a signed structural invariant while preserving\napplication-level policy independence. Fourth, kernel-mediated\ncryptographic audit trails bind usage, delegation, and execution traces to\nagent identity without requiring a consensus ledger.</p>\n    \n<p id=\"abstract1.3\" class=\"ltx_p\"><span id=\"abstract1.3.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> does not replace existing agent protocols such as MCP, A2A, ANP, or AG-UI; it defines the missing\ntrust-relevant primitives that those protocols need: AIC capability boundaries,\nDID-bound manifest VCs, least-privilege session tokens, and signed execution traces.\nThis separation ensures that communication protocols can evolve\nindependently, while trust semantics remain explicit, portable, and\nverifiable. We compare <span id=\"abstract1.3.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> against 50+ related efforts across agent\nprotocols, decentralized identity, OAuth/OIDC extensions, zero-trust\ngovernance, delegation systems, and audit architectures.\nWe show that <span id=\"abstract1.3.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is the only\narchitecture that jointly enforces persistent identity,\ncapability-aware discovery, trust negotiation, and accountability as a single four-layer trust substrate for the Internet of Agents.</p>\n  \n</div>\n<section id=\"S1\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">1  Introduction</h2>\n\n<div id=\"S1.p1\" class=\"ltx_para\">\n<p id=\"S1.p1.1\" class=\"ltx_p\">The emergence of LLM-powered autonomous agents marks a qualitative shift in\nhow software interacts with the world. Unlike traditional microservices that\nexecute deterministic APIs, these agents reason over natural language, invoke\ntools dynamically, and collaborate with other agents to accomplish complex,\nmulti-step tasks <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib45\" title=\"\" class=\"ltx_ref\">1</a>, <a href=\"#bib.bib46\" title=\"\" class=\"ltx_ref\">2</a>, <a href=\"#bib.bib47\" title=\"\" class=\"ltx_ref\">3</a>, <a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">4</a>]</cite>. Industry analysts\nproject that by 2029 agentic AI will autonomously resolve a large share of\ncommon customer service issues without human intervention <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib53\" title=\"\" class=\"ltx_ref\">5</a>]</cite>, and major cloud providers\nhave already released agent-to-agent communication\nprotocols <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">6</a>, <a href=\"#bib.bib44\" title=\"\" class=\"ltx_ref\">7</a>, <a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">8</a>]</cite> to enable such\ncollaboration at scale.</p>\n</div>\n<div id=\"S1.p2\" class=\"ltx_para\">\n<p id=\"S1.p2.1\" class=\"ltx_p\">This trajectory evolves toward an <em id=\"S1.p2.1.1\" class=\"ltx_emph ltx_font_italic\">Internet of Agents</em>\n(IoA) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">4</a>, <a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">9</a>, <a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>]</cite>—a global network where\nbillions of heterogeneous agents discover one another, negotiate task\nparameters, exchange value, and compose into ad-hoc workflows across\norganizational boundaries. Multiple research groups have begun designing\nprotocol stacks for this vision: Fleming et al. propose reference layers for\nagent communication (L8) and semantics (L9) atop TCP/IP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">11</a>]</cite>; the Agent-OSI\nproject outlines a six-layer reference architecture including settlement and\nprovenance <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>]</cite>; and comprehensive surveys catalog the growing\nzoo of protocols spanning agent-to-agent (A2A), agent-to-tool (MCP), and\nrelated interaction axes <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib9\" title=\"\" class=\"ltx_ref\">12</a>, <a href=\"#bib.bib10\" title=\"\" class=\"ltx_ref\">13</a>, <a href=\"#bib.bib6\" title=\"\" class=\"ltx_ref\">14</a>]</cite>.<span id=\"footnote1\" class=\"ltx_note ltx_role_footnote\"><sup class=\"ltx_note_mark\">1</sup><span class=\"ltx_note_outer\"><span class=\"ltx_note_content\"><sup class=\"ltx_note_mark\">1</sup>\n            <span class=\"ltx_tag ltx_tag_note\">1</span>\n            \n            \n            \n            \n            \n            \n            \n          In Ehtesham et al., “ACP” denotes the Agent Communication Protocol (REST/HTTP), not the Agent Client Protocol <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib57\" title=\"\" class=\"ltx_ref\">15</a>]</cite>.</span></span></span></p>\n</div>\n<div id=\"S1.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p3.1\" class=\"ltx_p\"><span id=\"S1.p3.1.1\" class=\"ltx_text ltx_font_bold\">The missing trust layer.</span> \nA striking pattern emerges across these efforts: they focus predominantly on\n<em id=\"S1.p3.1.2\" class=\"ltx_emph ltx_font_italic\">how agents communicate</em> where security is again treated as the second-class citizen. Yet the agent threat landscape is qualitatively different from the traditional\nnetworking and computer systems. Agents operate with delegated authority, make\nnon-deterministic decisions, and dynamically compose into workflows whose\nauthorization requirements cannot be statically pre-computed. An agent that\nimpersonates a supply-chain optimizer, escalates its capabilities beyond\ndelegation scope, or repudiates a financial commitment can cause cascading\ndamage that no transport-layer encryption or OAuth token can\nprevent <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">16</a>, <a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">17</a>, <a href=\"#bib.bib40\" title=\"\" class=\"ltx_ref\">18</a>]</cite>. A first wave of\n<em id=\"S1.p3.1.3\" class=\"ltx_emph ltx_font_italic\">trust-layer</em> proposals has begun to address this gap—Microsoft’s\nAgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite>, which its documentation describes as “SSL for AI agents”;\nHuang et al.’s unified zero-trust architecture for the agentic\nweb <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">20</a>]</cite>; AIP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite>, which fuses identity,\nattenuation, and provenance into invocation-bound capability tokens; and\nRamachandran and Mishra’s enterprise identity-aware governance\nframework <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">22</a>]</cite>. These efforts converge on the\ndiagnosis but diverge in mechanism: each enforces least-privilege through\n<em id=\"S1.p3.1.4\" class=\"ltx_emph ltx_font_italic\">runtime</em> policy evaluation, behavioral attestation, or per-call\nDatalog rather than through structural invariants signed into the agent’s\ncredential at issuance. In the language of classical protocol design, the\nIoA still lacks its <em id=\"S1.p3.1.5\" class=\"ltx_emph ltx_font_italic\">trust plane</em>—the security substrate that binds\nidentity, authorization, and accountability into a coherent whole that\nholds even when downstream policy engines, attestors, or operators are\nmisconfigured or compromised.</p>\n</div>\n<div id=\"S1.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p4.1\" class=\"ltx_p\"><span id=\"S1.p4.1.1\" class=\"ltx_text ltx_font_bold\">Lessons from our prior work.</span> \nIn <span id=\"S1.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite>, we presented a unified trust framework\nfor multi-agent systems, integrating decentralized identifiers (DIDs),\nblockchain-anchored ledgers, and smart-contract-enforced access control. The\nframework demonstrated that security <em id=\"S1.p4.1.3\" class=\"ltx_emph ltx_font_italic\">can</em> be systematically layered\nonto agent collaboration protocols such as A2A <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">6</a>]</cite>. However, its\nreliance on blockchain infrastructure introduced deployment constraints:\non-chain transaction latency, gas costs, and the requirement for a shared\nledger among all participants limited applicability to environments where\nblockchain nodes are available and economically viable. The core security\n<em id=\"S1.p4.1.4\" class=\"ltx_emph ltx_font_italic\">ideas</em>—cryptographic agent identity, capability-bounded access\ncontrol, immutable audit trails, and defense orchestration—remain sound,\nbut their <em id=\"S1.p4.1.5\" class=\"ltx_emph ltx_font_italic\">realization</em> must be generalized beyond any specific type of\ninfrastructure.</p>\n</div>\n<div id=\"S1.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p5.1\" class=\"ltx_p\"><span id=\"S1.p5.1.1\" class=\"ltx_text ltx_font_bold\">This paper: <span id=\"S1.p5.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \nWe present <span id=\"S1.p5.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>, the first trust-native protocol suite for secure and verifiable agent-to-agent interoperability.\nRather than proposing another communication stack, <span id=\"S1.p5.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> provides the <em id=\"S1.p5.1.4\" class=\"ltx_emph ltx_font_italic\">trust layers</em> that any communication protocol\n(MCP, A2A, or future designs) can build upon. Its four layers address\nnine critical aspects of agent-native security:</p>\n</div>\n<div id=\"S1.p6\" class=\"ltx_para\">\n<ol id=\"S1.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S1.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S1.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Layer 0 — Agent Identity:</span> <em id=\"S1.I1.i1.p1.1.2\" class=\"ltx_emph ltx_font_italic\">persistent identity</em> via cryptographic agent\nidentity cards (AICs) with four-dimensional binding to developer, code\npackage, operator, and deployment context.</p>\n</div></li>\n<li id=\"S1.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S1.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Layer 1 — Discovery:</span> <em id=\"S1.I1.i2.p1.1.2\" class=\"ltx_emph ltx_font_italic\">capability-aware discovery</em> in which\neach skill and tool is a signed Verifiable Credential (VC) bound to the\nagent’s DID. Manifest VCs are presented during discovery and verified for\nsupply-chain authenticity, subject binding, and permission alignment.</p>\n</div></li>\n<li id=\"S1.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S1.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Layer 2 — Trust Negotiation:</span> <em id=\"S1.I1.i3.p1.1.2\" class=\"ltx_emph ltx_font_italic\">authentication</em> via mutual attestation,\n<em id=\"S1.I1.i3.p1.1.3\" class=\"ltx_emph ltx_font_italic\">delegation</em> via chains with monotonic capability attenuation, and a two-tier\n<em id=\"S1.I1.i3.p1.1.4\" class=\"ltx_emph ltx_font_italic\">access control</em> model.</p>\n</div></li>\n<li id=\"S1.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S1.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Layer 3 — Accountability:</span> <em id=\"S1.I1.i4.p1.1.2\" class=\"ltx_emph ltx_font_italic\">token-usage tracing</em>, <em id=\"S1.I1.i4.p1.1.3\" class=\"ltx_emph ltx_font_italic\">payment</em>\nprimitives, and <em id=\"S1.I1.i4.p1.1.4\" class=\"ltx_emph ltx_font_italic\">action accountability</em> via identity-signed execution traces\nand non-repudiation.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S1.p7\" class=\"ltx_para\">\n<p id=\"S1.p7.1\" class=\"ltx_p\"><span id=\"S1.p7.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is guided by five design principles (detailed in\n§<a href=\"#S3.SS1\" title=\"3.1 Design Principles ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3.1</span></a>) and introduces four novel design primitives.\nWe summarize each below using a uniform pattern—shared goal with prior\nwork, the specific divergence, and the operationally observable\nconsequence—a pattern we apply throughout §<a href=\"#S9\" title=\"9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">9</span></a> when\ncontrasting <span id=\"S1.p7.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> with related systems.</p>\n</div>\n<div id=\"S1.p8\" class=\"ltx_para\">\n<ul id=\"S1.I2\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S1.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i1.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Persistent Identity (L0).</span> An Agent Identity Card (AIC)\ncryptographically binds four identity dimensions—developer, code\npackage, operator, and operational context—into a single verifiable\ncredential. The goal of giving each agent a verifiable persistent\nidentity is shared with SPIFFE workload identities, OAuth 2.0 client\ncredentials, W3C DIDs, OIDC for Agents (OIDC-A) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">24</a>]</cite>, the\nOpenID Foundation’s strategic agenda for agentic\nIAM <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">25</a>]</cite>, and AIP’s capability\ntokens <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite>; the divergence is that each of those\nmodels binds only a single dimension—workload instance, client\napplication, holder key, or token issuer—whereas the AIC binds all\nfour dimensions independently and signs their conjunction. The\nconsequence is that an attacker who compromises the operator’s\ndeployment cannot impersonate a different developer or substitute a\ndifferent code package, because each dimension carries its own\nindependently verifiable signature.</p>\n</div></li>\n<li id=\"S1.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i2.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Capability-Aware Discovery (L1).</span> Each skill and tool an\nagent advertises is a signed Verifiable Credential (VC) whose\n<span id=\"S1.I2.i2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">credentialSubject.id</span> is the agent’s own DID—making it\nnon-transferable and replay-resistant. Skill VCs are issued by skill\ndistributors, tool VCs are issued by tool providers, and both can carry\noptional GAR endorsements before being presented in the agent’s\nregistration record during discovery. The goal of\nmaking agents discoverable is shared with ANP’s DID-based\ndiscovery <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">8</a>]</cite>, A2A’s well-known Agent\nCards <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">6</a>]</cite>, and registry-style agent catalogs; the\ndivergence is that <span id=\"S1.I2.i2.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> treats discovery results as <em id=\"S1.I2.i2.p1.1.4\" class=\"ltx_emph ltx_font_italic\">verified\ncapability credentials</em> rather than self-declared descriptions.\nRequesters verify each manifest VC for supply-chain authenticity,\nsubject binding to the presenter’s AIC, and permission alignment\nagainst the agent’s capability boundary <math id=\"S1.I2.i2.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math>. The consequence is\nthat discovery cannot become an implicit escalation channel: an\nagent cannot advertise skills it does not hold, tools it has not been\nauthorized to use, or permissions it was not granted, because every\nclaim is cryptographically bound to the agent’s identity and\nindependently verifiable at discovery time.</p>\n</div></li>\n<li id=\"S1.I2.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i3.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i3.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Trust Negotiation (L2).</span> <span id=\"S1.I2.i3.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> combines a four-stage\nmonotonic attenuation chain (Developer <math id=\"S1.I2.i3.p1.m1\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math> Operator <math id=\"S1.I2.i3.p1.m2\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math> GAR\n<math id=\"S1.I2.i3.p1.m3\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math> Runtime) with a two-tier access control model that separates\ninfrastructure-tier cryptographic verification from application-tier\ndeclarative policy. The goal of bounded authorization is shared with\nAIP’s Biscuit/Datalog attenuation <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite>, Saavedra’s\nDelegation Grants <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib34\" title=\"\" class=\"ltx_ref\">26</a>]</cite>, AgentMesh’s policy\nplane <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite>, OAuth 2.0 token exchange <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib50\" title=\"\" class=\"ltx_ref\">27</a>]</cite>, and\nenterprise governance frameworks <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">22</a>]</cite>;\nthe divergence is that <span id=\"S1.I2.i3.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> encodes the capability boundary into\nsigned credentials and then evaluates application policy on an\nindependent path. The consequence is that no policy edit, JIT\ndecision, or misconfigured PDP downstream of issuance can grant\ncapabilities the preceding stage did not authorize, while an\napplication-tier regression still cannot weaken cryptographic\nidentity verification.</p>\n</div></li>\n<li id=\"S1.I2.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i4.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i4.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Accountability (L3).</span> Every agent\naction is recorded in a tamper-evident hash chain and signed by the\nagent’s kernel-protected private key. The goal of immutable\naccountability is shared with blockchain-anchored ledgers\n(like <span id=\"S1.I2.i4.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite>) and centralized audit logs; the\ndivergence is that <span id=\"S1.I2.i4.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> achieves non-repudiation via trusted\nkernel-mediated cryptography rather than distributed consensus or\ntrusted third parties. The consequence is that agents can prove\ntheir execution history and attribute costs across boundaries in\ncompletely decentralized or resource-constrained environments where\nglobal ledgers are unviable.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"S1.p9\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p9.1\" class=\"ltx_p\"><span id=\"S1.p9.1.1\" class=\"ltx_text ltx_font_bold\">Scope and positioning.</span> \n<span id=\"S1.p9.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is a <em id=\"S1.p9.1.3\" class=\"ltx_emph ltx_font_italic\">positioning paper</em>: it presents the conceptual framework,\nprotocol architecture, and design rationale at a level suitable for guiding\nsubsequent protocol specifications, formal verification, and systems\nimplementation. Detailed cryptographic proofs, performance benchmarks, and\nproduction deployment experiences are deferred to companion publications\ncurrently in preparation.</p>\n</div>\n<div id=\"S1.p10\" class=\"ltx_para ltx_noindent\">\n<p id=\"S1.p10.1\" class=\"ltx_p\"><span id=\"S1.p10.1.1\" class=\"ltx_text ltx_font_bold\">Contributions.</span> \nIn summary, this paper makes the following contributions:</p>\n<ol id=\"S1.I3\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S1.I3.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S1.I3.i1.p1\" class=\"ltx_para\">\n<p id=\"S1.I3.i1.p1.1\" class=\"ltx_p\">We articulate the case for <em id=\"S1.I3.i1.p1.1.1\" class=\"ltx_emph ltx_font_italic\">secure interoperability</em> as the\nfoundational missing layer in the Internet of Agents, distinct from\ncommunication interoperability and grounded in a dedicated trust\nsubstrate.</p>\n</div></li>\n<li id=\"S1.I3.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S1.I3.i2.p1\" class=\"ltx_para\">\n<p id=\"S1.I3.i2.p1.1\" class=\"ltx_p\">We present <span id=\"S1.I3.i2.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>, a four-layer security protocol suite that\ncoherently addresses nine security aspects: persistent identity,\ncapability-aware discovery, authentication, delegation, access\ncontrol, payment, semantic tagging, token-usage tracing, and action\naccountability. The first five receive detailed protocol-level\ntreatment; the latter four are specified as framework-level\nprimitives that establish architectural slots for future refinement.</p>\n</div></li>\n<li id=\"S1.I3.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S1.I3.i3.p1\" class=\"ltx_para\">\n<p id=\"S1.I3.i3.p1.1\" class=\"ltx_p\">We introduce four novel design primitives: the Agent Identity\nCard for persistent identity, capability-aware discovery through\nDID-bound Verifiable Credential manifests that make skill and tool\nclaims cryptographically verifiable at discovery time, trust\nnegotiation combining the monotonic capability attenuation chain\nwith the two-tier A2A access control model, and kernel-mediated\ncryptographic audit trails for accountability.</p>\n</div></li>\n<li id=\"S1.I3.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S1.I3.i4.p1\" class=\"ltx_para\">\n<p id=\"S1.I3.i4.p1.1\" class=\"ltx_p\">We position <span id=\"S1.I3.i4.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> within the current landscape of agent protocol,\nidentity, and governance efforts (§<a href=\"#S9\" title=\"9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">9</span></a>)—organized\ninto six clusters spanning IoA stacks and surveys, agent IAM and\nOAuth/OIDC extensions, zero-trust DID/VC architectures,\ndelegation-centric protocols, security-design principles, and\nindustry trust overlays—and make the joint-coverage argument\nexplicit: each individual primitive in <span id=\"S1.I3.i4.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is anticipated by some\nprior work, but the conjunction of persistent identity,\ncapability-aware discovery, trust negotiation with monotonic\nattenuation and two-tier access control, and kernel-mediated\naccountability appears in\nno prior single architecture (<a href=\"#S9.T7\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">7</span></a>).</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S1.p11\" class=\"ltx_para\">\n<p id=\"S1.p11.1\" class=\"ltx_p\">The remainder of this paper is organized as follows.\n§<a href=\"#S2\" title=\"2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> surveys the agent interaction landscape and threat\nmodel. §<a href=\"#S3\" title=\"3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> presents the design philosophy and protocol suite\noverview. §<a href=\"#S4\" title=\"4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a>–§<a href=\"#S7\" title=\"7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">7</span></a> detail each\nlayer. §<a href=\"#S8\" title=\"8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">8</span></a> provides a security analysis and comparison with\nexisting approaches. §<a href=\"#S9\" title=\"9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">9</span></a> discusses related work in depth.\n§<a href=\"#S10\" title=\"10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">10</span></a> outlines limitations and future directions.\n§<a href=\"#S11\" title=\"11 Conclusion ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">11</span></a> concludes.</p>\n</div>\n</section>\n<section id=\"S2\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">2  Background &amp; Threat Landscape</h2>\n\n<section id=\"S2.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">2.1  The Agent Interaction Landscape</h3>\n\n<div id=\"S2.SS1.p1\" class=\"ltx_para\">\n<p id=\"S2.SS1.p1.1\" class=\"ltx_p\">Modern agent-to-agent communication is shaped by a rapidly growing set of\nprotocols, each targeting a different facet of the problem:</p>\n</div>\n<div id=\"S2.SS1.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS1.p2.1\" class=\"ltx_p\"><span id=\"S2.SS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Model Context Protocol (MCP).</span> \nThe Model Context Protocol (MCP) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib44\" title=\"\" class=\"ltx_ref\">7</a>]</cite>, introduced by Anthropic and\nnow maintained as an open, vendor-neutral specification, standardizes how an\nagent (client) discovers and invokes external tools hosted by MCP servers via\nJSON-RPC. Third-party deployment surveys report over 97 million monthly SDK\ndownloads as of early 2026 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib18\" title=\"\" class=\"ltx_ref\">28</a>]</cite>; MCP is widely adopted for\nagent-to-tool integration. The core specification, however, does not define\nagent-native identity, mutual authentication between agents, or authorization\nsemantics beyond transport-level security.</p>\n</div>\n<div id=\"S2.SS1.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS1.p3.1\" class=\"ltx_p\"><span id=\"S2.SS1.p3.1.1\" class=\"ltx_text ltx_font_bold\">Agent-to-Agent Protocol (A2A).</span> \nThe Agent-to-Agent (A2A) protocol <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">6</a>]</cite>, developed under the\nA2A open specification effort, enables peer-to-peer task delegation between\nagents using capability-based <em id=\"S2.SS1.p3.1.2\" class=\"ltx_emph ltx_font_italic\">Agent Cards</em>. A2A supports both\nsynchronous and asynchronous interactions and provides structured task\nlifecycle management. Published security guidance centers on HTTPS and\nOAuth 2.0; the specification does not yet standardize agent-native identity,\nstructured delegation chains, or cross-domain trust comparable to a dedicated\ntrust plane.</p>\n</div>\n<div id=\"S2.SS1.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS1.p4.1\" class=\"ltx_p\"><span id=\"S2.SS1.p4.1.1\" class=\"ltx_text ltx_font_bold\">Agent Network Protocol (ANP).</span> \nANP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">8</a>]</cite> introduces a three-layer architecture—identity\nand encrypted communication, meta-protocol negotiation, and application\nprotocol—using W3C DIDs and JSON-LD for open agent discovery. ANP focuses\non the “agentic web” vision but, in its published white paper, treats\naccess control and end-to-end accountability less extensively than\nidentity and discovery.</p>\n</div>\n<div id=\"S2.SS1.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS1.p5.1\" class=\"ltx_p\"><span id=\"S2.SS1.p5.1.1\" class=\"ltx_text ltx_font_bold\">Emerging protocol stacks.</span> \nSeveral groups propose higher-level architectures. Fleming\net al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">11</a>]</cite> propose reference layers for agent communication\n(L8) and agent semantics (L9) above TCP/IP (not part of the classical OSI\nstack). Agent-OSI <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>]</cite> proposes a six-layer\ndecentralized stack including settlement and provenance. ACPS <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib6\" title=\"\" class=\"ltx_ref\">14</a>]</cite>\ndefines registration, discovery, interaction, and tooling protocols.\nCoral Protocol <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib5\" title=\"\" class=\"ltx_ref\">29</a>]</cite> provides open infrastructure for\nagent communication, coordination, trust, and payments framed as the\n“Internet of Agents.” Surveys <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib9\" title=\"\" class=\"ltx_ref\">12</a>, <a href=\"#bib.bib10\" title=\"\" class=\"ltx_ref\">13</a>, <a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">30</a>]</cite> catalog and compare these efforts.</p>\n</div>\n<div id=\"S2.SS1.p6\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS1.p6.1\" class=\"ltx_p\"><span id=\"S2.SS1.p6.1.1\" class=\"ltx_text ltx_font_bold\">Beyond A2A: adjacent interaction axes and trust overlays.</span> \nThe protocol space continues to multiply along distinct interaction axes\nthat complement A2A: AG-UI <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib56\" title=\"\" class=\"ltx_ref\">31</a>]</cite> for agent-to-user\nstreaming, the Agent Client Protocol (ACP) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib57\" title=\"\" class=\"ltx_ref\">15</a>]</cite> for\neditor-to-coding-agent flows, IBM ContextForge <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib58\" title=\"\" class=\"ltx_ref\">32</a>]</cite>\nas a federated gateway proxying MCP/A2A/REST, and the\n<span id=\"S2.SS1.p6.1.2\" class=\"ltx_text ltx_font_typewriter\">agents.json</span> specification <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib61\" title=\"\" class=\"ltx_ref\">33</a>]</cite> extending OpenAPI\nwith agent-specific interaction contracts. Most recently, Microsoft’s\nAgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite> describes itself in project documentation as\n“SSL for AI agents,”\nlayering SPIFFE/SVID workload identity, a runtime policy engine, and\nA2A/MCP/IATP protocol translators atop existing communication stacks; a\nparallel academic effort, Huang et al.’s unified zero-trust\narchitecture <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">20</a>]</cite>, adds behavioral attestation and trust-adaptive runtime environments to the same trust-overlay paradigm. We\nreturn to both as our primary industry and academic comparators in\n§<a href=\"#S9\" title=\"9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">9</span></a>.</p>\n</div>\n<div id=\"S2.SS1.p7\" class=\"ltx_para\"><span id=\"S2.SS1.p7.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S2.SS1.p7.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S2.SS1.p7.p1.1\" class=\"ltx_p\"><span id=\"S2.SS1.p7.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Key Insight 1: Observation.</span>  \nExisting protocols and stacks overwhelmingly prioritize <em id=\"S2.SS1.p7.p1.1.2\" class=\"ltx_emph ltx_font_italic\">communication\ninteroperability</em>: how agents find each other, exchange messages, and\ninvoke tools. Security is treated as an aspect to be satisfied at each\nlayer rather than as a <em id=\"S2.SS1.p7.p1.1.3\" class=\"ltx_emph ltx_font_italic\">foundational design center</em> with its own\ncoherent architecture. Even the most security-conscious trust overlays\n(AgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite>, the unified zero-trust\narchitecture of Huang et al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">20</a>]</cite>) enforce least-privilege\nthrough runtime policy evaluation and behavioral attestation rather than\nthrough monotonic capability attenuation that holds at the credential\nlevel—so a misconfigured policy or a compromised attestor can silently\nwiden capability. This leaves critical gaps that individual protocol\npatches cannot close.</span>\n</span></span>\n</div>\n</section>\n<section id=\"S2.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">2.2  Agent-Specific Threat Model</h3>\n\n<div id=\"S2.SS2.p1\" class=\"ltx_para\">\n<p id=\"S2.SS2.p1.1\" class=\"ltx_p\">The agent ecosystem introduces threats that are qualitatively different from\ntraditional web services. We identify six categories that motivate the design\nof <span id=\"S2.SS2.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</p>\n</div>\n<figure id=\"S2.T1\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\"><span id=\"S2.T1.3\" class=\"ltx_text\" style=\"font-size:90%;\">Table 1</span>: </span><span id=\"S2.T1.4\" class=\"ltx_text\" style=\"font-size:90%;\">Agent-specific threat categories and their structural causes.</span></figcaption>\n<table id=\"S2.T1.5\" class=\"ltx_tabular ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S2.T1.5.1\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.1.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_th_row ltx_border_tt\"><span id=\"S2.T1.5.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Threat</span></th>\n<th id=\"S2.T1.5.1.2\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S2.T1.5.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.1.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Description</span></span>\n</span></th>\n<th id=\"S2.T1.5.1.3\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S2.T1.5.1.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.1.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Structural Cause</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S2.T1.5.2\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.2.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\" style=\"padding-bottom: 4.0pt;\"><span id=\"S2.T1.5.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T1: Identity spoofing</span></th>\n<td id=\"S2.T1.5.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.2.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">An agent claims to be built by a trusted developer or to possess capabilities it lacks.</span></span>\n</span></td>\n<td id=\"S2.T1.5.2.3\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_t\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.2.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.2.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agents use self-declared names or API keys; no binding to developer, code, or operator.</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.5.3\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.3.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\" style=\"padding-bottom: 4.0pt;\"><span id=\"S2.T1.5.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T2: Capability escalation</span></th>\n<td id=\"S2.T1.5.3.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.3.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">A child agent exercises permissions beyond what its parent delegated.</span></span>\n</span></td>\n<td id=\"S2.T1.5.3.3\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.3.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.3.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Static permission models lack monotonic attenuation; delegation is often unconstrained.</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.5.4\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.4.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\" style=\"padding-bottom: 4.0pt;\"><span id=\"S2.T1.5.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T3: Delegation abuse</span></th>\n<td id=\"S2.T1.5.4.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.4.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Unbounded delegation chains create laundering paths for authority.</span></span>\n</span></td>\n<td id=\"S2.T1.5.4.3\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.4.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.4.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">No depth bounding, no cascading revocation, no tenant isolation in delegation.</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.5.5\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.5.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\" style=\"padding-bottom: 4.0pt;\"><span id=\"S2.T1.5.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T4: Cross-domain trust breakdown</span></th>\n<td id=\"S2.T1.5.5.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.5.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agents from different organizations cannot verify each other’s identity or capabilities.</span></span>\n</span></td>\n<td id=\"S2.T1.5.5.3\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.5.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.5.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">No shared trust anchor; each framework uses its own identity model.</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.5.6\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.6.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\" style=\"padding-bottom: 4.0pt;\"><span id=\"S2.T1.5.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T5: Payment &amp; usage fraud</span></th>\n<td id=\"S2.T1.5.6.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.6.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.6.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.6.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">An agent consumes LLM tokens or services without traceable identity.</span></span>\n</span></td>\n<td id=\"S2.T1.5.6.3\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 4.0pt;\">\n<span id=\"S2.T1.5.6.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.6.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.6.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Token usage is tied to API keys, not to cryptographic agent identity; no metering protocol.</span></span>\n</span></td></tr>\n<tr id=\"S2.T1.5.7\" class=\"ltx_tr\">\n<th id=\"S2.T1.5.7.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_bb\"><span id=\"S2.T1.5.7.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T6: Action repudiation</span></th>\n<td id=\"S2.T1.5.7.2\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S2.T1.5.7.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.7.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.7.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">An agent denies having performed a high-impact action (e.g., financial transfer).</span></span>\n</span></td>\n<td id=\"S2.T1.5.7.3\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_bb\">\n<span id=\"S2.T1.5.7.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S2.T1.5.7.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S2.T1.5.7.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Execution traces are not cryptographically signed; audit logs are mutable.</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S2.SS2.p2\" class=\"ltx_para\">\n<p id=\"S2.SS2.p2.1\" class=\"ltx_p\"><a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a> summarizes these threats. Prior threat\nanalyses <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">16</a>, <a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">17</a>, <a href=\"#bib.bib40\" title=\"\" class=\"ltx_ref\">18</a>, <a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite> have\nidentified overlapping subsets; our contribution is to map them to their\n<em id=\"S2.SS2.p2.1.1\" class=\"ltx_emph ltx_font_italic\">structural causes</em>—the architectural deficiencies that enable\neach threat—which directly motivates the layered design of <span id=\"S2.SS2.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</p>\n</div>\n<div id=\"S2.SS2.p3\" class=\"ltx_para\">\n<p id=\"S2.SS2.p3.1\" class=\"ltx_p\">The taxonomy in <a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a> is not constructed in isolation. It\nsynthesizes three independent lines of analysis: Anbiaee\net al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">17</a>]</cite> compare MCP, A2A, Agora, and ANP and\nidentify twelve protocol-level risks, several of which (cross-protocol\ncredential laundering, executable-component attestation, lifecycle\nrisks) map directly onto T1–T4. AgentRFC <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">16</a>]</cite> formalizes\neleven security principles as TLA+ invariants and introduces the\nComposition Safety principle—the observation that properties holding\nfor individual protocols can break under composition—which underlies\nT2 and T4. Identity-aware governance\nanalyses <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">22</a>]</cite> ground these abstract risks\nin production incidents reported in that survey (e.g., the ClawHavoc\nsupply-chain attack on 824+ malicious agent skills, Cisco’s finding that\n26% of analyzed agent skills contain security vulnerabilities, and\n30,000+ internet-exposed OpenClaw instances), making T1–T6 verifiable\nrather than purely analytical.</p>\n</div>\n</section>\n<section id=\"S2.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">2.3  Why Traditional Internet Security Falls Short</h3>\n\n<div id=\"S2.SS3.p1\" class=\"ltx_para\">\n<p id=\"S2.SS3.p1.1\" class=\"ltx_p\">The Internet’s existing security mechanisms were designed for human users\ninteracting with web services. Three fundamental mismatches arise when they\nare applied to autonomous agents.</p>\n</div>\n<div id=\"S2.SS3.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS3.p2.1\" class=\"ltx_p\"><span id=\"S2.SS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">OAuth/OIDC assumes human principals.</span> \nOAuth 2.0 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib48\" title=\"\" class=\"ltx_ref\">34</a>]</cite> and OpenID Connect <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib49\" title=\"\" class=\"ltx_ref\">35</a>]</cite> model a three-party\nflow: a human user authorizes a client application to access a resource\nserver. Agent-to-agent interactions invert this model—both parties are\nnon-human, may be ephemeral, and require mutual (not unilateral)\nauthentication. The OpenID Foundation’s strategic agenda for agentic\nIAM <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">25</a>]</cite> explicitly catalogs these gaps and surveys\ncandidate extensions; OIDC-A <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">24</a>]</cite> is the most concrete\nextension to date, defining standard claims for representing agent\nidentity, attestation, and delegation chains within OAuth. Yet such\nextensions still inherit OAuth’s interactive-flow assumptions and bind\nto a single <em id=\"S2.SS3.p2.1.2\" class=\"ltx_emph ltx_font_italic\">client</em> dimension, not to the developer, code\npackage, operator, and operational context that agent provenance\nrequires <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib27\" title=\"\" class=\"ltx_ref\">36</a>, <a href=\"#bib.bib36\" title=\"\" class=\"ltx_ref\">37</a>]</cite>.</p>\n</div>\n<div id=\"S2.SS3.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS3.p3.1\" class=\"ltx_p\"><span id=\"S2.SS3.p3.1.1\" class=\"ltx_text ltx_font_bold\">TLS provides transport, not identity semantics.</span> \nTLS <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib51\" title=\"\" class=\"ltx_ref\">38</a>]</cite> secures the channel but does not tell the recipient\n<em id=\"S2.SS3.p3.1.2\" class=\"ltx_emph ltx_font_italic\">who built</em> the agent, <em id=\"S2.SS3.p3.1.3\" class=\"ltx_emph ltx_font_italic\">what code</em> it runs, or <em id=\"S2.SS3.p3.1.4\" class=\"ltx_emph ltx_font_italic\">who\nauthorized</em> its deployment. A TLS certificate binds a public key to a\ndomain name, not to a developer-code-operator triple. Mutual TLS (mTLS)\nadds client-side certificates but still does not express agent\ncapabilities, delegation depth, or revocation cascades. Recent\nzero-trust frameworks add SPIFFE/SVID workload identity above\nmTLS <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib26\" title=\"\" class=\"ltx_ref\">39</a>, <a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">40</a>, <a href=\"#bib.bib22\" title=\"\" class=\"ltx_ref\">41</a>]</cite>, which\nremoves static API keys and enables short-lived attestation, but binds\nkeys to <em id=\"S2.SS3.p3.1.5\" class=\"ltx_emph ltx_font_italic\">workload instances</em>—a single dimension—rather than to\nthe conjunction of developer, code package, operator, and operational\ncontext that agent trust decisions require.</p>\n</div>\n<div id=\"S2.SS3.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S2.SS3.p4.1\" class=\"ltx_p\"><span id=\"S2.SS3.p4.1.1\" class=\"ltx_text ltx_font_bold\">X.509 does not bind agent semantics.</span> \nX.509 certificates <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib52\" title=\"\" class=\"ltx_ref\">42</a>]</cite> bind a public key to a subject name and\nare widely used in PKI. However, agent identity requires richer\nsemantics: capability boundaries, delegation chains, code-package\nhashes, and operational context. Encoding these in X.509 extensions is\ntechnically possible but semantically awkward and incompatible with the\nexisting CA ecosystem. SPIFFE/SPIRE <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">40</a>]</cite> provides\nworkload identity for Kubernetes but, as noted above, does not model\nagent-native concepts such as delegation depth, capability attenuation,\nor developer-code provenance.</p>\n</div>\n<div id=\"S2.SS3.p5\" class=\"ltx_para\"><span id=\"S2.SS3.p5.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S2.SS3.p5.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S2.SS3.p5.p1.1\" class=\"ltx_p\"><span id=\"S2.SS3.p5.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Key Insight 2: Gap.</span>  \nNo existing Internet security mechanism provides the combination of\n<em id=\"S2.SS3.p5.p1.1.2\" class=\"ltx_emph ltx_font_italic\">persistent identity</em> with four-dimensional binding,\n<em id=\"S2.SS3.p5.p1.1.3\" class=\"ltx_emph ltx_font_italic\">capability-aware discovery</em> with verifiable skill and tool\nmanifests, <em id=\"S2.SS3.p5.p1.1.4\" class=\"ltx_emph ltx_font_italic\">trust negotiation</em> that combines monotonic capability\nattenuation with two-tier access control, and <em id=\"S2.SS3.p5.p1.1.5\" class=\"ltx_emph ltx_font_italic\">accountability</em> via\ntamper-evident execution traces. <span id=\"S2.SS3.p5.p1.1.6\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> fills this gap with a dedicated\nsecurity protocol suite.</span>\n</span></span>\n</div>\n</section>\n</section>\n<section id=\"S3\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">3  <span id=\"S3.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>: Design Philosophy &amp; Protocol Suite Overview</h2>\n\n<section id=\"S3.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">3.1  Design Principles</h3>\n\n<div id=\"S3.SS1.p1\" class=\"ltx_para\">\n<p id=\"S3.SS1.p1.1\" class=\"ltx_p\"><span id=\"S3.SS1.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is guided by five principles distilled from lessons learned in\n<span id=\"S3.SS1.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite>, the <span id=\"S3.SS1.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">DeepKernel</span> security\nkernel, and the broader agent security literature:</p>\n</div>\n<div id=\"S3.SS1.p2\" class=\"ltx_para\">\n<ol id=\"S3.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2.5em;\">\n<li id=\"S3.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S3.I1.i1.1\" class=\"ltx_text ltx_font_bold\">P1.</span></span> \n<div id=\"S3.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S3.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S3.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Trust as a binding layer, not an add-on.</span>\nExisting IoA stacks <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">11</a>, <a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>, <a href=\"#bib.bib6\" title=\"\" class=\"ltx_ref\">14</a>]</cite> design communication\nfirst and add security externally—via auth headers, gateway proxies, or\nprotocol-specific translators <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite>. <span id=\"S3.I1.i1.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> inverts this: its\ntrust primitives (AIC capability boundaries, manifest VCs, session tokens,\ntrace entries) are designed to be <em id=\"S3.I1.i1.p1.1.3\" class=\"ltx_emph ltx_font_italic\">embedded into</em> existing protocol\nmessages. An MCP invocation carries an AIC-bound capability context; an\nANP discovery response carries manifest VCs; an A2A interaction carries a\nLayer 2 session token; an AG-UI event stream attaches provenance metadata.\nThe trust layer <em id=\"S3.I1.i1.p1.1.4\" class=\"ltx_emph ltx_font_italic\">pervades</em> the communication layer rather than\nwrapping around it.</p>\n</div></li>\n<li id=\"S3.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S3.I1.i2.1\" class=\"ltx_text ltx_font_bold\">P2.</span></span> \n<div id=\"S3.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S3.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S3.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Complementary to existing Internet layers.</span>\n<span id=\"S3.I1.i2.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> does not replace TCP/IP, HTTP, or application-layer protocols such as\nMCP and A2A. Instead, it provides a <em id=\"S3.I1.i2.p1.1.3\" class=\"ltx_emph ltx_font_italic\">trust overlay</em> that any\ntransport and any agent protocol can bind to. An agent using A2A over HTTPS\ncan adopt <span id=\"S3.I1.i2.p1.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s identity and access control layers without modifying A2A’s\nmessage format.</p>\n</div></li>\n<li id=\"S3.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S3.I1.i3.1\" class=\"ltx_text ltx_font_bold\">P3.</span></span> \n<div id=\"S3.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S3.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S3.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">General cryptographic primitives, no infrastructure lock-in.</span>\n<span id=\"S3.I1.i3.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> demonstrated the value of blockchain-anchored auditability, but\nat the cost of deployment generality. <span id=\"S3.I1.i3.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> uses standard Ed25519 signatures,\na PKI-style Global Agent Registry (GAR), and challenge-response protocols\nthat work in any environment—cloud, edge, or air-gapped.\nSpecific deployments can optionally layer additional trust anchors\n(TEEs, HSMs, distributed ledgers) without changing the core protocol.</p>\n</div></li>\n<li id=\"S3.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S3.I1.i4.1\" class=\"ltx_text ltx_font_bold\">P4.</span></span> \n<div id=\"S3.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S3.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S3.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Deny-by-default, converge-on-strict.</span>\nCapabilities, permissions, and access are denied unless explicitly granted.\nWhen multiple policies combine (e.g., developer declaration, operator\nprovisioning, runtime policy), the system computes the\n<em id=\"S3.I1.i4.p1.1.2\" class=\"ltx_emph ltx_font_italic\">intersection</em>, never the union. Authority can only be attenuated,\nnever amplified—a property we call <em id=\"S3.I1.i4.p1.1.3\" class=\"ltx_emph ltx_font_italic\">monotonic capability\nattenuation</em>.</p>\n</div></li>\n<li id=\"S3.I1.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S3.I1.i5.1\" class=\"ltx_text ltx_font_bold\">P5.</span></span> \n<div id=\"S3.I1.i5.p1\" class=\"ltx_para\">\n<p id=\"S3.I1.i5.p1.1\" class=\"ltx_p\"><span id=\"S3.I1.i5.p1.1.1\" class=\"ltx_text ltx_font_bold\">Structural guarantees over policy-based assurances.</span>\nWhere possible, <span id=\"S3.I1.i5.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> encodes security properties as structural invariants\n(e.g., a child AIC’s capability set is a cryptographically signed subset of\nits parent’s) rather than relying on runtime policy engines to enforce\nthem. Structural guarantees survive misconfiguration; policy-based\nassurances do not.</p>\n</div></li>\n</ol>\n</div>\n</section>\n<section id=\"S3.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">3.2  Protocol Suite Architecture</h3>\n\n<div id=\"S3.SS2.p1\" class=\"ltx_para\">\n<p id=\"S3.SS2.p1.1\" class=\"ltx_p\"><span id=\"S3.SS2.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is organized into four layers, each addressing a distinct set of\nsecurity concerns. <a href=\"#S3.F1\" title=\"In 3.2 Protocol Suite Architecture ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Figure</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a> illustrates the architecture\nand its relationship to the existing Internet protocol stack.