{"slug":"treating-the-program-binary-itself-as-the-identity","citations":[{"url":"https://arxiv.org/abs/2512.17538","committed_hash":"sha256:92d58bfdb9ca667d18179ed9c06e4586d12e1dc0d1597056fe01eb1636e58b40","committed_hash_short":"sha256:92d58bfd…36e58b40","mime_type":"text/html","committed_at":"2026-09-08T20:00:19.994592+00:00","content_snapshot":"<!DOCTYPE html>\n<html lang=\"en\">\n\n<head><script>document.documentElement.classList.add('js');</script>  <title>[2512.17538] Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility</title>\n  <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n  <link rel=\"apple-touch-icon\" sizes=\"180x180\" href=\"/static/browse/0.3.4/images/icons/apple-touch-icon.png\">\n  <link rel=\"icon\" type=\"image/png\" sizes=\"32x32\" href=\"/static/browse/0.3.4/images/icons/favicon-32x32.png\">\n  <link rel=\"icon\" type=\"image/png\" sizes=\"16x16\" href=\"/static/browse/0.3.4/images/icons/favicon-16x16.png\">\n  <link rel=\"manifest\" href=\"/static/browse/0.3.4/images/icons/site.webmanifest\">\n  <link rel=\"mask-icon\" href=\"/static/browse/0.3.4/images/icons/safari-pinned-tab.svg\" color=\"#5bbad5\">\n  <meta name=\"msapplication-TileColor\" content=\"#da532c\">\n  <meta name=\"theme-color\" content=\"#ffffff\">\n  <link rel=\"stylesheet\" type=\"text/css\" media=\"screen\" href=\"/static/browse/0.3.4/css/arXiv.css?v=20260318\" />\n  <link rel=\"stylesheet\" type=\"text/css\" media=\"print\" href=\"/static/browse/0.3.4/css/arXiv-print.css?v=20200611\" />\n  <link rel=\"stylesheet\" type=\"text/css\" media=\"screen\" href=\"/static/browse/0.3.4/css/browse_search.css\" />\n  <link rel=\"stylesheet\" type=\"text/css\" media=\"screen\" href=\"/static/base/1.0.1/css/arxiv-header-footer.css?v=20260626\" />\n  <script language=\"javascript\" src=\"/static/browse/0.3.4/js/accordion.js\" ></script>\n  <script language=\"javascript\" src=\"/static/browse/0.3.4/js/optin-modal.js?v=20250819\"></script>\n  \n  <link rel=\"canonical\" href=\"https://arxiv.org/abs/2512.17538\"/>\n  <meta name=\"description\" content=\"Abstract page for arXiv paper 2512.17538: Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\"><meta property=\"og:type\" content=\"website\" />\n<meta property=\"og:site_name\" content=\"arXiv.org\" />\n<meta property=\"og:title\" content=\"Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" />\n<meta property=\"og:url\" content=\"https://arxiv.org/abs/2512.17538v1\" />\n<meta property=\"og:image\" content=\"/static/browse/0.3.4/images/arxiv-logo-fb.png\" />\n<meta property=\"og:image:secure_url\" content=\"/static/browse/0.3.4/images/arxiv-logo-fb.png\" />\n<meta property=\"og:image:width\" content=\"1200\" />\n<meta property=\"og:image:height\" content=\"700\" />\n<meta property=\"og:image:alt\" content=\"arXiv logo\"/>\n<meta property=\"og:description\" content=\"Autonomous AI agents lack traceable accountability mechanisms, creating a fundamental dilemma where systems must either operate as ``downgraded tools&#39;&#39; or risk real-world abuse. This vulnerability stems from the limitations of traditional key-based authentication, which guarantees neither the operator&#39;s physical identity nor the agent&#39;s code integrity. To bridge this gap, we propose BAID (Binding Agent ID), a comprehensive identity infrastructure establishing verifiable user-code binding. BAID integrates three orthogonal mechanisms: local binding via biometric authentication, decentralized on-chain identity management, and a novel zkVM-based Code-Level Authentication protocol. By leveraging recursive proofs to treat the program binary as the identity, this protocol provides cryptographic guarantees for operator identity, agent configuration integrity, and complete execution provenance, thereby effectively preventing unauthorized operation and code substitution. We implement and evaluate a complete prototype system, demonstrating the practical feasibility of blockchain-based identity management and zkVM-based authentication protocol.\"/>\n<meta name=\"twitter:site\" content=\"@arxiv\"/>\n<meta name=\"twitter:card\" content=\"summary\"/>\n<meta name=\"twitter:title\" content=\"Binding Agent ID: Unleashing the Power of AI Agents with...\"/>\n<meta name=\"twitter:description\" content=\"Autonomous AI agents lack traceable accountability mechanisms, creating a fundamental dilemma where systems must either operate as ``downgraded tools&#39;&#39; or risk real-world abuse. This vulnerability...\"/>\n<meta name=\"twitter:image\" content=\"https://static.arxiv.org/icons/twitter/arxiv-logo-twitter-square.png\"/>\n<meta name=\"twitter:image:alt\" content=\"arXiv logo\"/>\n  <link rel=\"stylesheet\" media=\"screen\" type=\"text/css\" href=\"/static/browse/0.3.4/css/tooltip.css\"/><link rel=\"stylesheet\" media=\"screen\" type=\"text/css\" href=\"https://static.arxiv.org/js/bibex-dev/bibex.css?20200709\"/>  <script src=\"/static/browse/0.3.4/js/mathjaxToggle.min.js\" type=\"text/javascript\"></script>  <script src=\"//code.jquery.com/jquery-latest.min.js\" type=\"text/javascript\"></script>\n  <script src=\"//cdn.jsdelivr.net/npm/js-cookie@2/src/js.cookie.min.js\" type=\"text/javascript\"></script>\n  <script src=\"//cdn.jsdelivr.net/npm/dompurify@2.3.5/dist/purify.min.js\"></script>\n  <script src=\"/static/browse/0.3.4/js/toggle-labs.js?20241022\" type=\"text/javascript\"></script>\n  <script src=\"/static/browse/0.3.4/js/cite.js\" type=\"text/javascript\"></script><meta name=\"citation_title\" content=\"Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" /><meta name=\"citation_author\" content=\"Lin, Zibin\" /><meta name=\"citation_author\" content=\"Zhang, Shengli\" /><meta name=\"citation_author\" content=\"Liao, Guofu\" /><meta name=\"citation_author\" content=\"Tao, Dacheng\" /><meta name=\"citation_author\" content=\"Wang, Taotao\" /><meta name=\"citation_date\" content=\"2025/12/19\" /><meta name=\"citation_online_date\" content=\"2025/12/19\" /><meta name=\"citation_pdf_url\" content=\"https://arxiv.org/pdf/2512.17538\" /><meta name=\"citation_arxiv_id\" content=\"2512.17538\" /><meta name=\"citation_abstract\" content=\"Autonomous AI agents lack traceable accountability mechanisms, creating a fundamental dilemma where systems must either operate as ``downgraded tools&#39;&#39; or risk real-world abuse. This vulnerability stems from the limitations of traditional key-based authentication, which guarantees neither the operator&#39;s physical identity nor the agent&#39;s code integrity. To bridge this gap, we propose BAID (Binding Agent ID), a comprehensive identity infrastructure establishing verifiable user-code binding. BAID integrates three orthogonal mechanisms: local binding via biometric authentication, decentralized on-chain identity management, and a novel zkVM-based Code-Level Authentication protocol. By leveraging recursive proofs to treat the program binary as the identity, this protocol provides cryptographic guarantees for operator identity, agent configuration integrity, and complete execution provenance, thereby effectively preventing unauthorized operation and code substitution. We implement and evaluate a complete prototype system, demonstrating the practical feasibility of blockchain-based identity management and zkVM-based authentication protocol.\" />\n</head>\n\n<body ><div class=\"flex-wrap-footer\">\n    <a href=\"#content\" class=\"ds-skip-link\">Skip to main content</a>\n  \n  \n  \n<header class=\"ds-site-header\">\n  <a aria-hidden=\"true\" tabindex=\"-1\" href=\"https://arxiv.org/IgnoreMe\" class=\"is-sr-only\"></a>\n\n  <a href=\"https://arxiv.org/\" class=\"ds-site-header-logo\" aria-label=\"archive home\">\n    <img src=\"/static/base/1.0.1/images/arxiv-logo-primary-light.svg\" alt=\"archive\">\n  </a>\n\n  <button type=\"button\" id=\"ds-nav-toggle\" class=\"ds-site-header-nav-toggle\"\n    aria-label=\"Open menu\" aria-controls=\"ds-site-header-nav\" aria-expanded=\"false\">\n    <svg viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" aria-hidden=\"true\" focusable=\"false\">\n      <line x1=\"3\" y1=\"6\" x2=\"21\" y2=\"6\"/>\n      <line x1=\"3\" y1=\"12\" x2=\"21\" y2=\"12\"/>\n      <line x1=\"3\" y1=\"18\" x2=\"21\" y2=\"18\"/>\n    </svg>\n  </button>\n\n  <nav class=\"ds-site-header-nav\" id=\"ds-site-header-nav\" aria-label=\"Main navigation\"><a id=\"arxiv-search-toggle\" href=\"https://arxiv.org/search\"\n      aria-controls=\"arxiv-search-overlay\" aria-expanded=\"false\">\n      <svg class=\"ds-nav-icon\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" aria-hidden=\"true\" focusable=\"false\">\n        <circle cx=\"11\" cy=\"11\" r=\"8\"/>\n        <line x1=\"21\" y1=\"21\" x2=\"16.65\" y2=\"16.65\"/>\n      </svg>\n      Search\n    </a>\n    <a href=\"https://arxiv.org/user/create\">Submit</a>\n    <a href=\"https://info.arxiv.org/about/donate.html\">Donate</a>\n    <span class=\"ds-site-header-divider\" aria-hidden=\"true\"></span>\n      <a href=\"https://arxiv.org/login\" class=\"ds-site-header-login\">Log in</a>\n  </nav>\n</header>\n\n<div class=\"arxiv-search-overlay\" id=\"arxiv-search-overlay\" hidden>\n  <div class=\"arxiv-search-panel\" role=\"search\">\n    <form method=\"GET\" action=\"https://arxiv.org/search\">\n      <label for=\"arxiv-search-input\" class=\"is-sr-only\">Search arXiv</label>\n      <input type=\"text\" name=\"query\" id=\"arxiv-search-input\" autocomplete=\"off\"\n        placeholder=\"Search papers by title, author, abstract, or ID...\">\n      <input type=\"hidden\" name=\"searchtype\" value=\"all\">\n      <input type=\"hidden\" name=\"source\" value=\"header\">\n    </form>\n    <div class=\"arxiv-search-hint\">\n      Press Enter to search &middot; <a href=\"https://arxiv.org/search/advanced\">Advanced search</a>\n    </div>\n  </div>\n</div>\n    <main>\n      <div id=\"content\">\n<!--\nrdf:RDF xmlns:rdf=\"http://www.w3.org/1999/02/22-rdf-syntax-ns#\"\n         xmlns:dc=\"http://purl.org/dc/elements/1.1/\"\n         xmlns:trackback=\"http://madskills.com/public/xml/rss/module/trackback/\">\n    <rdf:Description\n        rdf:about=\"/abs/2512.17538\"\n        dc:identifier=\"/abs/2512.17538\"\n        dc:title=\"Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\"\n        trackback:ping=\"/trackback/2512.17538\" />\n    </rdf:RDF>\n--><div id=\"abs-outer\">\n\n  <div class=\"leftcolumn\">\n    <div class=\"subheader\">\n      <h1>Computer Science > Networking and Internet Architecture</h1>\n    </div>\n\n    <div class=\"header-breadcrumbs-mobile\">\n      <strong>arXiv:2512.17538</strong> (cs)\n    </div>\n<link rel=\"stylesheet\" type=\"text/css\" href=\"/static/base/1.0.1/css/abs.css\">\n<div id=\"content-inner\">\n  <div id=\"abs\">\n    <div class=\"dateline\">\n  [Submitted on 19 Dec 2025]</div>\n    <h1 class=\"title mathjax\"><span class=\"descriptor\">Title:</span>Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility</h1>\n    <div class=\"authors\"><span class=\"descriptor\">Authors:</span><a href=\"https://arxiv.org/search/cs?searchtype=author&amp;query=Lin,+Z\" rel=\"nofollow\">Zibin Lin</a>, <a href=\"https://arxiv.org/search/cs?searchtype=author&amp;query=Zhang,+S\" rel=\"nofollow\">Shengli Zhang</a>, <a href=\"https://arxiv.org/search/cs?searchtype=author&amp;query=Liao,+G\" rel=\"nofollow\">Guofu Liao</a>, <a href=\"https://arxiv.org/search/cs?searchtype=author&amp;query=Tao,+D\" rel=\"nofollow\">Dacheng Tao</a>, <a href=\"https://arxiv.org/search/cs?searchtype=author&amp;query=Wang,+T\" rel=\"nofollow\">Taotao Wang</a></div>            <div id=\"download-button-info\" hidden>View a PDF of the paper titled Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility, by Zibin Lin and 3 other authors</div>\n    <a class=\"mobile-submission-download\" href=\"/pdf/2512.17538\">View PDF</a>\n    <a class=\"mobile-submission-download\" href=\"https://arxiv.org/html/2512.17538v1\">HTML (experimental)</a>\n\n\n\n    <blockquote class=\"abstract mathjax\">\n            <span class=\"descriptor\">Abstract:</span>Autonomous AI agents lack traceable accountability mechanisms, creating a fundamental dilemma where systems must either operate as ``downgraded tools&#39;&#39; or risk real-world abuse. This vulnerability stems from the limitations of traditional key-based authentication, which guarantees neither the operator&#39;s physical identity nor the agent&#39;s code integrity. To bridge this gap, we propose BAID (Binding Agent ID), a comprehensive identity infrastructure establishing verifiable user-code binding. BAID integrates three orthogonal mechanisms: local binding via biometric authentication, decentralized on-chain identity management, and a novel zkVM-based Code-Level Authentication protocol. By leveraging recursive proofs to treat the program binary as the identity, this protocol provides cryptographic guarantees for operator identity, agent configuration integrity, and complete execution provenance, thereby effectively preventing unauthorized operation and code substitution. We implement and evaluate a complete prototype system, demonstrating the practical feasibility of blockchain-based identity management and zkVM-based authentication protocol.\n    </blockquote>\n\n    <!--CONTEXT-->\n    <div class=\"metatable\">\n      <table summary=\"Additional metadata\"><tr>\n          <td class=\"tablecell label\">Subjects:</td>\n          <td class=\"tablecell subjects\">\n            <span class=\"primary-subject\">Networking and Internet Architecture (cs.NI)</span>; Cryptography and Security (cs.CR)</td>\n        </tr><tr>\n          <td class=\"tablecell label\">Cite as:</td>\n          <td class=\"tablecell arxivid\"><span class=\"arxivid\"><a href=\"https://arxiv.org/abs/2512.17538\">arXiv:2512.17538</a> [cs.NI]</span></td>\n        </tr>\n        <tr>\n          <td class=\"tablecell label\">&nbsp;</td>\n          <td class=\"tablecell arxividv\">(or <span class=\"arxivid\">\n              <a href=\"https://arxiv.org/abs/2512.17538v1\">arXiv:2512.17538v1</a> [cs.NI]</span> for this version)\n          </td>\n        </tr>\n        <tr>\n          <td class=\"tablecell label\">&nbsp;</td>\n          <td class=\"tablecell arxivdoi\">              <a href=\"https://doi.org/10.48550/arXiv.2512.17538\"  id=\"arxiv-doi-link\">https://doi.org/10.48550/arXiv.2512.17538</a><div class=\"button-and-tooltip\">\n              <button class=\"more-info\" aria-describedby=\"more-info-desc-1\">\n                <svg height=\"15\" role=\"presentation\" xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 512 512\"><path fill=\"currentColor\" d=\"M256 8C119.043 8 8 119.083 8 256c0 136.997 111.043 248 248 248s248-111.003 248-248C504 119.083 392.957 8 256 8zm0 110c23.196 0 42 18.804 42 42s-18.804 42-42 42-42-18.804-42-42 18.804-42 42-42zm56 254c0 6.627-5.373 12-12 12h-88c-6.627 0-12-5.373-12-12v-24c0-6.627 5.373-12 12-12h12v-64h-12c-6.627 0-12-5.373-12-12v-24c0-6.627 5.373-12 12-12h64c6.627 0 12 5.373 12 12v100h12c6.627 0 12 5.373 12 12v24z\" class=\"\"></path></svg>\n                <span class=\"visually-hidden\">Focus to learn more</span>\n              </button>\n              <!-- tooltip description -->\n              <div role=\"tooltip\" id=\"more-info-desc-1\">\n                <span class=\"left-corner\"></span>                  arXiv-issued DOI via DataCite</div>\n            </div>\n          </td>\n        </tr></table>\n    </div>\n  </div>\n</div>\n    <div class=\"submission-history\">\n      <h2>Submission history</h2> From: Zibin Lin [<a href=\"/show-email/507aca72/2512.17538\" rel=\"nofollow\">view email</a>]      <br/>    <strong>[v1]</strong>\n        Fri, 19 Dec 2025 13:01:54 UTC (976 KB)<br/>\n</div>\n  </div>\n  <!--end leftcolumn-->\n<div class=\"extra-services\">    <div class=\"full-text\">\n      <a name=\"other\"></a>\n      <span class=\"descriptor\">Full-text links:</span>\n      <h2>Access Paper:</h2>\n      <ul>\n  <div id=\"download-button-info\" hidden>\nView a PDF of the paper titled Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility, by Zibin Lin and 3 other authors</div><li><a href=\"/pdf/2512.17538\" aria-describedby=\"download-button-info\" accesskey=\"f\" class=\"abs-button download-pdf\">View PDF</a></li><li><a href=\"https://arxiv.org/html/2512.17538v1\" class=\"abs-button\" id=\"latexml-download-link\">HTML (experimental)</a></li><li><a href=\"/src/2512.17538\" class=\"abs-button download-eprint\">TeX Source\n </a></li></ul>\n      <div class=\"abs-license\"><a href=\"http://arxiv.org/licenses/nonexclusive-distrib/1.0/\" title=\"Rights to this article\">view license</a></div>\n    </div>\n    <!--end full-text-->    <div class=\"browse\">\n    <h3 class=\"browse-context-heading\">Current browse context:</h3>\n  <div class=\"current\">cs.NI</div>\n\n  <div class=\"prevnext\">\n<span class=\"arrow\">\n      <a class=\"abs-button prev-url\" href=\"/prevnext?id=2512.17538&amp;function=prev&amp;context=cs.NI\"\n         accesskey=\"p\" title=\"previous in cs.NI (accesskey p)\" rel=\"nofollow\">&lt;&nbsp;prev</a>\n    </span>\n    <span class=\"is-hidden-mobile\">&nbsp; | &nbsp;</span>    <span class=\"arrow\">\n      <a class=\"abs-button next-url\" href=\"/prevnext?id=2512.17538&amp;function=next&amp;context=cs.NI\" accesskey=\"n\"\n         title=\"next in cs.NI (accesskey n)\"  rel=\"nofollow\">next&nbsp;&gt;</a>\n    </span><br/>\n  </div><div class=\"list\">\n    <a class=\"abs-button abs-button-grey abs-button-small context-new\" href=\"/list/cs.NI/new\"  rel=\"nofollow\">new</a>\n    <span class=\"is-hidden-mobile\"> | </span>\n    <a class=\"abs-button abs-button-grey abs-button-small context-recent\" href=\"/list/cs.NI/recent\" rel=\"nofollow\">recent</a>\n    <span class=\"is-hidden-mobile\"> | </span><a class=\"abs-button abs-button-grey abs-button-small context-id\" href=\"/list/cs.NI/2025-12\" rel=\"nofollow\">2025-12</a>\n  </div><div class=\"abs-switch-cat\">\n    Change to browse by:\n    <div class=\"switch context-change\">\n        <a href=\"/abs/2512.17538?context=cs\" rel=\"nofollow\">cs</a><br class=\"is-hidden-mobile\">\n        <a class=\"subclass\" href=\"/abs/2512.17538?context=cs.CR\" rel=\"nofollow\">cs.CR</a><br class=\"is-hidden-mobile\">\n    </div>\n  </div>\n\n    </div>\n      <div class=\"extra-ref-cite\">\n        <h3>References &amp; Citations</h3>\n        <ul>\n          <li><a  class=\"abs-button abs-button-small cite-ads\" href=\"https://ui.adsabs.harvard.edu/abs/arXiv:2512.17538\">NASA ADS</a></li><li><a  class=\"abs-button abs-button-small cite-google-scholar\" href=\"https://scholar.google.com/scholar_lookup?arxiv_id=2512.17538\" target=\"_blank\" rel=\"noopener\">Google Scholar</a></li>\n          <li><a  class=\"abs-button abs-button-small cite-semantic-scholar\" href=\"https://api.semanticscholar.org/arXiv:2512.17538\" target=\"_blank\" rel=\"noopener\">Semantic Scholar</a></li>\n        </ul>\n        <div style=\"clear:both;\"></div>\n      </div>\n\n<div class='extra-ref-cite'>\n    <button type=\"button\" id='bib-cite-trigger' class=\"bib-cite-button abs-button\">export BibTeX citation</button>\n    <span id='bib-cite-loading' hidden='true'>Loading...