</p>\n</div>\n<figure id=\"S3.F1\" class=\"ltx_figure\"><span class=\"ltx_inline-block\"><svg id=\"S3.F1.pic1\" class=\"ltx_picture ltx_centering\" height=\"357.89\" overflow=\"visible\" version=\"1.1\" viewBox=\"0 0 558.48 357.89\" width=\"558.48\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" stroke-width=\"0.4pt\" transform=\"translate(0,357.89) matrix(1 0 0 -1 0 0) translate(235.46,0) translate(0,30.57)\"><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#F0F0F0;\" fill=\"#F0F0F0\" stroke=\"#BDC3C7\"><path d=\"M 132.26 15.75 L -179.5 15.75 C -182.56 15.75 -185.04 13.27 -185.04 10.21 L -185.04 -10.21 C -185.04 -13.27 -182.56 -15.75 -179.5 -15.75 L 132.26 -15.75 C 135.32 -15.75 137.8 -13.27 137.8 -10.21 L 137.8 10.21 C 137.8 13.27 135.32 15.75 132.26 15.75 Z M -185.04 -15.75\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -153.33 -3.11)\"><foreignObject style=\"--ltx-fo-width:19.56em;--ltx-fo-height:0.73em;--ltx-fo-depth:0.24em;font-size:9.25pt;\" height=\"12.45\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.34)\" width=\"250.36\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.1\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;--ltx-fg-color:#4A4A4A;\">TCP/IP   <math id=\"S3.F1.pic1.m1\" class=\"ltx_Math\" alttext=\"\\cdot\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">⋅</mo><annotation encoding=\"application/x-tex\">\\cdot</annotation></semantics></math>   HTTP/gRPC/WebSocket   <math id=\"S3.F1.pic1.m2\" class=\"ltx_Math\" alttext=\"\\cdot\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">⋅</mo><annotation encoding=\"application/x-tex\">\\cdot</annotation></semantics></math>   TLS</span></span></span></foreignObject></g><g style=\"--ltx-fill-color:#000000;\" fill=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 0.69 -1.38)\"><path style=\"stroke:none\" d=\"M -190.57 25.96 h 333.9 v 54.38 h -333.9 Z\"></path></g><g style=\"--ltx-fill-color:#326E98;\" fill=\"#326E98\"><path style=\"stroke:none\" d=\"M 132.26 74.8 L -179.5 74.8 C -182.56 74.8 -185.04 72.33 -185.04 69.27 L -185.04 37.03 C -185.04 33.97 -182.56 31.5 -179.5 31.5 L 132.26 31.5 C 135.32 31.5 137.8 33.97 137.8 37.03 L 137.8 69.27 C 137.8 72.33 135.32 74.8 132.26 74.8 Z M -185.04 31.5\"></path></g><g style=\"--ltx-stroke-color:#FFFFFF;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#FFFFFF\" transform=\"matrix(1.0 0.0 0.0 1.0 -81.92 49.69)\"><foreignObject style=\"--ltx-fg-color:#FFFFFF;--ltx-fo-width:7.69em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:11pt;\" color=\"#FFFFFF\" height=\"12.3\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.61)\" width=\"117.02\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.2\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">L0: Agent Identity</span></span></span></foreignObject></g><g style=\"--ltx-fill-color:#000000;\" fill=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 0.69 -1.38)\"><path style=\"stroke:none\" d=\"M -190.57 98.8 h 333.9 v 54.38 h -333.9 Z\"></path></g><g style=\"--ltx-fill-color:#4993C4;\" fill=\"#4993C4\"><path style=\"stroke:none\" d=\"M 132.26 147.64 L -179.5 147.64 C -182.56 147.64 -185.04 145.16 -185.04 142.1 L -185.04 109.87 C -185.04 106.81 -182.56 104.33 -179.5 104.33 L 132.26 104.33 C 135.32 104.33 137.8 106.81 137.8 109.87 L 137.8 142.1 C 137.8 145.16 135.32 147.64 132.26 147.64 Z M -185.04 104.33\"></path></g><g style=\"--ltx-stroke-color:#FFFFFF;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#FFFFFF\" transform=\"matrix(1.0 0.0 0.0 1.0 -66.49 122.52)\"><foreignObject style=\"--ltx-fg-color:#FFFFFF;--ltx-fo-width:5.63em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:11pt;\" color=\"#FFFFFF\" height=\"12.3\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.61)\" width=\"85.74\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.3\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">L1: Discovery</span></span></span></foreignObject></g><g style=\"--ltx-fill-color:#000000;\" fill=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 0.69 -1.38)\"><path style=\"stroke:none\" d=\"M -190.57 171.63 h 333.9 v 54.38 h -333.9 Z\"></path></g><g style=\"--ltx-fill-color:#1F8B4D;\" fill=\"#1F8B4D\"><path style=\"stroke:none\" d=\"M 132.26 220.47 L -179.5 220.47 C -182.56 220.47 -185.04 217.99 -185.04 214.94 L -185.04 182.7 C -185.04 179.64 -182.56 177.17 -179.5 177.17 L 132.26 177.17 C 135.32 177.17 137.8 179.64 137.8 182.7 L 137.8 214.94 C 137.8 217.99 135.32 220.47 132.26 220.47 Z M -185.04 177.17\"></path></g><g style=\"--ltx-stroke-color:#FFFFFF;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#FFFFFF\" transform=\"matrix(1.0 0.0 0.0 1.0 -92.33 195.36)\"><foreignObject style=\"--ltx-fg-color:#FFFFFF;--ltx-fo-width:9.11em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:11pt;\" color=\"#FFFFFF\" height=\"12.3\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.61)\" width=\"138.69\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.4\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">L2: Trust Negotiation</span></span></span></foreignObject></g><g style=\"--ltx-fill-color:#000000;\" fill=\"#000000\" transform=\"matrix(1.0 0.0 0.0 1.0 0.69 -1.38)\"><path style=\"stroke:none\" d=\"M -190.57 244.46 h 333.9 v 54.38 h -333.9 Z\"></path></g><g style=\"--ltx-fill-color:#9F60BA;\" fill=\"#9F60BA\"><path style=\"stroke:none\" d=\"M 132.26 293.31 L -179.5 293.31 C -182.56 293.31 -185.04 290.83 -185.04 287.77 L -185.04 255.53 C -185.04 252.48 -182.56 250 -179.5 250 L 132.26 250 C 135.32 250 137.8 252.48 137.8 255.53 L 137.8 287.77 C 137.8 290.83 135.32 293.31 132.26 293.31 Z M -185.04 250\"></path></g><g style=\"--ltx-stroke-color:#FFFFFF;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#FFFFFF\" transform=\"matrix(1.0 0.0 0.0 1.0 -81.16 268.19)\"><foreignObject style=\"--ltx-fg-color:#FFFFFF;--ltx-fo-width:7.59em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:11pt;\" color=\"#FFFFFF\" height=\"12.3\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.61)\" width=\"115.5\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.5\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">L3: Accountability</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -137.03 83.29)\"><foreignObject style=\"--ltx-fo-width:23em;--ltx-fo-height:0.7em;--ltx-fo-depth:0.2em;font-size:7pt;\" height=\"8.72\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.78)\" width=\"222.75\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.6\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">Persistent Identity  •  Key Protection  • \nAIC Lifecycle</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -174.58 156.12)\"><foreignObject style=\"--ltx-fo-width:30.89em;--ltx-fo-height:0.7em;--ltx-fo-depth:0.2em;font-size:7pt;\" height=\"8.72\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.78)\" width=\"299.19\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.7\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">Semantic Tagging  •  Verifiable Manifests  • \nCapability-Aware Discovery</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -135.31 228.96)\"><foreignObject style=\"--ltx-fo-width:22.59em;--ltx-fo-height:0.7em;--ltx-fo-depth:0.2em;font-size:7pt;\" height=\"8.72\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.78)\" width=\"218.77\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.8\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">Authentication  •  Delegation  • \nA2A Access Control</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -147.36 301.79)\"><foreignObject style=\"--ltx-fo-width:25.35em;--ltx-fo-height:0.7em;--ltx-fo-depth:0.2em;font-size:7pt;\" height=\"8.72\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.78)\" width=\"245.55\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.9\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">Payment  •  Token Usage Tracing  • \nAction Accountability</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#BDC3C7\"><path d=\"M 302.94 83.66 L 208.88 83.66 C 206.58 83.66 204.72 81.8 204.72 79.51 L 204.72 26.79 C 204.72 24.5 206.58 22.64 208.88 22.64 L 302.94 22.64 C 305.23 22.64 307.09 24.5 307.09 26.79 L 307.09 79.51 C 307.09 81.8 305.23 83.66 302.94 83.66 Z M 204.72 22.64\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 241.07 48.83)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:2.17em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" color=\"#4A4A4A\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"29.68\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.10\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">MCP</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#BDC3C7\"><path d=\"M 204.72 95.47 h 102.36 v 61.02 h -102.36 Z\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 242.02 121.66)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:2.03em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" color=\"#4A4A4A\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"27.78\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.11\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">ANP</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#BDC3C7\"><path d=\"M 204.72 168.31 h 102.36 v 61.02 h -102.36 Z\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 243.35 194.49)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:1.83em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" color=\"#4A4A4A\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"25.11\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.12\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">A2A</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#BDC3C7\"><path d=\"M 302.94 302.17 L 208.88 302.17 C 206.58 302.17 204.72 300.31 204.72 298.01 L 204.72 245.29 C 204.72 243 206.58 241.14 208.88 241.14 L 302.94 241.14 C 305.23 241.14 307.09 243 307.09 245.29 L 307.09 298.01 C 307.09 300.31 305.23 302.17 302.94 302.17 Z M 204.72 241.14\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 237.87 267.33)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:2.66em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" color=\"#4A4A4A\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"36.46\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.13\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">AG-UI</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 193.4 315.02)\"><foreignObject style=\"--ltx-fo-width:10.07em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:8.8pt;\" height=\"9.84\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.69)\" width=\"122.65\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.14\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:80%;--ltx-fg-color:#4A4A4A;\">Agent Comm. Protocols</span></span></span></foreignObject></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\"><path style=\"fill:none\" d=\"M 138.07 53.15 L 200.86 53.15\"></path><g style=\"--ltx-fg-color:#2980B9;\" color=\"#2980B9\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 198.91 53.15)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#000000\"><path style=\"stroke:none\" d=\"M 211.34 69.09 L 131.18 69.09 C 130.41 69.09 129.79 68.47 129.79 67.71 L 129.79 57.72 C 129.79 56.95 130.41 56.33 131.18 56.33 L 211.34 56.33 C 212.11 56.33 212.72 56.95 212.72 57.72 L 212.72 67.71 C 212.72 68.47 212.11 69.09 211.34 69.09 Z M 129.79 56.33\"></path></g><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\" transform=\"matrix(1.0 0.0 0.0 1.0 131.87 60.29)\"><foreignObject style=\"--ltx-fo-width:8.16em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"79.05\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.15\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#2980B9;\">capability boundary</span></span></span></foreignObject></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\"><path style=\"fill:none\" d=\"M 138.07 125.98 L 200.86 125.98\"></path><g style=\"--ltx-fg-color:#2980B9;\" color=\"#2980B9\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 198.91 125.98)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#000000\"><path style=\"stroke:none\" d=\"M 196.83 140.04 L 145.69 140.04 C 144.93 140.04 144.31 139.42 144.31 138.66 L 144.31 130.55 C 144.31 129.79 144.93 129.17 145.69 129.17 L 196.83 129.17 C 197.59 129.17 198.21 129.79 198.21 130.55 L 198.21 138.66 C 198.21 139.42 197.59 140.04 196.83 140.04 Z M 144.31 129.17\"></path></g><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\" transform=\"matrix(1.0 0.0 0.0 1.0 146.39 131.24)\"><foreignObject style=\"--ltx-fo-width:5.16em;--ltx-fo-height:0.69em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.73\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"50.02\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.16\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#2980B9;\">manifest VC</span></span></span></foreignObject></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\"><path style=\"fill:none\" d=\"M 138.07 198.82 L 200.86 198.82\"></path><g style=\"--ltx-fg-color:#2980B9;\" color=\"#2980B9\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 198.91 198.82)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#000000\"><path style=\"stroke:none\" d=\"M 198.43 212.88 L 144.09 212.88 C 143.33 212.88 142.71 212.26 142.71 211.5 L 142.71 203.39 C 142.71 202.62 143.33 202 144.09 202 L 198.43 202 C 199.19 202 199.81 202.62 199.81 203.39 L 199.81 211.5 C 199.81 212.26 199.19 212.88 198.43 212.88 Z M 142.71 202\"></path></g><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\" transform=\"matrix(1.0 0.0 0.0 1.0 144.78 204.08)\"><foreignObject style=\"--ltx-fo-width:5.49em;--ltx-fo-height:0.69em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.73\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"53.22\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.17\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#2980B9;\">session token</span></span></span></foreignObject></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\"><path style=\"fill:none\" d=\"M 138.07 271.65 L 200.86 271.65\"></path><g style=\"--ltx-fg-color:#2980B9;\" color=\"#2980B9\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 198.91 271.65)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\" stroke=\"#000000\"><path style=\"stroke:none\" d=\"M 196.19 287.6 L 146.33 287.6 C 145.56 287.6 144.94 286.98 144.94 286.21 L 144.94 276.22 C 144.94 275.46 145.56 274.84 146.33 274.84 L 196.19 274.84 C 196.96 274.84 197.58 275.46 197.58 276.22 L 197.58 286.21 C 197.58 286.98 196.96 287.6 196.19 287.6 Z M 144.94 274.84\"></path></g><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\" transform=\"matrix(1.0 0.0 0.0 1.0 147.02 278.79)\"><foreignObject style=\"--ltx-fo-width:5.01em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"48.48\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.18\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#2980B9;\">signed trace</span></span></span></foreignObject></g></g><g stroke-width=\"0.8pt\"><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;--ltx-fg-color:#1B5E8C;\" color=\"#1B5E8C\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\"><path style=\"fill:none\" d=\"M -196.85 28.45 M -196.85 28.45 C -200.17 30.11 -202.39 33.99 -202.39 39.52 L -202.39 151.33 C -202.39 156.87 -204.6 160.74 -207.92 162.4 C -204.6 164.06 -202.39 167.94 -202.39 173.47 L -202.39 285.28 C -202.39 290.82 -200.17 294.69 -196.85 296.35\"></path></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" transform=\"matrix(0.0 1.0 -1.0 0.0 -221.39 120.94)\"><foreignObject style=\"--ltx-fo-width:6.02em;--ltx-fo-height:0.68em;--ltx-fo-depth:0em;font-size:10pt;\" height=\"9.46\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.46)\" width=\"83.31\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.19\" class=\"ltx_text ltx_font_sansserif ltx_font_bold ltx_font_smallcaps\" style=\"--ltx-fg-color:#1B5E8C;\">INTERSAGE</span></span></span></foreignObject></g></g><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\" transform=\"matrix(1.0 0.0 0.0 1.0 33 -24.08)\"><foreignObject style=\"--ltx-fg-color:#2980B9;--ltx-fo-width:14.53em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" color=\"#2980B9\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"140.77\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S3.F1.pic1.20\" class=\"ltx_text ltx_font_sansserif ltx_font_italic\" style=\"font-size:70%;\">trust primitives </span><em id=\"S3.F1.pic1.21\" class=\"ltx_emph ltx_font_sansserif\" style=\"font-size:70%;\">embed into</em><span id=\"S3.F1.pic1.22\" class=\"ltx_text ltx_font_sansserif ltx_font_italic\" style=\"font-size:70%;\"> protocol messages</span></span></span></foreignObject></g></g></svg></span>\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\"><span id=\"S3.F1.5\" class=\"ltx_text\" style=\"font-size:90%;\">Figure 1</span>: </span><span id=\"S3.F1.6\" class=\"ltx_text\" style=\"font-size:90%;\">The <span id=\"S3.F1.6.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> four-layer protocol suite. Each layer builds on the one\nbelow it and <em id=\"S3.F1.6.2\" class=\"ltx_emph ltx_font_italic\">embeds</em> trust primitives into existing agent communication\nprotocols: L0 constrains MCP tool invocation through AIC capability\nboundaries, L1 exposes DID-bound manifest VCs through discovery protocols\nsuch as ANP, L2 authorizes A2A interaction through session tokens, and L3\nattaches signed execution traces to AG-UI streams.</span></figcaption>\n</figure>\n<div id=\"S3.SS2.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.SS2.p2.1\" class=\"ltx_p\"><span id=\"S3.SS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Layer 0: Agent Identity.</span> \nThe foundation of <span id=\"S3.SS2.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>. Every agent receives a cryptographic <em id=\"S3.SS2.p2.1.3\" class=\"ltx_emph ltx_font_italic\">Agent\nIdentity Card</em> (AIC) that binds four identity dimensions—developer, code\npackage, operator, and operational context—into a single verifiable\ncredential signed by the Global Agent Registry. Layer 0 also manages the\nagent’s key lifecycle: provisioning, rotation, and revocation with cascading\nguarantees. (§<a href=\"#S4\" title=\"4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a>)</p>\n</div>\n<div id=\"S3.SS2.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.SS2.p3.1\" class=\"ltx_p\"><span id=\"S3.SS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Layer 1: Discovery.</span> \nBefore two agents can interact, they must find each other and understand\neach other’s capabilities. Layer 1 provides capability-aware discovery:\neach skill and tool is represented as a signed Verifiable Credential (VC)\nbound to the agent’s DID, issued by the relevant skill distributor or tool\nprovider, and presented in the agent’s registration record. Requesters\nverify each manifest VC for issuer authenticity, subject binding, and\npermission alignment against the agent’s AIC capability boundary—transforming\ndirectory lookup into a trust-establishing protocol step. Layer 1 supports\nboth registry-mediated and peer-to-peer discovery modes.\n(§<a href=\"#S5\" title=\"5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a>)</p>\n</div>\n<div id=\"S3.SS2.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.SS2.p4.1\" class=\"ltx_p\"><span id=\"S3.SS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Layer 2: Trust Negotiation.</span> \nThe interaction layer. When an agent wishes to collaborate with or delegate\nto another, Layer 2 orchestrates mutual attestation via challenge-response\nover AICs, computes the session capability boundary via intersection, and\nevaluates the responder’s application-level access policy. Its core\nprimitive combines monotonic capability attenuation with two-tier access\ncontrol: cryptographic credentials define the maximum boundary, while\napplication policy can only narrow the resulting session. Layer 2 also\nmanages delegation: a parent agent can issue a child AIC with strictly\nattenuated capabilities, forming a cryptographic delegation chain with\nbounded depth and cascading revocation. (§<a href=\"#S6\" title=\"6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6</span></a>)</p>\n</div>\n<div id=\"S3.SS2.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S3.SS2.p5.1\" class=\"ltx_p\"><span id=\"S3.SS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Layer 3: Accountability.</span> \nEvery interaction leaves a cryptographic trace. Layer 3 binds LLM\ntoken-usage records to agent identity, provides payment primitives for\nagent-to-agent service exchange, and ensures that execution traces are\nsigned by the agent’s kernel-held private key for non-repudiation.\n(§<a href=\"#S7\" title=\"7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">7</span></a>)</p>\n</div>\n</section>\n<section id=\"S3.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">3.3  Relationship to Existing Protocols</h3>\n\n<div id=\"S3.SS3.p1\" class=\"ltx_para\">\n<p id=\"S3.SS3.p1.1\" class=\"ltx_p\">The agent ecosystem already has a rich set of communication\nprotocols—MCP, A2A, ANP, AG-UI <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib56\" title=\"\" class=\"ltx_ref\">31</a>]</cite>,\nACP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib57\" title=\"\" class=\"ltx_ref\">15</a>]</cite>—that define <em id=\"S3.SS3.p1.1.1\" class=\"ltx_emph ltx_font_italic\">what agents say to each\nother</em>: message formats, task lifecycles, tool invocations, UI event\nstreams. <span id=\"S3.SS3.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> does not compete with any of them. Instead, it treats\nthem as <em id=\"S3.SS3.p1.1.3\" class=\"ltx_emph ltx_font_italic\">host protocols</em>—the transport and application channels\ninto which its trust primitives are embedded—and answers a different\nquestion: <em id=\"S3.SS3.p1.1.4\" class=\"ltx_emph ltx_font_italic\">why should agents trust each other?</em></p>\n</div>\n<div id=\"S3.SS3.p2\" class=\"ltx_para\">\n<p id=\"S3.SS3.p2.1\" class=\"ltx_p\">We discuss this compositional relationship here, rather than deferring\nit to Related Work, because it is integral to the design: every layer\nof <span id=\"S3.SS3.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> (<a href=\"#S3.F1\" title=\"In 3.2 Protocol Suite Architecture ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Figure</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>) is defined in terms of how its\nprimitives bind to host-protocol messages, so understanding that binding\nis a prerequisite for understanding the protocol suite itself.\nThe Related Work section (§<a href=\"#S9\" title=\"9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">9</span></a>) serves a different\npurpose: it compares <span id=\"S3.SS3.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> against <em id=\"S3.SS3.p2.1.3\" class=\"ltx_emph ltx_font_italic\">security-oriented</em> architectures\nand trust frameworks—AgentMesh, AIP, HDP, ZT-IAM, AgentRFC, among\nothers—that share <span id=\"S3.SS3.p2.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s goal of adding trust to the agent ecosystem\nbut differ in mechanism. Those works are <span id=\"S3.SS3.p2.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s <em id=\"S3.SS3.p2.1.6\" class=\"ltx_emph ltx_font_italic\">comparators</em>;\nthe protocols below are its <em id=\"S3.SS3.p2.1.7\" class=\"ltx_emph ltx_font_italic\">substrates</em>.</p>\n</div>\n<div id=\"S3.SS3.p3\" class=\"ltx_para\">\n<p id=\"S3.SS3.p3.1\" class=\"ltx_p\"><a href=\"#S3.F1\" title=\"In 3.2 Protocol Suite Architecture ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Figure</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a> shows this substrate relationship concretely.\n<span id=\"S3.SS3.p3.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> operates alongside—not above or below—the host protocols, and\nthe two concerns compose naturally:</p>\n</div>\n<div id=\"S3.SS3.p4\" class=\"ltx_para\">\n<ul id=\"S3.I2\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S3.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S3.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"S3.I2.i1.p1.1\" class=\"ltx_p\">An MCP tool invocation carries the agent’s AIC capability boundary\n(from Layer 0), ensuring that the tool server can verify the caller is\nauthorized to invoke the requested tool before execution.</p>\n</div></li>\n<li id=\"S3.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S3.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"S3.I2.i2.p1.1\" class=\"ltx_p\">ANP’s DID-based discovery responses embed the agent’s manifest VCs\n(from Layer 1), enabling any peer resolving an agent’s DID to verify\nskill and tool claims via subject binding and permission alignment.</p>\n</div></li>\n<li id=\"S3.I2.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S3.I2.i3.p1\" class=\"ltx_para\">\n<p id=\"S3.I2.i3.p1.1\" class=\"ltx_p\">An A2A interaction carries a session token issued by <span id=\"S3.I2.i3.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s Layer 2\nafter mutual attestation and capability intersection, scoping the\nsession to the least-privilege boundary of both parties.</p>\n</div></li>\n<li id=\"S3.I2.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S3.I2.i4.p1\" class=\"ltx_para\">\n<p id=\"S3.I2.i4.p1.1\" class=\"ltx_p\">AG-UI events streamed to a frontend include identity-signed\nexecution traces (from Layer 3), allowing the UI to display verified\nprovenance and non-repudiable action history for each agent.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"S3.SS3.p5\" class=\"ltx_para\">\n<p id=\"S3.SS3.p5.1\" class=\"ltx_p\">This composability is a direct consequence of Principle P2: by avoiding\nassumptions about the underlying transport or application protocol, <span id=\"S3.SS3.p5.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> remains agnostic to the rapidly evolving agent communication landscape.</p>\n</div>\n</section>\n</section>\n<section id=\"S4\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">4  Layer 0: Persistent Agent Identity</h2>\n\n<div id=\"S4.p1\" class=\"ltx_para\"><span id=\"S4.p1.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S4.p1.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S4.p1.p1.1\" class=\"ltx_p\"><span id=\"S4.p1.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Key Insight 3: Design Thesis.</span>  \nWithout verified identity, every other security property is built on air.\nLayer 0 ensures that every agent in the <span id=\"S4.p1.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> ecosystem is a\n<em id=\"S4.p1.p1.1.3\" class=\"ltx_emph ltx_font_italic\">cryptographic principal</em>—unforgeable, verifiable, and bound to its\nprovenance.</span>\n</span></span>\n</div>\n<section id=\"S4.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">4.1  Agent Identity Card (AIC)</h3>\n\n<div id=\"S4.SS1.p1\" class=\"ltx_para\">\n<p id=\"S4.SS1.p1.1\" class=\"ltx_p\">The <em id=\"S4.SS1.p1.1.1\" class=\"ltx_emph ltx_font_italic\">Agent Identity Card</em> is the foundational credential in <span id=\"S4.SS1.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>. An\nAIC is a verifiable credential that binds an agent’s identity to its\npermission boundary. Formally:</p>\n<table id=\"S4.E1\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S4.E1.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}=\\mathsf{Sign}_{\\mathsf{GAR}}\\!\\bigl(\\mathsf{DID}_{\\mathsf{agent}}\\;\\|\\;K_{\\mathsf{pub}}\\;\\|\\;S_{\\max}\\bigr)\" display=\"block\" intent=\":literal\"><semantics><mrow><mi>𝖠𝖨𝖢</mi><mo>=</mo><mrow><msub><mi>𝖲𝗂𝗀𝗇</mi><mi>𝖦𝖠𝖱</mi></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"1.200em\" minsize=\"1.200em\">(</mo><mrow><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo rspace=\"0.280em\" stretchy=\"false\">‖</mo><msub><mi>K</mi><mi>𝗉𝗎𝖻</mi></msub><mo stretchy=\"false\">‖</mo></mrow><mo lspace=\"0.280em\" rspace=\"0em\">​</mo><msub><mi>S</mi><mi>max</mi></msub></mrow><mo maxsize=\"1.200em\" minsize=\"1.200em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\mathsf{AIC}=\\mathsf{Sign}_{\\mathsf{GAR}}\\!\\bigl(\\mathsf{DID}_{\\mathsf{agent}}\\;\\|\\;K_{\\mathsf{pub}}\\;\\|\\;S_{\\max}\\bigr)</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(1)</span></td></tr></tbody>\n</table>\n<p id=\"S4.SS1.p1.2\" class=\"ltx_p\">where <math id=\"S4.SS1.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math> is a structured agent identifier derived from the\n<math id=\"S4.SS1.p1.m2\" class=\"ltx_Math\" alttext=\"\\langle\\textit{developer},\\allowbreak\\;\\textit{code\\_pkg},\\allowbreak\\;\\textit{deploy\\_ctx}\\rangle\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">⟨</mo><mrow><mtext class=\"ltx_mathvariant_italic\">developer</mtext><mo rspace=\"0.447em\">,</mo><mtext class=\"ltx_mathvariant_italic\">code_pkg</mtext><mo rspace=\"0.447em\">,</mo><mtext class=\"ltx_mathvariant_italic\">deploy_ctx</mtext></mrow><mo stretchy=\"false\">⟩</mo></mrow><annotation encoding=\"application/x-tex\">\\langle\\textit{developer},\\allowbreak\\;\\textit{code\\_pkg},\\allowbreak\\;\\textit{deploy\\_ctx}\\rangle</annotation></semantics></math> triple,\n<math id=\"S4.SS1.p1.m3\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗎𝖻</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}</annotation></semantics></math> is the agent’s Ed25519 public key (whose corresponding private key\n<math id=\"S4.SS1.p1.m4\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> never leaves the isolated trust boundary), and <math id=\"S4.SS1.p1.m5\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math> is the\n<em id=\"S4.SS1.p1.2.1\" class=\"ltx_emph ltx_font_italic\">capability boundary</em>—the maximum set of permissions this agent may\never exercise.</p>\n</div>\n<div id=\"S4.SS1.p2\" class=\"ltx_para\">\n<p id=\"S4.SS1.p2.1\" class=\"ltx_p\">The AIC is signed by the Global Agent Registry (GAR) using its root\nEd25519 key, analogous to a Certificate Authority signing an X.509\ncertificate. However, unlike X.509, the AIC natively encodes agent-specific\nsemantics: capability sets, delegation depth, identity assurance levels, and\noperational context.</p>\n</div>\n</section>\n<section id=\"S4.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">4.2  Four-Dimensional Identity Binding</h3>\n\n<div id=\"S4.SS2.p1\" class=\"ltx_para\">\n<p id=\"S4.SS2.p1.1\" class=\"ltx_p\">A persistent agent identity must answer four questions simultaneously:\n<em id=\"S4.SS2.p1.1.1\" class=\"ltx_emph ltx_font_italic\">who built it</em>, <em id=\"S4.SS2.p1.1.2\" class=\"ltx_emph ltx_font_italic\">what code does it run</em>, <em id=\"S4.SS2.p1.1.3\" class=\"ltx_emph ltx_font_italic\">who deployed it</em>,\nand <em id=\"S4.SS2.p1.1.4\" class=\"ltx_emph ltx_font_italic\">in what context does it operate</em>. <span id=\"S4.SS2.p1.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> binds all four into the AIC\nthrough what we call <em id=\"S4.SS2.p1.1.6\" class=\"ltx_emph ltx_font_italic\">four-dimensional identity binding</em>.</p>\n</div>\n<figure id=\"S4.F2\" class=\"ltx_figure\"><span class=\"ltx_inline-block\"><svg id=\"S4.F2.pic1\" class=\"ltx_picture ltx_centering\" height=\"335.61\" overflow=\"visible\" version=\"1.1\" viewBox=\"0 0 518.38 335.61\" width=\"518.38\"><g transform=\"translate(0,335.61) matrix(1 0 0 -1 0 0) translate(258.45,0) translate(0,201.48)\"><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#F4F7F9;\" fill=\"#F4F7F9\" stroke=\"#1B5E8C\" stroke-width=\"1.2pt\"><path d=\"M 96.76 43.31 L -96.76 43.31 C -101.35 43.31 -105.06 39.59 -105.06 35 L -105.06 -35 C -105.06 -39.59 -101.35 -43.31 -96.76 -43.31 L 96.76 -43.31 C 101.35 -43.31 105.06 -39.59 105.06 -35 L 105.06 35 C 105.06 39.59 101.35 43.31 96.76 43.31 Z M -105.06 -43.31\"></path></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" stroke-width=\"1.2pt\" transform=\"matrix(1.0 0.0 0.0 1.0 -100.45 -13.84)\"><g style=\"--ltx-fg-color:#1B5E8C;\" class=\"ltx_tikzmatrix\" color=\"#1B5E8C\" transform=\"matrix(1 0 0 -1 0 35.98)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 10.38)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 16.67 0)\"><foreignObject style=\"--ltx-fo-width:11.06em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.23em;font-size:11pt;\" height=\"13.84\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 10.38)\" width=\"168.41\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Agent Identity Card (AIC)</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 31.82)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:14.52em;--ltx-fo-height:0.9em;--ltx-fo-depth:0.3em;font-size:10pt;\" height=\"16.6\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 12.45)\" width=\"200.9\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S4.F2.pic1.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{Sign}_{\\mathsf{GAR}}\\!\\bigl(\\mathsf{DID}_{\\mathsf{agent}}\\;\\|\\;K_{\\mathsf{pub}}\\;\\|\\;S_{\\max}\\bigr)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>𝖲𝗂𝗀𝗇</mi><mi>𝖦𝖠𝖱</mi></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"1.200em\" minsize=\"1.200em\">(</mo><mrow><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo rspace=\"0.280em\" stretchy=\"false\">‖</mo><msub><mi>K</mi><mi>𝗉𝗎𝖻</mi></msub><mo stretchy=\"false\">‖</mo></mrow><mo lspace=\"0.280em\" rspace=\"0em\">​</mo><msub><mi>S</mi><mi>max</mi></msub></mrow><mo maxsize=\"1.200em\" minsize=\"1.200em\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\mathsf{Sign}_{\\mathsf{GAR}}\\!\\bigl(\\mathsf{DID}_{\\mathsf{agent}}\\;\\|\\;K_{\\mathsf{pub}}\\;\\|\\;S_{\\max}\\bigr)</annotation></semantics></math><span id=\"S4.F2.pic1.2\" class=\"ltx_text ltx_font_sansserif\">\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\"><g stroke-width=\"0.4pt\"><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#EDF2F6;\" fill=\"#EDF2F6\" stroke=\"#BDC3C7\"><path d=\"M -141.71 133.86 L -251.99 133.86 C -254.28 133.86 -256.14 132 -256.14 129.71 L -256.14 67.14 C -256.14 64.85 -254.28 62.99 -251.99 62.99 L -141.71 62.99 C -139.42 62.99 -137.56 64.85 -137.56 67.14 L -137.56 129.71 C -137.56 132 -139.42 133.86 -141.71 133.86 Z M -256.14 62.99\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -251.53 82.61)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 31.63)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 24.91)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 1.99 0)\"><foreignObject style=\"--ltx-fo-width:7.69em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"105.37\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.3\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Developer Identity</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:8.57em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"109.71\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.4\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Ed25519 signing key</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 31.64)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 7.16 0)\"><foreignObject style=\"--ltx-fo-width:9.81em;--ltx-fo-height:0.69em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.73\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"95.03\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.5\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">controlled at build time</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#EEF5F9;\" fill=\"#EEF5F9\" stroke=\"#BDC3C7\"><path d=\"M 251.75 133.86 L 141.95 133.86 C 139.65 133.86 137.8 132 137.8 129.71 L 137.8 67.14 C 137.8 64.85 139.65 62.99 141.95 62.99 L 251.75 62.99 C 254.05 62.99 255.91 64.85 255.91 67.14 L 255.91 129.71 C 255.91 132 254.05 133.86 251.75 133.86 Z M 137.8 62.99\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 154.99 83.55)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 33.51)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 24.91)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 1.43 0)\"><foreignObject style=\"--ltx-fo-width:5.93em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"81.26\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.6\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Code Package</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:6.54em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"83.73\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.7\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">SHA-256 digest</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 31.64)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 1.43 0)\"><foreignObject style=\"--ltx-fo-width:8.35em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"80.88\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.8\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">set by build pipeline</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#EEF9F2;\" fill=\"#EEF9F2\" stroke=\"#BDC3C7\"><path d=\"M -139.68 -62.99 L -254.02 -62.99 C -256.32 -62.99 -258.17 -64.85 -258.17 -67.14 L -258.17 -129.71 C -258.17 -132 -256.32 -133.86 -254.02 -133.86 L -139.68 -133.86 C -137.39 -133.86 -135.53 -132 -135.53 -129.71 L -135.53 -67.14 C -135.53 -64.85 -137.39 -62.99 -139.68 -62.99 Z M -258.17 -133.86\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -253.56 -112.09)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 31.09)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 22.49)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 7.18 0)\"><foreignObject style=\"--ltx-fo-width:7.26em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"99.44\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.9\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Operator Identity</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:8.86em;--ltx-fo-height:0.68em;--ltx-fo-depth:0em;font-size:9.25pt;\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"113.43\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.10\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">OIDC-verified human</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 29.22)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 12.99 0)\"><foreignObject style=\"--ltx-fo-width:9.03em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"87.44\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.11\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">bound at provisioning</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#FDF5ED;\" fill=\"#FDF5ED\" stroke=\"#BDC3C7\"><path d=\"M 255.5 -62.99 L 138.2 -62.99 C 135.9 -62.99 134.05 -64.85 134.05 -67.14 L 134.05 -129.71 C 134.05 -132 135.9 -133.86 138.2 -133.86 L 255.5 -133.86 C 257.8 -133.86 259.66 -132 259.66 -129.71 L 259.66 -67.14 C 259.66 -64.85 257.8 -62.99 255.5 -62.99 Z M 134.05 -133.86\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 138.66 -112.88)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 32.67)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 24.07)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:8.47em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"116.01\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.12\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Operational Context</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 22.49)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 2.74 0)\"><foreignObject style=\"--ltx-fo-width:8.75em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.12em;font-size:9.25pt;\" height=\"10.22\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"111.97\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.13\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Tenant, environment</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 30.79)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 27.6 0)\"><foreignObject style=\"--ltx-fo-width:6.37em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"61.72\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.14\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">set by platform</span></span></span></foreignObject></g></g></g></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" stroke-width=\"0.8pt\"><path style=\"fill:none\" d=\"M -137.28 62.72 L -109.74 46.41\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(0.86058 -0.50931 0.50931 0.86058 -111.85 47.66)\"><path d=\"M 5.44 0 L 1.79 1.35 L 2.73 0 L 1.79 -1.35 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" stroke-width=\"0.8pt\"><path style=\"fill:none\" d=\"M 137.52 62.72 L 109.74 46.4\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(-0.86224 -0.50652 0.50652 -0.86224 111.86 47.64)\"><path d=\"M 5.44 0 L 1.79 1.35 L 2.73 0 L 1.79 -1.35 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" stroke-width=\"0.8pt\"><path style=\"fill:none\" d=\"M -135.25 -62.72 L -109.67 -46.53\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(0.84502 0.53474 -0.53474 0.84502 -111.74 -47.84)\"><path d=\"M 5.44 0 L 1.79 1.35 L 2.73 0 L 1.79 -1.35 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" stroke-width=\"0.8pt\"><path style=\"fill:none\" d=\"M 133.77 -62.72 L 109.61 -46.61\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(-0.83212 0.5546 -0.5546 -0.83212 111.65 -47.97)\"><path d=\"M 5.44 0 L 1.79 1.35 L 2.73 0 L 1.79 -1.35 Z\"></path></g></g><g style=\"--ltx-stroke-color:#8E44AD;--ltx-fill-color:#F6F0F8;\" fill=\"#F6F0F8\" stroke=\"#8E44AD\" stroke-width=\"1.0pt\"><path d=\"M 64.57 -153.54 L -64.57 -153.54 C -67.63 -153.54 -70.11 -156.02 -70.11 -159.08 L -70.11 -195.25 C -70.11 -198.31 -67.63 -200.79 -64.57 -200.79 L 64.57 -200.79 C 67.63 -200.79 70.11 -198.31 70.11 -195.25 L 70.11 -159.08 C 70.11 -156.02 67.63 -153.54 64.57 -153.54 Z M -70.11 -200.79\"></path></g><g style=\"--ltx-stroke-color:#8E44AD;--ltx-fill-color:#8E44AD;\" fill=\"#8E44AD\" stroke=\"#8E44AD\" stroke-width=\"1.0pt\" transform=\"matrix(1.0 0.0 0.0 1.0 -65.5 -185.81)\"><g style=\"--ltx-fg-color:#8E44AD;\" class=\"ltx_tikzmatrix\" color=\"#8E44AD\" transform=\"matrix(1 0 0 -1 0 22.14)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 2.66 0)\"><foreignObject style=\"--ltx-fo-width:9.17em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"125.67\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.15\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Global Agent Registry</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 19.72)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:10.23em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"130.99\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S4.F2.pic1.16\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">signs with GAR root key</span></span></span></foreignObject></g></g></g></g><g stroke-width=\"0.8pt\"><g style=\"--ltx-stroke-color:#8E44AD;--ltx-fill-color:#8E44AD;--ltx-fg-color:#8E44AD;\" color=\"#8E44AD\" fill=\"#8E44AD\" stroke=\"#8E44AD\"><path style=\"fill:none\" d=\"M 0 -152.85 L 0 -48.6\"></path></g><g style=\"--ltx-stroke-color:#8E44AD;--ltx-fill-color:#8E44AD;--ltx-fg-color:#8E44AD;\" color=\"#8E44AD\" fill=\"#8E44AD\" stroke=\"#8E44AD\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(0.0 1.0 -1.0 0.0 0 -51.06)\"><path d=\"M 5.44 0 L 1.79 1.35 L 2.73 0 L 1.79 -1.35 Z\"></path></g><g style=\"--ltx-stroke-color:#808080;--ltx-fill-color:#808080;\" fill=\"#808080\" stroke=\"#808080\" transform=\"matrix(1.0 0.0 0.0 1.0 9.32 -100.92)\"><foreignObject style=\"--ltx-fo-width:2.79em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.17em;font-size:8.19pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"31.65\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S4.F2.pic1.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{Sign}_{\\mathsf{GAR}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#808080;\" mathcolor=\"#808080\" mathsize=\"0.700em\">𝖲𝗂𝗀𝗇</mi><mi style=\"--ltx-fg-color:#808080;\" mathcolor=\"#808080\" mathsize=\"0.700em\">𝖦𝖠𝖱</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{Sign}_{\\mathsf{GAR}}</annotation></semantics></math></span></span></foreignObject></g></g></g></g></svg></span>\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\"><span id=\"S4.F2.3\" class=\"ltx_text\" style=\"font-size:90%;\">Figure 2</span>: </span><span id=\"S4.F2.4\" class=\"ltx_text\" style=\"font-size:90%;\">Four-dimensional identity binding in the Agent Identity Card. Each\ndimension is controlled by a different party and verified independently.</span></figcaption>\n</figure>\n<figure id=\"S4.T2\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\"><span id=\"S4.T2.3\" class=\"ltx_text\" style=\"font-size:90%;\">Table 2</span>: </span><span id=\"S4.T2.4\" class=\"ltx_text\" style=\"font-size:90%;\">The four identity dimensions of an AIC.</span></figcaption>\n<table id=\"S4.T2.5\" class=\"ltx_tabular ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S4.T2.5.1\" class=\"ltx_tr\">\n<th id=\"S4.T2.5.1.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_th_row ltx_border_tt\"><span id=\"S4.T2.5.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Dimension</span></th>\n<th id=\"S4.T2.5.1.2\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S4.T2.5.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.1.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">What It Binds</span></span>\n</span></th>\n<th id=\"S4.T2.5.1.3\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S4.T2.5.1.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.1.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Who Controls</span></span>\n</span></th>\n<th id=\"S4.T2.5.1.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S4.T2.5.1.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.1.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.1.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Verification</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S4.T2.5.2\" class=\"ltx_tr\">\n<th id=\"S4.T2.5.2.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\" style=\"padding-bottom: 3.0pt;\"><span id=\"S4.T2.5.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Developer Identity</span></th>\n<td id=\"S4.T2.5.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.2.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Developer’s Ed25519 signing key</span></span>\n</span></td>\n<td id=\"S4.T2.5.2.3\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.2.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.2.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Developer (build time)</span></span>\n</span></td>\n<td id=\"S4.T2.5.2.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_t\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.2.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.2.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.2.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">GAR verifies developer enrollment</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.5.3\" class=\"ltx_tr\">\n<th id=\"S4.T2.5.3.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\" style=\"padding-bottom: 3.0pt;\"><span id=\"S4.T2.5.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Code Package</span></th>\n<td id=\"S4.T2.5.3.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.3.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Cryptographic digest of the agent’s code or container image</span></span>\n</span></td>\n<td id=\"S4.T2.5.3.3\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.3.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.3.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Build pipeline</span></span>\n</span></td>\n<td id=\"S4.T2.5.3.4\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.3.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.3.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.3.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">GAR checks code hash at issuance</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.5.4\" class=\"ltx_tr\">\n<th id=\"S4.T2.5.4.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\" style=\"padding-bottom: 3.0pt;\"><span id=\"S4.T2.5.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Operator Identity</span></th>\n<td id=\"S4.T2.5.4.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.4.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">OIDC-verified human operator (e.g., via Google, GitHub SSO)</span></span>\n</span></td>\n<td id=\"S4.T2.5.4.3\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.4.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.4.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Human operator (provisioning)</span></span>\n</span></td>\n<td id=\"S4.T2.5.4.4\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 3.0pt;\">\n<span id=\"S4.T2.5.4.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.4.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.4.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">GAR binds OIDC token to AIC</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.5.5\" class=\"ltx_tr\">\n<th id=\"S4.T2.5.5.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_bb\"><span id=\"S4.T2.5.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Operational Context</span></th>\n<td id=\"S4.T2.5.5.2\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S4.T2.5.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.5.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Tenant ID, deployment environment, region</span></span>\n</span></td>\n<td id=\"S4.T2.5.5.3\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S4.T2.5.5.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.5.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Platform operator</span></span>\n</span></td>\n<td id=\"S4.T2.5.5.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_bb\">\n<span id=\"S4.T2.5.5.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T2.5.5.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S4.T2.5.5.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">GAR records at issuance; inherited by delegates</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S4.SS2.p2\" class=\"ltx_para\">\n<p id=\"S4.SS2.p2.1\" class=\"ltx_p\">This four-dimensional binding addresses threat T1 (identity spoofing) from\n<a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>: an attacker cannot forge an AIC without simultaneously\ncontrolling the developer’s signing key, producing a matching code digest,\npresenting valid OIDC credentials, and registering with the correct\noperational context.</p>\n</div>\n<div id=\"S4.SS2.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S4.SS2.p3.1\" class=\"ltx_p\"><span id=\"S4.SS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Contrast with existing approaches.</span> \nDID-based identity <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib24\" title=\"\" class=\"ltx_ref\">43</a>, <a href=\"#bib.bib34\" title=\"\" class=\"ltx_ref\">26</a>]</cite> binds a public\nkey to a decentralized identifier but does not natively encode developer,\ncode, or operator dimensions. SPIFFE <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">40</a>]</cite> provides workload\nidentity attestation via platform-specific mechanisms but does not model\ncapability boundaries or delegation semantics. The AIP\nprotocol <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite> introduces Invocation-Bound Capability Tokens\nwithout separating developer and operator dimensions in the credential model. <span id=\"S4.SS2.p3.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s four-dimensional binding provides richer provenance than\nworkload-centric models such as SPIFFE/SVID (used by\nAgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite>) and, among the identity proposals surveyed in\n§<a href=\"#S9\" title=\"9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">9</span></a>, is the only one we found that jointly binds developer,\ncode, operator, and operational context within a single verifiable credential.</p>\n</div>\n</section>\n<section id=\"S4.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">4.3  Global Agent Registry (GAR)</h3>\n\n<div id=\"S4.SS3.p1\" class=\"ltx_para\">\n<p id=\"S4.SS3.p1.1\" class=\"ltx_p\">The GAR serves as the trust anchor for the <span id=\"S4.SS3.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> ecosystem, playing a role\nanalogous to a Certificate Authority in traditional PKI. Its responsibilities\ninclude:</p>\n</div>\n<div id=\"S4.SS3.p2\" class=\"ltx_para\">\n<ol id=\"S4.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S4.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S4.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Developer enrollment:</span> onboarding developers with verified\nsigning keys and policy governance.</p>\n</div></li>\n<li id=\"S4.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S4.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">AIC issuance:</span> validating that the requested capability\nboundary <math id=\"S4.I1.i2.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math> is a subset of the developer’s declared maximum,\nverifying the developer signature, binding the OIDC operator identity,\nand signing the AIC with the GAR root key.</p>\n</div></li>\n<li id=\"S4.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S4.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">AIC lookup and verification:</span> enabling any party to resolve\nan agent’s AIC by identifier and verify its signature chain.</p>\n</div></li>\n<li id=\"S4.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S4.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Revocation:</span> maintaining a revocation registry; revoking an\nAIC atomically invalidates it and all its delegated descendants\n(cascading revocation, detailed in §<a href=\"#S6.SS2\" title=\"6.2 AIC Delegation Chain ‣ 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6.2</span></a>).</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S4.SS3.p3\" class=\"ltx_para\">\n<p id=\"S4.SS3.p3.1\" class=\"ltx_p\">The GAR can be deployed as a centralized service (suitable for enterprise\nenvironments), a federated constellation (analogous to federated CAs), or\nbacked by a distributed ledger for environments that require decentralized\ntrust anchoring. This flexibility is a direct consequence of Principle P3.</p>\n</div>\n</section>\n<section id=\"S4.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">4.4  Key Protection Tiers</h3>\n\n<div id=\"S4.SS4.p1\" class=\"ltx_para\">\n<p id=\"S4.SS4.p1.1\" class=\"ltx_p\">The agent’s private key <math id=\"S4.SS4.p1.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> is the root of its cryptographic identity.\n<span id=\"S4.SS4.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> defines three protection tiers, allowing deployments to choose the\nappropriate security-cost trade-off:</p>\n</div>\n<figure id=\"S4.T3\" class=\"ltx_table\">\n<table id=\"S4.T3.3\" class=\"ltx_tabular ltx_centering ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S4.T3.3.1\" class=\"ltx_tr\">\n<th id=\"S4.T3.3.1.1\" class=\"ltx_td ltx_align_center ltx_th ltx_th_column ltx_border_tt\"><span id=\"S4.T3.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Tier</span></th>\n<th id=\"S4.T3.3.1.2\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\"><span id=\"S4.T3.3.1.2.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Mechanism</span></th>\n<th id=\"S4.T3.3.1.3\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S4.T3.3.1.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T3.3.1.3.1.1\" class=\"ltx_p\"><span id=\"S4.T3.3.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Security Level</span></span>\n</span></th>\n<th id=\"S4.T3.3.1.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_th ltx_th_column ltx_border_tt\"><span id=\"S4.T3.3.1.4.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Deployment</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S4.T3.3.2\" class=\"ltx_tr\">\n<td id=\"S4.T3.3.2.1\" class=\"ltx_td ltx_align_center ltx_border_t\"><span id=\"S4.T3.3.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">1</span></td>\n<td id=\"S4.T3.3.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S4.T3.3.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">OS file isolation (<span id=\"S4.T3.3.2.2.1.1\" class=\"ltx_text ltx_font_typewriter\">0o600</span>)</span></td>\n<td id=\"S4.T3.3.2.3\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S4.T3.3.2.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T3.3.2.3.1.1\" class=\"ltx_p\"><span id=\"S4.T3.3.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Moderate</span></span>\n</span></td>\n<td id=\"S4.T3.3.2.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_t\"><span id=\"S4.T3.3.2.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">Dev / testing</span></td></tr>\n<tr id=\"S4.T3.3.3\" class=\"ltx_tr\">\n<td id=\"S4.T3.3.3.1\" class=\"ltx_td ltx_align_center\"><span id=\"S4.T3.3.