</span>\n</div>\n\n<div id='bib-cite-modal' class='bib-modal' hidden='true'>\n    <div class='bib-modal-content'>\n        <div class='bib-modal-title'>\n            <h2>BibTeX formatted citation</h2>\n            <button type=\"button\" class='bib-modal-close' aria-label=\"Close\">&times;</button>\n        </div>\n        <div>\n            <textarea id='bib-cite-target' class=\"bib-citation-content\" aria-label=\"loading the citation\">loading...</textarea>\n        </div>\n        <div>\n            <span>Data provided by: </span>\n            <a id='bib-cite-source-api'></a>\n        </div>\n    </div>\n</div><div class=\"bookmarks\">\n  <div><h3>Bookmark</h3></div><a class=\"abs-button abs-button-grey abs-button-small\" href=\"http://www.bibsonomy.org/BibtexHandler?requTask=upload&amp;url=https://arxiv.org/abs/2512.17538&amp;description=Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\"\n     title=\"Bookmark on BibSonomy\">\n    <img src=\"/static/browse/0.3.4/images/icons/social/bibsonomy.png\"\n         alt=\"BibSonomy\"/>\n  </a>\n  <a class=\"abs-button abs-button-grey abs-button-small\" href=\"https://reddit.com/submit?url=https://arxiv.org/abs/2512.17538&amp;title=Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\"\n     title=\"Bookmark on Reddit\">\n    <img src=\"/static/browse/0.3.4/images/icons/social/reddit.png\"\n         alt=\"Reddit\"/>\n  </a>\n</div>  </div>\n  <!--end extra-services-->\n<!-- LABS AREA -->\n<div id=\"labstabs\">\n  <div class=\"labstabs\" role=\"tablist\" aria-label=\"arXivLabs tools\"><input type=\"radio\" name=\"tabs\" id=\"tabone\"checked=\"checked\"class=\"labs-tab-input\">\n    <label for=\"tabone\" role=\"tab\" aria-selected=\"true\" aria-controls=\"tabpanel-one\" id=\"tab-label-one\">Bibliographic Tools</label>\n    <div class=\"tab labs-display-bib\" role=\"tabpanel\" id=\"tabpanel-one\" aria-labelledby=\"tab-label-one\">\n      <h1>Bibliographic and Citation Tools</h1>\n      <div class=\"toggle\">\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input id=\"bibex-toggle\" type=\"checkbox\" class=\"lab-toggle\"\n                     data-script-url=\"/static/browse/0.3.4/bibex/bibex.js?20241202\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">Bibliographic Explorer Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-bibex\">Bibliographic Explorer</span> <em>(<a href=\"https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer\">What is the Explorer?</a>)</em>\n          </div>\n        </div>\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"connectedpapers-toggle\"\n                type=\"checkbox\"\n                class=\"lab-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/connectedpapers.js\"\n                aria-labelledby=\"label-for-connected-papers\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">Connected Papers Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-connected-papers\">Connected Papers</span> <em>(<a href=\"https://www.connectedpapers.com/about\" target=\"_blank\">What is Connected Papers?</a>)</em>\n          </div>\n        </div><div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"litmaps-toggle\"\n                type=\"checkbox\"\n                class=\"lab-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/litmaps.js?20210617\"\n                aria-labelledby=\"label-for-litmaps\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">Litmaps Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-litmaps\">Litmaps</span> <em>(<a href=\"https://www.litmaps.co/\" target=\"_blank\">What is Litmaps?</a>)</em>\n          </div>\n        </div>\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"scite-toggle\"\n                type=\"checkbox\"\n                class=\"lab-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/scite.js?20210617\"\n                aria-labelledby=\"label-for-scite\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">scite.ai Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-scite\">scite Smart Citations</span> <em>(<a href=\"https://www.scite.ai/\" target=\"_blank\">What are Smart Citations?</a>)</em>\n          </div>\n        </div>\n      </div>\n        <div class=\"labs-content-placeholder labs-display\" style=\"display: none;\"></div>\n        <div style=\"min-height: 15px\" id=\"connectedpapers-output\"></div>\n        <div style=\"min-height: 15px\" id=\"litmaps-open-in\"></div>\n        <div style=\"min-height: 15px\" id=\"scite-open-in\"></div>\n    </div>\n\n\n    <input type=\"radio\" name=\"tabs\" id=\"tabtwo\" class=\"labs-tab-input\">\n    <label for=\"tabtwo\" role=\"tab\" aria-selected=\"false\" aria-controls=\"tabpanel-two\" id=\"tab-label-two\">Code, Data, Media</label>\n    <div class=\"tab\" role=\"tabpanel\" id=\"tabpanel-two\" aria-labelledby=\"tab-label-two\">\n      <h1>Code, Data and Media Associated with this Article</h1>\n      <div class=\"toggle\">\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"alphaxiv-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/alphaxiv.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-alphaxiv\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">alphaXiv Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-alphaxiv\">alphaXiv</span> <em>(<a href=\"https://alphaxiv.org/\" target=\"_blank\">What is alphaXiv?</a>)</em>\n          </div>\n        </div>\n\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input        \n                id=\"catalyzex-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/catalyzex.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-cx\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">Links to Code Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-cx\">CatalyzeX Code Finder for Papers</span> <em>(<a href=\"https://www.catalyzex.com\" target=\"_blank\">What is CatalyzeX?</a>)</em>\n          </div>\n        </div>\n\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"dagshub-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/dagshub.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-dagshub\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">DagsHub Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-dagshub\">DagsHub</span> <em>(<a href=\"https://dagshub.com/\" target=\"_blank\">What is DagsHub?</a>)</em>\n          </div>\n        </div>\n  \n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"gotitpub-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/gotitpub.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-gotitpub\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">GotitPub Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-gotitpub\">Gotit.pub</span> <em>(<a href=\"http://gotit.pub/faq\" target=\"_blank\">What is GotitPub?</a>)</em>\n          </div>\n        </div>\n\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"huggingface-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/huggingface.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-huggingface\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">Huggingface Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-huggingface\">Hugging Face</span> <em>(<a href=\"https://huggingface.co/huggingface\" target=\"_blank\">What is Huggingface?</a>)</em>\n          </div>\n        </div>\n\n        <div class=\"columns is-mobile lab-row\">\n          <div class=\"column lab-switch\">\n            <label class=\"switch\">\n              <input\n                id=\"sciencecast-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/sciencecast.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-sciencecast\">\n              <span class=\"slider\"></span>\n              <span class=\"is-sr-only\">ScienceCast Toggle</span>\n            </label>\n          </div>\n          <div class=\"column lab-name\">\n            <span id=\"label-for-sciencecast\">ScienceCast</span> <em>(<a href=\"https://sciencecast.org/welcome\" target=\"_blank\">What is ScienceCast?</a>)</em>\n          </div>\n        </div>\n      </div>\n\n      <div id=\"alphaxiv-output\" style=\"display:none\"></div>\n      <div id=\"catalyzex-output\" style=\"display:none\"></div>\n      <div id=\"dagshub-output\" style=\"display:none\"></div>\n      <div id=\"gotitpub-output\" style=\"display:none\"></div>\n      <div id=\"sciencecast-output\" style=\"display:none\"></div>\n      <div id=\"huggingface-output\" style=\"display:none\"></div>\n    </div>\n\n\n      <input type=\"radio\" name=\"tabs\" id=\"labstabs-demos-input\" class=\"labs-tab-input\">\n      <label for=\"labstabs-demos-input\" id=\"labstabs-demos-label\" role=\"tab\" aria-selected=\"false\" aria-controls=\"tabpanel-demos\">Demos</label>\n      <div class=\"tab\" role=\"tabpanel\" id=\"tabpanel-demos\" aria-labelledby=\"labstabs-demos-label\">\n        <h1>Demos</h1>\n        <div class=\"toggle\">\n          <div class=\"columns is-mobile lab-row\">\n            <div class=\"column lab-switch\">\n              <label class=\"switch\">\n                <input\n                  id=\"replicate-toggle\"\n                  data-script-url=\"/static/browse/0.3.4/js/replicate.js\"\n                  type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-replicate\">\n                <span class=\"slider\"></span>\n                <span class=\"is-sr-only\">Replicate Toggle</span>\n              </label>\n            </div>\n            <div class=\"column lab-name\">\n              <span id=\"label-for-replicate\">Replicate</span> <em>(<a href=\"https://replicate.com/docs/arxiv/about\" target=\"_blank\">What is Replicate?</a>)</em>\n            </div>\n          </div>\n          <div class=\"columns is-mobile lab-row\">\n            <div class=\"column lab-switch\">\n              <label class=\"switch\">\n                <input\n                  id=\"spaces-toggle\"\n                  data-script-url=\"/static/browse/0.3.4/js/spaces.js\"\n                  type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-spaces\">\n                <span class=\"slider\"></span>\n                <span class=\"is-sr-only\">Spaces Toggle</span>\n              </label>\n            </div>\n            <div class=\"column lab-name\">\n              <span id=\"label-for-spaces\">Hugging Face Spaces</span> <em>(<a href=\"https://huggingface.co/docs/hub/spaces\" target=\"_blank\">What is Spaces?</a>)</em>\n            </div>\n          </div>\n          <div class=\"columns is-mobile lab-row\">\n            <div class=\"column lab-switch\">\n              <label class=\"switch\">\n                <input\n                  id=\"txyz-toggle\"\n                  data-script-url=\"/static/browse/0.3.4/js/txyz.js\"\n                  type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-txyz\">\n                <span class=\"slider\"></span>\n                <span class=\"is-sr-only\">Spaces Toggle</span>\n              </label>\n            </div>\n            <div class=\"column lab-name\">\n              <span id=\"label-for-txyz\">TXYZ.AI</span> <em>(<a href=\"https://txyz.ai\" target=\"_blank\">What is TXYZ.AI?</a>)</em>\n            </div>\n          </div>\n        </div>\n        <div id=\"replicate-output\"></div>\n        <div id=\"spaces-output\"></div>\n        <div id=\"txyz-output\"></div>\n      </div>\n      <input type=\"radio\" name=\"tabs\" id=\"tabfour\" class=\"labs-tab-input\">\n      <label for=\"tabfour\" role=\"tab\" aria-selected=\"false\" aria-controls=\"tabpanel-four\" id=\"tab-label-four\">Related Papers</label>\n      <div class=\"tab\" role=\"tabpanel\" id=\"tabpanel-four\" aria-labelledby=\"tab-label-four\">\n        <h1>Recommenders and Search Tools</h1>\n        <div class=\"toggle\">\n          <div class=\"columns is-mobile lab-row\">\n            <div class=\"column lab-switch\">\n              <label class=\"switch\">\n                <input id=\"influenceflower-toggle\"\n                data-script-url=\"/static/browse/0.3.4/js/influenceflower.js\"\n                type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-influenceflower\">\n                <span class=\"slider\"></span>\n                <span class=\"is-sr-only\">Link to Influence Flower</span>\n              </label>\n            </div>\n            <div class=\"column lab-name\">\n              <span id=\"label-for-influenceflower\">Influence Flower</span> <em>(<a href=\"https://influencemap.cmlab.dev/\" target=\"_blank\">What are Influence Flowers?</a>)</em>\n            </div>\n          </div>\n          <div class=\"columns is-mobile lab-row\">\n            <div class=\"column lab-switch\">\n              <label class=\"switch\">\n                <input id=\"core-recommender-toggle\" type=\"checkbox\" class=\"lab-toggle\" aria-labelledby=\"label-for-core\">\n                <span class=\"slider\"></span>\n                <span class=\"is-sr-only\">Core recommender toggle</span>\n              </label>\n            </div>\n            <div class=\"column lab-name\">\n              <span id=\"label-for-core\">CORE Recommender</span> <em>(<a href=\"https://core.ac.uk/services/recommender\">What is CORE?</a>)</em>\n            </div>\n          </div></div>\n        <div id=\"influenceflower-output\"></div>\n        <div id=\"influenceflower-output-graph\" style=\"display:none\">\n          <ul class=\"flower-tabs\">\n            <li class=\"active\"><a class=\"btn tab-btn\" onclick=\"openTab(event, 'tab-author')\">Author</a></li>\n            <li><a class=\"btn tab-btn\" onclick=\"openTab(event, 'tab-venue')\">Venue</a></li>\n            <li><a class=\"btn tab-btn\" onclick=\"openTab(event, 'tab-inst')\">Institution</a></li>\n            <li><a class=\"btn tab-btn\" onclick=\"openTab(event, 'tab-topic')\">Topic</a></li>\n          </ul>\n          <div class=\"flower-tab-content\">\n            <div class=\"tab-flower active\" id=\"tab-author\"><svg id=\"flower-graph-author\"></svg></div>\n            <div class=\"tab-flower\" id=\"tab-venue\"><svg id=\"flower-graph-venue\"></svg></div>\n            <div class=\"tab-flower\" id=\"tab-inst\"><svg id=\"flower-graph-inst\"></svg></div>\n            <div class=\"tab-flower\" id=\"tab-topic\"><svg id=\"flower-graph-topic\"></svg></div>\n          </div>\n        </div>\n        <div id=\"coreRecommenderOutput\"></div>\n        <div id=\"iarxivOutput\"></div>\n      </div>\n\n      <input type=\"radio\" name=\"tabs\" id=\"tabfive\" class=\"labs-tab-input\">\n      <label for=\"tabfive\" role=\"tab\" aria-selected=\"false\" aria-controls=\"tabpanel-five\" id=\"tab-label-five\">\n        About arXivLabs\n      </label>\n      <div class=\"tab\" role=\"tabpanel\" id=\"tabpanel-five\" aria-labelledby=\"tab-label-five\">\n        <div class=\"columns\">\n          <div class=\"column\">\n            <h1>arXivLabs: experimental projects with community collaborators</h1>\n            <p>arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.</p>\n            <p>Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.</p>\n            <p>Have an idea for a project that will add value for arXiv's community? <a href=\"https://info.arxiv.org/labs/index.html\"><strong>Learn more about arXivLabs</strong></a>.</p>\n          </div>\n          <div class=\"column is-narrow is-full-mobile\">\n            <p class=\"icon-labs\"><svg xmlns=\"http://www.w3.org/2000/svg\" role=\"presentation\" viewBox=\"0 0 635.572 811\"><path d=\"M175.6 676v27h-27v-27zm-54 27v27h27v-27zm-27 27v27h27v-27zm396-54v27h-27v-27zm0 27v27h27v-27zm27 27v27h27v-27zm-27-414h27v27h-27zm27 0h27v-27h-27zm27-27h27v-27h-27zm-396 45h-27v-27h27zm-27-54h-27v27h27zm-27-27h-27v27h27z\"/><path d=\"M94.6 730v27h-27v-27zm477 0v27h-27v-27zm-27-495h27v27h-27zm-450 18h-27v-27h27zm477 9h27v27h-27zm-54 495h27v27h-27zm-423 0h27v27h-27zm-54-504h27v27h-27z\" fill=\"#666\"/><path d=\"M67.6 730v27h-27v-27zm54 54v27h-27v-27zm0-108v27h27v-27zm-27 27v27h27v-27zm-81 0v27h27v-27zm585 27v27h-27v-27zm-108-54v27h27v-27zm27 27v27h27v-27zm81 0v27h27v-27zm-54-495h27v27h-27zm-54 108h27v-27h-27zm27-27h27v-27h-27zm0-81h27v-27h-27zm-423 18h-27v-27h27zm54 54h-27v27h27zm-27-27h-27v27h27zm0-81h-27v27h27zm423 612v27h-27v-27zm81-522v27h-27v-27zm-585-9v27h-27v-27z\" fill=\"#999\"/><path d=\"M94.6 784v27h-27v-27zm-27-27v27h27v-27zm-27-54v27h27v-27zm27 0v27h27v-27zm0-27v27h27v-27zm27 0v27h27v-27zm0-27v27h27v-27zm27 0v27h27v-27zm-108 81v27h27v-27zm558 54v27h-27v-27zm-27-27v27h27v-27zm27-54v27h27v-27zm-27 0v27h27v-27zm0-27v27h27v-27zm-27 0v27h27v-27zm0-27v27h27v-27zm-27 0v27h27v-27zm108 81v27h27v-27zm0-495h27v27h-27zm-27 27h27v-27h-27zm-54-27h27v-27h-27zm0 27h27v-27h-27zm-27 0h27v-27h-27zm0 27h27v-27h-27zm-27 0h27v-27h-27zm0 27h27v-27h-27zm81-108h27v-27h-27zm-504 45h-27v-27h27zm27-27h-27v27h27zm54-27h-27v27h27zm0 27h-27v27h27zm27 0h-27v27h27zm0 27h-27v27h27zm27 0h-27v27h27zm0 27h-27v27h27zm-81-108h-27v27h27z\" fill=\"#ccc\"/><path d=\"M598.6 665.1H41.5C-76.5 667 176 280.2 176 280.2h53a46.5 46.5 0 0162.8-56.3 29.2 29.2 0 1128.5 35.9h-1a46.5 46.5 0 01-1.5 20.3l142.5-.1s255.3 387 138.3 385.1zM291 181a29.3 29.3 0 10-29.2-29.3A29.3 29.3 0 00291 181zm65.4-66.8a22.4 22.4 0 10-22.5-22.4 22.4 22.4 0 0022.5 22.4z\" fill=\"#fc0\"/><path d=\"M245.5 172V10h153v162s324 495 198 495h-558c-126 0 207-495 207-495zm126 54h56m-13 72h56m-9 72h56m-20 72h56m-22 72h56m-29 72h56m-457-45c20.8 41.7 87.3 81 160.7 81 72.1 0 142.1-38.2 163.4-81\" fill=\"none\" stroke=\"#000\" stroke-miterlimit=\"10\" stroke-width=\"20\"/><path d=\"M273.3 421.7c0 31-9.8 56.3-21.9 56.3s-21.8-25.2-21.8-56.3 9.8-56.3 21.8-56.3 21.9 25.2 21.9 56.3zm114.4-56.3c-12 0-21.8 25.2-21.8 56.3s9.7 56.3 21.8 56.3 21.9-25.2 21.9-56.3-9.8-56.3-21.9-56.3zM150.1 526.6c-18.2 6.7-27.5 22.9-23.2 30.2s14.8-5.5 33-12.2 37.4-4.9 33-12.2-24.5-12.6-42.8-5.8zm296 5.8c-4.2 7.3 14.9 5.5 33.1 12.2s28.7 19.5 33 12.2-5-23.5-23.2-30.2-38.5-1.5-42.8 5.8z\"/></svg></p>\n          </div>\n        </div>\n      </div>\n\n    </div>\n</div>\n<!