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">2</span></td>\n<td id=\"S4.T3.3.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S4.T3.3.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">OS keychain (Keychain, DPAPI)</span></td>\n<td id=\"S4.T3.3.3.3\" class=\"ltx_td ltx_align_left\">\n<span id=\"S4.T3.3.3.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T3.3.3.3.1.1\" class=\"ltx_p\"><span id=\"S4.T3.3.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Good (HW-backed)</span></span>\n</span></td>\n<td id=\"S4.T3.3.3.4\" class=\"ltx_td ltx_nopad_r ltx_align_left\"><span id=\"S4.T3.3.3.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">Production</span></td></tr>\n<tr id=\"S4.T3.3.4\" class=\"ltx_tr\">\n<td id=\"S4.T3.3.4.1\" class=\"ltx_td ltx_align_center ltx_border_bb\"><span id=\"S4.T3.3.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">3</span></td>\n<td id=\"S4.T3.3.4.2\" class=\"ltx_td ltx_align_left ltx_border_bb\"><span id=\"S4.T3.3.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">TEE enclave (SGX, Nitro)</span></td>\n<td id=\"S4.T3.3.4.3\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S4.T3.3.4.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T3.3.4.3.1.1\" class=\"ltx_p\"><span id=\"S4.T3.3.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Strong (key never leaves HW)</span></span>\n</span></td>\n<td id=\"S4.T3.3.4.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_bb\"><span id=\"S4.T3.3.4.4.1\" class=\"ltx_text\" style=\"font-size:90%;\">High-assurance</span></td></tr>\n</tbody>\n</table>\n<figcaption class=\"ltx_caption ltx_centering\" style=\"font-size:90%;\"><span class=\"ltx_tag ltx_tag_table\">Table 3: </span>Key protection tiers. <math id=\"S4.T3.m2\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> never leaves the local trust boundary regardless of tier.</figcaption>\n</figure>\n<div id=\"S4.SS4.p2\" class=\"ltx_para\">\n<p id=\"S4.SS4.p2.1\" class=\"ltx_p\">Regardless of the tier, a fundamental invariant holds: <math id=\"S4.SS4.p2.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> <em id=\"S4.SS4.p2.1.1\" class=\"ltx_emph ltx_font_italic\">never\nleaves the isolated trust boundary</em>. All signing operations are mediated by the\nagent’s designated kernel, which acts as an HSM-like custodian. External agents and\neven the agent’s own application logic interact only with opaque\n<em id=\"S4.SS4.p2.1.2\" class=\"ltx_emph ltx_font_italic\">handles</em>—they can request signatures but never access the raw key\nmaterial.</p>\n</div>\n</section>\n<section id=\"S4.SS5\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">4.5  Identity Lifecycle</h3>\n\n<div id=\"S4.SS5.p1\" class=\"ltx_para\">\n<p id=\"S4.SS5.p1.1\" class=\"ltx_p\">An AIC progresses through a well-defined lifecycle:</p>\n</div>\n<div id=\"S4.SS5.p2\" class=\"ltx_para\">\n<ol id=\"S4.I2\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S4.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S4.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"S4.I2.i1.p1.1\" class=\"ltx_p\"><span id=\"S4.I2.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Provisioning:</span> The operator submits a registration request\n(agent ID, capabilities, OIDC token) to the kernel. The kernel generates\na fresh Ed25519 keypair, constructs the AIC payload, and forwards it to\nthe GAR for signing. The signed AIC is returned and cached locally.</p>\n</div></li>\n<li id=\"S4.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S4.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"S4.I2.i2.p1.1\" class=\"ltx_p\"><span id=\"S4.I2.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Active use:</span> The AIC is used for mutual attestation\n(§<a href=\"#S6\" title=\"6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6</span></a>), session token issuance, and delegation.</p>\n</div></li>\n<li id=\"S4.I2.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S4.I2.i3.p1\" class=\"ltx_para\">\n<p id=\"S4.I2.i3.p1.1\" class=\"ltx_p\"><span id=\"S4.I2.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Rotation:</span> Key rotation generates a new keypair, revokes the\nold AIC, and issues a replacement preserving all identity dimensions.\nActive sessions are invalidated to prevent stale credential use.</p>\n</div></li>\n<li id=\"S4.I2.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S4.I2.i4.p1\" class=\"ltx_para\">\n<p id=\"S4.I2.i4.p1.1\" class=\"ltx_p\"><span id=\"S4.I2.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Revocation:</span> An AIC can be revoked by the operator, the GAR\nadministrator, or automatically upon expiration. Revocation cascades to\nall delegated descendants (§<a href=\"#S6.SS2\" title=\"6.2 AIC Delegation Chain ‣ 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6.2</span></a>), ensuring that\nrevoking a parent instantly invalidates the entire subtree.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S4.SS5.p3\" class=\"ltx_para\">\n<p id=\"S4.SS5.p3.1\" class=\"ltx_p\">The lifecycle is designed so that identity is <em id=\"S4.SS5.p3.1.1\" class=\"ltx_emph ltx_font_italic\">persistent</em> (the agent’s\nidentity dimensions survive key rotation) while credentials are\n<em id=\"S4.SS5.p3.1.2\" class=\"ltx_emph ltx_font_italic\">ephemeral</em> (AICs have bounded validity and can be revoked at any time).\nThis distinction is crucial for long-lived agents that operate across\nsessions and deployments.</p>\n</div>\n</section>\n</section>\n<section id=\"S5\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">5  Layer 1: Registration, Discovery &amp; Semantic Interoperability</h2>\n\n<div id=\"S5.p1\" class=\"ltx_para\">\n<p id=\"S5.p1.1\" class=\"ltx_p\">Layer 0 establishes <em id=\"S5.p1.1.1\" class=\"ltx_emph ltx_font_italic\">who an agent is</em>; Layer 1 establishes <em id=\"S5.p1.1.2\" class=\"ltx_emph ltx_font_italic\">what\nan agent can do and how to find it</em>. This layer bridges identity to\ninteraction by providing the infrastructure for agents to advertise their\ncapabilities, discover peers, and cryptographically verify the authenticity\nof advertised skills before any trust negotiation begins.</p>\n</div>\n<div id=\"S5.p2\" class=\"ltx_para\">\n<p id=\"S5.p2.1\" class=\"ltx_p\">The central insight of Layer 1 is that discovery must be a <em id=\"S5.p2.1.1\" class=\"ltx_emph ltx_font_italic\">security\nprimitive</em>: every capability claim an agent advertises is backed by a signed\nVerifiable Credential (VC) bound to the agent’s DID and verifiable against\nthe AIC trust chain. This transforms agent discovery from a directory\nlookup into a trust-establishing protocol step.</p>\n</div>\n<section id=\"S5.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">5.1  Capability-Aware Registration</h3>\n\n<div id=\"S5.SS1.p1\" class=\"ltx_para\">\n<p id=\"S5.SS1.p1.1\" class=\"ltx_p\">When an agent is provisioned (Layer 0), its AIC already contains a capability\nboundary <math id=\"S5.SS1.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math>. Layer 1 extends this with a richer <em id=\"S5.SS1.p1.1.1\" class=\"ltx_emph ltx_font_italic\">registration\nrecord</em> that the agent publishes to the GAR or a federated discovery service:</p>\n</div>\n<div id=\"S5.SS1.p2\" class=\"ltx_para\"><span id=\"S5.SS1.p2.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S5.SS1.p2.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S5.SS1.p2.p1.1\" class=\"ltx_p\"><span id=\"S5.SS1.p2.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Registration Record</span></span>\n</span>\n<span id=\"S5.SS1.p2.p2\" class=\"ltx_para\">\n<span id=\"S5.SS1.p2.p2.1\" class=\"ltx_tabular ltx_tabbing\">\n<span id=\"S5.SS1.p2.p2.1.1\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.1.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">agent_id<span id=\"S5.SS1.p2.p2.1.1.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.1.2\" class=\"ltx_td ltx_align_left\"><math id=\"S5.SS1.p2.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖣𝖨𝖣</mi><mi mathsize=\"0.900em\">𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math><span id=\"S5.SS1.p2.p2.1.1.2.1\" class=\"ltx_text\" style=\"font-size:90%;\"> from the AIC</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.2\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.2.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">aic_ref<span id=\"S5.SS1.p2.p2.1.2.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.2.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">reference to the signed AIC</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.3\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.3.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">capabilities<span id=\"S5.SS1.p2.p2.1.3.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">structured list from the capability vocabulary</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.4\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.4.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">semantic_tags<span id=\"S5.SS1.p2.p2.1.4.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.4.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">tags for capability-aware search</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.5\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.5.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">endpoints<span id=\"S5.SS1.p2.p2.1.5.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.5.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.5.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">transport endpoints (HTTP, gRPC, WebSocket)</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.6\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.6.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">protocols<span id=\"S5.SS1.p2.p2.1.6.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.6.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.6.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">supported protocols (A2A, MCP, ANP)</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.7\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.7.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.7.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">manifests<span id=\"S5.SS1.p2.p2.1.7.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.7.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.7.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">list of signed skill/tool manifest VCs</span></span></span>\n<span id=\"S5.SS1.p2.p2.1.8\" class=\"ltx_tr\">\n<span id=\"S5.SS1.p2.p2.1.8.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.8.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">metadata<span id=\"S5.SS1.p2.p2.1.8.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS1.p2.p2.1.8.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS1.p2.p2.1.8.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">description, version, pricing hints</span></span></span>\n</span>\n</span></span>\n</div>\n<div id=\"S5.SS1.p3\" class=\"ltx_para\">\n<p id=\"S5.SS1.p3.1\" class=\"ltx_p\">The registration record is itself signed by the agent’s <math id=\"S5.SS1.p3.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> (via the\nkernel), ensuring that only the agent can create or update its own record.\nThe GAR or discovery service verifies this signature against the AIC’s\n<math id=\"S5.SS1.p3.m2\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗎𝖻</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}</annotation></semantics></math> before accepting the registration.</p>\n</div>\n</section>\n<section id=\"S5.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">5.2  Semantic Capability Tagging</h3>\n\n<div id=\"S5.SS2.p1\" class=\"ltx_para\">\n<p id=\"S5.SS2.p1.1\" class=\"ltx_p\">Raw capability enumerations (e.g., <span id=\"S5.SS2.p1.1.1\" class=\"ltx_text ltx_font_typewriter\">fs.read</span>, <span id=\"S5.SS2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">network.fetch</span>)\ndescribe what system surfaces an agent can touch but not the <em id=\"S5.SS2.p1.1.3\" class=\"ltx_emph ltx_font_italic\">semantic\ndomain</em> of the agent’s expertise. <span id=\"S5.SS2.p1.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> introduces a two-level tagging scheme:</p>\n</div>\n<div id=\"S5.SS2.p2\" class=\"ltx_para\">\n<ol id=\"S5.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S5.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S5.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S5.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">System capabilities</span> (from Layer 0): a closed vocabulary of\npermission classes bound to the AIC. These are machine-enforced at\nruntime.</p>\n</div></li>\n<li id=\"S5.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S5.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S5.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Semantic tags</span> (from Layer 1): an open vocabulary of\ndomain-specific labels (e.g., <span id=\"S5.I1.i2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">legal-review</span>,\n<span id=\"S5.I1.i2.p1.1.3\" class=\"ltx_text ltx_font_typewriter\">code-generation</span>, <span id=\"S5.I1.i2.p1.1.4\" class=\"ltx_text ltx_font_typewriter\">financial-analysis</span>) that describe the\nagent’s expertise at a human-understandable and LLM-parseable level.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S5.SS2.p3\" class=\"ltx_para\">\n<p id=\"S5.SS2.p3.1\" class=\"ltx_p\">Semantic tags are <em id=\"S5.SS2.p3.1.1\" class=\"ltx_emph ltx_font_italic\">not</em> capability grants—they carry no enforcement\nweight. Their purpose is to enable capability-aware discovery: a requester\nsearching for a “code review” agent can filter candidates by semantic tag,\nthen verify actual capabilities via the AIC and manifest VCs before\nLayer 2 negotiation.\nThis separation prevents semantic labels from being abused as implicit\npermission escalation vectors.</p>\n</div>\n</section>\n<section id=\"S5.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">5.3  Capability-Aware Discovery</h3>\n\n<div id=\"S5.SS3.p1\" class=\"ltx_para\">\n<p id=\"S5.SS3.p1.1\" class=\"ltx_p\"><span id=\"S5.SS3.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> treats discovery as a security primitive rather than a directory lookup.\nA discovery response is only useful if the requester can verify not just that\nan agent claims a skill or tool, but that the advertised capability is backed by a\nsigned manifest VC and fits within the agent’s AIC capability boundary. This\nturns Layer 1 into <em id=\"S5.SS3.p1.1.2\" class=\"ltx_emph ltx_font_italic\">capability-aware discovery</em>: semantic search narrows\nthe candidate set, while DID-bound manifest VCs and AIC-bound capabilities\nmake the result safe to consume during Layer 2 negotiation.</p>\n</div>\n<div id=\"S5.SS3.p2\" class=\"ltx_para\">\n<p id=\"S5.SS3.p2.1\" class=\"ltx_p\"><span id=\"S5.SS3.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> supports two discovery modes that can coexist within the same ecosystem:</p>\n</div>\n<div id=\"S5.SS3.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS3.p3.1\" class=\"ltx_p\"><span id=\"S5.SS3.p3.1.1\" class=\"ltx_text ltx_font_bold\">Registry-mediated discovery.</span> \nAgents query the GAR (or a federated registry constellation) with structured\nqueries over capabilities, semantic tags, protocol support, and trust\nattributes (e.g., minimum identity assurance level, trusted developer list).\nThe registry returns matching registration records, each verifiable against\nthe corresponding AIC. This mode is analogous to DNS resolution and is\nsuitable for enterprise and platform-managed environments.</p>\n</div>\n<div id=\"S5.SS3.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS3.p4.1\" class=\"ltx_p\"><span id=\"S5.SS3.p4.1.1\" class=\"ltx_text ltx_font_bold\">Peer-to-peer discovery.</span> \nIn decentralized environments, agents can discover peers via protocol-native\nmechanisms (e.g., ANP’s DID-based discovery <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">8</a>]</cite>, A2A’s\nwell-known Agent Cards <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">6</a>]</cite>). <span id=\"S5.SS3.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> does not replace these\nmechanisms but <em id=\"S5.SS3.p4.1.3\" class=\"ltx_emph ltx_font_italic\">augments</em> them: once a candidate agent is discovered via\nany means, its AIC can be resolved and verified through the GAR, adding a\ntrust verification step that the native discovery protocol may lack.</p>\n</div>\n<div id=\"S5.SS3.p5\" class=\"ltx_para\">\n<p id=\"S5.SS3.p5.1\" class=\"ltx_p\">Both modes converge on the same verification flow: the discovered agent’s AIC\nis verified against the GAR’s trust chain, and each manifest VC in its\nregistration record is validated via the four-check protocol\n(§<a href=\"#S5.SS4\" title=\"5.4 Verifiable Skill &amp; Tool Manifests ‣ 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5.4</span></a>). Discovery thus answers three questions\nsimultaneously: “who is out there” (AIC verification), “what can they\ndo” (manifest VC verification), and “should I trust them” (subject\nbinding + permission alignment).</p>\n</div>\n</section>\n<section id=\"S5.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">5.4  Verifiable Skill &amp; Tool Manifests</h3>\n\n<div id=\"S5.SS4.p1\" class=\"ltx_para\">\n<p id=\"S5.SS4.p1.1\" class=\"ltx_p\">An agent’s capabilities are realized through two mechanisms:</p>\n<ul id=\"S5.I2\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S5.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S5.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"S5.I2.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I2.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Skills</span>—reusable capability modules (code packages) that\nrun within the agent’s execution environment.</p>\n</div></li>\n<li id=\"S5.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S5.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"S5.I2.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I2.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Tools</span>—external service bindings (API endpoints, MCP\nservers) that the agent invokes over the network.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"S5.SS4.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p2.1\" class=\"ltx_p\">In <span id=\"S5.SS4.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>, both skills and tools are represented as <em id=\"S5.SS4.p2.1.2\" class=\"ltx_emph ltx_font_italic\">signed\nVerifiable Credentials (VCs)</em> cryptographically bound to the agent’s DID\nand verifiable against the AIC trust chain. This design ensures that\ncapability claims—whether local code or remote services—carry the same\nstructural trust guarantees as agent identity itself. The two types share a\ncommon credential structure but differ in their issuance model, reflecting\ntheir distinct trust relationships.</p>\n</div>\n<div id=\"S5.SS4.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p3.1\" class=\"ltx_p\"><span id=\"S5.SS4.p3.1.1\" class=\"ltx_text ltx_font_bold\">Credential structure.</span> \nBoth skill and tool manifest VCs follow the W3C Verifiable Credentials\ndata model <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib64\" title=\"\" class=\"ltx_ref\">44</a>]</cite> adapted for agent semantics:</p>\n</div>\n<div id=\"S5.SS4.p4\" class=\"ltx_para\"><span id=\"S5.SS4.p4.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S5.SS4.p4.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S5.SS4.p4.p1.1\" class=\"ltx_p\"><span id=\"S5.SS4.p4.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Skill Manifest VC</span></span>\n</span>\n<span id=\"S5.SS4.p4.p2\" class=\"ltx_para\">\n<span id=\"S5.SS4.p4.p2.1\" class=\"ltx_tabular ltx_tabbing\">\n<span id=\"S5.SS4.p4.p2.1.1\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.1.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">@context<span id=\"S5.SS4.p4.p2.1.1.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.1.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.1.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">W3C VC context + <span id=\"S5.SS4.p4.p2.1.1.2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> skill vocabulary</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.2\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.2.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">id<span id=\"S5.SS4.p4.p2.1.2.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.2.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">unique credential URI</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.3\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.3.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">type<span id=\"S5.SS4.p4.p2.1.3.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">[“VerifiableCredential”, “SkillManifest”]</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.4\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.4.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">issuer<span id=\"S5.SS4.p4.p2.1.4.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.4.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">distributor DID (skill author)</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.5\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.5.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">credentialSubject<span id=\"S5.SS4.p4.p2.1.5.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.5.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.5.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">{</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.6\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p4.p2.1.6.1.1.1\" class=\"ltx_text ltx_font_bold\">id</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.6.2\" class=\"ltx_td ltx_align_left\"><math id=\"S5.SS4.p4.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖣𝖨𝖣</mi><mi mathsize=\"0.900em\">𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math><span id=\"S5.SS4.p4.p2.1.6.2.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (the agent holding this skill)</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.7\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.7.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.7.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p4.p2.1.7.1.1.1\" class=\"ltx_text ltx_font_bold\">manifest_id</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.7.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.7.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">unique manifest identifier</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.8\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.8.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.8.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p4.p2.1.8.1.1.1\" class=\"ltx_text ltx_font_bold\">perms_required</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.8.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.8.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">system capabilities the skill needs</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.9\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.9.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.9.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p4.p2.1.9.1.1.1\" class=\"ltx_text ltx_font_bold\">caps_provided</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.9.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.9.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">what the skill enables for the agent</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.10\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.10.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.10.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p4.p2.1.10.1.1.1\" class=\"ltx_text ltx_font_bold\">code_hash</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.10.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.10.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">digest of the skill code package</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.11\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.11.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.11.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">}<span id=\"S5.SS4.p4.p2.1.11.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.11.2\" class=\"ltx_td ltx_align_left\"></span></span>\n<span id=\"S5.SS4.p4.p2.1.12\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.12.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.12.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">proof<span id=\"S5.SS4.p4.p2.1.12.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.12.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.12.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Ed25519 signature by the distributor</span></span></span>\n<span id=\"S5.SS4.p4.p2.1.13\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p4.p2.1.13.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.13.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">gar_endorsement<span id=\"S5.SS4.p4.p2.1.13.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p4.p2.1.13.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p4.p2.1.13.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">optional GAR endorsement</span></span></span>\n</span>\n</span></span>\n</div>\n<div id=\"S5.SS4.p5\" class=\"ltx_para\"><span id=\"S5.SS4.p5.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S5.SS4.p5.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S5.SS4.p5.p1.1\" class=\"ltx_p\"><span id=\"S5.SS4.p5.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Tool Manifest VC</span></span>\n</span>\n<span id=\"S5.SS4.p5.p2\" class=\"ltx_para\">\n<span id=\"S5.SS4.p5.p2.1\" class=\"ltx_tabular ltx_tabbing\">\n<span id=\"S5.SS4.p5.p2.1.1\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.1.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">@context<span id=\"S5.SS4.p5.p2.1.1.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.1.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.1.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">W3C VC context + <span id=\"S5.SS4.p5.p2.1.1.2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> tool vocabulary</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.2\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.2.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">id<span id=\"S5.SS4.p5.p2.1.2.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.2.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">unique credential URI</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.3\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.3.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">type<span id=\"S5.SS4.p5.p2.1.3.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">[“VerifiableCredential”, “ToolManifest”]</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.4\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.4.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">issuer<span id=\"S5.SS4.p5.p2.1.4.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.4.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">tool provider DID (service operator)</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.5\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.5.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">credentialSubject<span id=\"S5.SS4.p5.p2.1.5.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.5.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.5.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">{</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.6\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p5.p2.1.6.1.1.1\" class=\"ltx_text ltx_font_bold\">id</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.6.2\" class=\"ltx_td ltx_align_left\"><math id=\"S5.SS4.p5.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖣𝖨𝖣</mi><mi mathsize=\"0.900em\">𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math><span id=\"S5.SS4.p5.p2.1.6.2.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (the agent authorized to use this tool)</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.7\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.7.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.7.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p5.p2.1.7.1.1.1\" class=\"ltx_text ltx_font_bold\">manifest_id</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.7.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.7.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">unique manifest identifier</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.8\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.8.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.8.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p5.p2.1.8.1.1.1\" class=\"ltx_text ltx_font_bold\">perms_required</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.8.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.8.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">capabilities the tool invocation needs</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.9\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.9.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.9.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p5.p2.1.9.1.1.1\" class=\"ltx_text ltx_font_bold\">caps_provided</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.9.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.9.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">what the tool enables for the agent</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.10\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.10.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.10.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p5.p2.1.10.1.1.1\" class=\"ltx_text ltx_font_bold\">endpoint</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.10.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.10.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">service URI (MCP server, REST API, etc.)</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.11\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.11.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.11.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">   <span id=\"S5.SS4.p5.p2.1.11.1.1.1\" class=\"ltx_text ltx_font_bold\">api_hash</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.11.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.11.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">digest of the tool’s interface schema</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.12\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.12.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.12.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">}<span id=\"S5.SS4.p5.p2.1.12.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.12.2\" class=\"ltx_td ltx_align_left\"></span></span>\n<span id=\"S5.SS4.p5.p2.1.13\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.13.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.13.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">proof<span id=\"S5.SS4.p5.p2.1.13.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.13.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.13.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Ed25519 signature by the tool provider</span></span></span>\n<span id=\"S5.SS4.p5.p2.1.14\" class=\"ltx_tr\">\n<span id=\"S5.SS4.p5.p2.1.14.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.14.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">gar_endorsement<span id=\"S5.SS4.p5.p2.1.14.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S5.SS4.p5.p2.1.14.2\" class=\"ltx_td ltx_align_left\"><span id=\"S5.SS4.p5.p2.1.14.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">optional GAR endorsement</span></span></span>\n</span>\n</span></span>\n</div>\n<div id=\"S5.SS4.p6\" class=\"ltx_para\">\n<p id=\"S5.SS4.p6.1\" class=\"ltx_p\">In both cases the <span id=\"S5.SS4.p6.1.1\" class=\"ltx_text ltx_font_bold\">credentialSubject.id</span> field binds the manifest to\na specific agent DID (<math id=\"S5.SS4.p6.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math>). This binding means that a manifest VC is\nnon-transferable: even if an attacker obtains the credential, it cannot be\npresented on behalf of a different agent because the verifier checks that\nthe subject DID matches the presenter’s AIC.</p>\n</div>\n<div id=\"S5.SS4.p7\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p7.1\" class=\"ltx_p\"><span id=\"S5.SS4.p7.1.1\" class=\"ltx_text ltx_font_bold\">Skill manifest issuance.</span> \nThe lifecycle of a <em id=\"S5.SS4.p7.1.2\" class=\"ltx_emph ltx_font_italic\">skill</em> manifest VC proceeds as follows:</p>\n<ol id=\"S5.I3\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S5.I3.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S5.I3.i1.p1\" class=\"ltx_para\">\n<p id=\"S5.I3.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I3.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Distributor publishes skill.</span> The skill author (the\ndistributor) creates the manifest, signs it with their distributor key,\nand optionally submits it to the GAR for endorsement.</p>\n</div></li>\n<li id=\"S5.I3.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S5.I3.i2.p1\" class=\"ltx_para\">\n<p id=\"S5.I3.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I3.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Agent acquires skill.</span> When an agent installs a skill, the\nkernel verifies the distributor’s signature and (if present) the GAR\nendorsement. The kernel then issues a <em id=\"S5.I3.i2.p1.1.2\" class=\"ltx_emph ltx_font_italic\">binding proof</em>: a secondary\nsignature using the agent’s <math id=\"S5.I3.i2.p1.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> that attests “I hold this skill\nand my AIC permits its required capabilities.”</p>\n</div></li>\n<li id=\"S5.I3.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S5.I3.i3.p1\" class=\"ltx_para\">\n<p id=\"S5.I3.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I3.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Agent presents during discovery.</span> The agent includes its\nbound skill manifest VCs in its registration record.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S5.SS4.p8\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p8.1\" class=\"ltx_p\"><span id=\"S5.SS4.p8.1.1\" class=\"ltx_text ltx_font_bold\">Tool manifest issuance.</span> \nTools differ from skills because their trust anchor is the <em id=\"S5.SS4.p8.1.2\" class=\"ltx_emph ltx_font_italic\">tool\nprovider</em> (the external service operator), not a code distributor:</p>\n<ol id=\"S5.I4\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S5.I4.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S5.I4.i1.p1\" class=\"ltx_para\">\n<p id=\"S5.I4.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I4.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Tool provider registers service.</span> The service operator\npublishes a tool manifest describing the tool’s endpoint, interface\nschema, and required permissions. The provider signs the manifest with\ntheir provider key and optionally obtains a GAR endorsement.</p>\n</div></li>\n<li id=\"S5.I4.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S5.I4.i2.p1\" class=\"ltx_para\">\n<p id=\"S5.I4.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I4.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Provider issues VC to agent.</span> When an agent requests access\nto a tool, the provider verifies the agent’s AIC and checks that the\nagent’s capability boundary <math id=\"S5.I4.i2.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math> is a superset of the tool’s\n<span id=\"S5.I4.i2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">perms_required</span>. If satisfied, the provider issues a tool\nmanifest VC with <span id=\"S5.I4.i2.p1.1.3\" class=\"ltx_text ltx_font_typewriter\">credentialSubject.id</span> set to the agent’s\n<math id=\"S5.I4.i2.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math>—effectively granting the agent verifiable authorization to\ninvoke the service.</p>\n</div></li>\n<li id=\"S5.I4.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S5.I4.i3.p1\" class=\"ltx_para\">\n<p id=\"S5.I4.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I4.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Agent presents during discovery.</span> The agent includes its\ntool manifest VCs alongside skill manifest VCs in its registration\nrecord. Requesters can now verify that the agent not only claims access\nto a tool but has been explicitly authorized by the tool provider.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S5.SS4.p9\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p9.1\" class=\"ltx_p\">In both flows, the agent’s registration record ultimately\ncontains a set of manifest VCs—some for skills, some for tools—each\nindependently verifiable by any requester or registry.</p>\n</div>\n<div id=\"S5.SS4.p10\" class=\"ltx_para ltx_noindent\">\n<p id=\"S5.SS4.p10.1\" class=\"ltx_p\"><span id=\"S5.SS4.p10.1.1\" class=\"ltx_text ltx_font_bold\">Verification during discovery.</span> \nWhen a requester discovers an agent and retrieves its registration record,\nthe following checks are performed on each manifest VC before the agent is\nconsidered a valid candidate for Layer 2 negotiation:</p>\n<ul id=\"S5.I5\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S5.I5.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S5.I5.i1.p1\" class=\"ltx_para\">\n<p id=\"S5.I5.i1.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Supply-chain verification:</span> The issuer’s signature\n(skill distributor or tool provider) and any GAR endorsement are\nverified, preventing supply-chain attacks analogous to the “ClawHavoc”\nincident <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">22</a>]</cite>.</p>\n</div></li>\n<li id=\"S5.I5.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S5.I5.i2.p1\" class=\"ltx_para\">\n<p id=\"S5.I5.i2.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Subject binding:</span> The <span id=\"S5.I5.i2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">credentialSubject.id</span> must\nmatch the discovered agent’s <math id=\"S5.I5.i2.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math>. This prevents manifest replay\nattacks where an adversary copies another agent’s manifest credentials.</p>\n</div></li>\n<li id=\"S5.I5.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S5.I5.i3.p1\" class=\"ltx_para\">\n<p id=\"S5.I5.i3.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Permission alignment:</span> The manifest’s\n<span id=\"S5.I5.i3.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">perms_required</span> must be a subset of the agent’s AIC capability\nboundary <math id=\"S5.I5.i3.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math>. If a skill or tool requires permissions beyond the agent’s\nboundary, the manifest is rejected, ensuring that discovery cannot\nsurface agents whose advertised claims exceed their actual authorization.</p>\n</div></li>\n<li id=\"S5.I5.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S5.I5.i4.p1\" class=\"ltx_para\">\n<p id=\"S5.I5.i4.p1.1\" class=\"ltx_p\"><span id=\"S5.I5.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Freshness:</span> The manifest VC must not be expired or revoked\n(checked against the GAR’s revocation list or status endpoint).</p>\n</div></li>\n</ul>\n</div>\n<div id=\"S5.SS4.p11\" class=\"ltx_para\">\n<p id=\"S5.SS4.p11.1\" class=\"ltx_p\">This four-check verification protocol transforms discovery from a trust-me\ndirectory into a <em id=\"S5.SS4.p11.1.1\" class=\"ltx_emph ltx_font_italic\">verify-then-interact</em> security boundary. The\nconsequence is structural: an agent cannot advertise capabilities it does\nnot possess, because every advertised skill or tool must be backed by a VC whose\nsubject binding, issuer provenance, and permission alignment are all\nindependently verifiable.</p>\n</div>\n</section>\n</section>\n<section id=\"S6\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">6  Layer 2: Trust Negotiation</h2>\n\n<div id=\"S6.p1\" class=\"ltx_para\">\n<p id=\"S6.p1.1\" class=\"ltx_p\">Layer 2 is the interaction layer of <span id=\"S6.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>. It governs three critical\nprocesses: <em id=\"S6.p1.1.2\" class=\"ltx_emph ltx_font_italic\">mutual attestation</em> (how two agents establish trust),\n<em id=\"S6.p1.1.3\" class=\"ltx_emph ltx_font_italic\">delegation</em> (how a parent agent creates bounded child identities), and\n<em id=\"S6.p1.1.4\" class=\"ltx_emph ltx_font_italic\">access control</em> (how a responder decides what a requester may do).\nTogether, these processes address threats T2–T4 from <a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>.</p>\n</div>\n<div id=\"S6.p2\" class=\"ltx_para\"><span id=\"S6.p2.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<section id=\"S6.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">6.1  Mutual Attestation Protocol</h3>\n\n<span id=\"S6.SS1.p1\" class=\"ltx_para\">\n<span id=\"S6.SS1.p1.1\" class=\"ltx_p\">When two agents wish to interact, neither should blindly trust the other. The\nmutual attestation protocol establishes bilateral trust through a\nchallenge-response exchange grounded in the agents’ AICs.</span>\n</span>\n<span id=\"S6.SS1.p2\" class=\"ltx_para\">\n<span id=\"S6.SS1.p2.1\" class=\"ltx_p\"><span id=\"S6.SS1.p2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">We write <span id=\"S6.SS1.p2.1.1.1\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.SS1.p2.1.1.1.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span> and <span id=\"S6.SS1.p2.1.1.2\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.SS1.p2.1.1.2.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span> for the kernels that hold <math id=\"S6.SS1.p2.m3\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}^{A}\" display=\"inline\" intent=\":literal\"><semantics><msubsup><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi><mi>A</mi></msubsup><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}^{A}</annotation></semantics></math> and\n<math id=\"S6.SS1.p2.m4\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}^{B}\" display=\"inline\" intent=\":literal\"><semantics><msubsup><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi><mi>B</mi></msubsup><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}^{B}</annotation></semantics></math> respectively. When both agents reside on the same host,\n<span id=\"S6.SS1.p2.1.1.3\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.SS1.p2.1.1.3.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.m5\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span> <math id=\"S6.SS1.p2.m6\" class=\"ltx_Math\" alttext=\"{}={}\" display=\"inline\" intent=\":literal\"><semantics><mo>=</mo><annotation encoding=\"application/x-tex\">{}={}</annotation></semantics></math><span id=\"S6.SS1.p2.1.1.4\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.SS1.p2.1.1.4.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.m7\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span> and the protocol reduces to local operations.</span></span>\n<span id=\"S6.SS1.p2.2\" class=\"ltx_inline-block ltx_align_center ltx_transformed_outer\" style=\"width:348.7pt;height:351.7pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"transform:translate(-30.8pt,31.0pt) scale(0.8,0.8) ;\"><span class=\"ltx_inline-block\"><svg id=\"S6.SS1.p2.pic1\" class=\"ltx_picture\" height=\"572.46\" overflow=\"visible\" version=\"1.1\" viewBox=\"0 0 563.55 572.46\" width=\"563.55\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" stroke-width=\"0.4pt\" transform=\"translate(0,572.46) matrix(1 0 0 -1 0 0) translate(51.46,0) translate(0,527.84)\"><g style=\"--ltx-stroke-color:#F6F9FA;--ltx-fill-color:#F6F9FA;--ltx-fg-color:#F6F9FA;\" color=\"#F6F9FA\" fill=\"#F6F9FA\" stroke=\"#F6F9FA\"><path style=\"stroke:none\" d=\"M -51.18 -27.56 M -51.18 -33.09 L -51.18 -285.8 C -51.18 -288.86 -48.7 -291.34 -45.65 -291.34 L 506.28 -291.34 C 509.33 -291.34 511.81 -288.86 511.81 -285.8 L 511.81 -33.09 C 511.81 -30.04 509.33 -27.56 506.28 -27.56 L -45.65 -27.56 C -48.7 -27.56 -51.18 -30.04 -51.18 -33.09 Z M 511.81 -291.34\"></path></g><g style=\"--ltx-stroke-color:#A4BED1;--ltx-fill-color:#A4BED1;--ltx-fg-color:#A4BED1;\" color=\"#A4BED1\" fill=\"#A4BED1\" stroke=\"#A4BED1\" stroke-dasharray=\"3.0pt,3.0pt\" stroke-dashoffset=\"0.0pt\"><path style=\"fill:none\" d=\"M -51.18 -27.56 M -51.18 -33.09 L -51.18 -285.8 C -51.18 -288.86 -48.7 -291.34 -45.65 -291.34 L 506.28 -291.34 C 509.33 -291.34 511.81 -288.86 511.81 -285.8 L 511.81 -33.09 C 511.81 -30.04 509.33 -27.56 506.28 -27.56 L -45.65 -27.56 C -48.7 -27.56 -51.18 -30.04 -51.18 -33.09 Z M 511.81 -291.34\"></path></g><g style=\"--ltx-stroke-color:#F6FCF9;--ltx-fill-color:#F6FCF9;--ltx-fg-color:#F6FCF9;\" color=\"#F6FCF9\" fill=\"#F6FCF9\" stroke=\"#F6FCF9\"><path style=\"stroke:none\" d=\"M -51.18 -299.21 M -51.18 -304.75 L -51.18 -364.54 C -51.18 -367.6 -48.7 -370.08 -45.65 -370.08 L 506.28 -370.08 C 509.33 -370.08 511.81 -367.6 511.81 -364.54 L 511.81 -304.75 C 511.81 -301.69 509.33 -299.21 506.28 -299.21 L -45.65 -299.21 C -48.7 -299.21 -51.18 -301.69 -51.18 -304.75 Z M 511.81 -370.08\"></path></g><g style=\"--ltx-stroke-color:#A9DFBF;--ltx-fill-color:#A9DFBF;--ltx-fg-color:#A9DFBF;\" color=\"#A9DFBF\" fill=\"#A9DFBF\" stroke=\"#A9DFBF\" stroke-dasharray=\"3.0pt,3.0pt\" stroke-dashoffset=\"0.0pt\"><path style=\"fill:none\" d=\"M -51.18 -299.21 M -51.18 -304.75 L -51.18 -364.54 C -51.18 -367.6 -48.7 -370.08 -45.65 -370.08 L 506.28 -370.08 C 509.33 -370.08 511.81 -367.6 511.81 -364.54 L 511.81 -304.75 C 511.81 -301.69 509.33 -299.21 506.28 -299.21 L -45.65 -299.21 C -48.7 -299.21 -51.18 -301.69 -51.18 -304.75 Z M 511.81 -370.08\"></path></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#E8EFF4;\" fill=\"#E8EFF4\" stroke=\"#BDC3C7\"><path d=\"M 27.93 15.75 L -27.93 15.75 C -30.99 15.75 -33.46 13.27 -33.46 10.21 L -33.46 -10.21 C -33.46 -13.27 -30.99 -15.75 -27.93 -15.75 L 27.93 -15.75 C 30.99 -15.75 33.46 -13.27 33.46 -10.21 L 33.46 10.21 C 33.46 13.27 30.99 15.75 27.93 15.75 Z M -33.46 -15.75\"></path></g><g style=\"--ltx-stroke-color:#164B70;--ltx-fill-color:#164B70;\" fill=\"#164B70\" stroke=\"#164B70\" transform=\"matrix(1.0 0.0 0.0 1.0 -24.27 -3.11)\"><foreignObject style=\"--ltx-fo-width:2.84em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"38.93\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;--ltx-fg-color:#164B70;\">Agent <math id=\"S6.SS1.p2.pic1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#164B70;\" mathcolor=\"#164B70\">A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#F4ECF7;\" fill=\"#F4ECF7\" stroke=\"#BDC3C7\"><path d=\"M 138.17 15.75 L 82.31 15.75 C 79.25 15.75 76.77 13.27 76.77 10.21 L 76.77 -10.21 C 76.77 -13.27 79.25 -15.75 82.31 -15.75 L 138.17 -15.75 C 141.22 -15.75 143.7 -13.27 143.7 -10.21 L 143.7 10.21 C 143.7 13.27 141.22 15.75 138.17 15.75 Z M 76.77 -15.75\"></path></g><g style=\"--ltx-stroke-color:#72368B;--ltx-fill-color:#72368B;\" fill=\"#72368B\" stroke=\"#72368B\" transform=\"matrix(1.0 0.0 0.0 1.0 86.91 -4.32)\"><foreignObject style=\"--ltx-fo-width:2.7em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"37.05\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.2\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;--ltx-fg-color:#72368B;\">Kernel<sub id=\"S6.SS1.p2.pic1.2.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.pic1.m2\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#72368B;\" mathcolor=\"#72368B\">A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#F4ECF7;\" fill=\"#F4ECF7\" stroke=\"#BDC3C7\"><path d=\"M 272.02 15.75 L 216.16 15.75 C 213.11 15.75 210.63 13.27 210.63 10.21 L 210.63 -10.21 C 210.63 -13.27 213.11 -15.75 216.16 -15.75 L 272.02 -15.75 C 275.08 -15.75 277.56 -13.27 277.56 -10.21 L 277.56 10.21 C 277.56 13.27 275.08 15.75 272.02 15.75 Z M 210.63 -15.75\"></path></g><g style=\"--ltx-stroke-color:#72368B;--ltx-fill-color:#72368B;\" fill=\"#72368B\" stroke=\"#72368B\" transform=\"matrix(1.0 0.0 0.0 1.0 220.42 -4.32)\"><foreignObject style=\"--ltx-fo-width:2.7em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"37.05\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.3\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;--ltx-fg-color:#72368B;\">Kernel<sub id=\"S6.SS1.p2.pic1.3.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.pic1.m3\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#72368B;\" mathcolor=\"#72368B\">B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#E8EFF4;\" fill=\"#E8EFF4\" stroke=\"#BDC3C7\"><path d=\"M 390.13 15.75 L 334.27 15.75 C 331.22 15.75 328.74 13.27 328.74 10.21 L 328.74 -10.21 C 328.74 -13.27 331.22 -15.75 334.27 -15.75 L 390.13 -15.75 C 393.19 -15.75 395.67 -13.27 395.67 -10.21 L 395.67 10.21 C 395.67 13.27 393.19 15.75 390.13 15.75 Z M 328.74 -15.75\"></path></g><g style=\"--ltx-stroke-color:#164B70;--ltx-fill-color:#164B70;\" fill=\"#164B70\" stroke=\"#164B70\" transform=\"matrix(1.0 0.0 0.0 1.0 337.59 -3.11)\"><foreignObject style=\"--ltx-fo-width:2.84em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"38.93\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.4\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;--ltx-fg-color:#164B70;\">Agent <math id=\"S6.SS1.p2.pic1.m4\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#164B70;\" mathcolor=\"#164B70\">B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#E9F7EF;\" fill=\"#E9F7EF\" stroke=\"#BDC3C7\"><path d=\"M 500.37 15.75 L 444.51 15.75 C 441.45 15.75 438.98 13.27 438.98 10.21 L 438.98 -10.21 C 438.98 -13.27 441.45 -15.75 444.51 -15.75 L 500.37 -15.75 C 503.43 -15.75 505.91 -13.27 505.91 -10.21 L 505.91 10.21 C 505.91 13.27 503.43 15.75 500.37 15.75 Z M 438.98 -15.75\"></path></g><g style=\"--ltx-stroke-color:#1F8B4D;--ltx-fill-color:#1F8B4D;\" fill=\"#1F8B4D\" stroke=\"#1F8B4D\" transform=\"matrix(1.0 0.0 0.0 1.0 458.93 -4.32)\"><foreignObject style=\"--ltx-fo-width:1.97em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"27.02\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.5\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;--ltx-fg-color:#1F8B4D;\">GAR</span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#BB8FCE;--ltx-fill-color:#BB8FCE;--ltx-fg-color:#BB8FCE;\" color=\"#BB8FCE\" fill=\"#BB8FCE\" stroke=\"#BB8FCE\" stroke-dasharray=\"3.0pt,3.0pt\" stroke-dashoffset=\"0.0pt\" stroke-width=\"0.6pt\"><path style=\"fill:none\" d=\"M 110.24 22.94 L 110.24 31.25 L 244.09 31.25 L 244.09 22.94\"></path></g><g style=\"--ltx-stroke-color:#72368B;--ltx-fill-color:#72368B;\" fill=\"#72368B\" stroke=\"#72368B\" transform=\"matrix(1.0 0.0 0.0 1.0 129.62 35.67)\"><foreignObject style=\"--ltx-fo-width:10.57em;--ltx-fo-height:0.69em;--ltx-fo-depth:0em;font-size:5pt;\" height=\"4.8\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 4.8)\" width=\"73.13\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.6\" class=\"ltx_text ltx_font_sansserif ltx_font_italic\" style=\"font-size:50%;--ltx-fg-color:#72368B;\">co-located: Kernel<sub id=\"S6.SS1.p2.pic1.6.1\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.pic1.m5\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#72368B;\" mathcolor=\"#72368B\" mathvariant=\"normal\">A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub> <math id=\"S6.SS1.p2.pic1.m6\" class=\"ltx_Math\" alttext=\"{}={}\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#72368B;\" mathcolor=\"#72368B\">=</mo><annotation encoding=\"application/x-tex\">{}={}</annotation></semantics></math>Kernel<sub id=\"S6.SS1.p2.pic1.6.2\" class=\"ltx_sub\"><math id=\"S6.SS1.p2.pic1.m7\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#72368B;\" mathcolor=\"#72368B\" mathvariant=\"normal\">B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#DEE1E3;--ltx-fill-color:#DEE1E3;--ltx-fg-color:#DEE1E3;\" color=\"#DEE1E3\" fill=\"#DEE1E3\" stroke=\"#DEE1E3\" stroke-width=\"0.4pt\"><path style=\"fill:none\" d=\"M 0 -15.75 L 0 -527.56\"></path></g><g style=\"--ltx-stroke-color:#DEE1E3;--ltx-fill-color:#DEE1E3;--ltx-fg-color:#DEE1E3;\" color=\"#DEE1E3\" fill=\"#DEE1E3\" stroke=\"#DEE1E3\" stroke-width=\"0.4pt\"><path style=\"fill:none\" d=\"M 110.24 -15.75 L 110.24 -527.56\"></path></g><g style=\"--ltx-stroke-color:#DEE1E3;--ltx-fill-color:#DEE1E3;--ltx-fg-color:#DEE1E3;\" color=\"#DEE1E3\" fill=\"#DEE1E3\" stroke=\"#DEE1E3\" stroke-width=\"0.4pt\"><path style=\"fill:none\" d=\"M 244.09 -15.75 L 244.09 -527.56\"></path></g><g style=\"--ltx-stroke-color:#DEE1E3;--ltx-fill-color:#DEE1E3;--ltx-fg-color:#DEE1E3;\" color=\"#DEE1E3\" fill=\"#DEE1E3\" stroke=\"#DEE1E3\" stroke-width=\"0.4pt\"><path style=\"fill:none\" d=\"M 362.2 -15.75 L 362.2 -527.56\"></path></g><g style=\"--ltx-stroke-color:#DEE1E3;--ltx-fill-color:#DEE1E3;--ltx-fg-color:#DEE1E3;\" color=\"#DEE1E3\" fill=\"#DEE1E3\" stroke=\"#DEE1E3\" stroke-width=\"0.4pt\"><path style=\"fill:none\" d=\"M 472.44 -15.75 L 472.44 -527.56\"></path></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" transform=\"matrix(1.0 0.0 0.0 1.0 419.53 -41.86)\"><foreignObject style=\"--ltx-fo-width:7.69em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:7.7pt;\" height=\"6.73\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"81.95\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.7\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:70%;--ltx-fg-color:#1B5E8C;\">Infrastructure Tier</span></span></span></foreignObject></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 0 -47.24 L 106.65 -47.24\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 104.7 -47.24)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 3.73 -38.87)\"><foreignObject style=\"--ltx-fo-width:8.76em;--ltx-fo-height:0.75em;--ltx-fo-depth:0.25em;font-size:7pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"84.86\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.8\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">1.  