-- END LABS AREA -->\n  <div class=\"endorsers\">\n    <a href=\"/auth/show-endorsers/2512.17538\" class=\"endorser-who\" rel=\"nofollow\">Which authors of this paper are endorsers?</a> |\n    <a id=\"mathjax_toggle\" href=\"javascript:setMathjaxCookie()\">Disable MathJax</a> (<a href=\"https://info.arxiv.org/help/mathjax.html\">What is MathJax?</a>)\n    <span class=\"help\" style=\"font-style: normal; float: right; margin-top: 0; margin-right: 1em;\"></span>\n  </div>\n  <script type=\"text/javascript\" language=\"javascript\">mathjaxToggle();</script>\n</div>\n      </div>\n    </main>\n\n<footer class=\"ds-site-footer\">\n  <div class=\"ds-site-footer-grid\">\n    <div class=\"ds-site-footer-main\">\n      <div class=\"ds-site-footer-ack\">\n        We gratefully acknowledge support from\n        our <strong>major funders</strong>,\n        <a href=\"https://info.arxiv.org/about/ourmembers.html\"><strong>member institutions</strong></a><span class=\"ack-member-inline\" hidden>, <strong></strong></span>,\n        and all contributors.\n      </div>\n      <nav class=\"ds-site-footer-links\" aria-label=\"Site navigation\">\n        <a href=\"https://info.arxiv.org/about\">About</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help\">Help</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/contact.html\">Contact</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/subscribe\">Subscribe</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/license/index.html\">Copyright</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/policies/privacy_policy.html\">Privacy</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/web_accessibility.html\">Accessibility</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://status.arxiv.org\" target=\"_blank\" rel=\"noopener noreferrer\">Operational Status<span class=\"is-sr-only\"> (opens in new tab)</span></a>\n      </nav>\n    </div>\n\n    <div class=\"ds-site-footer-funders\" aria-label=\"Major funders\">\n      <div class=\"ds-site-footer-funders-label\">Major funding support from</div>\n      <div class=\"ds-site-footer-funders-logos\">\n        <a class=\"ds-funder-link\" href=\"https://www.simonsfoundation.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation.png\" alt=\"Simons Foundation\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.sfi.org.bm/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation-international.png\" alt=\"Simons Foundation International\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.schmidtsciences.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/schmidt-sciences.png\" alt=\"Schmidt Sciences\">\n        </a>\n      </div>\n    </div>\n  </div>\n</footer>  </div>\n\n  <script src=\"/static/base/1.0.1/js/arxiv-header.js?v=20260626\"></script>\n\n</body>\n\n</html>","snapshot_chars":41436,"live_check":"matches"},{"url":"https://arxiv.org/html/2512.17538","committed_hash":"sha256:504ab6560381b82251aff3b58b9ce3d8324c9d259ff9eb6d81d02a41ddbfe971","committed_hash_short":"sha256:504ab656…ddbfe971","mime_type":"text/html","committed_at":"2026-09-08T20:00:20.661017+00:00","content_snapshot":"<!DOCTYPE html><html lang=\"en\">\n<head>\n<meta http-equiv=\"content-type\" content=\"text/html; charset=UTF-8\">\n<title>Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility</title>\n<!--Generated by LaTeXML oxide (version 0.7.6) http://dlmf.nist.gov/LaTeXML/.-->\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1, shrink-to-fit=no\">\n<link rel=\"stylesheet\" href=\"/static/browse/0.3.4/css/arxiv-html-papers-20260823.css\" type=\"text/css\">\n<script src=\"/static/browse/0.3.4/js/arxiv-html-papers-20260131.js\"> </script>\n<script>\n  // Restore the saved color scheme preference, or\n  // enact the browser preference if \"automatic\", \n  // without expecting DOM load to have completed.\n  //\n  // Also restore any saved readingmode and ToC display preferences.\n  function initializeReadingPreferences() {\n    let saved_theme = localStorage.getItem(\"ar5iv_theme\") || \"automatic\";\n    if (saved_theme === \"automatic\") {\n      if (window.matchMedia(\"(prefers-color-scheme: dark)\").matches) {\n        saved_theme = \"dark\";\n      }\n    }\n    if (saved_theme == \"dark\") {\n      document.documentElement.setAttribute(\"data-theme\", \"dark\");\n    } else {\n      document.documentElement.setAttribute(\"data-theme\", \"light\");\n    }\n\n    const tocDisplay = localStorage.getItem('arxiv_html_paper_toc_display');\n    if (tocDisplay) {\n      document.documentElement.setAttribute(\"data-toc-display\", tocDisplay);\n    }\n    const readingMode = localStorage.getItem('arxiv_html_paper_reading_mode');\n    if (readingMode) {\n      document.documentElement.setAttribute(\"data-reading-mode\", readingMode);\n    }\n    // Pre-apply spinout-banner dismissal here, before the banner paints, so it\n    // never flashes in only to be hidden later by the deferred arxiv-header.js.\n    // Key matches arxiv-header.js: \"arxiv-banner-dismissed:\" + data-banner-name.\n    if (localStorage.getItem('arxiv-banner-dismissed:spinout-nonprofit')) {\n      document.documentElement.setAttribute(\"data-banner-dismissed\", \"\");\n    }\n  }\n  // Run as soon as JS starts, to minimize repainting\n  initializeReadingPreferences();\n</script>\n<link rel=\"apple-touch-icon\" sizes=\"180x180\"\n  href=\"/static/browse/0.3.4/images/icons/apple-touch-icon.png\">\n<link rel=\"icon\" type=\"image/png\" sizes=\"32x32\"\n  href=\"/static/browse/0.3.4/images/icons/favicon-32x32.png\">\n<link rel=\"icon\" type=\"image/png\" sizes=\"16x16\"\n  href=\"/static/browse/0.3.4/images/icons/favicon-16x16.png\">\n<link rel=\"manifest\" href=\"/static/browse/0.3.4/images/icons/site.webmanifest\">\n<link rel=\"mask-icon\" href=\"/static/browse/0.3.4/images/icons/safari-pinned-tab.svg\" color=\"#5bbad5\">\n<link rel=\"stylesheet\" type=\"text/css\" media=\"screen\" href=\"https://use.typekit.net/utz6mli.css\"><link rel=\"stylesheet\" type=\"text/css\" media=\"screen\"\n  href=\"/static/base/1.0.1/css/arxiv-header-footer.css?v=20260626\"><style>\n  /* Banner pre-dismissal (set above before paint -> no flash-then-hide) and\n     reading-mode chrome hiding. */\n  html[data-banner-dismissed] .ds-announcement { display: none; }\n  html[data-reading-mode=\"enabled\"] .ds-announcement,\n  html[data-reading-mode=\"enabled\"] .ds-site-footer { display: none; }\n  /* Keep the announcement text dark on the Open-Blue band in both colour themes\n     (otherwise it inherits the paper's warm-wash text in dark mode and washes out). */\n  .ds-announcement-text { color: var(--arxiv-ink, #1c1a17); }\n</style>\n<script defer src=\"/static/base/1.0.1/js/arxiv-header.js?v=20260626\"></script>\n</head>\n<body>\n<dialog id=\"modal-form\" aria-labelledby=\"modal-title\" closedby=\"any\">\n  <form id=\"modal-form-content\" method=\"dialog\" enctype=\"multipart/form-data\">\n    <header class=\"modal-header\">\n      <h5 id=\"modal-title\" class=\"modal-title\">Report GitHub Issue</h5>\n      <button type=\"submit\" formnovalidate class=\"modal-close\" aria-label=\"Close\">×</button>\n    </header>\n\n    <div class=\"modal-body\">\n      <label for=\"form_title\">Title:</label>\n      <input class=\"form-control\" id=\"form_title\" name=\"form_title\" required placeholder=\"Enter title\">\n\n      <p id=\"selectedTextModalDescription\" hidden>Content selection saved. Describe the issue below:</p>\n\n      <label for=\"description\">Description:</label>\n      <textarea class=\"form-control\" id=\"description\" name=\"description\" required maxlength=\"500\"\n        placeholder=\"500 characters maximum\"></textarea>\n    </div>\n\n    <footer class=\"modal-footer\">\n      <button type=\"submit\" value=\"internal-report\" class=\"sr-only modal-submit\">Submit without GitHub</button>\n      <button type=\"submit\" value=\"github-report\" class=\"modal-submit\">Submit in GitHub</button>\n    </footer>\n  </form>\n</dialog><div class=\"ds-announcement\" id=\"announcement-banner\" role=\"region\" aria-label=\"Announcement\"\n    data-banner-name=\"spinout-nonprofit\">\n    <img class=\"ds-announcement-glyph\" src=\"/static/base/1.0.1/images/icons/smileybones-small.svg\" alt=\"\" aria-hidden=\"true\">\n    <span class=\"ds-announcement-text\">arXiv is now an independent nonprofit!