request_attest(<math id=\"S6.SS1.p2.pic1.m8\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math>, <math id=\"S6.SS1.p2.pic1.m9\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math>)</span></span></span></foreignObject></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 110.24 -74.8 L 468.86 -74.8\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 466.91 -74.8)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 244.9 -66.97)\"><foreignObject style=\"--ltx-fo-width:5.03em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"48.73\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.9\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">2.  verify  <math id=\"S6.SS1.p2.pic1.m10\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">𝖠𝖨𝖢</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{A}</annotation></semantics></math>,  <math id=\"S6.SS1.p2.pic1.m11\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">𝖠𝖨𝖢</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">B</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{B}</annotation></semantics></math></span></span></span></foreignObject></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" stroke-dasharray=\"3.0pt,3.0pt\" stroke-dashoffset=\"0.0pt\" stroke-width=\"0.6pt\"><path style=\"fill:none\" d=\"M 472.44 -94.49 L 113.82 -94.49\"></path><g stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(-1.0 0.0 0.0 -1.0 115.77 -94.49)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;--ltx-fg-color:#000000;\" color=\"#000000\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 274 -88.54)\"><foreignObject style=\"--ltx-fo-width:3.5em;--ltx-fo-height:0.69em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.73\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"33.92\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.10\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">✓  valid</span></span></span></foreignObject></g></g><g style=\"--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\"><path style=\"stroke:none\" d=\"M 251.48 -110.51 L 117.8 -110.51 C 117.04 -110.51 116.42 -111.13 116.42 -111.9 L 116.42 -129.09 C 116.42 -129.85 117.04 -130.47 117.8 -130.47 L 251.48 -130.47 C 252.25 -130.47 252.87 -129.85 252.87 -129.09 L 252.87 -111.9 C 252.87 -111.13 252.25 -110.51 251.48 -110.51 Z M 116.42 -130.47\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 120.57 -121.93)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:4.07em;--ltx-fo-height:0.66em;--ltx-fo-depth:0.19em;font-size:7pt;\" color=\"#4A4A4A\" height=\"8.23\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"39.44\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.11\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">3.  gen </span><math id=\"S6.SS1.p2.pic1.m12\" class=\"ltx_Math\" alttext=\"n_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">n</mi><mi mathsize=\"0.700em\">A</mi></msub><annotation encoding=\"application/x-tex\">n_{A}</annotation></semantics></math><span id=\"S6.SS1.p2.pic1.12\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">;  </span><math id=\"S6.SS1.p2.pic1.m13\" class=\"ltx_Math\" alttext=\"\\sigma_{A}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{A}}(n_{A})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.700em\">σ</mi><mi mathsize=\"0.700em\">A</mi></msub><mo mathsize=\"0.700em\">=</mo><mrow><msub><mi mathsize=\"0.700em\">𝖲𝗂𝗀𝗇</mi><msubsup><mi mathsize=\"0.700em\">K</mi><mi mathsize=\"0.700em\">𝗉𝗋𝗂𝗏</mi><mi mathsize=\"0.700em\">A</mi></msubsup></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"0.700em\" minsize=\"0.700em\">(</mo><msub><mi mathsize=\"0.700em\">n</mi><mi mathsize=\"0.700em\">A</mi></msub><mo maxsize=\"0.700em\" minsize=\"0.700em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\sigma_{A}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{A}}(n_{A})</annotation></semantics></math></span></span></foreignObject></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 110.24 -141.73 L 240.51 -141.73\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 238.56 -141.73)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 150.72 -133.36)\"><foreignObject style=\"--ltx-fo-width:1.39em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"13.45\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.13\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">4.  <math id=\"S6.SS1.p2.pic1.m14\" class=\"ltx_Math\" alttext=\"(n_{A},\\,\\sigma_{A})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" stretchy=\"false\">(</mo><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">n</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">A</mi></msub><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" rspace=\"0.337em\">,</mo><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">σ</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">A</mi></msub><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" stretchy=\"false\">)</mo></mrow><annotation encoding=\"application/x-tex\">(n_{A},\\,\\sigma_{A})</annotation></semantics></math></span></span></span></foreignObject></g></g><g style=\"--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\"><path style=\"stroke:none\" d=\"M 372.31 -157.76 L 251.66 -157.76 C 250.9 -157.76 250.28 -158.38 250.28 -159.14 L 250.28 -189.23 C 250.28 -189.99 250.9 -190.61 251.66 -190.61 L 372.31 -190.61 C 373.08 -190.61 373.7 -189.99 373.7 -189.23 L 373.7 -159.14 C 373.7 -158.38 373.08 -157.76 372.31 -157.76 Z M 250.28 -190.61\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 254.43 -182.07)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 24.55)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.81)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:4.38em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"42.38\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.14\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">verify </span><math id=\"S6.SS1.p2.pic1.m15\" class=\"ltx_Math\" alttext=\"\\sigma_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">σ</mi><mi mathsize=\"0.700em\">A</mi></msub><annotation encoding=\"application/x-tex\">\\sigma_{A}</annotation></semantics></math><span id=\"S6.SS1.p2.pic1.15\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\"> vs. </span><math id=\"S6.SS1.p2.pic1.m16\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}^{A}\" display=\"inline\" intent=\":literal\"><semantics><msubsup><mi mathsize=\"0.700em\">K</mi><mi mathsize=\"0.700em\">𝗉𝗎𝖻</mi><mi mathsize=\"0.700em\">A</mi></msubsup><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}^{A}</annotation></semantics></math></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 20.15)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:2.68em;--ltx-fo-height:0.44em;--ltx-fo-depth:0.19em;font-size:7pt;\" height=\"6.19\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 4.3)\" width=\"25.99\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.16\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">gen </span><math id=\"S6.SS1.p2.pic1.m17\" class=\"ltx_Math\" alttext=\"n_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">n</mi><mi mathsize=\"0.700em\">B</mi></msub><annotation encoding=\"application/x-tex\">n_{B}</annotation></semantics></math><span id=\"S6.SS1.p2.pic1.17\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">;  </span><math id=\"S6.SS1.p2.pic1.m18\" class=\"ltx_Math\" alttext=\"\\sigma_{B}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{B}}(n_{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.700em\">σ</mi><mi mathsize=\"0.700em\">B</mi></msub><mo mathsize=\"0.700em\">=</mo><mrow><msub><mi mathsize=\"0.700em\">𝖲𝗂𝗀𝗇</mi><msubsup><mi mathsize=\"0.700em\">K</mi><mi mathsize=\"0.700em\">𝗉𝗋𝗂𝗏</mi><mi mathsize=\"0.700em\">B</mi></msubsup></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"0.700em\" minsize=\"0.700em\">(</mo><msub><mi mathsize=\"0.700em\">n</mi><mi mathsize=\"0.700em\">B</mi></msub><mo maxsize=\"0.700em\" minsize=\"0.700em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\sigma_{B}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{B}}(n_{B})</annotation></semantics></math></span></span></foreignObject></g></g></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 244.09 -204.72 L 113.82 -204.72\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(-1.0 0.0 0.0 -1.0 115.77 -204.72)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 150.33 -196.35)\"><foreignObject style=\"--ltx-fo-width:1.39em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"13.45\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.18\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">5.  <math id=\"S6.SS1.p2.pic1.m19\" class=\"ltx_Math\" alttext=\"(n_{B},\\,\\sigma_{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" stretchy=\"false\">(</mo><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">n</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">B</mi></msub><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" rspace=\"0.337em\">,</mo><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">σ</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">B</mi></msub><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" stretchy=\"false\">)</mo></mrow><annotation encoding=\"application/x-tex\">(n_{B},\\,\\sigma_{B})</annotation></semantics></math></span></span></span></foreignObject></g></g><g style=\"--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\"><path style=\"stroke:none\" d=\"M 201.09 -216.81 L 117.8 -216.81 C 117.04 -216.81 116.42 -217.43 116.42 -218.2 L 116.42 -235.24 C 116.42 -236.01 117.04 -236.63 117.8 -236.63 L 201.09 -236.63 C 201.86 -236.63 202.47 -236.01 202.47 -235.24 L 202.47 -218.2 C 202.47 -217.43 201.86 -216.81 201.09 -216.81 Z M 116.42 -236.63\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 120.57 -229.77)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:4.38em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.19em;font-size:7pt;\" color=\"#4A4A4A\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"42.38\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.19\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">verify </span><math id=\"S6.SS1.p2.pic1.m20\" class=\"ltx_Math\" alttext=\"\\sigma_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">σ</mi><mi mathsize=\"0.700em\">B</mi></msub><annotation encoding=\"application/x-tex\">\\sigma_{B}</annotation></semantics></math><span id=\"S6.SS1.p2.pic1.20\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\"> vs. </span><math id=\"S6.SS1.p2.pic1.m21\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}^{B}\" display=\"inline\" intent=\":literal\"><semantics><msubsup><mi mathsize=\"0.700em\">K</mi><mi mathsize=\"0.700em\">𝗉𝗎𝖻</mi><mi mathsize=\"0.700em\">B</mi></msubsup><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}^{B}</annotation></semantics></math></span></span></foreignObject></g><g style=\"--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\"><path style=\"stroke:none\" d=\"M 221.23 -248.31 L 117.8 -248.31 C 117.04 -248.31 116.42 -248.93 116.42 -249.69 L 116.42 -265.42 C 116.42 -266.18 117.04 -266.8 117.8 -266.8 L 221.23 -266.8 C 222 -266.8 222.62 -266.18 222.62 -265.42 L 222.62 -249.69 C 222.62 -248.93 222 -248.31 221.23 -248.31 Z M 116.42 -266.8\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 120.57 -261.27)\"><foreignObject style=\"--ltx-fg-color:#4A4A4A;--ltx-fo-width:1.39em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" color=\"#4A4A4A\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"13.45\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.21\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">6.  </span><math id=\"S6.SS1.p2.pic1.m22\" class=\"ltx_Math\" alttext=\"S_{\\text{infra}}=S_{\\max}^{A}\\cap S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_sans-serif\" mathsize=\"0.700em\">infra</mtext></msub><mo mathsize=\"0.700em\">=</mo><mrow><msubsup><mi mathsize=\"0.700em\">S</mi><mi mathsize=\"0.700em\">max</mi><mi mathsize=\"0.700em\">A</mi></msubsup><mo mathsize=\"0.700em\">∩</mo><msubsup><mi mathsize=\"0.700em\">S</mi><mi mathsize=\"0.700em\">max</mi><mi mathsize=\"0.700em\">B</mi></msubsup></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{infra}}=S_{\\max}^{A}\\cap S_{\\max}^{B}</annotation></semantics></math></span></span></foreignObject></g><g style=\"--ltx-stroke-color:#1B7A43;--ltx-fill-color:#1B7A43;\" fill=\"#1B7A43\" stroke=\"#1B7A43\" transform=\"matrix(1.0 0.0 0.0 1.0 -38.88 -314.3)\"><foreignObject style=\"--ltx-fo-width:6.72em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:7.7pt;\" height=\"8.61\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"71.58\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.22\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:70%;--ltx-fg-color:#1B7A43;\">Application Tier</span></span></span></foreignObject></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 244.09 -318.9 L 358.62 -318.9\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 356.67 -318.9)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 251.74 -310.53)\"><foreignObject style=\"--ltx-fo-width:8.33em;--ltx-fo-height:0.75em;--ltx-fo-depth:0.25em;font-size:7pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"80.66\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.23\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">7.  evaluate policy(<math id=\"S6.SS1.p2.pic1.m23\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">𝖠𝖨𝖢</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{A}</annotation></semantics></math>)</span></span></span></foreignObject></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" stroke-dasharray=\"3.0pt,3.0pt\" stroke-dashoffset=\"0.0pt\" stroke-width=\"0.6pt\"><path style=\"fill:none\" d=\"M 362.2 -342.52 L 247.68 -342.52\"></path><g stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(-1.0 0.0 0.0 -1.0 249.63 -342.52)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;--ltx-fg-color:#000000;\" color=\"#000000\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 265.14 -333.87)\"><foreignObject style=\"--ltx-fo-width:6.71em;--ltx-fo-height:0.64em;--ltx-fo-depth:0.24em;font-size:8.19pt;\" height=\"9.97\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"76.03\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS1.p2.pic1.m24\" class=\"ltx_Math\" alttext=\"(\\mathit{allowed},\\;S_{\\text{policy}})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" maxsize=\"0.700em\" minsize=\"0.700em\">(</mo><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" mathsize=\"0.700em\">𝑎𝑙𝑙𝑜𝑤𝑒𝑑</mi><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" mathsize=\"0.700em\" rspace=\"0.447em\">,</mo><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" mathsize=\"0.700em\">S</mi><mtext style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_mathvariant_sans-serif\" mathcolor=\"#4A4A4A\" mathsize=\"0.700em\">policy</mtext></msub><mo style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\" maxsize=\"0.700em\" minsize=\"0.700em\">)</mo></mrow><annotation encoding=\"application/x-tex\">(\\mathit{allowed},\\;S_{\\text{policy}})</annotation></semantics></math></span></span></foreignObject></g></g><g style=\"--ltx-fill-color:#FFFFFF;\" fill=\"#FFFFFF\"><path style=\"stroke:none\" d=\"M 249.26 -382.17 L 117.8 -382.17 C 117.04 -382.17 116.42 -382.79 116.42 -383.55 L 116.42 -409.48 C 116.42 -410.24 117.04 -410.86 117.8 -410.86 L 249.26 -410.86 C 250.03 -410.86 250.65 -410.24 250.65 -409.48 L 250.65 -383.55 C 250.65 -382.79 250.03 -382.17 249.26 -382.17 Z M 116.42 -410.86\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 120.57 -404.29)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 20.39)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 6.62)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:1.67em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"16.14\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.24\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">8.   </span><math id=\"S6.SS1.p2.pic1.m25\" class=\"ltx_Math\" alttext=\"S_{\\text{sess}}=S_{\\text{policy}}\\cap S_{\\text{infra}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_sans-serif\" mathsize=\"0.700em\">sess</mtext></msub><mo mathsize=\"0.700em\">=</mo><mrow><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_sans-serif\" mathsize=\"0.700em\">policy</mtext></msub><mo mathsize=\"0.700em\">∩</mo><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_sans-serif\" mathsize=\"0.700em\">infra</mtext></msub></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{sess}}=S_{\\text{policy}}\\cap S_{\\text{infra}}</annotation></semantics></math></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 17.96)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:1.67em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"16.14\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.25\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">9.   </span><math id=\"S6.SS1.p2.pic1.m26\" class=\"ltx_math_unparsed\" alttext=\"k=\\mathsf{H}(n_{A}\\|\\sigma_{A}\\|n_{B}\\|\\sigma_{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi mathsize=\"0.700em\">k</mi><mo mathsize=\"0.700em\">=</mo><mi mathsize=\"0.700em\">𝖧</mi><mrow><mo maxsize=\"0.700em\" minsize=\"0.700em\">(</mo><msub><mi mathsize=\"0.700em\">n</mi><mi mathsize=\"0.700em\">A</mi></msub><mo lspace=\"0em\" mathsize=\"0.700em\" rspace=\"0.167em\">∥</mo><msub><mi mathsize=\"0.700em\">σ</mi><mi mathsize=\"0.700em\">A</mi></msub><mo lspace=\"0em\" mathsize=\"0.700em\" rspace=\"0.167em\">∥</mo><msub><mi mathsize=\"0.700em\">n</mi><mi mathsize=\"0.700em\">B</mi></msub><mo lspace=\"0em\" mathsize=\"0.700em\" rspace=\"0.167em\">∥</mo><msub><mi mathsize=\"0.700em\">σ</mi><mi mathsize=\"0.700em\">B</mi></msub><mo maxsize=\"0.700em\" minsize=\"0.700em\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">k=\\mathsf{H}(n_{A}\\|\\sigma_{A}\\|n_{B}\\|\\sigma_{B})</annotation></semantics></math></span></span></foreignObject></g></g></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 110.24 -433.07 L 3.58 -433.07\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(-1.0 0.0 0.0 -1.0 5.53 -433.07)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 35.43 -425.74)\"><foreignObject style=\"--ltx-fo-width:1.89em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"18.3\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.26\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">10.  <math id=\"S6.SS1.p2.pic1.m27\" class=\"ltx_Math\" alttext=\"\\mathit{ST}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">𝑆𝑇</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathit{ST}_{A}</annotation></semantics></math></span></span></span></foreignObject></g></g><g stroke-width=\"0.6pt\"><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\"><path style=\"fill:none\" d=\"M 244.09 -456.69 L 358.62 -456.69\"></path><g style=\"--ltx-fg-color:#4A4A4A;\" color=\"#4A4A4A\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" transform=\"matrix(1.0 0.0 0.0 1.0 356.67 -456.69)\"><path d=\"M 4.43 0 L 1.34 1.14 L 2.16 0 L 1.34 -1.14 Z\"></path></g></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 283.27 -449.36)\"><foreignObject style=\"--ltx-fo-width:1.89em;--ltx-fo-height:0.66em;--ltx-fo-depth:0em;font-size:7pt;\" height=\"6.35\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.35)\" width=\"18.3\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.27\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;--ltx-fg-color:#4A4A4A;\">10.  <math id=\"S6.SS1.p2.pic1.m28\" class=\"ltx_Math\" alttext=\"\\mathit{ST}_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">𝑆𝑇</mi><mi style=\"--ltx-fg-color:#4A4A4A;\" mathcolor=\"#4A4A4A\">B</mi></msub><annotation encoding=\"application/x-tex\">\\mathit{ST}_{B}</annotation></semantics></math></span></span></span></foreignObject></g></g><g style=\"--ltx-stroke-color:#2980B9;--ltx-fill-color:#2980B9;\" fill=\"#2980B9\" stroke=\"#2980B9\" transform=\"matrix(1.0 0.0 0.0 1.0 52.81 -503.28)\"><foreignObject style=\"--ltx-fo-width:23.1em;--ltx-fo-height:0.69em;--ltx-fo-depth:0.13em;font-size:7pt;\" height=\"7.94\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.73)\" width=\"223.77\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS1.p2.pic1.28\" class=\"ltx_text ltx_font_sansserif ltx_font_italic\" style=\"font-size:70%;--ltx-fg-color:#2980B9;\">Session established with <math id=\"S6.SS1.p2.pic1.m29\" class=\"ltx_Math\" alttext=\"S_{\\text{sess}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi style=\"--ltx-fg-color:#2980B9;\" mathcolor=\"#2980B9\" mathvariant=\"normal\">S</mi><mtext style=\"--ltx-fg-color:#2980B9;\" class=\"ltx_mathvariant_sans-serif-italic\" mathcolor=\"#2980B9\">sess</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{sess}}</annotation></semantics></math>, shared secret <math id=\"S6.SS1.p2.pic1.m30\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi style=\"--ltx-fg-color:#2980B9;\" mathcolor=\"#2980B9\" mathvariant=\"normal\">k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math>, bounded TTL</span></span></span></foreignObject></g></g></svg></span>\n</span></span>\n</span>\n<span id=\"S6.F3\" class=\"ltx_figure\">\n<span class=\"ltx_caption\" style=\"font-size:90%;\"><span class=\"ltx_tag ltx_tag_figure\">Figure 3: </span>Mutual attestation protocol. Each agent’s kernel (<span id=\"S6.F3.10\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.F3.10.1\" class=\"ltx_sub\"><math id=\"S6.F3.m4\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span>, <span id=\"S6.F3.11\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.F3.11.1\" class=\"ltx_sub\"><math id=\"S6.F3.m5\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span>)\nmediates its own signing operations; private keys never leave the isolated\ntrust boundary. When both agents share a host, the two kernels collapse to\none. The protocol produces a pair of session tokens with capabilities\nscoped to <math id=\"S6.F3.m6\" class=\"ltx_Math\" alttext=\"S_{\\max}^{A}\\cap S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msubsup><mi>S</mi><mi>max</mi><mi>A</mi></msubsup><mo>∩</mo><msubsup><mi>S</mi><mi>max</mi><mi>B</mi></msubsup></mrow><annotation encoding=\"application/x-tex\">S_{\\max}^{A}\\cap S_{\\max}^{B}</annotation></semantics></math> (further narrowed by any\napplication-level policy).</span>\n</span>\n<span id=\"S6.SS1.p3\" class=\"ltx_para\">\n<span id=\"S6.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S6.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<span id=\"S6.I1.i1.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent </span><math id=\"S6.I1.i1.p1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math><span id=\"S6.I1.i1.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> requests attestation with Agent </span><math id=\"S6.I1.i1.p1.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math><span id=\"S6.I1.i1.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> through </span><span id=\"S6.I1.i1.p1.1.4\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i1.p1.1.4.1\" class=\"ltx_sub\"><math id=\"S6.I1.i1.p1.m3\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span><span id=\"S6.I1.i1.p1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<span id=\"S6.I1.i2.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i2.p1.1.1.1\" class=\"ltx_sub\"><math id=\"S6.I1.i2.p1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span><span id=\"S6.I1.i2.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> resolves </span><math id=\"S6.I1.i2.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖠𝖨𝖢</mi><mi mathsize=\"0.900em\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{A}</annotation></semantics></math><span id=\"S6.I1.i2.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> and </span><math id=\"S6.I1.i2.p1.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖠𝖨𝖢</mi><mi mathsize=\"0.900em\">B</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{B}</annotation></semantics></math><span id=\"S6.I1.i2.p1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">, verifying both against\nthe GAR (signature validity, expiration, revocation status).</span></span>\n</span></span>\n<span id=\"S6.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<span id=\"S6.I1.i3.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i3.p1.1.1.1\" class=\"ltx_sub\"><math id=\"S6.I1.i3.p1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span><span id=\"S6.I1.i3.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> generates a fresh nonce </span><math id=\"S6.I1.i3.p1.m2\" class=\"ltx_Math\" alttext=\"n_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">A</mi></msub><annotation encoding=\"application/x-tex\">n_{A}</annotation></semantics></math><span id=\"S6.I1.i3.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> (32 bytes, 60 s TTL) and\nsigns it: </span><math id=\"S6.I1.i3.p1.m3\" class=\"ltx_Math\" alttext=\"\\sigma_{A}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{A}}(n_{A})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">A</mi></msub><mo mathsize=\"0.900em\">=</mo><mrow><msub><mi mathsize=\"0.900em\">𝖲𝗂𝗀𝗇</mi><msubsup><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗋𝗂𝗏</mi><mi mathsize=\"0.900em\">A</mi></msubsup></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">A</mi></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\sigma_{A}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{A}}(n_{A})</annotation></semantics></math><span id=\"S6.I1.i3.p1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<span id=\"S6.I1.i4.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i4.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">The challenge </span><math id=\"S6.I1.i4.p1.m1\" class=\"ltx_Math\" alttext=\"(n_{A},\\sigma_{A})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">A</mi></msub><mo mathsize=\"0.900em\">,</mo><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">A</mi></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow><annotation encoding=\"application/x-tex\">(n_{A},\\sigma_{A})</annotation></semantics></math><span id=\"S6.I1.i4.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> is delivered to </span><span id=\"S6.I1.i4.p1.1.3\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i4.p1.1.3.1\" class=\"ltx_sub\"><math id=\"S6.I1.i4.p1.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span><span id=\"S6.I1.i4.p1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">.\n</span><span id=\"S6.I1.i4.p1.1.5\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i4.p1.1.5.1\" class=\"ltx_sub\"><math id=\"S6.I1.i4.p1.m3\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span><span id=\"S6.I1.i4.p1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\"> verifies </span><math id=\"S6.I1.i4.p1.m4\" class=\"ltx_Math\" alttext=\"\\sigma_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">A</mi></msub><annotation encoding=\"application/x-tex\">\\sigma_{A}</annotation></semantics></math><span id=\"S6.I1.i4.p1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\"> against </span><math id=\"S6.I1.i4.p1.m5\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}^{A}\" display=\"inline\" intent=\":literal\"><semantics><msubsup><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗎𝖻</mi><mi mathsize=\"0.900em\">A</mi></msubsup><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}^{A}</annotation></semantics></math><span id=\"S6.I1.i4.p1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\"> from </span><math id=\"S6.I1.i4.p1.m6\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖠𝖨𝖢</mi><mi mathsize=\"0.900em\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{A}</annotation></semantics></math><span id=\"S6.I1.i4.p1.1.9\" class=\"ltx_text\" style=\"font-size:90%;\">,\ngenerates a fresh nonce </span><math id=\"S6.I1.i4.p1.m7\" class=\"ltx_Math\" alttext=\"n_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">B</mi></msub><annotation encoding=\"application/x-tex\">n_{B}</annotation></semantics></math><span id=\"S6.I1.i4.p1.1.10\" class=\"ltx_text\" style=\"font-size:90%;\">, and signs:\n</span><math id=\"S6.I1.i4.p1.m8\" class=\"ltx_Math\" alttext=\"\\sigma_{B}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{B}}(n_{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">B</mi></msub><mo mathsize=\"0.900em\">=</mo><mrow><msub><mi mathsize=\"0.900em\">𝖲𝗂𝗀𝗇</mi><msubsup><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗋𝗂𝗏</mi><mi mathsize=\"0.900em\">B</mi></msubsup></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">B</mi></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\sigma_{B}=\\mathsf{Sign}_{K_{\\mathsf{priv}}^{B}}(n_{B})</annotation></semantics></math><span id=\"S6.I1.i4.p1.1.11\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">5.</span> \n<span id=\"S6.I1.i5.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i5.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i5.p1.1.1\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i5.p1.1.1.1\" class=\"ltx_sub\"><math id=\"S6.I1.i5.p1.m1\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span><span id=\"S6.I1.i5.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> returns </span><math id=\"S6.I1.i5.p1.m2\" class=\"ltx_Math\" alttext=\"(n_{B},\\sigma_{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">B</mi></msub><mo mathsize=\"0.900em\">,</mo><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">B</mi></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow><annotation encoding=\"application/x-tex\">(n_{B},\\sigma_{B})</annotation></semantics></math><span id=\"S6.I1.i5.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> to </span><span id=\"S6.I1.i5.p1.1.4\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i5.p1.1.4.1\" class=\"ltx_sub\"><math id=\"S6.I1.i5.p1.m3\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span><span id=\"S6.I1.i5.p1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">.\n</span><span id=\"S6.I1.i5.p1.1.6\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i5.p1.1.6.1\" class=\"ltx_sub\"><math id=\"S6.I1.i5.p1.m4\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span><span id=\"S6.I1.i5.p1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\"> verifies </span><math id=\"S6.I1.i5.p1.m5\" class=\"ltx_Math\" alttext=\"\\sigma_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">B</mi></msub><annotation encoding=\"application/x-tex\">\\sigma_{B}</annotation></semantics></math><span id=\"S6.I1.i5.p1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\"> against </span><math id=\"S6.I1.i5.p1.m6\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}^{B}\" display=\"inline\" intent=\":literal\"><semantics><msubsup><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗎𝖻</mi><mi mathsize=\"0.900em\">B</mi></msubsup><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}^{B}</annotation></semantics></math><span id=\"S6.I1.i5.p1.1.9\" class=\"ltx_text\" style=\"font-size:90%;\"> from </span><math id=\"S6.I1.i5.p1.m7\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖠𝖨𝖢</mi><mi mathsize=\"0.900em\">B</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{B}</annotation></semantics></math><span id=\"S6.I1.i5.p1.1.10\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i6\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">6.</span> \n<span id=\"S6.I1.i6.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i6.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i6.p1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Infrastructure capability bound:</span><span id=\"S6.I1.i6.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">\n</span><math id=\"S6.I1.i6.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{infra}}=S_{\\max}^{A}\\cap S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">infra</mtext></msub><mo mathsize=\"0.900em\">=</mo><mrow><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mi mathsize=\"0.900em\">A</mi></msubsup><mo mathsize=\"0.900em\">∩</mo><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mi mathsize=\"0.900em\">B</mi></msubsup></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{infra}}=S_{\\max}^{A}\\cap S_{\\max}^{B}</annotation></semantics></math><span id=\"S6.I1.i6.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i7\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">7.</span> \n<span id=\"S6.I1.i7.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i7.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i7.p1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Application-level policy</span><span id=\"S6.I1.i7.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> (if registered for </span><math id=\"S6.I1.i7.p1.m1\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math><span id=\"S6.I1.i7.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">): the\nresponder’s access policy evaluates </span><math id=\"S6.I1.i7.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖠𝖨𝖢</mi><mi mathsize=\"0.900em\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{A}</annotation></semantics></math><span id=\"S6.I1.i7.p1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">’s attributes and returns\n</span><math id=\"S6.I1.i7.p1.m3\" class=\"ltx_Math\" alttext=\"({\\mathit{allowed}},\\;S_{\\text{policy}})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><mi mathsize=\"0.900em\">𝑎𝑙𝑙𝑜𝑤𝑒𝑑</mi><mo mathsize=\"0.900em\" rspace=\"0.447em\">,</mo><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">policy</mtext></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow><annotation encoding=\"application/x-tex\">({\\mathit{allowed}},\\;S_{\\text{policy}})</annotation></semantics></math><span id=\"S6.I1.i7.p1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i8\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">8.</span> \n<span id=\"S6.I1.i8.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i8.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i8.p1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Session capabilities:</span><span id=\"S6.I1.i8.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">\n</span><math id=\"S6.I1.i8.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}=S_{\\text{policy}}\\cap S_{\\text{infra}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">session</mtext></msub><mo mathsize=\"0.900em\">=</mo><mrow><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">policy</mtext></msub><mo mathsize=\"0.900em\">∩</mo><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">infra</mtext></msub></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{session}}=S_{\\text{policy}}\\cap S_{\\text{infra}}</annotation></semantics></math><span id=\"S6.I1.i8.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i9\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">9.</span> \n<span id=\"S6.I1.i9.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i9.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i9.p1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Shared secret:</span><span id=\"S6.I1.i9.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">\n</span><math id=\"S6.I1.i9.p1.m1\" class=\"ltx_math_unparsed\" alttext=\"k=\\mathsf{H}(n_{A}\\,\\|\\,\\sigma_{A}\\,\\|\\,n_{B}\\,\\|\\,\\sigma_{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi mathsize=\"0.900em\">k</mi><mo mathsize=\"0.900em\">=</mo><mi mathsize=\"0.900em\">𝖧</mi><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">A</mi></msub><mo lspace=\"0em\" mathsize=\"0.900em\" rspace=\"0.337em\">∥</mo><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">A</mi></msub><mo lspace=\"0em\" mathsize=\"0.900em\" rspace=\"0.337em\">∥</mo><msub><mi mathsize=\"0.900em\">n</mi><mi mathsize=\"0.900em\">B</mi></msub><mo lspace=\"0em\" mathsize=\"0.900em\" rspace=\"0.337em\">∥</mo><msub><mi mathsize=\"0.900em\">σ</mi><mi mathsize=\"0.900em\">B</mi></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">k=\\mathsf{H}(n_{A}\\,\\|\\,\\sigma_{A}\\,\\|\\,n_{B}\\,\\|\\,\\sigma_{B})</annotation></semantics></math><span id=\"S6.I1.i9.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I1.i10\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">10.</span> \n<span id=\"S6.I1.i10.p1\" class=\"ltx_para\">\n<span id=\"S6.I1.i10.p1.1\" class=\"ltx_p\"><span id=\"S6.I1.i10.p1.1.1\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i10.p1.1.1.1\" class=\"ltx_sub\"><math id=\"S6.I1.i10.p1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span><span id=\"S6.I1.i10.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> issues session token </span><math id=\"S6.I1.i10.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathit{ST}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝑆𝑇</mi><mi mathsize=\"0.900em\">A</mi></msub><annotation encoding=\"application/x-tex\">\\mathit{ST}_{A}</annotation></semantics></math><span id=\"S6.I1.i10.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> and </span><span id=\"S6.I1.i10.p1.1.4\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">Kernel<sub id=\"S6.I1.i10.p1.1.4.1\" class=\"ltx_sub\"><math id=\"S6.I1.i10.p1.m3\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span><span id=\"S6.I1.i10.p1.1.5\" class=\"ltx_text\" style=\"font-size:90%;\"> issues\n</span><math id=\"S6.I1.i10.p1.m4\" class=\"ltx_Math\" alttext=\"\\mathit{ST}_{B}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝑆𝑇</mi><mi mathsize=\"0.900em\">B</mi></msub><annotation encoding=\"application/x-tex\">\\mathit{ST}_{B}</annotation></semantics></math><span id=\"S6.I1.i10.p1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">, each with capabilities </span><math id=\"S6.I1.i10.p1.m5\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">session</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{session}}</annotation></semantics></math><span id=\"S6.I1.i10.p1.1.7\" class=\"ltx_text\" style=\"font-size:90%;\">,\nshared secret </span><math id=\"S6.I1.i10.p1.m6\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math><span id=\"S6.I1.i10.p1.1.8\" class=\"ltx_text\" style=\"font-size:90%;\">, and bounded TTL.</span></span>\n</span></span>\n</span>\n</span>\n</section></span>\n</div>\n<div id=\"Thmremarkx1\" class=\"ltx_theorem ltx_theorem_remark\">\n<h6 class=\"ltx_title ltx_runin ltx_title_theorem\"><span class=\"ltx_tag ltx_tag_theorem\"><span id=\"Thmremarkx1.2\" class=\"ltx_text ltx_font_italic\">Remark</span></span><span id=\"Thmremarkx1.3\" class=\"ltx_text ltx_font_italic\"> </span>(Deployment Topologies)<span id=\"Thmremarkx1.4\" class=\"ltx_text ltx_font_italic\">.</span></h6>\n<div id=\"Thmremarkx1.p1\" class=\"ltx_para\">\n<p id=\"Thmremarkx1.p1.1\" class=\"ltx_p\">The protocol above is parameterized by the relationship between <span id=\"Thmremarkx1.p1.1.1\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"Thmremarkx1.p1.1.1.1\" class=\"ltx_sub\"><math id=\"Thmremarkx1.p1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span> and <span id=\"Thmremarkx1.p1.1.2\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"Thmremarkx1.p1.1.2.1\" class=\"ltx_sub\"><math id=\"Thmremarkx1.p1.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span>. Three instantiations cover the practical deployment spectrum:</p>\n</div>\n<div id=\"Thmremarkx1.p2\" class=\"ltx_para\">\n<dl id=\"S6.I2\" class=\"ltx_description\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<dt id=\"S6.I2.ix1\" class=\"ltx_item\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S6.I2.ix1.1\" class=\"ltx_text ltx_font_bold\">Co-located (single kernel).</span></span></dt>\n<dd class=\"ltx_item\">\n<div id=\"S6.I2.ix1.p1\" class=\"ltx_para\">\n<p id=\"S6.I2.ix1.p1.1\" class=\"ltx_p\">When <math id=\"S6.I2.ix1.p1.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math> and <math id=\"S6.I2.ix1.p1.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math> reside on the same host, <span id=\"S6.I2.ix1.p1.1.1\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.I2.ix1.p1.1.1.1\" class=\"ltx_sub\"><math id=\"S6.I2.ix1.p1.m3\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span> <math id=\"S6.I2.ix1.p1.m4\" class=\"ltx_Math\" alttext=\"{}={}\" display=\"inline\" intent=\":literal\"><semantics><mo>=</mo><annotation encoding=\"application/x-tex\">{}={}</annotation></semantics></math><span id=\"S6.I2.ix1.p1.1.2\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S6.I2.ix1.p1.1.2.1\" class=\"ltx_sub\"><math id=\"S6.I2.ix1.p1.m5\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span> and\nsteps 3–5 collapse to kernel-internal operations with no network\nround-trip. This is the natural mode for <span id=\"S6.I2.ix1.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">DeepKernel</span>-managed\nmulti-agent orchestration on a single device.</p>\n</div></dd>\n<dt id=\"S6.I2.ix2\" class=\"ltx_item\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S6.I2.ix2.1\" class=\"ltx_text ltx_font_bold\">Remote-mediated (Trusted Attestation Service).</span></span></dt>\n<dd class=\"ltx_item\">\n<div id=\"S6.I2.ix2.p1\" class=\"ltx_para\">\n<p id=\"S6.I2.ix2.p1.1\" class=\"ltx_p\">A standalone service—architecturally identical to an agent kernel\nbut deployed as a remote endpoint—coordinates the exchange. Each\nagent’s designated kernel retains <math id=\"S6.I2.ix2.p1.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> and signs within its\ntrust boundary; the <span id=\"S6.I2.ix2.p1.1.1\" class=\"ltx_text ltx_font_sansserif\">TAS</span> relays challenges, caches GAR verification results, and issues session\ntokens. The <span id=\"S6.I2.ix2.p1.1.2\" class=\"ltx_text ltx_font_sansserif\">TAS</span> plays a role analogous to an OIDC Provider in human\nweb SSO: it centralizes session establishment while each agent\nretains sovereign control of its private key.</p>\n</div></dd>\n<dt id=\"S6.I2.ix3\" class=\"ltx_item\"><span class=\"ltx_tag ltx_tag_item\"><span id=\"S6.I2.ix3.1\" class=\"ltx_text ltx_font_bold\">Direct peer-to-peer.</span></span></dt>\n<dd class=\"ltx_item\">\n<div id=\"S6.I2.ix3.p1\" class=\"ltx_para\">\n<p id=\"S6.I2.ix3.p1.1\" class=\"ltx_p\">Each kernel signs its own nonce and verifies the counterpart’s signature\nindependently via the GAR. No trusted intermediary is required.\nThis mode is fully decentralized but incurs higher latency: each side\nperforms an independent GAR round-trip, and every attestation requires\na full network challenge-response exchange. AIC caching with\nrevocation-push notifications (§<a href=\"#S10\" title=\"10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">10</span></a>) can amortize\nthe GAR cost.</p>\n</div></dd>\n</dl>\n</div>\n<div id=\"Thmremarkx1.p3\" class=\"ltx_para\">\n<p id=\"Thmremarkx1.p3.1\" class=\"ltx_p\">The three modes can coexist within a single ecosystem: co-located\nattestation for intra-device workflows, mediated attestation for\norganizational clusters, and direct P2P for open cross-organization\ninteractions.</p>\n</div>\n</div>\n<div id=\"S6.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S6.p3.1\" class=\"ltx_p\"><span id=\"S6.p3.1.1\" class=\"ltx_text ltx_font_bold\">Anti-spoofing guarantees.</span> \nSession tokens are bound to specific agent instances (AIC + execution\ncontext). Tokens expire on agent termination; replay is impossible because\nnonces are single-use and time-bounded. Private keys never leave the\nagent’s isolated kernel, so stolen tokens are useless outside the authorized\nexecution context.</p>\n</div>\n<section id=\"S6.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">6.2  AIC Delegation Chain</h3>\n\n<div id=\"S6.SS2.p1\" class=\"ltx_para\">\n<p id=\"S6.SS2.p1.1\" class=\"ltx_p\">In multi-agent orchestration scenarios, a parent agent often needs to\ndynamically spawn task-specific child agents. <span id=\"S6.SS2.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> supports this through\n<em id=\"S6.SS2.p1.1.2\" class=\"ltx_emph ltx_font_italic\">AIC delegation</em>: the parent requests the kernel to issue a child AIC\nwith strictly attenuated capabilities, forming a cryptographic chain\nanalogous to an X.509 intermediate-CA hierarchy.</p>\n</div>\n<div id=\"S6.SS2.p2\" class=\"ltx_para\"><span id=\"S6.SS2.p2.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S6.SS2.p2.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S6.SS2.p2.p1.1\" class=\"ltx_p\"><span id=\"S6.SS2.p2.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Delegation Protocol</span></span>\n</span>\n<span id=\"S6.SS2.p2.p2\" class=\"ltx_para\">\n<span id=\"S6.I3\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S6.I3.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<span id=\"S6.I3.i1.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i1.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i1.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Parent requests child AIC from the kernel, specifying desired\ncapabilities </span><math id=\"S6.I3.i1.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{child}}\\subseteq S_{\\max}^{\\text{parent}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">child</mtext></msub><mo mathsize=\"0.900em\">⊆</mo><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mtext mathsize=\"0.900em\">parent</mtext></msubsup></mrow><annotation encoding=\"application/x-tex\">S_{\\text{child}}\\subseteq S_{\\max}^{\\text{parent}}</annotation></semantics></math><span id=\"S6.I3.i1.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">.</span></span>\n</span></span>\n<span id=\"S6.I3.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<span id=\"S6.I3.i2.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i2.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Kernel verifies the parent’s AIC chain (iterative walk to GAR root).</span></span>\n</span></span>\n<span id=\"S6.I3.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<span id=\"S6.I3.i3.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i3.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Kernel checks:\n</span><math id=\"S6.I3.i3.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{child}}\\subseteq S_{\\max}^{\\text{parent}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">child</mtext></msub><mo mathsize=\"0.900em\">⊆</mo><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mtext mathsize=\"0.900em\">parent</mtext></msubsup></mrow><annotation encoding=\"application/x-tex\">S_{\\text{child}}\\subseteq S_{\\max}^{\\text{parent}}</annotation></semantics></math><span id=\"S6.I3.i3.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\">\n(no capability escalation).</span></span>\n</span></span>\n<span id=\"S6.I3.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<span id=\"S6.I3.i4.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i4.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i4.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Kernel checks: delegation depth </span><math id=\"S6.I3.i4.p1.m1\" class=\"ltx_Math\" alttext=\"\\leq\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.900em\">≤</mo><annotation encoding=\"application/x-tex\">\\leq</annotation></semantics></math><span id=\"S6.I3.i4.p1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> configured ceiling.</span></span>\n</span></span>\n<span id=\"S6.I3.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">5.</span> \n<span id=\"S6.I3.i5.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i5.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i5.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Kernel generates fresh Ed25519 keypair for the child.</span></span>\n</span></span>\n<span id=\"S6.I3.i6\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">6.</span> \n<span id=\"S6.I3.i6.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i6.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i6.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">GAR issues child AIC signed by the parent’s key, with:</span></span>\n<span id=\"S6.I3.i6.I1\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<span id=\"S6.I3.i6.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S6.I3.i6.I1.i1.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i6.I1.i1.p1.1\" class=\"ltx_p\"><math id=\"S6.I3.i6.I1.i1.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}^{\\text{child}}=S_{\\text{child}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mtext mathsize=\"0.900em\">child</mtext></msubsup><mo mathsize=\"0.900em\">=</mo><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">child</mtext></msub></mrow><annotation encoding=\"application/x-tex\">S_{\\max}^{\\text{child}}=S_{\\text{child}}</annotation></semantics></math></span>\n</span></span>\n<span id=\"S6.I3.i6.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S6.I3.i6.I1.i2.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i6.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i6.I1.i2.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Inherited </span><span id=\"S6.I3.i6.I1.i2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">tenant_id</span><span id=\"S6.I3.i6.I1.i2.p1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> and\n</span><span id=\"S6.I3.i6.I1.i2.p1.1.4\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">deployment_environment</span></span>\n</span></span>\n<span id=\"S6.I3.i6.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<span id=\"S6.I3.i6.I1.i3.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i6.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i6.I1.i3.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Validity capped to parent’s remaining lifetime</span></span>\n</span></span>\n</span>\n</span></span>\n<span id=\"S6.I3.i7\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">7.</span> \n<span id=\"S6.I3.i7.p1\" class=\"ltx_para\">\n<span id=\"S6.I3.i7.p1.1\" class=\"ltx_p\"><span id=\"S6.I3.i7.p1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Child AIC is returned; parent-to-child link is recorded.