</span>\n    <a class=\"ds-announcement-link\" href=\"https://info.arxiv.org/about\">Learn more</a>\n    <button type=\"button\" class=\"ds-announcement-close\" aria-label=\"Dismiss announcement\">&times;</button>\n  </div>\n\n<header class=\"arxiv-html-header\">\n  <div class=\"html-header-logo\">\n    <a href=\"/\"><img alt=\"arXiv logo\" class=\"logo desktop-only\" width=\"100\"\n        src=\"/static/base/1.0.1/images/arxiv-logo-primary-light.svg\">\n      <span class=\"sr-only\">Back to arXiv</span>\n    </a>\n  </div>\n  <!--TOC, dark mode, links-->\n  <nav class=\"html-header-nav\">\n    <a class=\"header-button hover-effect desktop-only\" href=\"https://info.arxiv.org/about/accessible_HTML.html\"\n      target=\"_blank\">Why HTML?</a>\n    <a class=\"header-button\" title=\"Report an Issue\" href=\"#\" title=\"Report an issue\"\n      onclick=\"event.preventDefault(); showModalForm();\">\n      <svg role=\"presentation\" class=\"mobile-only toggle-icon\" aria-hidden=\"true\" height=\"1.25rem\"\n        viewBox=\"0 0 640 640\">\n        <path\n          d=\"M224 160C224 107 267 64 320 64C373 64 416 107 416 160L416 163.6C416 179.3 403.3 192 387.6 192L252.5 192C236.8 192 224.1 179.3 224.1 163.6L224.1 160zM569.6 172.8C580.2 186.9 577.3 207 563.2 217.6L465.4 290.9C470.7 299.8 474.7 309.6 477.2 320L576 320C593.7 320 608 334.3 608 352C608 369.7 593.7 384 576 384L480 384L480 416C480 418.6 479.9 421.3 479.8 423.9L563.2 486.4C577.3 497 580.2 517.1 569.6 531.2C559 545.3 538.9 548.2 524.8 537.6L461.7 490.3C438.5 534.5 395.2 566.5 344 574.2L344 344C344 330.7 333.3 320 320 320C306.7 320 296 330.7 296 344L296 574.2C244.8 566.5 201.5 534.5 178.3 490.3L115.2 537.6C101.1 548.2 81 545.3 70.4 531.2C59.8 517.1 62.7 497 76.8 486.4L160.2 423.9C160.1 421.3 160 418.7 160 416L160 384L64 384C46.3 384 32 369.7 32 352C32 334.3 46.3 320 64 320L162.8 320C165.3 309.6 169.3 299.8 174.6 290.9L76.8 217.6C62.7 207 59.8 186.9 70.4 172.8C81 158.7 101.1 155.8 115.2 166.4L224 248C236.3 242.9 249.8 240 264 240L376 240C390.2 240 403.7 242.8 416 248L524.8 166.4C538.9 155.8 559 158.7 569.6 172.8z\" />\n      </svg>\n      <span class=\"desktop-only\">Report Issue</span></a>\n    <!--back to abstract-->\n    <a class=\"header-button\" title=\"Back to abstract page\" aria-label=\"Back to abstract page\"\n      href=\"/abs/2512.17538v1\">\n      <svg class=\"mobile-only toggle-icon\" role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 512 512\" fill=\"#ffffff\"\n        aria-hidden=\"true\">\n        <path\n          d=\"M502.6 278.6c12.5-12.5 12.5-32.8 0-45.3l-128-128c-12.5-12.5-32.8-12.5-45.3 0s-12.5 32.8 0 45.3L402.7 224 192 224c-17.7 0-32 14.3-32 32s14.3 32 32 32l210.7 0-73.4 73.4c-12.5 12.5-12.5 32.8 0 45.3s32.8 12.5 45.3 0l128-128zM160 96c17.7 0 32-14.3 32-32s-14.3-32-32-32L96 32C43 32 0 75 0 128L0 384c0 53 43 96 96 96l64 0c17.7 0 32-14.3 32-32s-14.3-32-32-32l-64 0c-17.7 0-32-14.3-32-32l0-256c0-17.7 14.3-32 32-32l64 0z\">\n        </path>\n      </svg>\n      <span class=\"desktop-only\">Back to Abstract</span>\n    </a>\n    <!-- PDF download link -->\n    <a class=\"header-button\" title=\"Download PDF\" href=\"/pdf/2512.17538v1\"\n      target=\"_blank\">\n      <svg class=\"mobile-only toggle-icon\" role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 576 542\">\n        <path\n          d=\"M208 48L96 48c-8.8 0-16 7.2-16 16l0 384c0 8.8 7.2 16 16 16l80 0 0 48-80 0c-35.3 0-64-28.7-64-64L32 64C32 28.7 60.7 0 96 0L229.5 0c17 0 33.3 6.7 45.3 18.7L397.3 141.3c12 12 18.7 28.3 18.7 45.3l0 149.5-48 0 0-128-88 0c-39.8 0-72-32.2-72-72l0-88zM348.1 160L256 67.9 256 136c0 13.3 10.7 24 24 24l68.1 0zM240 380l32 0c33.1 0 60 26.9 60 60s-26.9 60-60 60l-12 0 0 28c0 11-9 20-20 20s-20-9-20-20l0-128c0-11 9-20 20-20zm32 80c11 0 20-9 20-20s-9-20-20-20l-12 0 0 40 12 0zm96-80l32 0c28.7 0 52 23.3 52 52l0 64c0 28.7-23.3 52-52 52l-32 0c-11 0-20-9-20-20l0-128c0-11 9-20 20-20zm32 128c6.6 0 12-5.4 12-12l0-64c0-6.6-5.4-12-12-12l-12 0 0 88 12 0zm76-108c0-11 9-20 20-20l48 0c11 0 20 9 20 20s-9 20-20 20l-28 0 0 24 28 0c11 0 20 9 20 20s-9 20-20 20l-28 0 0 44c0 11-9 20-20 20s-20-9-20-20l0-128z\" />\n      </svg>\n      <span class=\"desktop-only\">Download PDF</span></a>\n    <!-- navigational table of contents toggle -->\n    <a class=\"header-button toggle-icon\" href=\"javascript:toggleNavTOC();\" title=\"Toggle navigation\"\n      aria-label=\"Toggle navigation\">\n      <svg height=\"1.25rem\" role=\"presentation\" viewBox=\"0 0 512 512\">\n        <path\n          d=\"M40 48C26.7 48 16 58.7 16 72v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V72c0-13.3-10.7-24-24-24H40zM192 64c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zm0 160c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zm0 160c-17.7 0-32 14.3-32 32s14.3 32 32 32H480c17.7 0 32-14.3 32-32s-14.3-32-32-32H192zM16 232v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V232c0-13.3-10.7-24-24-24H40c-13.3 0-24 10.7-24 24zM40 368c-13.3 0-24 10.7-24 24v48c0 13.3 10.7 24 24 24H88c13.3 0 24-10.7 24-24V392c0-13.3-10.7-24-24-24H40z\">\n        </path>\n      </svg>\n    </a>\n    <!--- collapsable header / reading mode toggle -->\n    <a class=\"header-button toggle-icon\" href=\"javascript:toggleReadingMode();\"\n      title=\"Disable reading mode, show header and footer\">\n      <svg role=\"presentation\" height=\"1.25rem\"\n        viewBox=\"0 0 448 512\"><!--!Font Awesome Free v7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.-->\n        <path\n          d=\"M32 32C14.3 32 0 46.3 0 64l0 96c0 17.7 14.3 32 32 32s32-14.3 32-32l0-64 64 0c17.7 0 32-14.3 32-32s-14.3-32-32-32L32 32zM64 352c0-17.7-14.3-32-32-32S0 334.3 0 352l0 96c0 17.7 14.3 32 32 32l96 0c17.7 0 32-14.3 32-32s-14.3-32-32-32l-64 0 0-64zM320 32c-17.7 0-32 14.3-32 32s14.3 32 32 32l64 0 0 64c0 17.7 14.3 32 32 32s32-14.3 32-32l0-96c0-17.7-14.3-32-32-32l-96 0zM448 352c0-17.7-14.3-32-32-32s-32 14.3-32 32l0 64-64 0c-17.7 0-32 14.3-32 32s14.3 32 32 32l96 0c17.7 0 32-14.3 32-32l0-96z\" />\n      </svg>\n    </a>\n    <!--- colored theme toggle -->\n    <button type=\"button\" class=\"header-button color-tog\" onclick=\"toggleColorScheme();\" title=\"Toggle dark/light mode\" aria-label=\"Toggle color scheme\">\n      <span class=\"toggle-icon automatic-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"m14.3 16-.7-2h-3.2l-.7 2H7.8L11 7h2l3.2 9h-1.9M20 8.69V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69m-9.15 3.96h2.3L12 9l-1.15 3.65Z\">\n          </path>\n        </svg>\n      </span>\n      <span class=\"toggle-icon light-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"M12 8a4 4 0 0 0-4 4 4 4 0 0 0 4 4 4 4 0 0 0 4-4 4 4 0 0 0-4-4m0 10a6 6 0 0 1-6-6 6 6 0 0 1 6-6 6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69Z\">\n          </path>\n        </svg>\n      </span>\n      <span class=\"toggle-icon dark-tog\" aria-hidden=\"true\">\n        <svg role=\"presentation\" height=\"1.25rem\" viewBox=\"0 0 24 24\">\n          <path\n            d=\"M12 18c-.89 0-1.74-.2-2.5-.55C11.56 16.5 13 14.42 13 12c0-2.42-1.44-4.5-3.5-5.45C10.26 6.2 11.11 6 12 6a6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12 20 8.69Z\">\n          </path>\n        </svg>\n      </span>\n    </button>\n  </nav>\n</header><nav class=\"ltx_page_navbar\">\n<nav class=\"ltx_TOC\">\n<ol class=\"ltx_toclist\">\n<li class=\"ltx_tocentry ltx_tocentry_abstract\"><a href=\"#abstract1\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\">Abstract</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S1\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">1 </span>Introduction</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S1.SS1\" title=\"In 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">1.1 </span>Motivating Example: E-commerce Procurement</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S1.SS2\" title=\"In 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">1.2 </span>The Gap: Autonomous Capabilities Without Identity Infrastructure</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S1.SS3\" title=\"In 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">1.3 </span>Our Contributions</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S2\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2 </span>Technical Preliminaries</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS1\" title=\"In 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.1 </span>Blockchain</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS2\" title=\"In 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.2 </span>Zero-Knowledge Virtual Machine</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S2.SS3\" title=\"In 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">2.3 </span>Verifiable Credentials</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S3\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">3 </span>BAID System Overview</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S4\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4 </span>BAID System Designs</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS1\" title=\"In 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.1 </span>Local User-Agent Binding via Biometric Authentication</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#S4.SS1.SSS1\" title=\"In 4.1 Local User-Agent Binding via Biometric Authentication ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.1.1 </span>Agent Architecture</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#S4.SS1.SSS2\" title=\"In 4.1 Local User-Agent Binding via Biometric Authentication ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.1.2 </span>Biometric Template Registration and Verification</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS2\" title=\"In 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.2 </span>On-Chain Identity Management</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#S4.SS2.SSS1\" title=\"In 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.2.1 </span>Identity Management Smart Contract Framework</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#S4.SS2.SSS2\" title=\"In 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.2.2 </span>On-Chain Identity Registration and Binding Workflow</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S4.SS3\" title=\"In 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.3 </span>zkVM-Based Agent Identity Authentication Protocol</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#S4.SS3.SSS1\" title=\"In 4.3 zkVM-Based Agent Identity Authentication Protocol ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.3.1 </span>User-to-Agent Authorization</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#S4.SS3.SSS2\" title=\"In 4.3 zkVM-Based Agent Identity Authentication Protocol ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">4.3.2 </span>zkVM-Based Agent Identity Authentication</span></a></li>\n</ol></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S5\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5 </span>Implementation and Performance Evaluation</span></a>\n<ol class=\"ltx_toclist ltx_toclist_section\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS1\" title=\"In 5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.1 </span>Identity Management Smart Contracts Performance</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#S5.SS2\" title=\"In 5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">5.2 </span>Verifiable Agent System Performance</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S6\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">6 </span>Related Work</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_section\"><a href=\"#S7\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">7 </span>Conclusion</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_bibliography\"><a href=\"#bib\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\">References</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_appendix\"><a href=\"#A1\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A </span>zkVM-based Authentication Protocol Technical Specifications</span></a>\n<ol class=\"ltx_toclist ltx_toclist_appendix\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A1.SS1\" title=\"In Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.1 </span>Limitations of Key-Based Authentication</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A1.SS2\" title=\"In Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.2 </span>Code-Level Authentication</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A1.SS3\" title=\"In Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.3 </span>zkVM-Based Agent Authentication Protocol Workflow</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A1.SS4\" title=\"In Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.4 </span>Execution Continuity Across Conversational Turns</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS4.SSS1\" title=\"In A.4 Execution Continuity Across Conversational Turns ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.4.1 </span>Problem Statement</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS4.SSS2\" title=\"In A.4 Execution Continuity Across Conversational Turns ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.4.2 </span>Recursive Proof Algorithm</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A1.SS5\" title=\"In Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.5 </span>External Communication Provenance</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS5.SSS1\" title=\"In A.5 External Communication Provenance ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.5.1 </span>Problem Statement</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS5.SSS2\" title=\"In A.5 External Communication Provenance ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.5.2 </span>zkTLS Integration for Verifiable HTTPS Communications</span></a></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A1.SS6\" title=\"In Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.6 </span>Three-Phase Verification Pipeline</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS6.SSS1\" title=\"In A.6 Three-Phase Verification Pipeline ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.6.1 </span>Phase 1: Operator Biometric Authentication</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS6.SSS2\" title=\"In A.6 Three-Phase Verification Pipeline ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.6.2 </span>Phase 2: Agent Configuration Integrity</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A1.SS6.SSS3\" title=\"In A.6 Three-Phase Verification Pipeline ‣ Appendix A zkVM-based Authentication Protocol Technical Specifications ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">A.6.3 </span>Phase 3: Iterative Task Execution</span></a></li>\n</ol></li>\n</ol></li>\n<li class=\"ltx_tocentry ltx_tocentry_appendix\"><a href=\"#A2\" title=\"In Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B </span>Security Analysis</span></a>\n<ol class=\"ltx_toclist ltx_toclist_appendix\">\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A2.SS1\" title=\"In Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B.1 </span>Threat Model</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsection\"><a href=\"#A2.SS2\" title=\"In Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B.2 </span>Security Properties and Defenses</span></a>\n<ol class=\"ltx_toclist ltx_toclist_subsection\">\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A2.SS2.SSS1\" title=\"In B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B.2.1 </span>Defense Against Code Substitution Attacks</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A2.SS2.SSS2\" title=\"In B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B.2.2 </span>Defense Against Replay and Reordering Attacks</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A2.SS2.SSS3\" title=\"In B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B.2.3 </span>Defense Against Data Fabrication (Man-in-the-Middle)</span></a></li>\n<li class=\"ltx_tocentry ltx_tocentry_subsubsection\"><a href=\"#A2.SS2.SSS4\" title=\"In B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_title\"><span class=\"ltx_tag ltx_tag_ref\">B.2.4 </span>Defense Against Sybil and Impersonation Attacks</span></a></li>\n</ol></li>\n</ol></li>\n</ol></nav>\n</nav>\n<div class=\"ltx_page_main\">\n<div id=\"infobox\" class=\"infobox\">\n  <a id=\"license-tr\" href=\"https://info.arxiv.org/help/license/index.html#licenses-available\">\n    License: arXiv.org perpetual non-exclusive license\n  </a>\n  <div id=\"watermark-tr\">\narXiv:2512.17538v1 [cs.NI] 19 Dec 2025</div>\n</div><div class=\"ltx_page_content\">\n<article class=\"ltx_document ltx_authors_1line\">\n<div id=\"p1\" class=\"ltx_para\">\n<p id=\"p1.1\" class=\"ltx_p\">[style=chinese]</p>\n</div>\n<div id=\"p2\" class=\"ltx_para\">\n<p id=\"p2.1\" class=\"ltx_p\">[style=chinese]</p>\n</div>\n<div id=\"p3\" class=\"ltx_para\">\n<p id=\"p3.1\" class=\"ltx_p\">[style=chinese]</p>\n</div>\n<div id=\"p4\" class=\"ltx_para\">\n<p id=\"p4.1\" class=\"ltx_p\">[style=chinese]</p>\n</div>\n<div id=\"p5\" class=\"ltx_para\">\n<p id=\"p5.1\" class=\"ltx_p\">[style=chinese]</p>\n</div>\n<h1 class=\"ltx_title ltx_title_document\">Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility</h1>\n<div class=\"ltx_authors\">\n<span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Zibin Lin\n</span><span class=\"ltx_author_notes\"><span class=\"ltx_author_notes_content\">\n<span class=\"ltx_contact\">linaacc9595@gmail.com\n</span></span></span></span>\n<span class=\"ltx_author_before\">  </span><span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Shengli Zhang\n</span><span class=\"ltx_author_notes\"><span class=\"ltx_author_notes_content\">\n<span class=\"ltx_contact\">zsl@szu.edu.cn\n</span></span></span></span>\n<span class=\"ltx_author_before\">  </span><span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Guofu Liao\n</span><span class=\"ltx_author_notes\"><span class=\"ltx_author_notes_content\">\n<span class=\"ltx_contact\">liaoguofu2022@email.szu.edu.cn\n</span></span></span></span>\n<span class=\"ltx_author_before\">  </span><span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Dacheng Tao\n</span><span class=\"ltx_author_notes\"><span