</span></span>\n</span></span>\n</span>\n</span>\n<span id=\"S6.SS2.p2.p3\" class=\"ltx_para\"><span class=\"ltx_inline-block\"><svg id=\"S6.SS2.p2.pic1\" class=\"ltx_picture ltx_centering\" height=\"150.11\" overflow=\"visible\" version=\"1.1\" viewBox=\"0 0 559.61 150.11\" width=\"559.61\"><g style=\"--ltx-stroke-color:#000000;--ltx-fill-color:#000000;\" fill=\"#000000\" stroke=\"#000000\" stroke-width=\"0.4pt\" transform=\"translate(0,150.11) matrix(1 0 0 -1 0 0) translate(55.4,0) translate(0,118.34)\"><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#EDF2F6;\" fill=\"#EDF2F6\" stroke=\"#BDC3C7\"><path d=\"M 49.58 31.5 L -49.58 31.5 C -52.64 31.5 -55.12 29.02 -55.12 25.96 L -55.12 -25.96 C -55.12 -29.02 -52.64 -31.5 -49.58 -31.5 L 49.58 -31.5 C 52.64 -31.5 55.12 -29.02 55.12 -25.96 L 55.12 25.96 C 55.12 29.02 52.64 31.5 49.58 31.5 Z M -55.12 -31.5\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 -28.63 -7.96)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 20.75)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:4.15em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"56.87\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Developer</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 18.33)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 4.52 0)\"><foreignObject style=\"--ltx-fo-width:3.77em;--ltx-fo-height:0.57em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"48.21\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.2\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">(build time)</span><span id=\"S6.SS2.p2.pic1.3\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" transform=\"matrix(1.0 0.0 0.0 1.0 -48.6 -66.34)\"><g style=\"--ltx-fg-color:#1B5E8C;\" class=\"ltx_tikzmatrix\" color=\"#1B5E8C\" transform=\"matrix(1 0 0 -1 0 30.14)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 15.27)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 17.69)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 6.62)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:3.22em;--ltx-fo-height:0.58em;--ltx-fo-depth:0.12em;font-size:8.19pt;\" height=\"8\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.62)\" width=\"36.49\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{declared}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_monospace\" mathsize=\"0.700em\">declared</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{declared}}</annotation></semantics></math></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 15.26)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:9.56em;--ltx-fo-height:0.71em;--ltx-fo-depth:0.24em;font-size:7.35pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"97.2\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.4\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">{fs.read, fs.write,</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 27.38)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:9.14em;--ltx-fo-height:0.95em;--ltx-fo-depth:0.27em;font-size:7.35pt;\" height=\"12.45\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 9.69)\" width=\"92.91\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.5\" class=\"ltx_text ltx_phantom ltx_font_typewriter\" style=\"font-size:70%;\"><span style=\"visibility:hidden\">{</span></span><span id=\"S6.SS2.p2.pic1.6\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">process.exec, …}\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#EEF5F9;\" fill=\"#EEF5F9\" stroke=\"#BDC3C7\"><path d=\"M 199.19 31.5 L 100.02 31.5 C 96.97 31.5 94.49 29.02 94.49 25.96 L 94.49 -25.96 C 94.49 -29.02 96.97 -31.5 100.02 -31.5 L 199.19 -31.5 C 202.25 -31.5 204.72 -29.02 204.72 -25.96 L 204.72 25.96 C 204.72 29.02 202.25 31.5 199.19 31.5 Z M 94.49 -31.5\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 121.99 -7.96)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 20.75)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 2.15 0)\"><foreignObject style=\"--ltx-fo-width:3.72em;--ltx-fo-height:0.63em;--ltx-fo-depth:0.18em;font-size:9.9pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"50.94\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.7\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Operator</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 18.33)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:4.34em;--ltx-fo-height:0.57em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"55.51\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.8\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">(provisioning)</span><span id=\"S6.SS2.p2.pic1.9\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" transform=\"matrix(1.0 0.0 0.0 1.0 115.14 -64.35)\"><g style=\"--ltx-fg-color:#1B5E8C;\" class=\"ltx_tikzmatrix\" color=\"#1B5E8C\" transform=\"matrix(1 0 0 -1 0 27.81)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 15.7)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 18.12)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 6.64)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:6.08em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.16em;font-size:8.19pt;\" height=\"8.44\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.64)\" width=\"68.93\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m2\" class=\"ltx_Math\" alttext=\"S_{\\max}\\subseteq S_{\\text{declared}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.700em\">S</mi><mi mathsize=\"0.700em\">max</mi></msub><mo mathsize=\"0.700em\">⊆</mo><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_monospace\" mathsize=\"0.700em\">declared</mtext></msub></mrow><annotation encoding=\"application/x-tex\">S_{\\max}\\subseteq S_{\\text{declared}}</annotation></semantics></math></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 15.7)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:4.56em;--ltx-fo-height:0.71em;--ltx-fo-depth:0.24em;font-size:7.35pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"46.35\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.10\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">{fs.read,</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 25.38)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:5.11em;--ltx-fo-height:0.71em;--ltx-fo-depth:0.24em;font-size:7.35pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"52.02\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.11\" class=\"ltx_text ltx_phantom ltx_font_typewriter\" style=\"font-size:70%;\"><span style=\"visibility:hidden\">{</span></span><span id=\"S6.SS2.p2.pic1.12\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">fs.write}\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#F6F0F8;\" fill=\"#F6F0F8\" stroke=\"#BDC3C7\"><path d=\"M 348.8 31.5 L 249.63 31.5 C 246.57 31.5 244.09 29.02 244.09 25.96 L 244.09 -25.96 C 244.09 -29.02 246.57 -31.5 249.63 -31.5 L 348.8 -31.5 C 351.85 -31.5 354.33 -29.02 354.33 -25.96 L 354.33 25.96 C 354.33 29.02 351.85 31.5 348.8 31.5 Z M 244.09 -31.5\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 278.94 -6.75)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 18.33)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 6.76 0)\"><foreignObject style=\"--ltx-fo-width:1.97em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"27.02\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.13\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">GAR</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 15.91)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:3.17em;--ltx-fo-height:0.57em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"40.55\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.14\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">(issuance)</span><span id=\"S6.SS2.p2.pic1.15\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" transform=\"matrix(1.0 0.0 0.0 1.0 263.62 -62.09)\"><g style=\"--ltx-fg-color:#1B5E8C;\" class=\"ltx_tikzmatrix\" color=\"#1B5E8C\" transform=\"matrix(1 0 0 -1 0 24.51)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 14.36)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 16.51)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 6.64)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:4.5em;--ltx-fo-height:0.58em;--ltx-fo-depth:0em;font-size:7.35pt;\" height=\"5.92\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 5.92)\" width=\"45.77\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.16\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">verifies </span><math id=\"S6.SS2.p2.pic1.m3\" class=\"ltx_Math\" alttext=\"\\subseteq\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.700em\">⊆</mo><annotation encoding=\"application/x-tex\">\\subseteq</annotation></semantics></math></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 14.36)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:7em;--ltx-fo-height:0.58em;--ltx-fo-depth:0.21em;font-size:7.35pt;\" height=\"8.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 5.92)\" width=\"71.19\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.17\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">signs AIC with</span></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 23.13)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:2.03em;--ltx-fo-height:0.65em;--ltx-fo-depth:0.14em;font-size:7.35pt;\" height=\"8\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.62)\" width=\"20.63\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m4\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">S</mi><mi mathsize=\"0.700em\">max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math><span id=\"S6.SS2.p2.pic1.18\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#BDC3C7;--ltx-fill-color:#EEF9F2;\" fill=\"#EEF9F2\" stroke=\"#BDC3C7\"><path d=\"M 498.4 31.5 L 399.24 31.5 C 396.18 31.5 393.7 29.02 393.7 25.96 L 393.7 -25.96 C 393.7 -29.02 396.18 -31.5 399.24 -31.5 L 498.4 -31.5 C 501.46 -31.5 503.94 -29.02 503.94 -25.96 L 503.94 25.96 C 503.94 29.02 501.46 31.5 498.4 31.5 Z M 393.7 -31.5\"></path></g><g style=\"--ltx-stroke-color:#4A4A4A;--ltx-fill-color:#4A4A4A;\" fill=\"#4A4A4A\" stroke=\"#4A4A4A\" transform=\"matrix(1.0 0.0 0.0 1.0 423.19 -6.75)\"><g style=\"--ltx-fg-color:#4A4A4A;\" class=\"ltx_tikzmatrix\" color=\"#4A4A4A\" transform=\"matrix(1 0 0 -1 0 18.33)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 8.65)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 1.58 0)\"><foreignObject style=\"--ltx-fo-width:3.51em;--ltx-fo-height:0.63em;--ltx-fo-depth:0em;font-size:9.9pt;\" height=\"8.65\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"48.1\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.19\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\" style=\"font-size:90%;\">Runtime</span></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 15.91)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:3.98em;--ltx-fo-height:0.57em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"9.69\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 7.26)\" width=\"50.99\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.20\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:70%;\">(per session)</span><span id=\"S6.SS2.p2.pic1.21\" class=\"ltx_text ltx_font_sansserif\" style=\"font-size:90%;\">\n</span></span></span></foreignObject></g></g></g></g><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\" transform=\"matrix(1.0 0.0 0.0 1.0 418.99 -63.78)\"><g style=\"--ltx-fg-color:#1B5E8C;\" class=\"ltx_tikzmatrix\" color=\"#1B5E8C\" transform=\"matrix(1 0 0 -1 0 27.7)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 16.81)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><g class=\"ltx_tikzmatrix\" transform=\"matrix(1 0 0 -1 0 18.19)\"><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 6.62)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:2.9em;--ltx-fo-height:0.58em;--ltx-fo-depth:0.12em;font-size:8.19pt;\" height=\"8\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.62)\" width=\"32.93\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m5\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_monospace\" mathsize=\"0.700em\">session</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{session}}</annotation></semantics></math></span></span></foreignObject></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 16.81)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:5.26em;--ltx-fo-height:0.78em;--ltx-fo-depth:0.12em;font-size:8.19pt;\" height=\"10.19\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.81)\" width=\"59.66\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m6\" class=\"ltx_Math\" alttext=\"=S_{\\max}^{A}\\!\\cap\\!S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mphantom></mphantom><mo mathsize=\"0.700em\">=</mo><mrow><msubsup><mi mathsize=\"0.700em\">S</mi><mi mathsize=\"0.700em\">max</mi><mi mathsize=\"0.700em\">A</mi></msubsup><mo mathsize=\"0.700em\" rspace=\"0.102em\">∩</mo><msubsup><mi mathsize=\"0.700em\">S</mi><mi mathsize=\"0.700em\">max</mi><mi mathsize=\"0.700em\">B</mi></msubsup></mrow></mrow><annotation encoding=\"application/x-tex\">=S_{\\max}^{A}\\!\\cap\\!S_{\\max}^{B}</annotation></semantics></math></span></span></foreignObject></g></g></g></g></g><g class=\"ltx_tikzmatrix_row\" transform=\"matrix(1 0 0 1 0 24.82)\"><g class=\"ltx_tikzmatrix_col ltx_nopad_l ltx_nopad_r\" transform=\"matrix(1 0 0 -1 0 0)\"><foreignObject style=\"--ltx-fo-width:3.96em;--ltx-fo-height:0.65em;--ltx-fo-depth:0.28em;font-size:7.35pt;\" height=\"9.51\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.62)\" width=\"40.29\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m7\" class=\"ltx_Math\" alttext=\"\\cap\\;S_{\\text{policy}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo mathsize=\"0.700em\" rspace=\"0em\">∩</mo><msub><mi mathsize=\"0.700em\">S</mi><mtext class=\"ltx_mathvariant_monospace\" mathsize=\"0.700em\">policy</mtext></msub></mrow><annotation encoding=\"application/x-tex\">\\cap\\;S_{\\text{policy}}</annotation></semantics></math><span id=\"S6.SS2.p2.pic1.22\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:70%;\">\n</span></span></span></foreignObject></g></g></g></g><g stroke-width=\"1.2pt\"><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\"><path style=\"fill:none\" d=\"M 55.39 0 L 88.86 0\"></path><g style=\"--ltx-fg-color:#1B5E8C;\" color=\"#1B5E8C\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" stroke-width=\"1.0125pt\" transform=\"matrix(1.0 0.0 0.0 1.0 85.91 0)\"><path d=\"M 6.43 0 L 2.26 1.54 L 3.31 0 L 2.26 -1.54 Z\"></path></g></g><g style=\"--ltx-stroke-color:#C0392B;--ltx-fill-color:#C0392B;\" fill=\"#C0392B\" stroke=\"#C0392B\" transform=\"matrix(1.0 0.0 0.0 1.0 70.48 6.78)\"><foreignObject style=\"--ltx-fo-width:0.76em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.16em;font-size:8.19pt;\" height=\"8.44\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.64)\" width=\"8.65\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m8\" class=\"ltx_Math\" alttext=\"\\subseteq\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#C0392B;\" mathcolor=\"#C0392B\" mathsize=\"0.700em\">⊆</mo><annotation encoding=\"application/x-tex\">\\subseteq</annotation></semantics></math></span></span></foreignObject></g></g><g stroke-width=\"1.2pt\"><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\"><path style=\"fill:none\" d=\"M 205 0 L 238.47 0\"></path><g style=\"--ltx-fg-color:#1B5E8C;\" color=\"#1B5E8C\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" stroke-width=\"1.0125pt\" transform=\"matrix(1.0 0.0 0.0 1.0 235.52 0)\"><path d=\"M 6.43 0 L 2.26 1.54 L 3.31 0 L 2.26 -1.54 Z\"></path></g></g><g style=\"--ltx-stroke-color:#C0392B;--ltx-fill-color:#C0392B;\" fill=\"#C0392B\" stroke=\"#C0392B\" transform=\"matrix(1.0 0.0 0.0 1.0 220.09 6.78)\"><foreignObject style=\"--ltx-fo-width:0.76em;--ltx-fo-height:0.59em;--ltx-fo-depth:0.16em;font-size:8.19pt;\" height=\"8.44\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 6.64)\" width=\"8.65\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m9\" class=\"ltx_Math\" alttext=\"\\subseteq\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#C0392B;\" mathcolor=\"#C0392B\" mathsize=\"0.700em\">⊆</mo><annotation encoding=\"application/x-tex\">\\subseteq</annotation></semantics></math></span></span></foreignObject></g></g><g stroke-width=\"1.2pt\"><g style=\"--ltx-stroke-color:#1B5E8C;--ltx-fill-color:#1B5E8C;\" fill=\"#1B5E8C\" stroke=\"#1B5E8C\"><path style=\"fill:none\" d=\"M 354.61 0 L 388.08 0\"></path><g style=\"--ltx-fg-color:#1B5E8C;\" color=\"#1B5E8C\" stroke-dasharray=\"none\" stroke-dashoffset=\"0.0pt\" stroke-linejoin=\"miter\" stroke-width=\"1.0125pt\" transform=\"matrix(1.0 0.0 0.0 1.0 385.12 0)\"><path d=\"M 6.43 0 L 2.26 1.54 L 3.31 0 L 2.26 -1.54 Z\"></path></g></g><g style=\"--ltx-stroke-color:#C0392B;--ltx-fill-color:#C0392B;\" fill=\"#C0392B\" stroke=\"#C0392B\" transform=\"matrix(1.0 0.0 0.0 1.0 370.29 4.98)\"><foreignObject style=\"--ltx-fo-width:0.66em;--ltx-fo-height:0.47em;--ltx-fo-depth:0em;font-size:8.19pt;\" height=\"5.38\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 5.38)\" width=\"7.46\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><math id=\"S6.SS2.p2.pic1.m10\" class=\"ltx_Math\" alttext=\"\\cap\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#C0392B;\" mathcolor=\"#C0392B\" mathsize=\"0.700em\">∩</mo><annotation encoding=\"application/x-tex\">\\cap</annotation></semantics></math></span></span></foreignObject></g></g><g style=\"--ltx-stroke-color:#C0392B;--ltx-fill-color:#C0392B;\" fill=\"#C0392B\" stroke=\"#C0392B\" transform=\"matrix(1.0 0.0 0.0 1.0 8.23 -111.76)\"><foreignObject style=\"--ltx-fo-width:31.95em;--ltx-fo-height:0.68em;--ltx-fo-depth:0.19em;font-size:9.25pt;\" height=\"11.07\" overflow=\"visible\" transform=\"matrix(1 0 0 -1 0 8.65)\" width=\"408.9\"><span class=\"ltx_foreignobject_container\"><span class=\"ltx_foreignobject_content\"><span id=\"S6.SS2.p2.pic1.23\" class=\"ltx_text ltx_font_sansserif ltx_font_italic\" style=\"font-size:90%;--ltx-fg-color:#C0392B;\">Each stage can only <span id=\"S6.SS2.p2.pic1.23.1\" class=\"ltx_text ltx_font_bold\">narrow</span>, never widen.\nAuthority flows left<math id=\"S6.SS2.p2.pic1.m11\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#C0392B;\" mathcolor=\"#C0392B\" stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math>right via <math id=\"S6.SS2.p2.pic1.m12\" class=\"ltx_Math\" alttext=\"\\subseteq\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#C0392B;\" mathcolor=\"#C0392B\">⊆</mo><annotation encoding=\"application/x-tex\">\\subseteq</annotation></semantics></math> and <math id=\"S6.SS2.p2.pic1.m13\" class=\"ltx_Math\" alttext=\"\\cap\" display=\"inline\" intent=\":literal\"><semantics><mo style=\"--ltx-fg-color:#C0392B;\" mathcolor=\"#C0392B\">∩</mo><annotation encoding=\"application/x-tex\">\\cap</annotation></semantics></math>.</span></span></span></foreignObject></g></g></svg></span>\n</span>\n<span id=\"S6.F4\" class=\"ltx_figure\">\n<span class=\"ltx_caption\" style=\"font-size:90%;\"><span class=\"ltx_tag ltx_tag_figure\">Figure 4: </span>Monotonic capability attenuation chain. Each party can only\n<em id=\"S6.F4.7\" class=\"ltx_emph ltx_font_italic\">narrow</em> the boundary set by the preceding party. The runtime\nintersection further constrains per-invocation permissions.</span>\n</span></span>\n</div>\n<div id=\"S6.SS2.p3\" class=\"ltx_para\">\n<p id=\"S6.SS2.p3.1\" class=\"ltx_p\">The delegation mechanism provides six structural security properties:</p>\n</div>\n<figure id=\"S6.T4\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\" style=\"font-size:90%;\"><span class=\"ltx_tag ltx_tag_table\">Table 4: </span>Security properties of AIC delegation.</figcaption>\n<table id=\"S6.T4.5\" class=\"ltx_tabular ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S6.T4.5.1\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.1.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_th_row ltx_border_tt\"><span id=\"S6.T4.5.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Property</span></th>\n<th id=\"S6.T4.5.1.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S6.T4.5.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.1.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S6.T4.5.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Mechanism</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S6.T4.5.2\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.2.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_t\"><span id=\"S6.T4.5.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Monotonic attenuation</span></th>\n<td id=\"S6.T4.5.2.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_t\">\n<span id=\"S6.T4.5.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.2.2.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S6.T4.m1\" class=\"ltx_Math\" alttext=\"S_{\\max}^{\\text{child}}\\subseteq S_{\\max}^{\\text{parent}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mtext mathsize=\"0.900em\">child</mtext></msubsup><mo mathsize=\"0.900em\">⊆</mo><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mtext mathsize=\"0.900em\">parent</mtext></msubsup></mrow><annotation encoding=\"application/x-tex\">S_{\\max}^{\\text{child}}\\subseteq S_{\\max}^{\\text{parent}}</annotation></semantics></math><span id=\"S6.T4.5.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> enforced\ncryptographically at delegation time.</span></span>\n</span></td></tr>\n<tr id=\"S6.T4.5.3\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.3.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S6.T4.5.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Tenant isolation</span></th>\n<td id=\"S6.T4.5.3.2\" class=\"ltx_td ltx_nopad_r ltx_align_left\">\n<span id=\"S6.T4.5.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.3.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S6.T4.5.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Child inherits </span><span id=\"S6.T4.5.3.2.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">tenant_id</span><span id=\"S6.T4.5.3.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> from parent; cross-tenant delegation is\nstructurally impossible.</span></span>\n</span></td></tr>\n<tr id=\"S6.T4.5.4\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.4.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S6.T4.5.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Depth bounding</span></th>\n<td id=\"S6.T4.5.4.2\" class=\"ltx_td ltx_nopad_r ltx_align_left\">\n<span id=\"S6.T4.5.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.4.2.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S6.T4.m2\" class=\"ltx_Math\" alttext=\"d_{\\text{eff}}=\\min(d_{\\text{kernel}},\\,d_{\\text{request}})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">d</mi><mtext mathsize=\"0.900em\">eff</mtext></msub><mo mathsize=\"0.900em\">=</mo><mrow><mi mathsize=\"0.900em\">min</mi><mo>⁡</mo><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><msub><mi mathsize=\"0.900em\">d</mi><mtext mathsize=\"0.900em\">kernel</mtext></msub><mo mathsize=\"0.900em\" rspace=\"0.337em\">,</mo><msub><mi mathsize=\"0.900em\">d</mi><mtext mathsize=\"0.900em\">request</mtext></msub><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">d_{\\text{eff}}=\\min(d_{\\text{kernel}},\\,d_{\\text{request}})</annotation></semantics></math><span id=\"S6.T4.5.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">; the\nrequest can only tighten, never loosen.</span></span>\n</span></td></tr>\n<tr id=\"S6.T4.5.5\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.5.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S6.T4.5.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Cascading revocation</span></th>\n<td id=\"S6.T4.5.5.2\" class=\"ltx_td ltx_nopad_r ltx_align_left\">\n<span id=\"S6.T4.5.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.5.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S6.T4.5.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Revoking a parent AIC atomically revokes all descendants; chain\nverification fails for the entire subtree.</span></span>\n</span></td></tr>\n<tr id=\"S6.T4.5.6\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.6.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row\"><span id=\"S6.T4.5.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Validity capping</span></th>\n<td id=\"S6.T4.5.6.2\" class=\"ltx_td ltx_nopad_r ltx_align_left\">\n<span id=\"S6.T4.5.6.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.6.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S6.T4.5.6.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Child’s </span><span id=\"S6.T4.5.6.2.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">expires_at</span><span id=\"S6.T4.5.6.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> </span><math id=\"S6.T4.m3\" class=\"ltx_Math\" alttext=\"\\leq\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.900em\">≤</mo><annotation encoding=\"application/x-tex\">\\leq</annotation></semantics></math><span id=\"S6.T4.5.6.2.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\"> parent’s </span><span id=\"S6.T4.5.6.2.1.1.5\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">expires_at</span><span id=\"S6.T4.5.6.2.1.1.6\" class=\"ltx_text\" style=\"font-size:90%;\">;\nparent expiry cascades temporally.</span></span>\n</span></td></tr>\n<tr id=\"S6.T4.5.7\" class=\"ltx_tr\">\n<th id=\"S6.T4.5.7.1\" class=\"ltx_td ltx_align_left ltx_th ltx_th_row ltx_border_bb\"><span id=\"S6.T4.5.7.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Cycle resistance</span></th>\n<td id=\"S6.T4.5.7.2\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_bb\">\n<span id=\"S6.T4.5.7.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S6.T4.5.7.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S6.T4.5.7.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Iterative chain verification with visited set and hard hop cap; no\nrecursion overflow or cycle attacks.</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n</section>\n<section id=\"S6.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">6.3  Two-Tier A2A Access Control</h3>\n\n<div id=\"S6.SS3.p1\" class=\"ltx_para\">\n<p id=\"S6.SS3.p1.1\" class=\"ltx_p\">A pure capability-intersection model (§<a href=\"#S6.SS1\" title=\"6.1 Mutual Attestation Protocol ‣ 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6.1</span></a>, step 6) is\nnecessary but insufficient: the responder agent may wish to restrict\ninteractions based on attributes beyond raw capabilities—for example,\nallowing only agents from trusted developers, requiring a minimum identity\nassurance level, or enforcing same-tenant isolation.</p>\n</div>\n<div id=\"S6.SS3.p2\" class=\"ltx_para\">\n<p id=\"S6.SS3.p2.1\" class=\"ltx_p\"><span id=\"S6.SS3.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> introduces a <em id=\"S6.SS3.p2.1.2\" class=\"ltx_emph ltx_font_italic\">two-tier access control model</em> that separates\nplatform-enforced trust from application-level policy:</p>\n</div>\n<div id=\"S6.SS3.p3\" class=\"ltx_para\">\n<ol id=\"S6.I4\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S6.I4.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S6.I4.i1.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i1.p1.1\" class=\"ltx_p\"><span id=\"S6.I4.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Infrastructure tier (mandatory, kernel-enforced):</span>\nCryptographic AIC verification via the GAR. This tier answers: “Is this\nagent who it claims to be?” Both parties’ AICs are verified for\nsignature validity, expiration, and revocation. The infrastructure\ncapability bound <math id=\"S6.I4.i1.p1.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{infra}}=S_{\\max}^{A}\\cap S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mtext>infra</mtext></msub><mo>=</mo><mrow><msubsup><mi>S</mi><mi>max</mi><mi>A</mi></msubsup><mo>∩</mo><msubsup><mi>S</mi><mi>max</mi><mi>B</mi></msubsup></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{infra}}=S_{\\max}^{A}\\cap S_{\\max}^{B}</annotation></semantics></math> is computed.</p>\n</div></li>\n<li id=\"S6.I4.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S6.I4.i2.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.p1.1\" class=\"ltx_p\"><span id=\"S6.I4.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Application tier (optional, agent-defined):</span>\nThe responder agent registers a declarative <em id=\"S6.I4.i2.p1.1.2\" class=\"ltx_emph ltx_font_italic\">access policy</em> that\nevaluates the requester’s AIC attributes:</p>\n<ul id=\"S6.I4.i2.I1\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:1.5em;\">\n<li id=\"S6.I4.i2.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I4.i2.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.I1.i1.p1.1\" class=\"ltx_p\">Required capabilities (requester must possess specific caps)</p>\n</div></li>\n<li id=\"S6.I4.i2.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I4.i2.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.I1.i2.p1.1\" class=\"ltx_p\">Trusted developers (glob patterns on <span id=\"S6.I4.i2.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_typewriter\">developer_id</span>)</p>\n</div></li>\n<li id=\"S6.I4.i2.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I4.i2.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.I1.i3.p1.1\" class=\"ltx_p\">Trusted operators (glob patterns on <span id=\"S6.I4.i2.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_typewriter\">operator_id</span>)</p>\n</div></li>\n<li id=\"S6.I4.i2.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I4.i2.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.I1.i4.p1.1\" class=\"ltx_p\">Minimum identity assurance level (IAL threshold)</p>\n</div></li>\n<li id=\"S6.I4.i2.I1.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I4.i2.I1.i5.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.I1.i5.p1.1\" class=\"ltx_p\">Maximum risk level</p>\n</div></li>\n<li id=\"S6.I4.i2.I1.i6\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I4.i2.I1.i6.p1\" class=\"ltx_para\">\n<p id=\"S6.I4.i2.I1.i6.p1.1\" class=\"ltx_p\">Same-tenant requirement</p>\n</div></li>\n</ul>\n<p id=\"S6.I4.i2.p1.2\" class=\"ltx_p\">The application tier answers: “Does this specific responder want to work\nwith this specific requester?” It produces a (possibly narrowed) set of\n<em id=\"S6.I4.i2.p1.2.1\" class=\"ltx_emph ltx_font_italic\">granted capabilities</em> that is intersected with the infrastructure\nbound.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S6.SS3.p4\" class=\"ltx_para\">\n<p id=\"S6.SS3.p4.1\" class=\"ltx_p\">The final session capability set is:</p>\n<table id=\"S6.E2\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S6.E2.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}=S_{\\text{policy}}\\cap\\bigl(S_{\\max}^{A}\\cap S_{\\max}^{B}\\bigr)\" display=\"block\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mtext>session</mtext></msub><mo>=</mo><mrow><msub><mi>S</mi><mtext>policy</mtext></msub><mo>∩</mo><mrow><mo maxsize=\"1.200em\" minsize=\"1.200em\">(</mo><mrow><msubsup><mi>S</mi><mi>max</mi><mi>A</mi></msubsup><mo>∩</mo><msubsup><mi>S</mi><mi>max</mi><mi>B</mi></msubsup></mrow><mo maxsize=\"1.200em\" minsize=\"1.200em\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{session}}=S_{\\text{policy}}\\cap\\bigl(S_{\\max}^{A}\\cap S_{\\max}^{B}\\bigr)</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(2)</span></td></tr></tbody>\n</table>\n</div>\n<div id=\"S6.SS3.p5\" class=\"ltx_para\">\n<p id=\"S6.SS3.p5.1\" class=\"ltx_p\">This two-tier design has three key advantages over single-layer approaches:</p>\n<ul id=\"S6.I5\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S6.I5.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I5.i1.p1\" class=\"ltx_para\">\n<p id=\"S6.I5.i1.p1.1\" class=\"ltx_p\"><span id=\"S6.I5.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Composability:</span> Infrastructure and application concerns are\nindependently auditable and evolvable.</p>\n</div></li>\n<li id=\"S6.I5.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I5.i2.p1\" class=\"ltx_para\">\n<p id=\"S6.I5.i2.p1.1\" class=\"ltx_p\"><span id=\"S6.I5.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Backward compatibility:</span> Agents without a registered policy\nfall back to the infrastructure tier alone.</p>\n</div></li>\n<li id=\"S6.I5.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S6.I5.i3.p1\" class=\"ltx_para\">\n<p id=\"S6.I5.i3.p1.1\" class=\"ltx_p\"><span id=\"S6.I5.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Fine-grained control:</span> The responder can make admission\ndecisions based on identity attributes that raw capability intersection\ncannot express.</p>\n</div></li>\n</ul>\n</div>\n</section>\n<section id=\"S6.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">6.4  The Capability Narrowing Chain</h3>\n\n<div id=\"S6.SS4.p1\" class=\"ltx_para\">\n<p id=\"S6.SS4.p1.1\" class=\"ltx_p\"><span id=\"S6.SS4.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s approach to authorization can be summarized as a four-stage\n<em id=\"S6.SS4.p1.1.2\" class=\"ltx_emph ltx_font_italic\">narrowing chain</em> in which each stage can only tighten the permission\nboundary:</p>\n</div>\n<div id=\"S6.SS4.p2\" class=\"ltx_para\">\n<table id=\"S6.SS4.p2.1\" class=\"ltx_tabular ltx_centering ltx_align_middle\">\n<tbody class=\"ltx_tbody\">\n<tr id=\"S6.SS4.p2.1.1\" class=\"ltx_tr\">\n<td id=\"S6.SS4.p2.1.1.1\" class=\"ltx_td ltx_align_right\"><span id=\"S6.SS4.p2.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Stage 1:</span></td>\n<td id=\"S6.SS4.p2.1.1.2\" class=\"ltx_td ltx_align_center\"><span id=\"S6.SS4.p2.1.1.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Developer</span></td>\n<td id=\"S6.SS4.p2.1.1.3\" class=\"ltx_td ltx_nopad_l ltx_align_left\"><span id=\"S6.SS4.p2.1.1.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">declares</span></td>\n<td id=\"S6.SS4.p2.1.1.4\" class=\"ltx_td ltx_nopad_l ltx_nopad_r ltx_align_left\"><math id=\"S6.SS4.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{declared}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">declared</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{declared}}</annotation></semantics></math></td></tr>\n<tr id=\"S6.SS4.p2.1.2\" class=\"ltx_tr\">\n<td id=\"S6.SS4.p2.1.2.1\" class=\"ltx_td ltx_align_right\"><span id=\"S6.SS4.p2.1.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Stage 2:</span></td>\n<td id=\"S6.SS4.p2.1.2.2\" class=\"ltx_td ltx_align_center\"><span id=\"S6.SS4.p2.1.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Operator</span></td>\n<td id=\"S6.SS4.p2.1.2.3\" class=\"ltx_td ltx_nopad_l ltx_align_left\"><span id=\"S6.SS4.p2.1.2.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">selects</span></td>\n<td id=\"S6.SS4.p2.1.2.4\" class=\"ltx_td ltx_nopad_l ltx_nopad_r ltx_align_left\"><math id=\"S6.SS4.m2\" class=\"ltx_Math\" alttext=\"S_{\\max}\\subseteq S_{\\text{declared}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi></msub><mo mathsize=\"0.900em\">⊆</mo><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">declared</mtext></msub></mrow><annotation encoding=\"application/x-tex\">S_{\\max}\\subseteq S_{\\text{declared}}</annotation></semantics></math></td></tr>\n<tr id=\"S6.SS4.p2.1.3\" class=\"ltx_tr\">\n<td id=\"S6.SS4.p2.1.3.1\" class=\"ltx_td ltx_align_right\"><span id=\"S6.SS4.p2.1.3.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Stage 3:</span></td>\n<td id=\"S6.SS4.p2.1.3.2\" class=\"ltx_td ltx_align_center\"><span id=\"S6.SS4.p2.1.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">GAR</span></td>\n<td id=\"S6.SS4.p2.1.3.3\" class=\"ltx_td ltx_nopad_l ltx_align_left\"><span id=\"S6.SS4.p2.1.3.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">enforces &amp; signs</span></td>\n<td id=\"S6.SS4.p2.1.3.4\" class=\"ltx_td ltx_nopad_l ltx_nopad_r ltx_align_left\"><math id=\"S6.SS4.m3\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math><span id=\"S6.SS4.p2.1.3.4.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (subset-checked, signed AIC)</span></td></tr>\n<tr id=\"S6.SS4.p2.1.4\" class=\"ltx_tr\">\n<td id=\"S6.SS4.p2.1.4.1\" class=\"ltx_td ltx_align_right\"><span id=\"S6.SS4.p2.1.4.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Stage 4:</span></td>\n<td id=\"S6.SS4.p2.1.4.2\" class=\"ltx_td ltx_align_center\"><span id=\"S6.SS4.p2.1.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">Runtime</span></td>\n<td id=\"S6.SS4.p2.1.4.3\" class=\"ltx_td ltx_nopad_l ltx_align_left\"><span id=\"S6.SS4.p2.1.4.3.1\" class=\"ltx_text\" style=\"font-size:90%;\">intersects</span></td>\n<td id=\"S6.SS4.p2.1.4.4\" class=\"ltx_td ltx_nopad_l ltx_nopad_r ltx_align_left\"><math id=\"S6.SS4.m4\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}\\subseteq S_{\\max}^{A}\\cap S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">S</mi><mtext mathsize=\"0.900em\">session</mtext></msub><mo mathsize=\"0.900em\">⊆</mo><mrow><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mi mathsize=\"0.900em\">A</mi></msubsup><mo mathsize=\"0.900em\">∩</mo><msubsup><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi><mi mathsize=\"0.900em\">B</mi></msubsup></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{session}}\\subseteq S_{\\max}^{A}\\cap S_{\\max}^{B}</annotation></semantics></math></td></tr>\n</tbody>\n</table>\n</div>\n<div id=\"S6.SS4.p3\" class=\"ltx_para\">\n<p id=\"S6.SS4.p3.1\" class=\"ltx_p\">At no point can any party <em id=\"S6.SS4.p3.1.1\" class=\"ltx_emph ltx_font_italic\">widen</em> the boundary set by the preceding\nparty. This is enforced cryptographically: the developer’s signature covers\n<math id=\"S6.SS4.p3.m1\" class=\"ltx_Math\" alttext=\"S_{\\text{declared}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mtext>declared</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{declared}}</annotation></semantics></math>; the GAR’s signature covers <math id=\"S6.SS4.p3.m2\" class=\"ltx_Math\" alttext=\"S_{\\max}\\subseteq S_{\\text{declared}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mi>max</mi></msub><mo>⊆</mo><msub><mi>S</mi><mtext>declared</mtext></msub></mrow><annotation encoding=\"application/x-tex\">S_{\\max}\\subseteq S_{\\text{declared}}</annotation></semantics></math>; the session token is kernel-signed over\n<math id=\"S6.SS4.p3.m3\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}\\subseteq S_{\\max}^{A}\\cap S_{\\max}^{B}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mtext>session</mtext></msub><mo>⊆</mo><mrow><msubsup><mi>S</mi><mi>max</mi><mi>A</mi></msubsup><mo>∩</mo><msubsup><mi>S</mi><mi>max</mi><mi>B</mi></msubsup></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{session}}\\subseteq S_{\\max}^{A}\\cap S_{\\max}^{B}</annotation></semantics></math>. Any attempt to insert\nadditional capabilities requires forging a signature.</p>\n</div>\n<div id=\"S6.SS4.p4\" class=\"ltx_para\">\n<p id=\"S6.SS4.p4.1\" class=\"ltx_p\">This monotonic attenuation provides <em id=\"S6.SS4.p4.1.1\" class=\"ltx_emph ltx_font_italic\">structural least-privilege</em>: the\nproperty holds by construction, not by correct policy configuration.\nMisconfiguring a policy can deny legitimate access but can never grant\nunauthorized capabilities.</p>\n</div>\n</section>\n</section>\n<section id=\"S7\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">7  Layer 3: Accountability &amp; Economics</h2>\n\n<div id=\"S7.p1\" class=\"ltx_para\">\n<p id=\"S7.p1.1\" class=\"ltx_p\">Layers 0–2 establish who an agent is, what it can do, and whom it trusts.\nLayer 3 closes the loop by ensuring that every agent action is\n<em id=\"S7.p1.1.1\" class=\"ltx_emph ltx_font_italic\">traceable</em>, <em id=\"S7.p1.1.2\" class=\"ltx_emph ltx_font_italic\">attributable</em>, and <em id=\"S7.p1.1.3\" class=\"ltx_emph ltx_font_italic\">economically accountable</em>.\nThis layer addresses threats T5 (payment and usage fraud) and T6 (action\nrepudiation) from <a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>.</p>\n</div>\n<section id=\"S7.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">7.1  Token-Usage Tracing</h3>\n\n<div id=\"S7.SS1.p1\" class=\"ltx_para\">\n<p id=\"S7.SS1.p1.1\" class=\"ltx_p\">LLM-powered agents consume computational resources (inference tokens, tool\ninvocations, storage) on behalf of their operators. In multi-agent\nworkflows, a single user request may trigger cascading agent interactions,\neach consuming tokens from different LLM providers. Without identity-aware\nmetering, costs are attributed to API keys rather than to the agents (and\nultimately the humans) who authorized the work.</p>\n</div>\n<div id=\"S7.SS1.p2\" class=\"ltx_para\">\n<p id=\"S7.SS1.p2.1\" class=\"ltx_p\"><span id=\"S7.SS1.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> binds token-usage records to cryptographic agent identity:</p>\n</div>\n<div id=\"S7.SS1.p3\" class=\"ltx_para\"><span id=\"S7.SS1.p3.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S7.SS1.p3.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S7.SS1.p3.p1.1\" class=\"ltx_p\"><span id=\"S7.SS1.p3.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Token-Usage Record</span></span>\n</span>\n<span id=\"S7.SS1.p3.p2\" class=\"ltx_para\">\n<span id=\"S7.SS1.p3.p2.1\" class=\"ltx_tabular ltx_tabbing\">\n<span id=\"S7.SS1.p3.p2.1.1\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.1.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">agent_id<span id=\"S7.SS1.p3.p2.1.1.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.1.2\" class=\"ltx_td ltx_align_left\"><math id=\"S7.SS1.p3.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖣𝖨𝖣</mi><mi mathsize=\"0.900em\">𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math><span id=\"S7.SS1.p3.p2.1.1.2.1\" class=\"ltx_text\" style=\"font-size:90%;\"> of the consuming agent</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.2\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.2.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">session_id<span id=\"S7.SS1.p3.p2.1.2.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.2.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">session token ID from Layer 2 attestation</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.3\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.3.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">provider<span id=\"S7.SS1.p3.p2.1.3.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">LLM provider identifier</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.4\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.4.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">model<span id=\"S7.SS1.p3.p2.1.4.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.4.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">model name and version</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.5\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.5.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">input_tokens<span id=\"S7.SS1.p3.p2.1.5.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.5.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.5.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">prompt token count</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.6\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.6.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">output_tokens<span id=\"S7.SS1.p3.p2.1.6.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.6.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.6.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">completion token count</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.7\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.7.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.7.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">timestamp<span id=\"S7.SS1.p3.p2.1.7.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.7.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.7.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">UTC timestamp</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.8\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.8.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.8.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">delegation_chain<span id=\"S7.SS1.p3.p2.1.8.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.8.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.8.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">ordered list of AIC IDs from root to leaf</span></span></span>\n<span id=\"S7.SS1.p3.p2.1.9\" class=\"ltx_tr\">\n<span id=\"S7.SS1.p3.p2.1.9.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS1.p3.p2.1.9.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">signature<span id=\"S7.SS1.p3.p2.1.9.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS1.p3.p2.1.9.2\" class=\"ltx_td ltx_align_left\"><math id=\"S7.SS1.p3.p2.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{Sign}_{K_{\\mathsf{priv}}}(\\text{record payload})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">𝖲𝗂𝗀𝗇</mi><msub><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗋𝗂𝗏</mi></msub></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><mtext mathsize=\"0.900em\">record payload</mtext><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\mathsf{Sign}_{K_{\\mathsf{priv}}}(\\text{record payload})</annotation></semantics></math><span id=\"S7.SS1.p3.p2.1.9.2.1\" class=\"ltx_text\"></span></span></span>\n</span>\n</span></span>\n</div>\n<div id=\"S7.SS1.p4\" class=\"ltx_para\">\n<p id=\"S7.SS1.p4.1\" class=\"ltx_p\">The delegation chain field enables <em id=\"S7.SS1.p4.1.1\" class=\"ltx_emph ltx_font_italic\">cost attribution up the delegation\ntree</em>: if agent <math id=\"S7.SS1.p4.m1\" class=\"ltx_Math\" alttext=\"C\" display=\"inline\" intent=\":literal\"><semantics><mi>C</mi><annotation encoding=\"application/x-tex\">C</annotation></semantics></math> was delegated by agent <math id=\"S7.SS1.p4.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math>, which was delegated by\nagent <math id=\"S7.SS1.p4.m3\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math> (the root), the usage record traces the cost back to <math id=\"S7.SS1.p4.m4\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math>’s\noperator. Combined with the AIC’s operator identity (OIDC-bound), this\nenables precise per-user, per-agent cost allocation in multi-tenant\nenvironments.</p>\n</div>\n</section>\n<section id=\"S7.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">7.2  Payment Primitives</h3>\n\n<div id=\"S7.SS2.p1\" class=\"ltx_para\">\n<p id=\"S7.SS2.p1.1\" class=\"ltx_p\">As agents increasingly provide services to other agents (e.g., a code-review\nagent charging per review, a data-analysis agent billing per query), the\nInternet of Agents requires payment primitives that are identity-aware and\nauditable.</p>\n</div>\n<div id=\"S7.SS2.p2\" class=\"ltx_para\">\n<p id=\"S7.SS2.p2.1\" class=\"ltx_p\"><span id=\"S7.SS2.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> defines a minimal payment protocol framework built on Layer 0–2\nprimitives:</p>\n</div>\n<div id=\"S7.SS2.p3\" class=\"ltx_para\">\n<ol id=\"S7.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S7.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S7.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S7.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S7.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Price advertisement:</span> An agent’s registration record\n(Layer 1) includes optional pricing metadata (rate type, currency, unit).</p>\n</div></li>\n<li id=\"S7.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S7.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S7.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S7.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Payment negotiation:</span> During mutual attestation (Layer 2),\nthe requester and responder can negotiate payment terms as part of the\nsession establishment. Payment terms are included in the session token\nmetadata.</p>\n</div></li>\n<li id=\"S7.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S7.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S7.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S7.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Service delivery with metering:</span> During the session, both\ntoken usage and service-specific metering events are recorded with\nidentity-signed records (§<a href=\"#S7.SS1\" title=\"7.1 Token-Usage Tracing ‣ 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">7.1</span></a>).</p>\n</div></li>\n<li id=\"S7.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S7.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S7.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S7.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Settlement:</span> After service completion, the metering records\nserve as cryptographically verifiable invoices. Settlement can occur\nthrough traditional payment rails, escrow services, or—for environments\nthat support it—on-chain settlement <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>]</cite>.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S7.SS2.p4\" class=\"ltx_para\">\n<p id=\"S7.SS2.p4.1\" class=\"ltx_p\"><span id=\"S7.SS2.p4.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is deliberately agnostic about the settlement mechanism: it provides the\n<em id=\"S7.SS2.p4.1.2\" class=\"ltx_emph ltx_font_italic\">identity and metering infrastructure</em> that any payment system requires,\nwithout mandating a specific payment rail. This follows Principle P3 (no\ninfrastructure lock-in). Notably, Google’s Agent Payments Protocol\n(AP2) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib55\" title=\"\" class=\"ltx_ref\">45</a>]</cite> is a recent open specification for AI-driven\nagent payments, focusing on the settlement rail and transaction flow. <span id=\"S7.SS2.p4.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> and AP2 are complementary: AP2 defines <em id=\"S7.SS2.p4.1.4\" class=\"ltx_emph ltx_font_italic\">how\nagents pay</em>, while <span id=\"S7.SS2.p4.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> defines <em id=\"S7.SS2.p4.1.6\" class=\"ltx_emph ltx_font_italic\">who is paying whom and with what\nauthority</em>, binding every payment event to a verified cryptographic\nidentity and a capability-bounded session.</p>\n</div>\n</section>\n<section id=\"S7.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">7.3  Action Accountability</h3>\n\n<div id=\"S7.SS3.p1\" class=\"ltx_para\">\n<p id=\"S7.SS3.p1.1\" class=\"ltx_p\">Every action an agent takes—tool invocations, delegations, message\nexchanges—generates an <em id=\"S7.SS3.p1.1.1\" class=\"ltx_emph ltx_font_italic\">execution trace entry</em> that is\ncryptographically signed by the agent’s kernel-held private key:</p>\n</div>\n<div id=\"S7.SS3.p2\" class=\"ltx_para\"><span id=\"S7.SS3.p2.1\" class=\"ltx_inline-logical-block ltx_framed ltx_framed_rectangle\">\n<span id=\"S7.SS3.p2.p1\" class=\"ltx_para ltx_noindent\">\n<span id=\"S7.SS3.p2.p1.1\" class=\"ltx_p\"><span id=\"S7.SS3.p2.p1.1.1\" class=\"ltx_text ltx_font_sansserif ltx_font_bold\">Trace Entry</span></span>\n</span>\n<span id=\"S7.SS3.p2.p2\" class=\"ltx_para\">\n<span id=\"S7.SS3.p2.p2.1\" class=\"ltx_tabular ltx_tabbing\">\n<span id=\"S7.SS3.p2.p2.1.1\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.1.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">trace_id<span id=\"S7.SS3.p2.p2.1.1.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.1.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.1.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">unique identifier</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.2\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.2.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.2.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">agent_id<span id=\"S7.SS3.p2.p2.1.2.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.2.2\" class=\"ltx_td ltx_align_left\"><math id=\"S7.SS3.p2.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">𝖣𝖨𝖣</mi><mi mathsize=\"0.900em\">𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math><span id=\"S7.SS3.p2.p2.1.2.2.1\" class=\"ltx_text\" style=\"font-size:90%;\"> of the acting agent</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.3\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.3.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">action_type<span id=\"S7.SS3.p2.p2.1.3.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.3.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.3.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">tool_call <math id=\"S7.SS3.p2.p2.m2\" class=\"ltx_Math\" alttext=\"|\" display=\"inline\" intent=\":literal\"><semantics><mo fence=\"false\" stretchy=\"false\">|</mo><annotation encoding=\"application/x-tex\">|</annotation></semantics></math> delegation <math id=\"S7.SS3.p2.p2.m3\" class=\"ltx_Math\" alttext=\"|\" display=\"inline\" intent=\":literal\"><semantics><mo fence=\"false\" stretchy=\"false\">|</mo><annotation encoding=\"application/x-tex\">|</annotation></semantics></math> message <math id=\"S7.SS3.p2.p2.m4\" class=\"ltx_Math\" alttext=\"|\" display=\"inline\" intent=\":literal\"><semantics><mo fence=\"false\" stretchy=\"false\">|</mo><annotation encoding=\"application/x-tex\">|</annotation></semantics></math> payment</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.4\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.4.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">action_params<span id=\"S7.SS3.p2.p2.1.4.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.4.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.4.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">structured parameters of the action</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.5\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.5.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">action_result<span id=\"S7.SS3.p2.p2.1.5.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.5.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.5.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">outcome or status</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.6\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.6.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">session_id<span id=\"S7.SS3.p2.p2.1.6.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.6.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.6.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">session context (from Layer 2)</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.7\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.7.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.7.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">timestamp<span id=\"S7.SS3.p2.p2.1.7.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.7.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.7.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">UTC timestamp</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.8\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.8.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.8.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">prev_hash<span id=\"S7.SS3.p2.p2.1.8.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.8.2\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.8.2.1\" class=\"ltx_text\" style=\"font-size:90%;\">hash of the preceding trace entry (chain integrity)</span></span></span>\n<span id=\"S7.SS3.p2.p2.1.9\" class=\"ltx_tr\">\n<span id=\"S7.SS3.p2.p2.1.9.1\" class=\"ltx_td ltx_align_left\"><span id=\"S7.SS3.p2.p2.1.9.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">signature<span id=\"S7.SS3.p2.p2.1.9.1.1.1\" class=\"ltx_text\"></span></span></span>\n<span id=\"S7.SS3.p2.p2.1.9.2\" class=\"ltx_td ltx_align_left\"><math id=\"S7.SS3.p2.p2.m5\" class=\"ltx_math_unparsed\" alttext=\"\\mathsf{Sign}_{K_{\\mathsf{priv}}}(\\text{entry payload}\\,\\|\\,\\text{prev\\_hash})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi mathsize=\"0.900em\">𝖲𝗂𝗀𝗇</mi><msub><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗋𝗂𝗏</mi></msub></msub><mrow><mo maxsize=\"0.900em\" minsize=\"0.900em\">(</mo><mtext mathsize=\"0.900em\">entry payload</mtext><mo lspace=\"0.170em\" mathsize=\"0.900em\" rspace=\"0.337em\">∥</mo><mtext mathsize=\"0.900em\">prev_hash</mtext><mo maxsize=\"0.900em\" minsize=\"0.900em\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\mathsf{Sign}_{K_{\\mathsf{priv}}}(\\text{entry payload}\\,\\|\\,\\text{prev\\_hash})</annotation></semantics></math><span id=\"S7.SS3.p2.p2.1.9.2.1\" class=\"ltx_text\"></span></span></span>\n</span>\n</span></span>\n</div>\n<div id=\"S7.SS3.p3\" class=\"ltx_para\">\n<p id=\"S7.SS3.p3.1\" class=\"ltx_p\">The <span id=\"S7.SS3.p3.1.1\" class=\"ltx_text ltx_font_typewriter\">prev_hash</span> field chains trace entries into a hash-linked log,\nproviding tamper evidence: any modification to\na historical entry breaks the hash chain from that point forward. The\nsignature binds each entry to its agent’s cryptographic identity, providing\nnon-repudiation.</p>\n</div>\n<div id=\"S7.SS3.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S7.SS3.p4.1\" class=\"ltx_p\"><span id=\"S7.SS3.p4.1.1\" class=\"ltx_text ltx_font_bold\">Key gains of kernel-mediated accountability.</span> \nWhat distinguishes <span id=\"S7.SS3.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s accountability model from application-level\nlogging or blockchain-anchored ledgers is its reliance on <em id=\"S7.SS3.p4.1.3\" class=\"ltx_emph ltx_font_italic\">trusted,\nkernel-mediated cryptography</em>. The kernel (whether running locally or as a\nremote service) provides a verifiable, isolated trust boundary, typically\nanchored by hardware mechanisms like Trusted Execution\nEnvironments (TEEs) and secure boot. Because the agent’s private key <math id=\"S7.SS3.p4.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> never leaves\nthis kernel, the architecture yields three key gains:\n(1) <em id=\"S7.SS3.p4.1.4\" class=\"ltx_emph ltx_font_italic\">Decentralized non-repudiation</em>: agents can cryptographically prove\ntheir execution history and attribute costs without relying on a global\nconsensus ledger or trusted third-party auditor.\n(2) <em id=\"S7.SS3.p4.1.5\" class=\"ltx_emph ltx_font_italic\">Deployment ubiquity</em>: immutable audit trails can be maintained even\nin air-gapped, edge, or resource-constrained environments where blockchain\nnodes are economically or technically unviable.\n(3) <em id=\"S7.SS3.p4.1.6\" class=\"ltx_emph ltx_font_italic\">Compromise containment</em>: because the application logic cannot access\nthe raw signing key or rewrite historical logs, an attacker compromising the\nagent’s LLM or memory cannot forge retroactive trace entries, guaranteeing\nthe integrity of the audit trail up to the exact moment of breach.</p>\n</div>\n<div id=\"S7.SS3.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S7.SS3.p5.1\" class=\"ltx_p\"><span id=\"S7.SS3.p5.1.1\" class=\"ltx_text ltx_font_bold\">Contrast with <span id=\"S7.SS3.p5.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span>.</span> \nIn <span id=\"S7.SS3.p5.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite>, audit trails were anchored to a blockchain via\nMerkle proofs, providing immutability backed by distributed consensus. <span id=\"S7.SS3.p5.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> achieves comparable tamper-evidence through identity-signed hash chains,\nwhich work in any environment. For deployments requiring stronger\nimmutability guarantees, the hash chain root can be periodically anchored to\na public timestamping service or distributed ledger.</p>\n</div>\n</section>\n<section id=\"S7.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">7.4  Non-Repudiation</h3>\n\n<div id=\"S7.SS4.p1\" class=\"ltx_para\">\n<p id=\"S7.SS4.p1.1\" class=\"ltx_p\">Non-repudiation in <span id=\"S7.SS4.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> rests on two pillars:</p>\n</div>\n<div id=\"S7.SS4.p2\" class=\"ltx_para\">\n<ol id=\"S7.I2\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S7.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S7.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"S7.I2.i1.p1.1\" class=\"ltx_p\"><span id=\"S7.I2.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Kernel-mediated signing:</span> The agent’s private key\n<math id=\"S7.I2.i1.p1.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> is held exclusively by the kernel. All signing operations\n(attestation challenges, session tokens, trace entries, usage records)\nare mediated by the kernel’s signing API. The agent’s application logic\ncannot forge signatures because it never has access to the raw key.</p>\n</div></li>\n<li id=\"S7.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S7.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"S7.I2.i2.p1.1\" class=\"ltx_p\"><span id=\"S7.I2.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">AIC chain binding:</span> Every signature can be verified against\nthe agent’s AIC, which chains back to the GAR root key. The verifier\nneeds only the GAR’s public key (a well-known trust anchor) to validate\nany trace entry from any agent in the ecosystem.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S7.SS4.p3\" class=\"ltx_para\">\n<p id=\"S7.SS4.p3.1\" class=\"ltx_p\">Together, these mechanisms ensure that if a trace entry bears a valid\nsignature under an agent’s <math id=\"S7.SS4.p3.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{pub}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗎𝖻</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{pub}}</annotation></semantics></math>, and the agent’s AIC chain verifies back\nto the GAR root, then the named agent <em id=\"S7.SS4.p3.1.1\" class=\"ltx_emph ltx_font_italic\">did</em> perform the recorded action.\nThe agent cannot repudiate it without claiming that the kernel was\ncompromised—a claim that can be evaluated against the key protection tier\n(<a href=\"#S4.T3\" title=\"In 4.4 Key Protection Tiers ‣ 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">3</span></a>) and deployment attestation records.</p>\n</div>\n</section>\n</section>\n<section id=\"S8\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">8  Security Analysis</h2>\n\n<div id=\"S8.p1\" class=\"ltx_para\">\n<p id=\"S8.p1.1\" class=\"ltx_p\">A protocol suite spanning identity, discovery, trust negotiation, and accountability must be evaluated by whether its properties hold jointly under a defined attacker model. This section provides a rigorous, property-centric security evaluation of <span id=\"S8.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>. <a href=\"#S8.T5\" title=\"In 8.1 Threat Model and Assumptions ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">5</span></a> summarizes the security properties provided by <span id=\"S8.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</p>\n</div>\n<section id=\"S8.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">8.1  Threat Model and Assumptions</h3>\n\n<div id=\"S8.SS1.p1\" class=\"ltx_para\">\n<p id=\"S8.SS1.p1.1\" class=\"ltx_p\">We assume a <em id=\"S8.SS1.p1.1.1\" class=\"ltx_emph ltx_font_italic\">Dolev-Yao network adversary</em> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">46</a>]</cite> capable of intercepting, replaying, and injecting messages across all network paths. Crucially, the adversary is augmented with <em id=\"S8.SS1.p1.1.2\" class=\"ltx_emph ltx_font_italic\">LLM-level compromise capabilities</em>: it can control an agent’s application logic, issue arbitrary API calls, and observe context data (e.g., via prompt injection or malicious memory retrieval). However, the attacker <em id=\"S8.SS1.p1.1.3\" class=\"ltx_emph ltx_font_italic\">cannot</em> extract the agent’s private key <math id=\"S8.SS1.p1.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> from the underlying kernel or compromise the kernel’s signing API.</p>\n</div>\n<div id=\"S8.SS1.p2\" class=\"ltx_para\">\n<p id=\"S8.SS1.p2.1\" class=\"ltx_p\">Our evaluation rests on three cryptographic and structural assumptions: (1) <span id=\"S8.SS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">GAR Honesty</span>: The Global Agent Registry root key is uncompromised and accurately verifies developer/operator bindings during AIC issuance. (2) <span id=\"S8.SS1.p2.1.2\" class=\"ltx_text ltx_font_bold\">Kernel Integrity</span>: The agent’s key-custody layer (the kernel) enforces delegation bounds and never signs payloads without authorization. (3) <span id=\"S8.SS1.p2.1.3\" class=\"ltx_text ltx_font_bold\">Cryptographic Soundness</span>: Ed25519 provides existential unforgeability (EUF-CMA) and <math id=\"S8.SS1.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{H}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖧</mi><annotation encoding=\"application/x-tex\">\\mathsf{H}</annotation></semantics></math> is collision-resistant. Graceful degradation assumptions, such as loose time synchronization and OIDC provider honesty, limit the scope of localized failures without causing systemic compromise.</p>\n</div>\n<figure id=\"S8.T5\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\"><span id=\"S8.T5.4\" class=\"ltx_text\" style=\"font-size:90%;\">Table 5</span>: </span><span id=\"S8.T5.5\" class=\"ltx_text\" style=\"font-size:90%;\">Security properties of the <span id=\"S8.T5.5.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> protocol suite. Threats refer to <a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>.</span></figcaption>\n<table id=\"S8.T5.6\" class=\"ltx_tabular ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S8.T5.6.1\" class=\"ltx_tr\">\n<th id=\"S8.T5.6.1.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_tt\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.1.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:69.0pt;\">\n<span id=\"S8.T5.6.1.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Property</span></span>\n</span></th>\n<th id=\"S8.T5.6.1.2\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T5.6.1.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Mechanism</span></span>\n</span></th>\n<th id=\"S8.T5.6.1.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_tt\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.1.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T5.6.1.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Guarantee Level</span></span>\n</span></th>\n<th id=\"S8.T5.6.1.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_tt\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.1.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:41.4pt;\">\n<span id=\"S8.T5.6.1.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.1.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Threats</span></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S8.T5.6.2\" class=\"ltx_tr\">\n<td id=\"S8.T5.6.2.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.2.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:69.0pt;\">\n<span id=\"S8.T5.6.2.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.2.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Identity Integrity</span></span>\n</span></td>\n<td id=\"S8.T5.6.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T5.6.2.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Four-dimensional AIC binding, GAR root anchor</span></span>\n</span></td>\n<td id=\"S8.T5.6.2.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.2.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T5.6.2.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Cryptographic</span></span>\n</span></td>\n<td id=\"S8.T5.6.2.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.2.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:41.4pt;\">\n<span id=\"S8.T5.6.2.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.2.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T1, T4</span></span>\n</span></td></tr>\n<tr id=\"S8.T5.6.3\" class=\"ltx_tr\">\n<td id=\"S8.T5.6.3.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.3.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:69.0pt;\">\n<span id=\"S8.T5.6.3.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.3.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Capability Confinement</span></span>\n</span></td>\n<td id=\"S8.T5.6.3.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T5.6.3.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Monotonic attenuation chain, two-tier access control</span></span>\n</span></td>\n<td id=\"S8.T5.6.3.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.3.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T5.6.3.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Structural</span></span>\n</span></td>\n<td id=\"S8.T5.6.3.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.3.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:41.4pt;\">\n<span id=\"S8.T5.6.3.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.3.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T2</span></span>\n</span></td></tr>\n<tr id=\"S8.T5.6.4\" class=\"ltx_tr\">\n<td id=\"S8.T5.6.4.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:69.0pt;\">\n<span id=\"S8.T5.6.4.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.4.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Delegation Safety</span></span>\n</span></td>\n<td id=\"S8.T5.6.4.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T5.6.4.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Subset enforcement, depth bounds, tenant isolation</span></span>\n</span></td>\n<td id=\"S8.T5.6.4.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.4.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T5.6.4.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Crypto + Structural</span></span>\n</span></td>\n<td id=\"S8.T5.6.4.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.4.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:41.4pt;\">\n<span id=\"S8.T5.6.4.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.4.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T2, T3</span></span>\n</span></td></tr>\n<tr id=\"S8.T5.6.5\" class=\"ltx_tr\">\n<td id=\"S8.T5.6.5.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.5.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:69.0pt;\">\n<span id=\"S8.T5.6.5.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.5.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Discovery Integrity</span></span>\n</span></td>\n<td id=\"S8.T5.6.5.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T5.6.5.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Verifiable credentials, supply-chain validation</span></span>\n</span></td>\n<td id=\"S8.T5.6.5.3\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.5.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T5.6.5.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Verifiable Cred.</span></span>\n</span></td>\n<td id=\"S8.T5.6.5.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.5.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:41.4pt;\">\n<span id=\"S8.T5.6.5.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.5.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T1, T2</span></span>\n</span></td></tr>\n<tr id=\"S8.T5.6.6\" class=\"ltx_tr\">\n<td id=\"S8.T5.6.6.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_bb\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.6.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:69.0pt;\">\n<span id=\"S8.T5.6.6.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.6.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Accountability</span></span>\n</span></td>\n<td id=\"S8.T5.6.6.2\" class=\"ltx_td ltx_align_left ltx_border_bb\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.6.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T5.6.6.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.6.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Kernel-mediated signing, hash-linked execution logs</span></span>\n</span></td>\n<td id=\"S8.T5.6.6.3\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_bb\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.6.3.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T5.6.6.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.6.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Cryptographic</span></span>\n</span></td>\n<td id=\"S8.T5.6.6.4\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_align_top ltx_border_bb\" style=\"padding-left:4.0pt;padding-right:4.0pt;\">\n<span id=\"S8.T5.6.6.4.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:41.4pt;\">\n<span id=\"S8.T5.6.6.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T5.6.6.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">T5, T6</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n</section>\n<section id=\"S8.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">8.2  Property-Centric Security Evaluation</h3>\n\n<div id=\"S8.SS2.p1\" class=\"ltx_para\">\n<p id=\"S8.SS2.p1.1\" class=\"ltx_p\">We prove that <span id=\"S8.SS2.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> satisfies its core security properties under the defined threat model, directly neutralizing threats T1–T6 (<a href=\"#S2.T1\" title=\"In 2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>).</p>\n</div>\n<div id=\"S8.SS2.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S8.SS2.p2.1\" class=\"ltx_p\"><span id=\"S8.SS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Identity &amp; Authenticity (T1, T4).</span> \nAn adversary attempting to spoof an agent’s identity (T1) must forge the Agent Identity Credential (AIC). The AIC requires four independently verified signatures: developer code-package digest, build pipeline attestation, OIDC operator binding, and the final GAR endorsement. Because each dimension is cryptographically bound and verified prior to GAR issuance, single-dimension compromise (e.g., a rogue OIDC provider) cannot yield full identity forgery. At runtime, mutual attestation defeats replay attacks by requiring fresh nonce signing, proving possession of <math id=\"S8.SS2.p2.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math>. Furthermore, the GAR acts as a shared root of trust, enabling cross-domain verification (T4) via a single AIC chain, eliminating the need for pairwise trust agreements.</p>\n</div>\n<div id=\"S8.SS2.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S8.SS2.p3.1\" class=\"ltx_p\"><span id=\"S8.SS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Capability Confinement &amp; Delegation Safety (T2, T3).</span> \n<span id=\"S8.SS2.p3.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> neutralizes capability escalation (T2) structurally. The monotonic attenuation chain ensures that permissions can only be narrowed at each delegation stage (developer <math id=\"S8.SS2.p3.m1\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math> operator <math id=\"S8.SS2.p3.m2\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math> GAR <math id=\"S8.SS2.p3.m3\" class=\"ltx_Math\" alttext=\"\\to\" display=\"inline\" intent=\":literal\"><semantics><mo stretchy=\"false\">→</mo><annotation encoding=\"application/x-tex\">\\to</annotation></semantics></math> session). For any chain <math id=\"S8.SS2.p3.m4\" class=\"ltx_Math\" alttext=\"\\mathsf{AIC}_{0}\\to\\dots\\to\\mathsf{AIC}_{n}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>𝖠𝖨𝖢</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><mi mathvariant=\"normal\">…</mi><mo stretchy=\"false\">→</mo><msub><mi>𝖠𝖨𝖢</mi><mi>n</mi></msub></mrow><annotation encoding=\"application/x-tex\">\\mathsf{AIC}_{0}\\to\\dots\\to\\mathsf{AIC}_{n}</annotation></semantics></math>, the invariant <math id=\"S8.SS2.p3.m5\" class=\"ltx_Math\" alttext=\"S_{\\max}^{\\mathsf{AIC}_{n}}\\subseteq\\dots\\subseteq S_{\\max}^{\\mathsf{AIC}_{0}}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msubsup><mi>S</mi><mi>max</mi><msub><mi>𝖠𝖨𝖢</mi><mi>n</mi></msub></msubsup><mo>⊆</mo><mi mathvariant=\"normal\">⋯</mi><mo>⊆</mo><msubsup><mi>S</mi><mi>max</mi><msub><mi>𝖠𝖨𝖢</mi><mn>0</mn></msub></msubsup></mrow><annotation encoding=\"application/x-tex\">S_{\\max}^{\\mathsf{AIC}_{n}}\\subseteq\\dots\\subseteq S_{\\max}^{\\mathsf{AIC}_{0}}</annotation></semantics></math> is enforced cryptographically; violating it requires forging a signature at a prior stage. At runtime, the two-tier access control model computes <math id=\"S8.SS2.p3.m6\" class=\"ltx_Math\" alttext=\"S_{\\text{session}}=S_{\\text{policy}}\\cap(S_{\\max}^{A}\\cap S_{\\max}^{B})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mtext>session</mtext></msub><mo>=</mo><mrow><msub><mi>S</mi><mtext>policy</mtext></msub><mo>∩</mo><mrow><mo stretchy=\"false\">(</mo><mrow><msubsup><mi>S</mi><mi>max</mi><mi>A</mi></msubsup><mo>∩</mo><msubsup><mi>S</mi><mi>max</mi><mi>B</mi></msubsup></mrow><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">S_{\\text{session}}=S_{\\text{policy}}\\cap(S_{\\max}^{A}\\cap S_{\\max}^{B})</annotation></semantics></math>. Even if the application-level policy (<math id=\"S8.SS2.p3.m7\" class=\"ltx_Math\" alttext=\"S_{\\text{policy}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mtext>policy</mtext></msub><annotation encoding=\"application/x-tex\">S_{\\text{policy}}</annotation></semantics></math>) is compromised or misconfigured, it cannot grant access beyond the cryptographically verified infrastructure bound. Delegation abuse (T3) is prevented via depth bounding, strict validity capping, tenant isolation, and cascading revocation, ensuring delegation cannot be used as a capability-laundering channel.</p>\n</div>\n<div id=\"S8.SS2.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S8.SS2.p4.1\" class=\"ltx_p\"><span id=\"S8.SS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Discovery Integrity (T1, T2).</span> \nExisting discovery directories suffer from self-declared, unverified claims. <span id=\"S8.SS2.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> transforms discovery into a verify-then-interact boundary using Verifiable Credentials (VCs). An agent cannot advertise unauthorized skills because manifest VCs undergo strict verification: supply-chain signature checks, subject binding against the presenter’s <math id=\"S8.SS2.p4.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{DID}_{\\mathsf{agent}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝖣𝖨𝖣</mi><mi>𝖺𝗀𝖾𝗇𝗍</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{DID}_{\\mathsf{agent}}</annotation></semantics></math>, and permission alignment against the agent’s <math id=\"S8.SS2.p4.m2\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math>. Consequently, discovery cannot serve as an implicit escalation path.</p>\n</div>\n<div id=\"S8.SS2.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S8.SS2.p5.1\" class=\"ltx_p\"><span id=\"S8.SS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Accountability &amp; Non-repudiation (T5, T6).</span> \nAction repudiation (T6) and usage fraud (T5) are mitigated without relying on distributed consensus. Every operational trace entry is signed by <math id=\"S8.SS2.p5.m1\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math> under kernel mediation. Since application logic never possesses <math id=\"S8.SS2.p5.m2\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mi>𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math>, an LLM-compromised agent cannot forge signatures. Furthermore, trace entries are linked via cryptographic hashes (<span id=\"S8.SS2.p5.1.2\" class=\"ltx_text ltx_font_typewriter\">prev_hash</span>); an attacker modifying past entries invalidates the chain. Hence, usage records remain cryptographically attributable up the delegation tree to a human-accountable operator.</p>\n</div>\n</section>\n<section id=\"S8.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">8.3  Security under Composition</h3>\n\n<div id=\"S8.SS3.p1\" class=\"ltx_para\">\n<p id=\"S8.SS3.p1.1\" class=\"ltx_p\">A common pitfall in protocol design is composition failure, where security properties holding in isolation break when layers interact. <span id=\"S8.SS3.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> achieves composition safety through strict <em id=\"S8.SS3.p1.1.2\" class=\"ltx_emph ltx_font_italic\">downward-only dependencies</em> and <em id=\"S8.SS3.p1.1.3\" class=\"ltx_emph ltx_font_italic\">independent failure domains</em>. The guarantees of higher layers rely only on the invariants of lower layers, never the reverse. For instance, L2 session capability intersection relies on L0’s AIC integrity; however, a misconfigured L2 application policy cannot widen L0’s cryptographic capability boundary. Similarly, L3 accountability depends solely on L0’s kernel-mediated key custody, remaining tamper-evident regardless of L1 discovery mechanisms or L2 trust negotiation flaws. This structural isolation ensures that a compromise at the application or discovery layer cannot weaken the cryptographic and identity invariants enforced by the infrastructure.</p>\n</div>\n</section>\n<section id=\"S8.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">8.4  Comparison and Residual Risks</h3>\n\n<div id=\"S8.SS4.p1\" class=\"ltx_para\">\n<p id=\"S8.SS4.p1.1\" class=\"ltx_p\"><a href=\"#S8.T6\" title=\"In 8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">6</span></a> illustrates <span id=\"S8.SS4.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s structural guarantees compared to AgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite>, AIP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite>, and <span id=\"S8.SS4.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite> under specific failure scenarios. Where existing approaches rely on correct runtime policy configuration (e.g., AgentMesh) or omit protocol-level delegation attenuation (e.g., <span id=\"S8.SS4.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span>), <span id=\"S8.SS4.p1.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> provides cryptographic bounds that fail closed independently of the policy engine.</p>\n</div>\n<figure id=\"S8.T6\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\"><span id=\"S8.T6.3\" class=\"ltx_text\" style=\"font-size:90%;\">Table 6</span>: </span><span id=\"S8.T6.4\" class=\"ltx_text\" style=\"font-size:90%;\">Security guarantee comparison under failure scenarios. <math id=\"S8.T6.m4\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi>✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math> = guarantee holds, <math id=\"S8.T6.m5\" class=\"ltx_Math\" alttext=\"\\times\" display=\"inline\" intent=\":literal\"><semantics><mo>×</mo><annotation encoding=\"application/x-tex\">\\times</annotation></semantics></math> = guarantee breaks, <math id=\"S8.T6.m6\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math> = bounded break.</span></figcaption>\n<table id=\"S8.T6.5\" class=\"ltx_tabular ltx_guessed_headers ltx_align_middle\">\n<thead class=\"ltx_thead\">\n<tr id=\"S8.T6.5.1\" class=\"ltx_tr\">\n<th id=\"S8.T6.5.1.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S8.T6.5.1.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T6.5.1.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Scenario</span></span>\n</span></th>\n<th id=\"S8.T6.5.1.2\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S8.T6.5.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.1.2.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.1.2.1.1.1\" class=\"ltx_text ltx_font_bold ltx_font_smallcaps\" style=\"font-size:90%;\">InterSAGE</span></span>\n</span></th>\n<th id=\"S8.T6.5.1.3\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S8.T6.5.1.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.1.3.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">AgentMesh</span><span id=\"S8.T6.5.1.3.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S8.T6.5.1.3.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a><span id=\"S8.T6.5.1.3.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite></span>\n</span></th>\n<th id=\"S8.T6.5.1.4\" class=\"ltx_td ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S8.T6.5.1.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.1.4.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.1.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">AIP</span><span id=\"S8.T6.5.1.4.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S8.T6.5.1.4.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a><span id=\"S8.T6.5.1.4.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite></span>\n</span></th>\n<th id=\"S8.T6.5.1.5\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_th ltx_th_column ltx_border_tt\">\n<span id=\"S8.T6.5.1.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.1.5.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.1.5.1.1.1\" class=\"ltx_text ltx_font_bold ltx_font_smallcaps\" style=\"font-size:90%;\">BlockA2A</span><span id=\"S8.T6.5.1.5.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> </span><cite class=\"ltx_cite ltx_citemacro_cite\"><span id=\"S8.T6.5.1.5.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">[</span><a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a><span id=\"S8.T6.5.1.5.1.1.4\" class=\"ltx_text\" style=\"font-size:90%;\">]</span></cite></span>\n</span></th></tr>\n</thead>\n<tbody class=\"ltx_tbody\">\n<tr id=\"S8.T6.5.2\" class=\"ltx_tr\">\n<td id=\"S8.T6.5.2.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.2.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T6.5.2.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.2.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">PDP misconfigured to allow </span><span id=\"S8.T6.5.2.1.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">tools:*</span></span>\n</span></td>\n<td id=\"S8.T6.5.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.2.2.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m7\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math><span id=\"S8.T6.5.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (bound by </span><math id=\"S8.T6.m8\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math><span id=\"S8.T6.5.2.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> intersection)</span></span>\n</span></td>\n<td id=\"S8.T6.5.2.3\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.2.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.2.3.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m9\" class=\"ltx_Math\" alttext=\"\\times\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.900em\">×</mo><annotation encoding=\"application/x-tex\">\\times</annotation></semantics></math><span id=\"S8.T6.5.2.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (single-PDP silently grants access)</span></span>\n</span></td>\n<td id=\"S8.T6.5.2.4\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.2.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.2.4.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m10\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\" mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math><span id=\"S8.T6.5.2.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (depends on Datalog correctness)</span></span>\n</span></td>\n<td id=\"S8.T6.5.2.5\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_t\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.2.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.2.5.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m11\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math><span id=\"S8.T6.5.2.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (smart contract enforced)</span></span>\n</span></td></tr>\n<tr id=\"S8.T6.5.3\" class=\"ltx_tr\">\n<td id=\"S8.T6.5.3.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.3.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T6.5.3.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.3.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Operator credential compromised</span></span>\n</span></td>\n<td id=\"S8.T6.5.3.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.3.2.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m12\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\" mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math><span id=\"S8.T6.5.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (developer + code signatures remain valid)</span></span>\n</span></td>\n<td id=\"S8.T6.5.3.3\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.3.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.3.3.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m13\" class=\"ltx_Math\" alttext=\"\\times\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.900em\">×</mo><annotation encoding=\"application/x-tex\">\\times</annotation></semantics></math><span id=\"S8.T6.5.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (workload impersonation)</span></span>\n</span></td>\n<td id=\"S8.T6.5.3.4\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.3.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.3.4.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m14\" class=\"ltx_Math\" alttext=\"\\times\" display=\"inline\" intent=\":literal\"><semantics><mo mathsize=\"0.900em\">×</mo><annotation encoding=\"application/x-tex\">\\times</annotation></semantics></math><span id=\"S8.T6.5.3.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (root issuer mints full capabilities)</span></span>\n</span></td>\n<td id=\"S8.T6.5.3.5\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.3.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.3.5.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m15\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\" mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math><span id=\"S8.T6.5.3.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (no dev/operator separation)</span></span>\n</span></td></tr>\n<tr id=\"S8.T6.5.4\" class=\"ltx_tr\">\n<td id=\"S8.T6.5.4.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T6.5.4.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.4.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Child escalating beyond parent’s </span><math id=\"S8.T6.m16\" class=\"ltx_Math\" alttext=\"S_{\\max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">S</mi><mi mathsize=\"0.900em\">max</mi></msub><annotation encoding=\"application/x-tex\">S_{\\max}</annotation></semantics></math></span>\n</span></td>\n<td id=\"S8.T6.5.4.2\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.4.2.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m17\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math><span id=\"S8.T6.5.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (cryptographic subset enforcement)</span></span>\n</span></td>\n<td id=\"S8.T6.5.4.3\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.4.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.4.3.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m18\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\" mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math><span id=\"S8.T6.5.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (runtime policy error enables escalation)</span></span>\n</span></td>\n<td id=\"S8.T6.5.4.4\" class=\"ltx_td ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.4.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.4.4.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m19\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math><span id=\"S8.T6.5.4.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (attenuation at token level)</span></span>\n</span></td>\n<td id=\"S8.T6.5.4.5\" class=\"ltx_td ltx_nopad_r ltx_align_left\" style=\"padding-bottom: 6.0pt;\">\n<span id=\"S8.T6.5.4.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.4.5.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.4.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">— (no protocol-level delegation attenuation)</span></span>\n</span></td></tr>\n<tr id=\"S8.T6.5.5\" class=\"ltx_tr\">\n<td id=\"S8.T6.5.5.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_bb\">\n<span id=\"S8.T6.5.5.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:75.9pt;\">\n<span id=\"S8.T6.5.5.1.1.1\" class=\"ltx_p ltx_align_left\"><span id=\"S8.T6.5.5.1.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Attacker rewrites past execution logs</span></span>\n</span></td>\n<td id=\"S8.T6.5.5.2\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S8.T6.5.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.5.2.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m20\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math><span id=\"S8.T6.5.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (</span><math id=\"S8.T6.m21\" class=\"ltx_Math\" alttext=\"K_{\\mathsf{priv}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi mathsize=\"0.900em\">K</mi><mi mathsize=\"0.900em\">𝗉𝗋𝗂𝗏</mi></msub><annotation encoding=\"application/x-tex\">K_{\\mathsf{priv}}</annotation></semantics></math><span id=\"S8.T6.5.5.2.1.1.2\" class=\"ltx_text\" style=\"font-size:90%;\"> kernel-mediated, hash chain)</span></span>\n</span></td>\n<td id=\"S8.T6.5.5.3\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S8.T6.5.5.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.5.3.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m22\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\" mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math><span id=\"S8.T6.5.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (application-level logging)</span></span>\n</span></td>\n<td id=\"S8.T6.5.5.4\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S8.T6.5.5.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.5.4.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m23\" class=\"ltx_Math\" alttext=\"\\triangle\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\" mathvariant=\"normal\">△</mi><annotation encoding=\"application/x-tex\">\\triangle</annotation></semantics></math><span id=\"S8.T6.5.5.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (application-level logging)</span></span>\n</span></td>\n<td id=\"S8.T6.5.5.5\" class=\"ltx_td ltx_nopad_r ltx_align_left ltx_border_bb\">\n<span id=\"S8.T6.5.5.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S8.T6.5.5.5.1.1\" class=\"ltx_p ltx_align_left\"><math id=\"S8.T6.m24\" class=\"ltx_Math\" alttext=\"\\checkmark\" display=\"inline\" intent=\":literal\"><semantics><mi mathsize=\"0.900em\">✓</mi><annotation encoding=\"application/x-tex\">\\checkmark</annotation></semantics></math><span id=\"S8.T6.5.5.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\"> (blockchain immutability)</span></span>\n</span></td></tr>\n</tbody>\n</table>\n</figure>\n<div id=\"S8.SS4.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S8.SS4.p2.1\" class=\"ltx_p\"><span id=\"S8.SS4.p2.1.1\" class=\"ltx_text ltx_font_bold\">Scope Boundaries.</span> \nCertain risks fall explicitly outside <span id=\"S8.SS4.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s protocol scope. <span id=\"S8.SS4.p2.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> secures <em id=\"S8.SS4.p2.1.4\" class=\"ltx_emph ltx_font_italic\">identity and authorization limits</em>, not cognitive correctness. If an agent suffers a prompt injection that causes it to misuse its <em id=\"S8.SS4.p2.1.5\" class=\"ltx_emph ltx_font_italic\">authorized</em> capabilities, this is an LLM-level cognitive failure rather than a protocol flaw. Furthermore, catastrophic infrastructure compromise (e.g., GAR root key theft) or hardware-level key extraction (bypassing the kernel) represent ultimate trust boundaries mitigated by external operational security measures, such as HSMs and Trusted Execution Environments (TEEs), rather than protocol-level invariants.</p>\n</div>\n</section>\n</section>\n<section id=\"S9\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">9  Related Work</h2>\n\n<div id=\"S9.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.p1.1\" class=\"ltx_p\"><span id=\"S9.p1.1.1\" class=\"ltx_text ltx_font_bold\">How we contrast <span id=\"S9.p1.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> with prior work.</span> \nWe organize the rapidly growing body of agent protocol and security\nresearch into six clusters and contrast <span id=\"S9.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> with each using a uniform\nthree-step pattern: (i) the goal or mechanism that <span id=\"S9.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> <em id=\"S9.p1.1.4\" class=\"ltx_emph ltx_font_italic\">shares</em>\nwith the cluster, (ii) the specific point of <em id=\"S9.p1.1.5\" class=\"ltx_emph ltx_font_italic\">divergence</em>, named\nin the canonical vocabulary of persistent identity,\ncapability-aware discovery, trust negotiation, and accountability, and\n(iii) the operationally observable <em id=\"S9.p1.1.6\" class=\"ltx_emph ltx_font_italic\">consequence</em>—typically a\nconcrete attacker action or misconfiguration that <span id=\"S9.p1.1.7\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> structurally\ndenies and the comparator catches only via runtime policy evaluation,\nbehavioral attestation, or operator vigilance. We use this pattern\nbecause it forces every distinction claim to be grounded in mechanism\nrather than rhetoric.</p>\n</div>\n<div id=\"S9.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.p2.1\" class=\"ltx_p\"><span id=\"S9.p2.1.1\" class=\"ltx_text ltx_font_bold\">What <span id=\"S9.p2.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> inherits.</span> \n<span id=\"S9.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is not built from scratch. It inherits decentralized identifiers\nand verifiable credentials from the W3C and SSI lineage, SPIFFE-style\nworkload attestation, OAuth/OIDC scoping vocabulary, capability tokens\nin the UCAN/Biscuit lineage, the idea of monotonic attenuation as a\ndelegation discipline, signed software manifests, and tamper-evident\nhash-chained audit. <span id=\"S9.p2.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s\ncontribution is the <em id=\"S9.p2.1.4\" class=\"ltx_emph ltx_font_italic\">architecture that combines and structurally\nenforces</em> these primitives within a single coherent four-layer trust\nplane; we therefore foreground the conjunction rather than any\nindividual primitive.</p>\n</div>\n<div id=\"S9.p3\" class=\"ltx_para\">\n<p id=\"S9.p3.1\" class=\"ltx_p\"><a href=\"#S9.T7\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">7</span></a> compares <span id=\"S9.p3.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> with representative approaches across\nthirteen evaluation dimensions ordered to mirror the four-layer trust\nsubstrate in <a href=\"#S3.F1\" title=\"In 3.2 Protocol Suite Architecture ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Figure</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>. <span id=\"S9.p3.1.2\" class=\"ltx_text ltx_font_italic\">Layer 0 (Agent\nIdentity)</span> uses rows 1–2 (<em id=\"S9.p3.1.3\" class=\"ltx_emph ltx_font_italic\">persistent identity</em>,\n<em id=\"S9.p3.1.4\" class=\"ltx_emph ltx_font_italic\">four-dimensional binding</em>). <span id=\"S9.p3.1.5\" class=\"ltx_text ltx_font_italic\">Layer 1 (Discovery)</span> uses\nrows 3–4 (<em id=\"S9.p3.1.6\" class=\"ltx_emph ltx_font_italic\">capability-aware discovery</em>, <em id=\"S9.p3.1.7\" class=\"ltx_emph ltx_font_italic\">verifiable\nmanifests</em>). <span id=\"S9.p3.1.8\" class=\"ltx_text ltx_font_italic\">Layer 2 (Trust Negotiation)</span> uses rows 5–8 in the\nsame sequence as §<a href=\"#S3.SS2\" title=\"3.2 Protocol Suite Architecture ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3.2</span></a>: <em id=\"S9.p3.1.9\" class=\"ltx_emph ltx_font_italic\">mutual attestation</em>,\n<em id=\"S9.p3.1.10\" class=\"ltx_emph ltx_font_italic\">monotonic attenuation</em>, <em id=\"S9.p3.1.11\" class=\"ltx_emph ltx_font_italic\">two-tier access control</em>, then\n<em id=\"S9.p3.1.12\" class=\"ltx_emph ltx_font_italic\">delegation chains</em>. <span id=\"S9.p3.1.13\" class=\"ltx_text ltx_font_italic\">Layer 3 (Accountability)</span> uses\nrows 9–12 in the same sequence as §<a href=\"#S7\" title=\"7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">7</span></a>:\n<em id=\"S9.p3.1.14\" class=\"ltx_emph ltx_font_italic\">token-usage tracing</em>, <em id=\"S9.p3.1.15\" class=\"ltx_emph ltx_font_italic\">payment primitives</em>, <em id=\"S9.p3.1.16\" class=\"ltx_emph ltx_font_italic\">action\naccountability</em>, <em id=\"S9.p3.1.17\" class=\"ltx_emph ltx_font_italic\">non-repudiation</em>. Row 13 is cross-cutting\n<em id=\"S9.p3.1.18\" class=\"ltx_emph ltx_font_italic\">deployment generality</em> (independent of any single layer).</p>\n</div>\n<figure id=\"S9.T7\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\"><span id=\"S9.T7.8\" class=\"ltx_text\" style=\"font-size:90%;\">Table 7</span>: </span><span id=\"S9.T7.9\" class=\"ltx_text\" style=\"font-size:90%;\">Comparison of <span id=\"S9.T7.9.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> with representative agent security approaches.\n<math id=\"S9.T7.m5\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math> = comprehensive support, <math id=\"S9.T7.m6\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math> = partial\nsupport, <span id=\"S9.T7.9.2\" class=\"ltx_text ltx_font_bold\">—</span> = not addressed.\nRows follow the <span id=\"S9.T7.9.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> four-layer suite (<a href=\"#S3.F1\" title=\"In 3.2 Protocol Suite Architecture ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Figure</span> <span class=\"ltx_text ltx_ref_tag\">1</span></a>): L0\nAgent Identity (1–2), L1 Discovery (3–4), L2 Trust Negotiation (5–8\nin protocol flow order), L3 Accountability (9–12), then deployment\ngenerality (13). The leftmost column labels the protocol layer for each\nblock; <em id=\"S9.T7.9.4\" class=\"ltx_emph ltx_font_italic\">Cross</em> marks a cross-cutting deployment dimension.\nFor deployment generality:\n<math id=\"S9.T7.m7\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math> = cloud + edge + air-gapped,\n<math id=\"S9.T7.m8\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math> = cloud-only or specific infrastructure,\n<span id=\"S9.T7.9.5\" class=\"ltx_text ltx_font_bold\">—</span> = blockchain required.</span></figcaption>\n<table id=\"S9.T7.10\" class=\"ltx_tabular ltx_align_middle\">\n<tbody class=\"ltx_tbody\">\n<tr id=\"S9.T7.10.1\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.1.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<span id=\"S9.T7.10.1.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:37.5pt;\">\n<span id=\"S9.T7.10.1.1.1.1\" class=\"ltx_p ltx_align_center\"><span id=\"S9.T7.10.1.1.1.1.1\" class=\"ltx_text ltx_font_bold\">Layer</span></span>\n</span></td>\n<td id=\"S9.T7.10.1.2\" class=\"ltx_td ltx_align_left ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><span id=\"S9.T7.10.1.2.1\" class=\"ltx_text ltx_font_bold\">Dimension</span></td>\n<td id=\"S9.T7.10.1.3\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.3.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:24.2pt;height:51.1pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"width:51.9pt;transform:translate(-13.9pt,-22.1pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.3.1.1\" class=\"ltx_p\"><span id=\"S9.T7.10.1.3.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span></p>\n</span></div></td>\n<td id=\"S9.T7.10.1.4\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.4.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:25.2pt;height:49.3pt;vertical-align:-0.7pt;\"><span class=\"ltx_transformed_inner\" style=\"width:49.2pt;transform:translate(-12.0pt,-20.2pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.4.1.1\" class=\"ltx_p\">AgentMesh</p>\n</span></div></td>\n<td id=\"S9.T7.10.1.5\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.5.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:12.5pt;height:19.2pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"width:17.9pt;transform:translate(-2.7pt,-6.2pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.5.1.1\" class=\"ltx_p\">AIP</p>\n</span></div></td>\n<td id=\"S9.T7.10.1.6\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.6.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:13.9pt;height:23pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"width:21.9pt;transform:translate(-4.0pt,-8.1pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.6.1.1\" class=\"ltx_p\">HDP</p>\n</span></div></td>\n<td id=\"S9.T7.10.1.7\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.7.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:13.9pt;height:22.8pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"width:21.8pt;transform:translate(-4.0pt,-8.0pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.7.1.1\" class=\"ltx_p\">ANP</p>\n</span></div></td>\n<td id=\"S9.T7.10.1.8\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.8.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:19.5pt;height:33.8pt;vertical-align:-0.7pt;\"><span class=\"ltx_transformed_inner\" style=\"width:32.8pt;transform:translate(-6.7pt,-12.5pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.8.1.1\" class=\"ltx_p\">Ag-OSI</p>\n</span></div></td>\n<td id=\"S9.T7.10.1.9\" class=\"ltx_td ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.9.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:19.1pt;height:37.1pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"width:36.9pt;transform:translate(-8.9pt,-15.1pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.9.1.1\" class=\"ltx_p\">ZT-IAM</p>\n</span></div></td>\n<td id=\"S9.T7.10.1.10\" class=\"ltx_td ltx_nopad_r ltx_align_center ltx_border_tt\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<div id=\"S9.T7.10.1.10.1\" class=\"ltx_inline-block ltx_transformed_outer\" style=\"width:22.9pt;height:47.4pt;vertical-align:-0.0pt;\"><span class=\"ltx_transformed_inner\" style=\"width:47.9pt;transform:translate(-12.5pt,-20.2pt) rotate(-70deg) ;\">\n<p id=\"S9.T7.10.1.10.1.1\" class=\"ltx_p\"><span id=\"S9.T7.10.1.10.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span></p>\n</span></div></td></tr>\n<tr id=\"S9.T7.10.2\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.2.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<span id=\"S9.T7.10.2.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:37.5pt;\">\n<span id=\"S9.T7.10.2.1.1.1\" class=\"ltx_p ltx_align_center\">L0</span>\n</span></td>\n<td id=\"S9.T7.10.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Persistent identity</td>\n<td id=\"S9.T7.10.2.3\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m9\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.2.4\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m10\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.2.5\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m11\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.2.6\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.2.7\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m12\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.2.8\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m13\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.2.9\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m14\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.2.10\" class=\"ltx_td ltx_nopad_r ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m15\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td></tr>\n<tr id=\"S9.T7.10.3\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.3.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.3.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">4-dim binding</td>\n<td id=\"S9.T7.10.3.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m16\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.3.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m17\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.3.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.3.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.3.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.3.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.3.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m18\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.3.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.4\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.4.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<span id=\"S9.T7.10.4.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:37.5pt;\">\n<span id=\"S9.T7.10.4.1.1.1\" class=\"ltx_p ltx_align_center\">L1</span>\n</span></td>\n<td id=\"S9.T7.10.4.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Capability-aware discovery</td>\n<td id=\"S9.T7.10.4.3\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m19\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.4.4\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m20\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.4.5\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.4.6\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.4.7\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m21\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.4.8\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m22\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.4.9\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m23\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.4.10\" class=\"ltx_td ltx_nopad_r ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.5\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.5.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.5.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Verifiable manifests</td>\n<td id=\"S9.T7.10.5.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m24\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.5.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.5.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.5.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.5.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.5.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.5.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m25\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.5.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.6\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.6.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<span id=\"S9.T7.10.6.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:37.5pt;\">\n<span id=\"S9.T7.10.6.1.1.1\" class=\"ltx_p ltx_align_center\">L2</span>\n</span></td>\n<td id=\"S9.T7.10.6.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Mutual attestation</td>\n<td id=\"S9.T7.10.6.3\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m26\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.6.4\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m27\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.6.5\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m28\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.6.6\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.6.7\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m29\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.6.8\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.6.9\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m30\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.6.10\" class=\"ltx_td ltx_nopad_r ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m31\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td></tr>\n<tr id=\"S9.T7.10.7\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.7.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.7.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Monotonic attenuation</td>\n<td id=\"S9.T7.10.7.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m32\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.7.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.7.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m33\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.7.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.7.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.7.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.7.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.7.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.8\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.8.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.8.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Two-tier access control</td>\n<td id=\"S9.T7.10.8.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m34\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.8.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.8.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.8.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.8.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.8.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.8.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.8.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m35\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td></tr>\n<tr id=\"S9.T7.10.9\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.9.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.9.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Delegation chains</td>\n<td id=\"S9.T7.10.9.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m36\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.9.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m37\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.9.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m38\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.9.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m39\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.9.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.9.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.9.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m40\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.9.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.10\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.10.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<span id=\"S9.T7.10.10.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:37.5pt;\">\n<span id=\"S9.T7.10.10.1.1.1\" class=\"ltx_p ltx_align_center\">L3</span>\n</span></td>\n<td id=\"S9.T7.10.10.2\" class=\"ltx_td ltx_align_left ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Token-usage tracing</td>\n<td id=\"S9.T7.10.10.3\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m41\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.10.4\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m42\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.10.5\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.10.6\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.10.7\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.10.8\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.10.9\" class=\"ltx_td ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.10.10\" class=\"ltx_td ltx_nopad_r ltx_align_center ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.11\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.11.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.11.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Payment primitives</td>\n<td id=\"S9.T7.10.11.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m43\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.11.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.11.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.11.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.11.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.11.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m44\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.11.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.11.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n<tr id=\"S9.T7.10.12\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.12.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.12.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Action accountability</td>\n<td id=\"S9.T7.10.12.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m45\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.12.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m46\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.12.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m47\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.12.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m48\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.12.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.12.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m49\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.12.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m50\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.12.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m51\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td></tr>\n<tr id=\"S9.T7.10.13\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.13.1\" class=\"ltx_td ltx_align_left ltx_align_top\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"></td>\n<td id=\"S9.T7.10.13.2\" class=\"ltx_td ltx_align_left\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Non-repudiation</td>\n<td id=\"S9.T7.10.13.3\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m52\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.13.4\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m53\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.13.5\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m54\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.13.6\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m55\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.13.7\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.13.8\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.13.9\" class=\"ltx_td ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.13.10\" class=\"ltx_td ltx_nopad_r ltx_align_center\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m56\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td></tr>\n<tr id=\"S9.T7.10.14\" class=\"ltx_tr\">\n<td id=\"S9.T7.10.14.1\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">\n<span id=\"S9.T7.10.14.1.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:37.5pt;\">\n<span id=\"S9.T7.10.14.1.1.1\" class=\"ltx_p ltx_align_center\"><em id=\"S9.T7.10.14.1.1.1.1\" class=\"ltx_emph ltx_font_italic\">Cross</em></span>\n</span></td>\n<td id=\"S9.T7.10.14.2\" class=\"ltx_td ltx_align_left ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">Deployment generality</td>\n<td id=\"S9.T7.10.14.3\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m57\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.14.4\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m58\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.14.5\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m59\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.14.6\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m60\" class=\"ltx_Math\" alttext=\"\\bullet\" display=\"inline\" intent=\":literal\"><semantics><mo>∙</mo><annotation encoding=\"application/x-tex\">\\bullet</annotation></semantics></math></td>\n<td id=\"S9.T7.10.14.7\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m61\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.14.8\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td>\n<td id=\"S9.T7.10.14.9\" class=\"ltx_td ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\"><math id=\"S9.T7.m62\" class=\"ltx_Math\" alttext=\"\\circ\" display=\"inline\" intent=\":literal\"><semantics><mo>∘</mo><annotation encoding=\"application/x-tex\">\\circ</annotation></semantics></math></td>\n<td id=\"S9.T7.10.14.10\" class=\"ltx_td ltx_nopad_r ltx_align_center ltx_border_bb ltx_border_t\" style=\"padding-left:3.0pt;padding-right:3.0pt;\">—</td></tr>\n</tbody>\n</table>\n</figure>\n<section id=\"S9.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.1  Communication Stacks vs. Security-First Substrates</h3>\n\n<div id=\"S9.SS1.p1\" class=\"ltx_para\">\n<p id=\"S9.SS1.p1.1\" class=\"ltx_p\">A first cluster of work designs communication-first stacks for the\nInternet of Agents. Fleming et al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">11</a>]</cite> propose reference layers for agent\ncommunication (L8) and semantics (L9) atop TCP/IP (outside the classical OSI\nmodel);\nAgent-OSI <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>]</cite> proposes a six-layer decentralized stack with\nidentity, settlement, and provenance; ACPS <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib6\" title=\"\" class=\"ltx_ref\">14</a>]</cite> defines\nregistration, discovery, interaction, and tooling protocols; Coral\nProtocol <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib5\" title=\"\" class=\"ltx_ref\">29</a>]</cite> provides open infrastructure for\ncommunication, coordination, trust, and payments; the OpenAgents\nNetwork Model <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib7\" title=\"\" class=\"ltx_ref\">47</a>]</cite> defines an event-centered\nnetwork abstraction with scoped networks, routable addresses, mods,\nresources, discovery, and transport bindings; Du\net al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib8\" title=\"\" class=\"ltx_ref\">48</a>]</cite> analyze agent communication from five\nclassical Internet-architecture perspectives; the IoA framework of Chen\net al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">4</a>]</cite> and the survey by Wang\net al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">9</a>]</cite> provide ecosystem perspectives; and\nGoogle’s Agent Payments Protocol (AP2) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib55\" title=\"\" class=\"ltx_ref\">45</a>]</cite> is a prominent\nopen effort focused on AI-driven agent payments. A parallel cluster of comparative\nsurveys <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib9\" title=\"\" class=\"ltx_ref\">12</a>, <a href=\"#bib.bib10\" title=\"\" class=\"ltx_ref\">13</a>, <a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">30</a>, <a href=\"#bib.bib12\" title=\"\" class=\"ltx_ref\">49</a>, <a href=\"#bib.bib13\" title=\"\" class=\"ltx_ref\">50</a>, <a href=\"#bib.bib14\" title=\"\" class=\"ltx_ref\">51</a>, <a href=\"#bib.bib15\" title=\"\" class=\"ltx_ref\">52</a>]</cite>\ncatalog and compare these efforts (including landscape surveys with limited\nsecurity depth, such as <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib13\" title=\"\" class=\"ltx_ref\">50</a>, <a href=\"#bib.bib14\" title=\"\" class=\"ltx_ref\">51</a>]</cite>); across these surveys, security is\ntypically treated as one dimension among several rather than as a dedicated,\ncryptographically bound trust layer.</p>\n</div>\n<div id=\"S9.SS1.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS1.p2.1\" class=\"ltx_p\"><span id=\"S9.SS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Relation to <span id=\"S9.SS1.p2.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \n<span id=\"S9.SS1.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> shares with these works the goal of supporting interoperable\nmulti-agent collaboration; it diverges by being a security-first\nprotocol suite that is agnostic to the underlying communication stack,\nand is therefore designed to <em id=\"S9.SS1.p2.1.3\" class=\"ltx_emph ltx_font_italic\">complement</em> rather than compete with\nany of the architectures above. In particular, OpenAgents is best\nunderstood as a network model rather than an in-depth security or\nverifiability design: its verification levels and guard mods name where\nauthentication, access control, and rate limiting can occur, but they do\nnot specify AIC-style multi-dimensional identity binding, signed\ncapability manifests, monotonic attenuation, two-tier authorization, or\ntamper-evident audit. Similarly, while ANP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">8</a>]</cite> uses\nW3C DIDs for discovery and mutual verification, its published design does\nnot specify structured delegation chains or a tamper-evident accountability\nlayer comparable to <span id=\"S9.SS1.p2.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>; attestation and access control are lighter than\ncryptographically bound, challenge-response attestation with monotonic\ncapability attenuation. Agent-OSI <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">10</a>]</cite> provides comprehensive\nlayering and prototypes on-chain escrow and verification in its reference\nimplementation, limiting deployment generality where blockchain is required. The observable consequence is that <span id=\"S9.SS1.p2.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> can layer\non top of MCP, A2A, ANP, ACPS, Agent-OSI, or OpenAgents-style event\nnetworks without changes to the host protocol’s wire format.</p>\n</div>\n</section>\n<section id=\"S9.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.2  Single-Dimension IAM vs. Multi-Dimensional Binding</h3>\n\n<div id=\"S9.SS2.p1\" class=\"ltx_para\">\n<p id=\"S9.SS2.p1.1\" class=\"ltx_p\">A second cluster retrofits human-IAM primitives onto agent flows. The\nOpenID Foundation’s strategic agenda <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">25</a>]</cite> catalogs the\ngaps in extending OAuth 2.0 and OpenID Connect to agentic\nauthorization; OIDC-A <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">24</a>]</cite> is the most concrete OIDC extension\nto date, defining standard claims for agent identity, attestation, and\ndelegation chains. South et\nal. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib27\" title=\"\" class=\"ltx_ref\">36</a>, <a href=\"#bib.bib28\" title=\"\" class=\"ltx_ref\">53</a>]</cite>\nextend OAuth 2.0 with agent-specific credentials and natural-language\npermission scoping. Bhushan et al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib36\" title=\"\" class=\"ltx_ref\">37</a>]</cite> provide a\nfive-pattern taxonomy organizing SPIFFE/SPIRE, OAuth 2.0, OIDC, Token\nExchange, DPoP, CIBA, and decentralized identity by interaction type\n(user-to-agent, orchestrator-to-agent, agent-to-internal,\nagent-to-external, cross-domain federation). On the\ndecentralized-identity side, Aydeger and\nZeydan <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib29\" title=\"\" class=\"ltx_ref\">54</a>]</cite> integrate SSI with LLM agents\non a blockchain backend; AGNTCY Identity <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib59\" title=\"\" class=\"ltx_ref\">55</a>]</cite> and\nBillionsNetwork <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib60\" title=\"\" class=\"ltx_ref\">56</a>]</cite> provide open-source\ntoolkits using W3C VCs and the iden3 protocol respectively.</p>\n</div>\n<div id=\"S9.SS2.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS2.p2.1\" class=\"ltx_p\"><span id=\"S9.SS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Relation to <span id=\"S9.SS2.p2.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \n<span id=\"S9.SS2.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> shares with this cluster the use of standardized credential\nformats and the goal of cross-domain agent authentication. It diverges\nby defining an agent-native AIC lifecycle whose four-dimensional\nbinding (developer, code package, operator, context) is signed at\nissuance, rather than treating the agent as a single OAuth client or a\nsingle VC holder. The consequence is that an attacker who steals an\noperator’s OAuth client secret or who phishes a holder key cannot\nsilently substitute a different code package or claim a different\ndeveloper, because each dimension carries its own independently\nverifiable signature—a property no OAuth or single-holder DID\nextension provides.</p>\n</div>\n</section>\n<section id=\"S9.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.3  Directory Discovery vs. Capability-Aware Manifests</h3>\n\n<div id=\"S9.SS3.p1\" class=\"ltx_para\">\n<p id=\"S9.SS3.p1.1\" class=\"ltx_p\">A third cluster builds zero-trust identity and discovery infrastructure\nfor agents. The DID/VC + Agent Name Service strand—Huang\net al.’s zero-trust framework with DIDs, VCs, ANS, and ZKPs <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib22\" title=\"\" class=\"ltx_ref\">41</a>]</cite>,\nthe ANS itself as a DNS-inspired PKI directory <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib25\" title=\"\" class=\"ltx_ref\">57</a>]</cite>, and Garzon\net al.’s ledger-anchored DID/VC prototype for cross-domain LLM-agent\nauthentication <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib24\" title=\"\" class=\"ltx_ref\">43</a>]</cite>—focuses on <em id=\"S9.SS3.p1.1.1\" class=\"ltx_emph ltx_font_italic\">discovery and\nauthentication</em>. The SPIFFE-on-Kubernetes strand—Huang and Hughes’s\nSpringer chapter on agentic AI identity\nsecurity <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib26\" title=\"\" class=\"ltx_ref\">39</a>]</cite>, Pappu et al.’s\nSPIFFE-based zero-trust authentication <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">40</a>]</cite>,\nBhushan’s explainable zero-trust framework <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib31\" title=\"\" class=\"ltx_ref\">58</a>]</cite>, and\nPalavali’s SSI-for-microservices framework <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">59</a>]</cite>—focuses\non <em id=\"S9.SS3.p1.1.2\" class=\"ltx_emph ltx_font_italic\">workload attestation and short-lived credentials</em>. A third\nstrand frames the problem at the enterprise governance layer:\nRamachandran and Mishra’s identity-aware\ngovernance <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">22</a>]</cite> explicitly proposes\nambient-authority elimination, infrastructure-level policy\nenforcement, sequence-aware authorization, independent action\nverification, and hallucination-aware audit, and grounds these in\ndocumented production incidents.</p>\n</div>\n<div id=\"S9.SS3.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS3.p2.1\" class=\"ltx_p\"><span id=\"S9.SS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">Relation to <span id=\"S9.SS3.p2.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \n<span id=\"S9.SS3.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> shares with this cluster the zero-trust posture and the use of\nDID/SPIFFE-style cryptographic identity. It diverges in two ways. First,\nthe DID/VC works typically bind only the <em id=\"S9.SS3.p2.1.3\" class=\"ltx_emph ltx_font_italic\">holder</em> dimension and\nthe SPIFFE works only the <em id=\"S9.SS3.p2.1.4\" class=\"ltx_emph ltx_font_italic\">workload-instance</em> dimension; <span id=\"S9.SS3.p2.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s\nAIC binds developer, code package, operator, and context as\nindependently signed dimensions, so the four-dimensional binding\nstrictly subsumes both. Second, the enterprise-governance proposals\nshare <span id=\"S9.SS3.p2.1.6\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s two-tier intuition (separating infrastructure from\napplication policy) but realize it through a single PDP at the\ninfrastructure layer; <span id=\"S9.SS3.p2.1.7\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> realizes it as two independent evaluation\npaths with independent failure semantics. The consequence is that a\nPDP misconfiguration in the application tier cannot weaken\ncryptographic AIC verification in the infrastructure tier, and vice\nversa—each tier fails closed independently.</p>\n</div>\n</section>\n<section id=\"S9.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.4  Policy-Evaluated vs. Structurally-Attenuated Delegation</h3>\n\n<div id=\"S9.SS4.p1\" class=\"ltx_para\">\n<p id=\"S9.SS4.p1.1\" class=\"ltx_p\">A fourth cluster focuses specifically on <em id=\"S9.SS4.p1.1.1\" class=\"ltx_emph ltx_font_italic\">delegation chains</em> as\nfirst-class protocol artifacts. We discuss this cluster in detail\nbecause it is where the monotonic-capability-attenuation primitive of\n<span id=\"S9.SS4.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> has the closest competitors.</p>\n</div>\n<div id=\"S9.SS4.p2\" class=\"ltx_para\">\n<p id=\"S9.SS4.p2.1\" class=\"ltx_p\">AIP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite> introduces Invocation-Bound Capability Tokens\n(IBCTs) that fuse identity, attenuated authorization, and provenance\ninto an append-only token chain, with compact (signed JWT) and chained\n(Biscuit/Datalog) wire formats and transport bindings for MCP, A2A,\nand HTTP. LDP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib17\" title=\"\" class=\"ltx_ref\">60</a>]</cite> extends this with rich delegate\nidentity cards carrying quality hints, governed sessions, and trust\ndomains as protocol-level boundaries. HDP <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib41\" title=\"\" class=\"ltx_ref\">61</a>]</cite> (an IETF\nInternet-Draft) provides a lightweight Ed25519 hop-chain dedicated to\n<em id=\"S9.SS4.p2.1.1\" class=\"ltx_emph ltx_font_italic\">human delegation provenance</em> in agentic systems. Saavedra’s\nframework <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib34\" title=\"\" class=\"ltx_ref\">26</a>]</cite> introduces Delegation Grants\n(DGs)—first-class authorization artifacts with explicitly enforced\nscope reduction—together with a Canonical Verification Context, a\nTrust Gateway, and optional blockchain anchoring. South et\nal.’s authenticated delegation <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib27\" title=\"\" class=\"ltx_ref\">36</a>, <a href=\"#bib.bib28\" title=\"\" class=\"ltx_ref\">53</a>]</cite> extends OAuth 2.0/OIDC with\nagent-specific credentials and natural-language scoping for delegation\nchains.</p>\n</div>\n<div id=\"S9.SS4.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS4.p3.1\" class=\"ltx_p\"><span id=\"S9.SS4.p3.1.1\" class=\"ltx_text ltx_font_bold\">Relation to <span id=\"S9.SS4.p3.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \nAll five works share with <span id=\"S9.SS4.p3.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> the goal of bounding what a delegated\nagent may do and producing an auditable chain of authority; AIP and\nSaavedra’s DGs go furthest by making attenuation a structural property\nof the credential rather than only a runtime check. The divergences\nare mechanism-specific. AIP’s attenuation is <em id=\"S9.SS4.p3.1.3\" class=\"ltx_emph ltx_font_italic\">invocation-scoped</em>\nand <em id=\"S9.SS4.p3.1.4\" class=\"ltx_emph ltx_font_italic\">policy-evaluated</em>: each IBCT carries Datalog rules\nre-evaluated at every hop, and the verifier must run a Datalog engine\nto reject a malformed token. <span id=\"S9.SS4.p3.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s attenuation is\n<em id=\"S9.SS4.p3.1.6\" class=\"ltx_emph ltx_font_italic\">lifecycle-scoped</em> and <em id=\"S9.SS4.p3.1.7\" class=\"ltx_emph ltx_font_italic\">intersection-evaluated</em>: the\ncapability boundary is signed into the AIC at issuance and every\nsubsequent narrowing reduces to set-intersection plus signature\nverification—no Datalog runtime, no per-hop policy interpretation.\nNeither AIP nor Saavedra’s DGs separate <em id=\"S9.SS4.p3.1.8\" class=\"ltx_emph ltx_font_italic\">developer</em> from\n<em id=\"S9.SS4.p3.1.9\" class=\"ltx_emph ltx_font_italic\">operator</em> as distinct issuance stages, so a compromised AIP\nroot issuer or a compromised DG-issuing trust gateway can mint a\ncredential with the full upstream capability set; <span id=\"S9.SS4.p3.1.10\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s\nfour-dimensional binding makes the developer-declared boundary and\nthe operator-provisioned subset two distinct cryptographic stages, so\nan operator-tier compromise structurally cannot escalate beyond the\ndeveloper-tier boundary. HDP and the OAuth-extension delegation\nproposals address human-to-agent provenance and OAuth compatibility\nrespectively, but do not extend monotonic attenuation across the\nmulti-stage agent supply chain. The observable consequence is that\nthe two attack categories that AIP’s chained model uniquely catches\n(delegation-depth violations and audit evasion via empty\ncontext <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">21</a>]</cite>) are also caught by <span id=\"S9.SS4.p3.1.11\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>, plus a third\ncategory—operator-tier capability widening—that AIP’s\nsingle-issuer model does not catch.</p>\n</div>\n</section>\n<section id=\"S9.SS5\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.5  Conformance Testing vs. Cryptographic Enforcement</h3>\n\n<div id=\"S9.SS5.p1\" class=\"ltx_para\">\n<p id=\"S9.SS5.p1.1\" class=\"ltx_p\">A fifth cluster articulates security principles and threat models for\nthe agentic ecosystem rather than full protocols. AgentRFC <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">16</a>]</cite>\nis the closest principles framework to <span id=\"S9.SS5.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>: it defines a six-layer\nAgent Protocol Stack analogous to ITU-T X.800 for OSI, formalizes\neleven security principles as TLA+ invariants with an explicit\nproperty taxonomy (spec-mandated, spec-recommended, AASM-hardening,\nAPS-completeness), and introduces the Composition Safety\nprinciple—the observation that security properties holding for\nindividual protocols can break when protocols are composed through\nshared infrastructure. The AgentConform tooling extracts normative\nclauses into a typed Protocol IR and model-checks the resulting TLA+\nmodel. Anbiaee et al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib39\" title=\"\" class=\"ltx_ref\">17</a>]</cite> present\ncomparative threat modeling across MCP, A2A, Agora, and ANP and\nenumerate twelve protocol-level risks. Wibowo and\nPolyzos <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib40\" title=\"\" class=\"ltx_ref\">18</a>]</cite> argue that agentic safety is an architectural\nprinciple rather than an add-on, and bottom-up deconstruct single-,\nmulti-, and interoperable-multi-agent stacks. Chaffer’s “Know Your\nAgent” <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib23\" title=\"\" class=\"ltx_ref\">62</a>]</cite> proposes a governance frame centered on\nidentity verification, behavioral monitoring, and accountability; the agent discovery survey by Guo\net al. <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib15\" title=\"\" class=\"ltx_ref\">52</a>]</cite> introduces a two-stage\ncapability-discovery framework with semantic modeling.</p>\n</div>\n<div id=\"S9.SS5.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS5.p2.1\" class=\"ltx_p\"><span id=\"S9.SS5.p2.1.1\" class=\"ltx_text ltx_font_bold\">Relation to <span id=\"S9.SS5.p2.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \n<span id=\"S9.SS5.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> shares with AgentRFC the diagnosis that agent protocols need a\nprincipled security framework, and we adopt the Composition Safety\nprinciple in our threat model (§<a href=\"#S2.SS2\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2.2</span></a>). The\ndivergence is that AgentRFC’s invariants are <em id=\"S9.SS5.p2.1.3\" class=\"ltx_emph ltx_font_italic\">model-checked</em>\nproperties intended for conformance testing of independent protocols,\nwhereas <span id=\"S9.SS5.p2.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s invariants are <em id=\"S9.SS5.p2.1.5\" class=\"ltx_emph ltx_font_italic\">cryptographically structural</em>—the\nmonotonic capability attenuation chain enforces the bound at the\ncredential level, not at the spec-conformance level. The consequence\nis complementary: AgentRFC can flag where existing specs leave\nComposition Safety gaps; <span id=\"S9.SS5.p2.1.6\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> provides a credential format that\ncloses those gaps by construction. The threat-modeling and\ngovernance-framework works are likewise complementary—they identify\nrisks that <span id=\"S9.SS5.p2.1.7\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is designed to neutralize architecturally rather than\narticulate.</p>\n</div>\n</section>\n<section id=\"S9.SS6\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.6  Single-Plane Overlays vs. Two-Tier Authorization</h3>\n\n<div id=\"S9.SS6.p1\" class=\"ltx_para\">\n<p id=\"S9.SS6.p1.1\" class=\"ltx_p\">The sixth cluster contains the two industry- or industry-adjacent\nefforts that share <span id=\"S9.SS6.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s framing as a trust layer added on top of\nexisting communication protocols: Microsoft’s\nAgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite> and Huang et al.’s unified zero-trust\narchitecture for the agentic web <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">20</a>]</cite>.</p>\n</div>\n<div id=\"S9.SS6.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS6.p2.1\" class=\"ltx_p\"><span id=\"S9.SS6.p2.1.1\" class=\"ltx_text ltx_font_bold\">AgentMesh.</span> \nAgentMesh, released as part of the Agent Governance Toolkit, is marketed in\nits documentation as “SSL for AI agents” (Public Preview). It organizes its architecture into\nfour layers: (i) an identity and zero-trust core using Agent CA with\nSPIFFE/SVID identities and Ed25519 or ML-DSA-65 signatures; (ii) a\ntrust and protocol bridge that translates between A2A, MCP, and IATP\nwith capability scoping; (iii) a compliance and policy plane; and\n(iv) a reward and learning engine. Project documentation claims alignment\nwith the OWASP Agentic Top 10 categories and ships an MCP proxy.</p>\n</div>\n<div id=\"S9.SS6.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS6.p3.1\" class=\"ltx_p\"><span id=\"S9.SS6.p3.1.1\" class=\"ltx_text ltx_font_bold\">Relation to <span id=\"S9.SS6.p3.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \n<span id=\"S9.SS6.p3.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> and AgentMesh share the high-level goal of adding a trust layer\nto the multi-agent ecosystem and both use signed credentials for\nidentity. They differ in five mechanism-level ways, each with a\nconcrete observable consequence:</p>\n<ol id=\"S9.I1\" class=\"ltx_enumerate\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S9.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S9.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S9.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S9.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Identity model.</span> AgentMesh’s SPIFFE-based identity\nbinds a key to a single workload instance; <span id=\"S9.I1.i1.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s AIC binds\ndeveloper, code package, operator, and operational context as\nfour independently signed dimensions. <em id=\"S9.I1.i1.p1.1.3\" class=\"ltx_emph ltx_font_italic\">Consequence:</em> an\nattacker who compromises an AgentMesh workload signs valid SVIDs\nfor the workload’s identity but cannot prove anything about its\ncode provenance; under <span id=\"S9.I1.i1.p1.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>, the same compromise cannot\nimpersonate a different developer or substitute a different code\npackage because the developer and code-package signatures are\nindependent of the operator-tier credential.</p>\n</div></li>\n<li id=\"S9.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S9.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S9.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S9.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Bound enforcement: structural vs. policy-based.</span>\nAgentMesh enforces least-privilege through a runtime policy\nengine: a misconfigured policy rule (e.g., a tenant operator\naccidentally granting <span id=\"S9.I1.i2.p1.1.2\" class=\"ltx_text ltx_font_typewriter\">tools:*</span>) can silently grant\nexcessive access. <span id=\"S9.I1.i2.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s monotonic capability attenuation chain\nencodes the bound at credential issuance, so the same policy edit\ncannot widen capability beyond the developer-declared boundary\nregardless of any subsequent runtime policy decision.\n<em id=\"S9.I1.i2.p1.1.4\" class=\"ltx_emph ltx_font_italic\">Consequence:</em> <span id=\"S9.I1.i2.p1.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> remains safe under PDP misconfiguration\nin a way AgentMesh does not.</p>\n</div></li>\n<li id=\"S9.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S9.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S9.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S9.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Access-control architecture.</span> AgentMesh uses a single\npolicy plane that conflates cryptographic verification with\ndeclarative authorization. <span id=\"S9.I1.i3.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s two-tier access control keeps\ninfrastructure-tier checks (AIC validity, capability\nintersection) on a separate evaluation path from application-tier\ndeclarative rules. <em id=\"S9.I1.i3.p1.1.3\" class=\"ltx_emph ltx_font_italic\">Consequence:</em> an application-tier\nregression cannot weaken cryptographic checks, and an\ninfrastructure-tier credential lapse cannot bypass per-agent\nauthorization—each failure mode is independently auditable.</p>\n</div></li>\n<li id=\"S9.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S9.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S9.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S9.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Protocol relationship.</span> AgentMesh ships explicit\nA2A/MCP/IATP protocol translators; <span id=\"S9.I1.i4.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is protocol-agnostic and\nprovides trust primitives that any host protocol can bind to.\n<em id=\"S9.I1.i4.p1.1.3\" class=\"ltx_emph ltx_font_italic\">Consequence:</em> <span id=\"S9.I1.i4.p1.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> does not require a translator update to\nsupport a new host protocol, and protocol additions do not\nexpand the trust-layer attack surface.</p>\n</div></li>\n<li id=\"S9.I1.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">5.</span> \n<div id=\"S9.I1.i5.p1\" class=\"ltx_para\">\n<p id=\"S9.I1.i5.p1.1\" class=\"ltx_p\"><span id=\"S9.I1.i5.p1.1.1\" class=\"ltx_text ltx_font_bold\">Scope.</span> AgentMesh embeds a reward and learning engine\nfor adaptive governance. <span id=\"S9.I1.i5.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> deliberately confines itself to\nthe trust and accountability layer and treats adaptive behavior\nas orthogonal. <em id=\"S9.I1.i5.p1.1.3\" class=\"ltx_emph ltx_font_italic\">Consequence:</em> <span id=\"S9.I1.i5.p1.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s verifier semantics\nremain pure cryptographic checks, simplifying formal verification\nand audit.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S9.SS6.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS6.p4.1\" class=\"ltx_p\"><span id=\"S9.SS6.p4.1.1\" class=\"ltx_text ltx_font_bold\">Unified zero-trust architecture (Huang et al.).</span> \n<span id=\"S9.SS6.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s closest <em id=\"S9.SS6.p4.1.3\" class=\"ltx_emph ltx_font_italic\">academic</em> comparator is Huang\net al.’s unified zero-trust architecture <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">20</a>]</cite>, which\nlikewise proposes a unified zero-trust architecture for the agentic web.\nIt builds on DIDs, VCs, and ANS for identity and discovery and adds\nthree mechanisms: Trust-Adaptive Runtime Environments (TARE), Causal\nChain Auditing, and Dynamic Identity with Behavioral Attestation. It\nshares with <span id=\"S9.SS6.p4.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> the diagnosis that the agentic web needs a unified\ntrust layer; it diverges by enforcing trust through <em id=\"S9.SS6.p4.1.5\" class=\"ltx_emph ltx_font_italic\">runtime\nbehavioral attestation and trust scoring</em> rather than through\nissuance-time cryptographic attenuation. The observable consequence is\nthat an agent whose behavior has not yet diverged from baseline\nreceives a high trust score from TARE even if its capability\nboundary has been silently widened upstream; under <span id=\"S9.SS6.p4.1.6\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> the same\nagent’s AIC-bounded capability set is unchanged regardless of\nbehavioral history.</p>\n</div>\n</section>\n<section id=\"S9.SS7\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.7  Our Prior Work: <span id=\"S9.SS7.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span></h3>\n\n<div id=\"S9.SS7.p1\" class=\"ltx_para\">\n<p id=\"S9.SS7.p1.1\" class=\"ltx_p\"><span id=\"S9.SS7.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib42\" title=\"\" class=\"ltx_ref\">23</a>]</cite> introduced a unified multi-agent trust\nframework combining DIDs for cross-domain authentication,\nblockchain-anchored ledgers for immutable audit, and smart contracts\nfor dynamic access control. It demonstrated effective defense against\ndiverse MAS attacks and practical integration with A2A <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib43\" title=\"\" class=\"ltx_ref\">6</a>]</cite>.</p>\n</div>\n<div id=\"S9.SS7.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S9.SS7.p2.1\" class=\"ltx_p\"><span id=\"S9.SS7.p2.1.1\" class=\"ltx_text ltx_font_bold\">Evolution to <span id=\"S9.SS7.p2.1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>.</span> \n<span id=\"S9.SS7.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> preserves <span id=\"S9.SS7.p2.1.3\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span>’s core security ambitions (unified trust,\nimmutable audit, dynamic access control) while making three key\nadvances: (1) removing the blockchain dependency in favor of\ngeneral-purpose cryptographic primitives, broadening deployment to\nedge and air-gapped environments; (2) introducing layer-aligned\nprimitives for persistent identity, capability-aware discovery, trust\nnegotiation, and accountability, whereas <span id=\"S9.SS7.p2.1.4\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> approximated\nidentity and authorization only at the smart-contract policy level; and\n(3) adding DID-bound skill/tool manifest VCs, payment, and token-usage\ntracing capabilities that <span id=\"S9.SS7.p2.1.5\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> did not address. <span id=\"S9.SS7.p2.1.6\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> can be\nviewed as the generalization of <span id=\"S9.SS7.p2.1.7\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> from a blockchain-specific\nrealization to a deployment-agnostic protocol suite.</p>\n</div>\n</section>\n<section id=\"S9.SS8\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">9.8  Summary: the Joint-Coverage Argument</h3>\n\n<div id=\"S9.SS8.p1\" class=\"ltx_para\">\n<p id=\"S9.SS8.p1.1\" class=\"ltx_p\">Each of <span id=\"S9.SS8.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s primitives is anticipated by at least one prior work\nsurveyed above: DID/VC and SPIFFE precede the AIC’s identity\nmachinery; UCAN, Biscuit, AIP IBCTs, and Saavedra DGs precede the\nattenuation discipline; AgentMesh’s policy plane and the enterprise\ngovernance frameworks precede the two-tier intuition; AgentRFC\nprecedes the principled-invariants framing; and <span id=\"S9.SS8.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> precedes\nthe unified-trust ambition. <span id=\"S9.SS8.p1.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s contribution is twofold.</p>\n</div>\n<div id=\"S9.SS8.p2\" class=\"ltx_para\">\n<p id=\"S9.SS8.p2.1\" class=\"ltx_p\">First, <span id=\"S9.SS8.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> <em id=\"S9.SS8.p2.1.2\" class=\"ltx_emph ltx_font_italic\">deepens</em> each primitive beyond its nearest\npredecessor. Where SPIFFE, OAuth, and DIDs each bind a single\nidentity dimension, the AIC binds four independently signed\ndimensions so that compromising one tier cannot impersonate another.\nWhere A2A Agent Cards and ANP’s DID-based discovery treat skill and tool\nadvertisements as self-declared descriptions, <span id=\"S9.SS8.p2.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> represents each\nskill and tool as a DID-bound Verifiable Credential that is verified\nfor supply-chain authenticity, subject binding, and permission\nalignment at discovery time—making discovery a trust-establishing\nsecurity boundary rather than a directory lookup.\nWhere AIP and Saavedra DGs attenuate capabilities via per-hop\nDatalog or runtime policy, <span id=\"S9.SS8.p2.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s monotonic chain signs the\ncapability boundary at issuance and reduces verification to signature\nchecking, so the bound holds even when the policy engine is wrong.\nWhere AgentMesh and the enterprise governance frameworks route\ncryptographic checks and application policy through a single PDP,\n<span id=\"S9.SS8.p2.1.5\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s two-tier split keeps them on independent evaluation paths\nwith independent failure semantics, so a regression in one tier\ncannot weaken the other. And where <span id=\"S9.SS8.p2.1.6\" class=\"ltx_text ltx_font_smallcaps\">BlockA2A</span> anchors audit trails\nto blockchain consensus, <span id=\"S9.SS8.p2.1.7\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> achieves tamper-evident\nnon-repudiation via kernel-mediated signing that works in air-gapped\nand resource-constrained environments without a distributed ledger.</p>\n</div>\n<div id=\"S9.SS8.p3\" class=\"ltx_para\">\n<p id=\"S9.SS8.p3.1\" class=\"ltx_p\">Second, <span id=\"S9.SS8.p3.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> provides the <em id=\"S9.SS8.p3.1.2\" class=\"ltx_emph ltx_font_italic\">conjunction</em>: no prior single\narchitecture jointly enforces persistent identity with four-dimensional\nbinding, capability-aware discovery through DID-bound Verifiable\nCredential manifests, trust negotiation that combines lifecycle-scoped\nmonotonic capability attenuation with two-tier access control, and\nkernel-mediated cryptographic audit trails.\n<a href=\"#S9.T7\" title=\"In 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table</span> <span class=\"ltx_text ltx_ref_tag\">7</span></a> makes both contributions visible across\nthirteen evaluation dimensions: every prior approach achieves at\nmost a strict subset of <span id=\"S9.SS8.p3.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s coverage in breadth, and the\nper-primitive depth gap is most pronounced precisely where\nstructural guarantees matter—under operator compromise, PDP\nmisconfiguration, or cross-protocol composition.</p>\n</div>\n</section>\n</section>\n<section id=\"S10\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">10  Discussion &amp; Future Directions</h2>\n\n<div id=\"S10.p1\" class=\"ltx_para\">\n<p id=\"S10.p1.1\" class=\"ltx_p\">In this section, we discuss the limitations of the <span id=\"S10.p1.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> framework and outline key directions for future research. We first acknowledge the boundaries of this positioning paper and the practical challenges of deploying a global trust anchor. We then highlight promising avenues for future work, ranging from formal verification and privacy-preserving extensions to scalable infrastructure and integration with existing agent frameworks.</p>\n</div>\n<section id=\"S10.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">10.1  Limitations</h3>\n\n<div id=\"S10.SS1.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS1.p1.1\" class=\"ltx_p\"><span id=\"S10.SS1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Positioning scope.</span> \n\n<span id=\"S10.SS1.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is a positioning paper that establishes the conceptual framework,\nprotocol architecture, and design rationale. A complete protocol\nspecification would additionally require formal proofs of security\nproperties, quantitative performance evidence, implementation detail, and\nadversarial validation; we defer these to companion work. Concretely, the\nfollowing aspects are explicitly out of scope here:</p>\n</div>\n<div id=\"S10.SS1.p2\" class=\"ltx_para\">\n<ul id=\"S10.I1\" class=\"ltx_itemize\" style=\"--ltx-enum-leftmargin:2em;\">\n<li id=\"S10.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S10.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S10.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S10.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_italic\">Formal verification:</span> TLA+ or ProVerif models of the\nattestation and delegation protocols.</p>\n</div></li>\n<li id=\"S10.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S10.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S10.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S10.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_italic\">Performance evaluation:</span> Latency and throughput benchmarks\nunder realistic multi-agent workloads.</p>\n</div></li>\n<li id=\"S10.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S10.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S10.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S10.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_italic\">Implementation details:</span> A companion <span id=\"S10.I1.i3.p1.1.2\" class=\"ltx_text ltx_font_smallcaps\">DeepKernel</span> system\npaper will describe the full implementation including kernel\narchitecture, eBPF enforcement, and perception/cognition layers.</p>\n</div></li>\n<li id=\"S10.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S10.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S10.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S10.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_italic\">Adversarial evaluation:</span> Red-team exercises and attack\nsimulation against the protocol suite.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"S10.SS1.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS1.p3.1\" class=\"ltx_p\"><span id=\"S10.SS1.p3.1.1\" class=\"ltx_text ltx_font_bold\">GAR as a trust anchor.</span> \nThe Global Agent Registry serves as a centralized (or federated) trust\nanchor, analogous to a Certificate Authority. This introduces the same\ntrade-offs as traditional PKI: the GAR must be highly available, its\ncompromise would be catastrophic, and cross-GAR trust requires federation\nagreements. Decentralized alternatives (e.g., blockchain-backed GARs, web\nof trust models) can mitigate these risks but introduce latency and\ngovernance complexity.</p>\n</div>\n<div id=\"S10.SS1.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS1.p4.1\" class=\"ltx_p\"><span id=\"S10.SS1.p4.1.1\" class=\"ltx_text ltx_font_bold\">Adoption bootstrapping.</span> \nThe value of <span id=\"S10.SS1.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> increases with adoption (network effects). Early\ndeployments may face a chicken-and-egg problem where few agents support\n<span id=\"S10.SS1.p4.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s identity layer, reducing the incentive for others to adopt. We\nenvision a phased adoption path: Layer 0 (identity) can be adopted\nindependently of Layers 1–3, providing immediate value for agent\nauthentication even when only a subset of the ecosystem participates.</p>\n</div>\n<div id=\"S10.SS1.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS1.p5.1\" class=\"ltx_p\"><span id=\"S10.SS1.p5.1.1\" class=\"ltx_text ltx_font_bold\">Semantic tag governance.</span> \nLayer 1’s semantic tagging relies on an open vocabulary. Without\ngovernance, semantic tags may become fragmented or misleading. We\nanticipate that domain-specific tag ontologies will emerge organically\n(similar to Docker image tags or npm package keywords) and can be curated\nby registry operators.</p>\n</div>\n</section>\n<section id=\"S10.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_font_bold ltx_title_subsection\">10.2  Future Directions</h3>\n\n<div id=\"S10.SS2.p1\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p1.1\" class=\"ltx_p\"><span id=\"S10.SS2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Formal verification.</span> \nThe attestation and delegation protocols lend themselves to formal\nverification using tools such as TLA+ <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib38\" title=\"\" class=\"ltx_ref\">16</a>]</cite> for safety\nproperties and ProVerif or Tamarin for cryptographic protocol analysis.\nFormalizing the monotonic attenuation chain as a lattice-theoretic\ninvariant would strengthen the structural guarantee claims.</p>\n</div>\n<div id=\"S10.SS2.p2\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p2.1\" class=\"ltx_p\"><span id=\"S10.SS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Attestation deployment topologies.</span> \nThe mutual attestation protocol (§<a href=\"#S6.SS1\" title=\"6.1 Mutual Attestation Protocol ‣ 6 Layer 2: Trust Negotiation ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6.1</span></a>) is\nparameterized by the relationship between <span id=\"S10.SS2.p2.1.2\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S10.SS2.p2.1.2.1\" class=\"ltx_sub\"><math id=\"S10.SS2.p2.m1\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span> and <span id=\"S10.SS2.p2.1.3\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S10.SS2.p2.1.3.1\" class=\"ltx_sub\"><math id=\"S10.SS2.p2.m2\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span>, yielding three\ndeployment modes with distinct trust and performance profiles.\n<em id=\"S10.SS2.p2.1.4\" class=\"ltx_emph ltx_font_italic\">Co-located attestation</em> (<span id=\"S10.SS2.p2.1.5\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S10.SS2.p2.1.5.1\" class=\"ltx_sub\"><math id=\"S10.SS2.p2.m3\" class=\"ltx_Math\" alttext=\"A\" display=\"inline\" intent=\":literal\"><semantics><mi>A</mi><annotation encoding=\"application/x-tex\">A</annotation></semantics></math></sub></span> <math id=\"S10.SS2.p2.m4\" class=\"ltx_Math\" alttext=\"{}={}\" display=\"inline\" intent=\":literal\"><semantics><mo>=</mo><annotation encoding=\"application/x-tex\">{}={}</annotation></semantics></math><span id=\"S10.SS2.p2.1.6\" class=\"ltx_text ltx_font_sansserif\">Kernel<sub id=\"S10.SS2.p2.1.6.1\" class=\"ltx_sub\"><math id=\"S10.SS2.p2.m5\" class=\"ltx_Math\" alttext=\"B\" display=\"inline\" intent=\":literal\"><semantics><mi>B</mi><annotation encoding=\"application/x-tex\">B</annotation></semantics></math></sub></span>) is the lowest-latency\noption, natural for <span id=\"S10.SS2.p2.1.7\" class=\"ltx_text ltx_font_smallcaps\">DeepKernel</span>-managed multi-agent orchestration on a\nsingle host; the entire challenge-response collapses to kernel-internal\noperations with no network round-trip.\n<em id=\"S10.SS2.p2.1.8\" class=\"ltx_emph ltx_font_italic\">Remote-mediated attestation</em> interposes a Trusted Attestation\nService (<span id=\"S10.SS2.p2.1.9\" class=\"ltx_text ltx_font_sansserif\">TAS</span>)—architecturally identical to a local agent kernel but\ndeployed as a cloud endpoint—that coordinates nonce exchange, caches GAR\nverification results, and issues session tokens. The <span id=\"S10.SS2.p2.1.10\" class=\"ltx_text ltx_font_sansserif\">TAS</span> plays a role\nanalogous to an OIDC Provider in human web SSO: it centralizes session\nestablishment at the cost of introducing a single point of trust that must\nitself be highly available and key-protected.\n<em id=\"S10.SS2.p2.1.11\" class=\"ltx_emph ltx_font_italic\">Direct peer-to-peer attestation</em> eliminates the intermediary: each\nkernel signs its own nonce and independently verifies the counterpart’s\nsignature via the GAR. This mode is fully decentralized but incurs at\nleast two independent GAR round-trips per attestation; AIC caching with\nrevocation-push notifications can amortize the cost.\nThe three modes can coexist within a single ecosystem—co-located for\nintra-device workflows, mediated for organizational clusters, and direct\nP2P for open cross-organization interactions—and the choice is\ndetermined by the deployment context rather than by the protocol itself.</p>\n</div>\n<div id=\"S10.SS2.p3\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p3.1\" class=\"ltx_p\"><span id=\"S10.SS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Privacy-preserving extensions.</span> \nThe current design exposes the requester’s full AIC attributes to the\nresponder during Layer 2 attestation. Zero-knowledge proofs (ZKPs) could\nenable selective disclosure: an agent could prove it possesses a required\ncapability or meets an IAL threshold without revealing its full identity.\nThis is particularly relevant for privacy-sensitive domains such as\nhealthcare and finance.</p>\n</div>\n<div id=\"S10.SS2.p4\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p4.1\" class=\"ltx_p\"><span id=\"S10.SS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Integration with agent frameworks.</span> \n<span id=\"S10.SS2.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is designed to be framework-agnostic, but practical adoption requires\nSDK integrations with popular agent frameworks (LangGraph, AutoGen,\nCrewAI, Semantic Kernel) and vendor SDKs (OpenAI Agents\nSDK <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib62\" title=\"\" class=\"ltx_ref\">63</a>]</cite>, Google ADK <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib63\" title=\"\" class=\"ltx_ref\">64</a>]</cite>). We envision\nthin adapter libraries that bridge each framework’s identity and tool\ninvocation APIs to <span id=\"S10.SS2.p4.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s protocol primitives. AgentMesh’s approach of\nbuilding explicit protocol translators for A2A, MCP, and IATP (in the same\nAgent Governance Toolkit monorepo as AgentMesh) <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite> suggests a\npragmatic integration pattern that <span id=\"S10.SS2.p4.1.4\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> could adopt for its initial deployment\ntargets.</p>\n</div>\n<div id=\"S10.SS2.p5\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p5.1\" class=\"ltx_p\"><span id=\"S10.SS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Scalability of the GAR.</span> \nAs the agent population grows to millions or billions, the GAR must scale\ncorrespondingly. Horizontal sharding by tenant or geographic region,\ncaching at the kernel level (with revocation push notifications), and\neventual consistency models for non-critical metadata are all viable\nstrategies that need empirical evaluation.</p>\n</div>\n<div id=\"S10.SS2.p6\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p6.1\" class=\"ltx_p\"><span id=\"S10.SS2.p6.1.1\" class=\"ltx_text ltx_font_bold\">Cross-GAR federation.</span> \nIn a multi-stakeholder ecosystem, multiple GARs will coexist (enterprise\nGARs, cloud-provider GARs, open-community GARs). Cross-GAR trust\nestablishment requires mutual recognition protocols analogous to\ncross-certification in PKI or trust federation in SAML. Designing these\nprotocols is a natural extension of <span id=\"S10.SS2.p6.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s architecture.</p>\n</div>\n<div id=\"S10.SS2.p7\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p7.1\" class=\"ltx_p\"><span id=\"S10.SS2.p7.1.1\" class=\"ltx_text ltx_font_bold\">Agentic payment infrastructure.</span> \nLayer 3’s payment primitives are deliberately minimal. A full agentic\npayment infrastructure would need to address escrow for long-running\ntasks, dispute resolution, quality-of-service guarantees, and\nmicro-payment efficiency. Google’s AP2 <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib55\" title=\"\" class=\"ltx_ref\">45</a>]</cite> is a leading open effort in this\ndirection, focusing on the payment rail and transaction flow. We view <span id=\"S10.SS2.p7.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s identity and metering layer as the\nfoundation upon which AP2-style settlement protocols can be built,\nproviding the “who is paying whom and with what authority” semantics that\npayment rails alone cannot supply.</p>\n</div>\n<div id=\"S10.SS2.p8\" class=\"ltx_para ltx_noindent\">\n<p id=\"S10.SS2.p8.1\" class=\"ltx_p\"><span id=\"S10.SS2.p8.1.1\" class=\"ltx_text ltx_font_bold\">Post-quantum readiness.</span> \nAgentMesh <cite class=\"ltx_cite ltx_citemacro_cite\">[<a href=\"#bib.bib54\" title=\"\" class=\"ltx_ref\">19</a>]</cite> already lists ML-DSA-65 alongside Ed25519 as a\nsupported signature scheme. As NIST post-quantum standards mature, <span id=\"S10.SS2.p8.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span>’s\nAIC and attestation protocols should be extended to support PQ signature\nalgorithms (e.g., ML-DSA, SLH-DSA) as drop-in replacements for Ed25519,\npreserving the structural security properties while future-proofing the\ncryptographic substrate.</p>\n</div>\n</section>\n</section>\n<section id=\"S11\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_font_bold ltx_title_section\" style=\"font-size:120%;\">11  Conclusion</h2>\n\n<div id=\"S11.p1\" class=\"ltx_para\">\n<p id=\"S11.p1.1\" class=\"ltx_p\">The Internet of Agents will not become secure merely by standardizing how\nagents exchange messages. The harder problem is whether independently built\nagents can make interoperable trust decisions: is this agent the entity it\nclaims to be, are its advertised skills and tools genuine, can its authority\nonly decrease as it is delegated, and can its actions later be attributed\nwithout ambiguity? This paper has argued that these questions require a\ntrust substrate, not another communication protocol.</p>\n</div>\n<div id=\"S11.p2\" class=\"ltx_para\">\n<p id=\"S11.p2.1\" class=\"ltx_p\"><span id=\"S11.p2.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> provides such a substrate as a four-layer protocol suite spanning\nPersistent Identity, Discovery, Trust Negotiation, and Accountability. Its\nprincipal contribution is the conjunction of four layer-aligned primitives:\nAgent Identity Cards with four-dimensional binding; capability-aware\ndiscovery through DID-bound skill/tool manifest VCs; trust negotiation that\ncombines monotonic capability attenuation with two-tier access control; and\nkernel-mediated cryptographic audit trails. Each primitive has antecedents\nin existing identity, delegation, policy, or audit systems. What is missing\nfrom prior work, and what <span id=\"S11.p2.1.2\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> supplies, is their joint enforcement across\nthe full agent lifecycle: from issuance and discovery, through negotiation\nand delegation, to metering and non-repudiation.</p>\n</div>\n<div id=\"S11.p3\" class=\"ltx_para\">\n<p id=\"S11.p3.1\" class=\"ltx_p\">This architecture deliberately remains communication-protocol agnostic.\nRather than competing with MCP, A2A, ANP, AG-UI, or future agent protocols,\n<span id=\"S11.p3.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> defines the trust objects those protocols can carry: AIC capability\nboundaries, manifest VCs, session tokens, and signed traces. This separation\nis what makes the design deployable across cloud, edge, and air-gapped\nsettings without relying on a single runtime, policy engine, registry\ntopology, or distributed ledger.</p>\n</div>\n<div id=\"S11.p4\" class=\"ltx_para\">\n<p id=\"S11.p4.1\" class=\"ltx_p\">As a positioning paper, <span id=\"S11.p4.1.1\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> establishes the conceptual framework and\nprotocol architecture; formal verification, performance benchmarks, and a\ncompanion <span id=\"S11.p4.1.2\" class=\"ltx_text ltx_font_smallcaps\">DeepKernel</span> systems paper are left to ongoing work. The claim of\nthis paper is therefore precise: communication interoperability is necessary\nfor agents to talk, but secure interoperability is necessary for agents to\nact across organizational boundaries. <span id=\"S11.p4.1.3\" class=\"ltx_text ltx_font_smallcaps\">InterSAGE</span> is a step toward making the\nunderlying trust layer explicit, composable, and verifiable.</p>\n</div>\n</section>\n<section id=\"bib\" class=\"ltx_bibliography\">\n<h2 class=\"ltx_title ltx_title_bibliography\">References</h2>\n\n<ul id=\"bib.L1\" class=\"ltx_biblist\">\n<li id=\"bib.bib45\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[1]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Yao, J. Zhao, D. Yu, N. Du, I. Shafran, K. Narasimhan, and Y. Cao</span><span class=\"ltx_text ltx_bib_year\"> (2022)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">ReAct: synergizing reasoning and acting in language models</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2210.03629</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib46\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[2]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Q. Wu, G. Bansal, J. Zhang, Y. Wu, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2023)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AutoGen: enabling next-gen LLM applications via multi-agent conversation</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2308.08155</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib47\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[3]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Hong, M. Zhuge, J. Chen, X. Zheng, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2023)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">MetaGPT: meta programming for a multi-agent collaborative framework</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2308.00352</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib4\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[4]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">W. Chen, Z. You, R. Li, Y. Guan, C. Qian, C. Zhao, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2024)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Internet of agents: weaving a web of heterogeneous agents for collaborative intelligence</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2407.07061</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib53\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[5]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Gartner</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Gartner predicts agentic AI will autonomously resolve 80% of common customer service issues by 2029</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Gartner Press Release</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.gartner.com/en/newsroom/press-releases/2025-03-05-gartner-predicts-agentic-ai-will-autonomously-resolve-80-percent-of-common-customer-service-issues-without-human-intervention-by-2029\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib43\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[6]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Google</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent-to-agent (A2A) protocol specification</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://a2a-protocol.org/latest/specification/\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://a2a-protocol.org/latest/specification/</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i2.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2nd item</span></a>,\n<a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S1.p4.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p3.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S5.SS3.p4.1\" title=\"5.3 Capability-Aware Discovery ‣ 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.3</span></a>,\n<a href=\"#S9.SS7.p1.1\" title=\"9.7 Our Prior Work: BlockA2A ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.7</span></a>.\n</span></li>\n<li id=\"bib.bib44\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[7]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Anthropic</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Model context protocol (MCP) specification</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://modelcontextprotocol.io/\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://modelcontextprotocol.io/</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p2.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib21\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[8]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">G. Chang, E. Lin, C. Yuan, R. Cai, B. Chen, X. Xie, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent network protocol technical white paper</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2508.00007</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i2.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2nd item</span></a>,\n<a href=\"#S1.p1.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p4.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S5.SS3.p4.1\" title=\"5.3 Capability-Aware Discovery ‣ 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.3</span></a>,\n<a href=\"#S9.SS1.p2.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib2\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[9]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Y. Wang, S. Guo, Y. Pan, Z. Su, F. Chen, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Internet of agents: fundamentals, applications, and challenges</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">IEEE Transactions on Cognitive Communications and Networking</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">arXiv:2505.07176; accepted by IEEE TCCN</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib3\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[10]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">W. Xu, T. Wang, Y. Xia, S. Zhang, and S. C. Liew</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent-OSI: a layered protocol stack toward a decentralized internet of agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2602.13795</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.I1.i1.p1.1\" title=\"In 3.1 Design Principles ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">item P1.</span></a>,\n<a href=\"#S7.I1.i4.p1.1\" title=\"In 7.2 Payment Primitives ‣ 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">item 4.</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>,\n<a href=\"#S9.SS1.p2.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib1\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[11]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Fleming, L. Muscariello, V. Pandey, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A layered protocol architecture for the internet of agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2511.19699</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.I1.i1.p1.1\" title=\"In 3.1 Design Principles ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">item P1.</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib9\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[12]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Y. Yang, H. Chai, Y. Song, S. Qi, M. Wen, N. Li, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A survey of AI agent protocols</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2504.16736</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib10\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[13]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Ehtesham, A. Singh, G. K. Gupta, and S. Kumar</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A survey of agent interoperability protocols: MCP, ACP, A2A, and ANP</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2505.02279</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib6\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[14]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Li, J. Wu, Q. Du, S. Yu, R. Zou, K. Yu, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">ACPS: agent collaboration protocols for the internet of agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2505.13523</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p2.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.I1.i1.p1.1\" title=\"In 3.1 Design Principles ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">item P1.</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib57\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[15]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Agent Client Protocol Project</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent client protocol (ACP): a protocol for connecting any editor to any agent</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/agentclientprotocol/agent-client-protocol\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/agentclientprotocol/agent-client-protocol</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p6.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.SS3.p1.1\" title=\"3.3 Relationship to Existing Protocols ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>,\n<a href=\"#footnote1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">footnote 1</span></a>.\n</span></li>\n<li id=\"bib.bib38\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[16]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Zheng and Q. Zhang</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AgentRFC: security design principles and conformance testing for agent protocols</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2603.23801</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S10.SS2.p1.1\" title=\"10.2 Future Directions ‣ 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§10.2</span></a>,\n<a href=\"#S2.SS2.p2.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S2.SS2.p3.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S9.SS5.p1.1\" title=\"9.5 Conformance Testing vs. Cryptographic Enforcement ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.5</span></a>.\n</span></li>\n<li id=\"bib.bib39\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[17]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Z. Anbiaee, M. Rabbani, M. Mirani, G. Piya, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Security threat modeling for emerging AI-agent protocols: a comparative analysis of MCP, A2A, agora, and ANP</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2602.11327</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS2.p2.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S2.SS2.p3.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S9.SS5.p1.1\" title=\"9.5 Conformance Testing vs. Cryptographic Enforcement ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.5</span></a>.\n</span></li>\n<li id=\"bib.bib40\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[18]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">J. A. Wibowo and G. C. Polyzos</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Toward a safe internet of agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2512.00520</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS2.p2.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S9.SS5.p1.1\" title=\"9.5 Conformance Testing vs. Cryptographic Enforcement ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.5</span></a>.\n</span></li>\n<li id=\"bib.bib54\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[19]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Microsoft</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AgentMesh: production-grade trust layer for multi-agent systems</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-python/agent-mesh\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-python/agent-mesh</a>Part of the Agent Governance Toolkit; SPIFFE/SVID-based identity, policy engine, A2A/MCP/IATP protocol bridge</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i3.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3rd item</span></a>,\n<a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S10.SS2.p4.1\" title=\"10.2 Future Directions ‣ 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§10.2</span></a>,\n<a href=\"#S10.SS2.p8.1\" title=\"10.2 Future Directions ‣ 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§10.2</span></a>,\n<a href=\"#S2.SS1.p6.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S2.SS1.p7.p1.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.I1.i1.p1.1\" title=\"In 3.1 Design Principles ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">item P1.</span></a>,\n<a href=\"#S4.SS2.p3.1\" title=\"4.2 Four-Dimensional Identity Binding ‣ 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S8.SS4.p1.1\" title=\"8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§8.4</span></a>,\n<a href=\"#S8.T6.5.1.3.1.1\" title=\"In 8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 6</span></a>,\n<a href=\"#S9.SS6.p1.1\" title=\"9.6 Single-Plane Overlays vs. Two-Tier Authorization ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.6</span></a>.\n</span></li>\n<li id=\"bib.bib30\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[20]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Huang, Y. Mehmood, H. Atta, J. Huang, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Fortifying the agentic web: a unified zero-trust architecture against logic-layer threats</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2508.12259</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS1.p6.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S2.SS1.p7.p1.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S9.SS6.p1.1\" title=\"9.6 Single-Plane Overlays vs. Two-Tier Authorization ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.6</span></a>,\n<a href=\"#S9.SS6.p4.1\" title=\"9.6 Single-Plane Overlays vs. Two-Tier Authorization ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.6</span></a>.\n</span></li>\n<li id=\"bib.bib16\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[21]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Prakash</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AIP: agent identity protocol for verifiable delegation across MCP and A2A</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2603.24775</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i1.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1st item</span></a>,\n<a href=\"#S1.I2.i3.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3rd item</span></a>,\n<a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S4.SS2.p3.1\" title=\"4.2 Four-Dimensional Identity Binding ‣ 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S8.SS4.p1.1\" title=\"8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§8.4</span></a>,\n<a href=\"#S8.T6.5.1.4.1.1\" title=\"In 8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 6</span></a>,\n<a href=\"#S9.SS4.p2.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>,\n<a href=\"#S9.SS4.p3.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>.\n</span></li>\n<li id=\"bib.bib35\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[22]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">H. Ramachandran and G. Mishra</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Identity-aware governance for autonomous AI agents: a framework for enterprise authorization, delegation, and audit</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">SSRN</span> (<span class=\"ltx_text ltx_bib_number\">6439998</span>).\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i3.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3rd item</span></a>,\n<a href=\"#S1.p3.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS2.p3.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S5.I5.i1.p1.1\" title=\"In 5.4 Verifiable Skill &amp; Tool Manifests ‣ 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1st item</span></a>,\n<a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib42\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[23]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Z. Zou, Z. Liu, L. Zhao, and Q. Zhan</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">BlockA2A: towards secure and verifiable agent-to-agent interoperability</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2508.01332</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i4.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4th item</span></a>,\n<a href=\"#S1.p4.1\" title=\"1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S2.SS2.p2.1\" title=\"2.2 Agent-Specific Threat Model ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>,\n<a href=\"#S3.SS1.p1.1\" title=\"3.1 Design Principles ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.1</span></a>,\n<a href=\"#S7.SS3.p5.1\" title=\"7.3 Action Accountability ‣ 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§7.3</span></a>,\n<a href=\"#S8.SS4.p1.1\" title=\"8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§8.4</span></a>,\n<a href=\"#S8.T6.5.1.5.1.1\" title=\"In 8.4 Comparison and Residual Risks ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">Table 6</span></a>,\n<a href=\"#S9.SS7.p1.1\" title=\"9.7 Our Prior Work: BlockA2A ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.7</span></a>.\n</span></li>\n<li id=\"bib.bib20\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[24]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Nagabhushanaradhya</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OpenID connect for agents (OIDC-A) 1.0: a standard extension for LLM-based agent identity and authorization</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2509.25974</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i1.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1st item</span></a>,\n<a href=\"#S2.SS3.p2.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>.\n</span></li>\n<li id=\"bib.bib19\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[25]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">T. South S. Nagabhushanaradhya <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Identity management for agentic AI: the new frontier of authorization, authentication, and security</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2510.25819</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">OpenID Foundation whitepaper</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i1.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1st item</span></a>,\n<a href=\"#S2.SS3.p2.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>.\n</span></li>\n<li id=\"bib.bib34\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[26]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. R. Saavedra</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Interoperable architecture for digital identity delegation for AI agents with blockchain integration</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2601.14982</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i3.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3rd item</span></a>,\n<a href=\"#S4.SS2.p3.1\" title=\"4.2 Four-Dimensional Identity Binding ‣ 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S9.SS4.p2.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>.\n</span></li>\n<li id=\"bib.bib50\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[27]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">M. B. Jones, B. Campbell, J. Bradley, and N. Sakimura</span><span class=\"ltx_text ltx_bib_year\"> (2020)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OAuth 2.0 token exchange (RFC 8693)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">IETF RFC 8693</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.I2.i3.p1.1\" title=\"In 1 Introduction ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3rd item</span></a>.\n</span></li>\n<li id=\"bib.bib18\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[28]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">V. Srinivasan</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Bridging protocol and production: design patterns for deploying AI agents with model context protocol</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2603.13417</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p2.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib5\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[29]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">R. Georgio, C. Forder, S. Deb, A. Rahimov, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Coral protocol: open infrastructure connecting the internet of agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2505.00749</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib11\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[30]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">H. Derouiche, Z. Brahmi, and H. Mazeni</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agentic AI frameworks: architectures, protocols, and design challenges</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2508.10146</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p5.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib56\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[31]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">CopilotKit</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AG-UI: the agent-user interaction protocol</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/ag-ui-protocol/ag-ui\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/ag-ui-protocol/ag-ui</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p6.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>,\n<a href=\"#S3.SS3.p1.1\" title=\"3.3 Relationship to Existing Protocols ‣ 3 InterSAGE: Design Philosophy &amp; Protocol Suite Overview ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§3.3</span></a>.\n</span></li>\n<li id=\"bib.bib58\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[32]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">IBM</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">ContextForge: an AI gateway, registry, and proxy for MCP, A2A, and REST/gRPC APIs</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/IBM/mcp-context-forge\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/IBM/mcp-context-forge</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p6.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib61\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[33]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Wild Card AI</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agents.json: an open specification for API and agent interaction contracts</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/wild-card-ai/agents-json\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/wild-card-ai/agents-json</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p6.1\" title=\"2.1 The Agent Interaction Landscape ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib48\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[34]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. Hardt</span><span class=\"ltx_text ltx_bib_year\"> (2012)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The OAuth 2.0 authorization framework (RFC 6749)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">IETF RFC 6749</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p2.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib49\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[35]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OpenID Foundation</span><span class=\"ltx_text ltx_bib_year\"> (2014)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OpenID connect core 1.0</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://openid.net/specs/openid-connect-core-1_0.html\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://openid.net/specs/openid-connect-core-1_0.html</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p2.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib27\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[36]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">T. South, S. Marro, T. Hardjono, R. Mahari, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Authenticated delegation and authorized AI agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2501.09674</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p2.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>,\n<a href=\"#S9.SS4.p2.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>.\n</span></li>\n<li id=\"bib.bib36\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[37]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">B. Bhushan, K. Pappu, and A. Mittal</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A conceptual framework for authentication in agentic AI ecosystems: protocol analysis and taxonomy</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">IEEE ICCA</span>,\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p2.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>.\n</span></li>\n<li id=\"bib.bib51\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[38]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">E. Rescorla</span><span class=\"ltx_text ltx_bib_year\"> (2018)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The transport layer security (TLS) protocol version 1.3 (RFC 8446)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">IETF RFC 8446</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p3.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib26\" class=\"ltx_bibitem ltx_bib_incollection\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[39]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Huang and C. Hughes</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agentic AI identity security</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">Securing AI Agents</span>,\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.1007/978-3-032-02130-4%5F3\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p3.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib33\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[40]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Pappu, B. Bhushan, and A. Mittal</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">SPIFFE-based zero-trust authentication for AI agent ecosystems</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">IEEE ICCA</span>,\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p3.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S2.SS3.p4.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S4.SS2.p3.1\" title=\"4.2 Four-Dimensional Identity Binding ‣ 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib22\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[41]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Huang, V. S. Narajala, J. Yeoh, J. Ross, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A novel zero-trust identity framework for agentic AI: decentralized authentication and fine-grained access control</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2505.19301</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p3.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>,\n<a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib52\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[42]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, and T. Polk</span><span class=\"ltx_text ltx_bib_year\"> (2008)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Internet X.509 public key infrastructure certificate and certificate revocation list profile (RFC 5280)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">IETF RFC 5280</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p4.1\" title=\"2.3 Why Traditional Internet Security Falls Short ‣ 2 Background &amp; Threat Landscape ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib24\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[43]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. R. Garzon, A. Vaziry, E. M. Kuzu, D. E. Gehrmann, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AI agents with decentralized identifiers and verifiable credentials</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2511.02841</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS2.p3.1\" title=\"4.2 Four-Dimensional Identity Binding ‣ 4 Layer 0: Persistent Agent Identity ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2</span></a>,\n<a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib64\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[44]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">W3C</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Verifiable credentials data model v2.0</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://www.w3.org/TR/vc-data-model-2.0/\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://www.w3.org/TR/vc-data-model-2.0/</a>W3C Recommendation, 2025-05-15</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S5.SS4.p3.1\" title=\"5.4 Verifiable Skill &amp; Tool Manifests ‣ 5 Layer 1: Registration, Discovery &amp; Semantic Interoperability ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.4</span></a>.\n</span></li>\n<li id=\"bib.bib55\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[45]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Google</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent payments protocol (AP2): building a secure and interoperable future for AI-driven payments</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/google-agentic-commerce/AP2\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/google-agentic-commerce/AP2</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S10.SS2.p7.1\" title=\"10.2 Future Directions ‣ 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§10.2</span></a>,\n<a href=\"#S7.SS2.p4.1\" title=\"7.2 Payment Primitives ‣ 7 Layer 3: Accountability &amp; Economics ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§7.2</span></a>,\n<a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib37\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[46]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. Dolev and A. C. Yao</span><span class=\"ltx_text ltx_bib_year\"> (1983)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">On the security of public key protocols</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">IEEE Transactions on Information Theory</span> <span class=\"ltx_text ltx_bib_volume\">29</span> (<span class=\"ltx_text ltx_bib_number\">2</span>), <span class=\"ltx_text ltx_bib_pages\">pp. 198–208</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.1109/TIT.1983.1056650\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S8.SS1.p1.1\" title=\"8.1 Threat Model and Assumptions ‣ 8 Security Analysis ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§8.1</span></a>.\n</span></li>\n<li id=\"bib.bib7\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[47]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OpenAgents</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OpenAgents network model</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://openagents.org/docs/zh/concepts/openagents-network-model\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://openagents.org/docs/zh/concepts/openagents-network-model</a>Version 1.0; updated May 8, 2026</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib8\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[48]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Du, C. Wang, Y. Chao, X. Xie, and Y. Cui</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AI agent communication from internet architecture perspective: challenges and opportunities</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2509.02317</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib12\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[49]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Jeong</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A study on the MCP x A2A framework for enhancing interoperability of LLM-based autonomous agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2506.01804</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib13\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[50]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Q. Duan and Z. Lu</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AI agent communications in the future internet—paving a path toward the agentic web</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Future Internet (MDPI)</span> <span class=\"ltx_text ltx_bib_volume\">18</span> (<span class=\"ltx_text ltx_bib_number\">3</span>), <span class=\"ltx_text ltx_bib_pages\">pp. 171</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib14\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[51]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Z. Liang, E. Cui, Q. Wei, R. She, T. Li, M. Guo, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A2H: agent-to-human protocol for AI agent</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2602.15831</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>.\n</span></li>\n<li id=\"bib.bib15\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[52]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Guo, Y. Wang, Z. Su, Y. Pan, Q. Hu, and T. H. Luan</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent discovery in internet of agents: challenges and solutions</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">IEEE Network</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">arXiv:2511.19113</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS1.p1.1\" title=\"9.1 Communication Stacks vs. Security-First Substrates ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.1</span></a>,\n<a href=\"#S9.SS5.p1.1\" title=\"9.5 Conformance Testing vs. Cryptographic Enforcement ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.5</span></a>.\n</span></li>\n<li id=\"bib.bib28\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[53]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">T. South, S. Marro, T. Hardjono, R. Mahari, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Position: AI agents need authenticated delegation</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">ICML</span>,\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Position paper</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>,\n<a href=\"#S9.SS4.p2.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>.\n</span></li>\n<li id=\"bib.bib29\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[54]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Aydeger E. Zeydan <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Decentralized digital identity management for large language model agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">IEEE Communications Standards Magazine</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>.\n</span></li>\n<li id=\"bib.bib59\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[55]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">AGNTCY</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">AGNTCY identity: onboarding, creating, and verifying identities for agents and MCP servers</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/agntcy/identity\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/agntcy/identity</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>.\n</span></li>\n<li id=\"bib.bib60\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[56]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">BillionsNetwork</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Verified agent identity: decentralized identity management for AI agents using iden3</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/BillionsNetwork/verified-agent-identity\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/BillionsNetwork/verified-agent-identity</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS2.p1.1\" title=\"9.2 Single-Dimension IAM vs. Multi-Dimensional Binding ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.2</span></a>.\n</span></li>\n<li id=\"bib.bib25\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[57]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Huang, V. S. Narajala, I. Habler, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent name service (ANS): a universal directory for secure AI agent discovery and interoperability</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2505.10609</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">arXiv:2505.10609</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib31\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[58]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">B. Bhushan</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">An explainable zero trust identity framework for LLMs, AI agents, and agentic AI systems</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">EuroLexis Open Access Journal</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib32\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[59]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. R. Palavali</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agentic AI for self-sovereign identity: a decentralized zero trust framework for autonomous microservices</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">IJCMI</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS3.p1.1\" title=\"9.3 Directory Discovery vs. Capability-Aware Manifests ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.3</span></a>.\n</span></li>\n<li id=\"bib.bib17\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[60]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Prakash</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">LDP: an identity-aware protocol for multi-agent LLM systems</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2603.08852</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS4.p2.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>.\n</span></li>\n<li id=\"bib.bib41\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[61]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Dalugoda</span><span class=\"ltx_text ltx_bib_year\"> (2026)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">HDP: a lightweight cryptographic protocol for human delegation provenance in agentic AI systems</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2604.04522</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">IETF Internet-Draft draft-helixar-hdp-agentic-delegation-00</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS4.p2.1\" title=\"9.4 Policy-Evaluated vs. Structurally-Attenuated Delegation ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.4</span></a>.\n</span></li>\n<li id=\"bib.bib23\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[62]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">T. Chaffer</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Know your agent: governing AI identity on the agentic web</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">SSRN Working PaperSSRN 5162127</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S9.SS5.p1.1\" title=\"9.5 Conformance Testing vs. Cryptographic Enforcement ‣ 9 Related Work ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§9.5</span></a>.\n</span></li>\n<li id=\"bib.bib62\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[63]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OpenAI</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OpenAI agents SDK: a lightweight framework for multi-agent workflows</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/openai/openai-agents-python\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/openai/openai-agents-python</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S10.SS2.p4.1\" title=\"10.2 Future Directions ‣ 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§10.2</span></a>.\n</span></li>\n<li id=\"bib.bib63\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_key ltx_role_refnum ltx_tag_bibitem\">[64]</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Google</span><span class=\"ltx_text ltx_bib_year\"> (2025)</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent development kit (ADK): an open-source python toolkit for building AI agents</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/google/adk-python\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/google/adk-python</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S10.SS2.p4.1\" title=\"10.2 Future Directions ‣ 10 Discussion &amp; Future Directions ‣ InterSAGE The Secure and Verifiable Interoperability Protocol for An Internet of Agents A Paper from the DeepKernel Lab\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§10.2</span></a>.\n</span></li>\n</ul>\n</section>\n</article>\n</div>\n</div>\n<footer class=\"arxiv-html-footer\">\n  <div class=\"ltx_page_logo\">\n    Experimental support, please\n    <a href=\"./2608.13030v1/__stdout.txt\" class=\"ltx_ref\"\n    target=\"_blank\" rel=\"nofollow\">view the build logs</a>\n    for errors. Generated by\n    <a href=\"https://math.nist.gov/~BMiller/LaTeXML/\" target=\"_blank\" class=\"ltx_ref ltx_LaTeXML_logo\">\n      <span style=\"letter-spacing: -0.2em; margin-right: 0.1em;\">\n        L\n        <span style=\"font-size: 70%; position: relative; bottom: 2.2pt;\">A</span>\n        T\n        <span style=\"position: relative; bottom: -0.4ex;\">E</span>\n      </span>\n      <span class=\"ltx_font_smallcaps\">xml</span>\n      <img alt=\"[LOGO]\"\n        src=\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAsAAAAOCAYAAAD5YeaVAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9wKExQZLWTEaOUAAAAddEVYdENvbW1lbnQAQ3JlYXRlZCB3aXRoIFRoZSBHSU1Q72QlbgAAAdpJREFUKM9tkL+L2nAARz9fPZNCKFapUn8kyI0e4iRHSR1Kb8ng0lJw6FYHFwv2LwhOpcWxTjeUunYqOmqd6hEoRDhtDWdA8ApRYsSUCDHNt5ul13vz4w0vWCgUnnEc975arX6ORqN3VqtVZbfbTQC4uEHANM3jSqXymFI6yWazP2KxWAXAL9zCUa1Wy2tXVxheKA9YNoR8Pt+aTqe4FVVVvz05O6MBhqUIBGk8Hn8HAOVy+T+XLJfLS4ZhTiRJgqIoVBRFIoric47jPnmeB1mW/9rr9ZpSSn3Lsmir1fJZlqWlUonKsvwWwD8ymc/nXwVBeLjf7xEKhdBut9Hr9WgmkyGEkJwsy5eHG5vN5g0AKIoCAEgkEkin0wQAfN9/cXPdheu6P33fBwB4ngcAcByHJpPJl+fn54mD3Gg0NrquXxeLRQAAwzAYj8cwTZPwPH9/sVg8PXweDAauqqr2cDjEer1GJBLBZDJBs9mE4zjwfZ85lAGg2+06hmGgXq+j3+/DsixYlgVN03a9Xu8jgCNCyIegIAgx13Vfd7vdu+FweG8YRkjXdWy329+dTgeSJD3ieZ7RNO0VAXAPwDEAO5VKndi2fWrb9jWl9Esul6PZbDY9Go1OZ7PZ9z/lyuD3OozU2wAAAABJRU5ErkJggg==\">\n    </a>.\n  </div>\n  <div class=\"keyboard-glossary\">\n    <h2>Instructions for reporting errors</h2>\n    <p>We are continuing to improve HTML versions of papers, and your feedback helps enhance accessibility and mobile\n      support. To report errors in the HTML that will help us improve conversion and rendering, choose any of the\n      methods listed below:</p>\n    <ul>\n      <li>Click the \"Report Issue\" <span class=\"mobile-only\">(<svg role=\"presentation\"\n            style=\"display: inline-block; vertical-align: middle; fill: var(--text-color);\" aria-hidden=\"true\"\n            height=\"1em\" viewBox=\"0 0 640 640\">\n            <path\n              d=\"M224 160C224 107 267 64 320 64C373 64 416 107 416 160L416 163.6C416 179.3 403.3 192 387.6 192L252.5 192C236.8 192 224.1 179.3 224.1 163.6L224.1 160zM569.6 172.8C580.2 186.9 577.3 207 563.2 217.6L465.4 290.9C470.7 299.8 474.7 309.6 477.2 320L576 320C593.7 320 608 334.3 608 352C608 369.7 593.7 384 576 384L480 384L480 416C480 418.6 479.9 421.3 479.8 423.9L563.2 486.4C577.3 497 580.2 517.1 569.6 531.2C559 545.3 538.9 548.2 524.8 537.6L461.7 490.3C438.5 534.5 395.2 566.5 344 574.2L344 344C344 330.7 333.3 320 320 320C306.7 320 296 330.7 296 344L296 574.2C244.8 566.5 201.5 534.5 178.3 490.3L115.2 537.6C101.1 548.2 81 545.3 70.4 531.2C59.8 517.1 62.7 497 76.8 486.4L160.2 423.9C160.1 421.3 160 418.7 160 416L160 384L64 384C46.3 384 32 369.7 32 352C32 334.3 46.3 320 64 320L162.8 320C165.3 309.6 169.3 299.8 174.6 290.9L76.8 217.6C62.7 207 59.8 186.9 70.4 172.8C81 158.7 101.1 155.8 115.2 166.4L224 248C236.3 242.9 249.8 240 264 240L376 240C390.2 240 403.7 242.8 416 248L524.8 166.4C538.9 155.8 559 158.7 569.6 172.8z\" />\n          </svg>)</span> button, located in the page header.</li>\n    </ul>\n    <p><strong>Tip:</strong> You can select the relevant text first, to include it in your report.</p>\n    <p>Our team has already identified <a class=\"ltx_ref\" href=\"https://github.com/arXiv/html_feedback/issues\"\n        target=\"_blank\">the following issues</a>. We appreciate your time reviewing and reporting rendering errors we\n      may not have found yet. Your efforts will help us improve the HTML versions for all readers, because disability\n      should not be a barrier to accessing research. Thank you for your continued support in championing open access for\n      all.</p>\n    <p>Have a free development cycle? Help support accessibility at arXiv! Our collaborators at LaTeXML maintain a <a\n        class=\"ltx_ref\" href=\"https://github.com/brucemiller/LaTeXML/wiki/Porting-LaTeX-packages-for-LaTeXML\"\n        target=\"_blank\">list of packages that need conversion</a>, and welcome <a class=\"ltx_ref\"\n        href=\"https://github.com/brucemiller/LaTeXML/issues\" target=\"_blank\">developer contributions</a>.</p>\n  </div>\n</footer><footer class=\"ds-site-footer\">\n  <div class=\"ds-site-footer-grid\">\n    <div class=\"ds-site-footer-main\">\n      <div class=\"ds-site-footer-ack\">\n        We gratefully acknowledge support from\n        our <strong>major funders</strong>,\n        <a href=\"https://info.arxiv.org/about/ourmembers.html\"><strong>member institutions</strong></a><span class=\"ack-member-inline\" hidden>, <strong></strong></span>,\n        and all contributors.\n      </div>\n      <nav class=\"ds-site-footer-links\" aria-label=\"Site navigation\">\n        <a href=\"https://info.arxiv.org/about\">About</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help\">Help</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/contact.html\">Contact</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/subscribe\">Subscribe</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/license/index.html\">Copyright</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/policies/privacy_policy.html\">Privacy</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/web_accessibility.html\">Accessibility</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://status.arxiv.org\" target=\"_blank\" rel=\"noopener noreferrer\">Operational Status<span class=\"is-sr-only\"> (opens in new tab)</span></a>\n      </nav>\n    </div>\n\n    <div class=\"ds-site-footer-funders\" aria-label=\"Major funders\">\n      <div class=\"ds-site-footer-funders-label\">Major funding support from</div>\n      <div class=\"ds-site-footer-funders-logos\">\n        <a class=\"ds-funder-link\" href=\"https://www.simonsfoundation.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation.png\" alt=\"Simons Foundation\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.sfi.org.bm/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation-international.png\" alt=\"Simons Foundation International\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.schmidtsciences.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/schmidt-sciences.png\" alt=\"Schmidt Sciences\">\n        </a>\n      </div>\n    </div>\n  </div>\n</footer><div id=\"fixed-buttons-container\">\n  <a id=\"disable-reading-mode-btn\" class=\"header-button\" href=\"javascript:toggleReadingMode();\"\n    title=\"Disable reading mode, show header and footer\">\n    <svg role=\"presentation\" height=\"1.25rem\"\n      viewBox=\"0 0 448 512\"><!--!Font Awesome Free v7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.-->\n      <path\n        d=\"M0 96C0 78.3 14.3 64 32 64l384 0c17.7 0 32 14.3 32 32s-14.3 32-32 32L32 128C14.3 128 0 113.7 0 96zM0 256c0-17.7 14.3-32 32-32l384 0c17.7 0 32 14.3 32 32s-14.3 32-32 32L32 288c-17.7 0-32-14.3-32-32zM448 416c0 17.7-14.3 32-32 32L32 448c-17.7 0-32-14.3-32-32s14.3-32 32-32l384 0c17.7 0 32 14.3 32 32z\" />\n    </svg>\n  </a>\n</div></body>\n</html>\n","snapshot_chars":588042,"live_check":"matches"}]}