class=\"ltx_author_notes_content\">\n<span class=\"ltx_contact\">dacheng.tao@gmail.com\n</span></span></span></span>\n<span class=\"ltx_author_before\">  </span><span class=\"ltx_creator ltx_role_author\">\n<span class=\"ltx_personname\">Taotao Wang\n</span><span class=\"ltx_author_notes\"><span class=\"ltx_author_notes_content\">\n<span class=\"ltx_contact\">ttwang@szu.edu.cn\n</span>\n<span class=\"ltx_contact ltx_role_affiliation\">organization=Shenzhen University,\ncity=Shenzhen,\ncountry=China\n</span>\n<span class=\"ltx_contact ltx_role_affiliation\">organization=Nanyang Technological University,\ncountry=Singapore\n</span></span></span></span></div>\n\n<div id=\"abstract1\" class=\"ltx_abstract\"><h6 class=\"ltx_title ltx_title_abstract\">Abstract</h6>\n    \n<p id=\"abstract1.1\" class=\"ltx_p\">Autonomous AI agents lack traceable accountability mechanisms, creating a fundamental dilemma where systems must either operate as “downgraded tools” or risk real-world abuse. This vulnerability stems from the limitations of traditional key-based authentication, which guarantees neither the operator’s physical identity nor the agent’s code integrity. To bridge this gap, we propose BAID (Binding Agent ID), a comprehensive identity infrastructure establishing verifiable user-code binding. BAID integrates three orthogonal mechanisms: local binding via biometric authentication, decentralized on-chain identity management, and a novel zkVM-based Code-Level Authentication protocol.\nBy leveraging recursive proofs to treat the program binary as the identity, this protocol provides cryptographic guarantees for operator identity, agent configuration integrity,\nand complete execution provenance, thereby effectively preventing unauthorized operation and code substitution. We implement and evaluate a complete prototype system, demonstrating the practical feasibility of blockchain-based identity management and zkVM-based authentication protocol.</p>\n  \n</div>\n<div class=\"ltx_classification\"><h6 class=\"ltx_title ltx_title_classification\">keywords</h6>\nAI Agent Identity ,Agent Authentication ,Agent Accountability ,Zero-Knowledge Virtual Machine ,Blockchain\n\n</div><span id=\"id1\" class=\"ltx_note ltx_role_corresponding\"><sup class=\"ltx_note_mark\">†</sup><span class=\"ltx_note_outer\"><span class=\"ltx_note_content\"><sup class=\"ltx_note_mark\">†</sup><span class=\"ltx_note_type\">corresponding: </span>Corresponding author</span></span></span>\n<section id=\"S1\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">1 </span>Introduction</h2>\n\n<div id=\"S1.p1\" class=\"ltx_para\">\n<p id=\"S1.p1.1\" class=\"ltx_p\">Artificial Intelligence (AI) agents are evolving from mere tools into autonomous entities capable of independent perception,\nreasoning, decision-making, and action execution <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib14\" title=\"\" class=\"ltx_ref\">Xi et al. (2025)</a>; <a href=\"#bib.bib13\" title=\"\" class=\"ltx_ref\">Guo et al. (2024)</a></cite>. These agents can decompose\nnatural language objectives into executable steps and dynamically adjust their plans by invoking external APIs and\ntools based on environmental feedback <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib1\" title=\"\" class=\"ltx_ref\">Wang et al. (2024a)</a></cite>. This capability enables them to bridge digital and physical\nboundaries, opening unprecedented opportunities for automation and intelligent assistance. However, their deployment\nfaces a fundamental challenge: the absence of traceable and accountable responsibility chains. Without proper identity\nand accountability mechanisms, this limitation creates a critical dilemma where systems must either be “downgraded to tools”\nrequiring step-by-step human confirmation, or risk real-world abuse including voice cloning fraud,\nmass information manipulation, and governance conflicts <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib2\" title=\"\" class=\"ltx_ref\">Verma (2023a)</a>; <a href=\"#bib.bib3\" title=\"\" class=\"ltx_ref\">Verma (2023b)</a>; <a href=\"#bib.bib24\" title=\"\" class=\"ltx_ref\">Chan et al. (2023)</a>; <a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">Raskar et al. (2025a)</a></cite>. These abstract\naccountability challenges manifest concretely when autonomous agents perform actions in the real world that cross organizational\nboundaries and require clear attribution of responsibility.</p>\n</div>\n<section id=\"S1.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">1.1 </span>Motivating Example: E-commerce Procurement</h3>\n\n<div id=\"S1.SS1.p1\" class=\"ltx_para\">\n<p id=\"S1.SS1.p1.1\" class=\"ltx_p\">Consider a laptop procurement scenario where an AI agent (Agent A) acting on behalf of a user must interact with a merchant’s agent (Agent B). The workflow showed in Fig. <a href=\"#S1.F1\" title=\"Figure 1 ‣ 1.1 Motivating Example: E-commerce Procurement ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a> proceeds as follows:\n(1) Agent A receives a purchase request from its user; (2) Agent A discovers and contacts merchant Agent B;\n(3) both agents mutually verify identities; (4) Agent B checks inventory availability; (5) Agent A executes payment\nwithin authorized limits; (6) Agent B confirms order and initiates delivery. This seemingly straightforward\ntransaction reveals fundamental security requirements across five critical security phases:</p>\n</div>\n<div id=\"S1.SS1.p2\" class=\"ltx_para\">\n<ol id=\"S1.I1\" class=\"ltx_enumerate\">\n<li id=\"S1.I1.1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\"></span>\n<div id=\"S1.I1.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.p1.1\" class=\"ltx_p\">[(1)]</p>\n</div></li>\n<li id=\"S1.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S1.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_italic\">User Identity Verification</span>: Agent A must authenticate that its operator is the legitimate bound user.\nWithout this verification, <span id=\"S1.I1.i1.p1.1.2\" class=\"ltx_text ltx_font_bold\">command injection attacks</span> can hijack the agent for unauthorized purchases.</p>\n</div></li>\n<li id=\"S1.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S1.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_italic\">Trusted Discovery</span>: Agent A must discover and validate Agent B through a secure directory system.\nWithout trusted discovery, Agent A risks connecting to <span id=\"S1.I1.i2.p1.1.2\" class=\"ltx_text ltx_font_bold\">fraudulent agents</span> or <span id=\"S1.I1.i2.p1.1.3\" class=\"ltx_text ltx_font_bold\">phishing services</span>.</p>\n</div></li>\n<li id=\"S1.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S1.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_italic\">Mutual Authentication</span>: Both agents must bilaterally verify identities to establish trust.\nWithout robust mutual authentication, <span id=\"S1.I1.i3.p1.1.2\" class=\"ltx_text ltx_font_bold\">identity spoofing</span> and <span id=\"S1.I1.i3.p1.1.3\" class=\"ltx_text ltx_font_bold\">man-in-the-middle</span> attacks can\ncompromise transaction integrity.</p>\n</div></li>\n<li id=\"S1.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S1.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_italic\">Permission Control</span>: Agent A must operate within strictly defined authorization policies following\nthe principle of least privilege. Inadequate controls enable <span id=\"S1.I1.i4.p1.1.2\" class=\"ltx_text ltx_font_bold\">permission boundary violations</span> that exceed\nspending limits or authorized scope.</p>\n</div></li>\n<li id=\"S1.I1.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">5.</span> \n<div id=\"S1.I1.i5.p1\" class=\"ltx_para\">\n<p id=\"S1.I1.i5.p1.1\" class=\"ltx_p\"><span id=\"S1.I1.i5.p1.1.1\" class=\"ltx_text ltx_font_italic\">Accountability Tracking</span>: The system must maintain comprehensive audit trails for responsibility\nattribution and dispute resolution. Without auditable records, <span id=\"S1.I1.i5.p1.1.2\" class=\"ltx_text ltx_font_bold\">no dispute resolution</span> to resolve disputes\nor hold parties accountable.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S1.SS1.p3\" class=\"ltx_para\">\n<p id=\"S1.SS1.p3.1\" class=\"ltx_p\">Without proper identity and accountability infrastructure, each phase presents significant security and\ntrust challenges that existing approaches cannot adequately address.</p>\n</div>\n<figure id=\"S1.F1\" class=\"ltx_figure\"><object type=\"image/svg+xml\" data=\"2512.17538v1/workflowLattop.svg\" id=\"S1.F1.g1\" class=\"ltx_graphics ltx_centering ltx_img_portrait\" style=\"aspect-ratio:294/418;\" width=\"294\" height=\"418\"></object>\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 1: </span>E-commerce laptop procurement workflow with security and accountability challenges across phases.</figcaption>\n</figure>\n</section>\n<section id=\"S1.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">1.2 </span>The Gap: Autonomous Capabilities Without Identity Infrastructure</h3>\n\n<div id=\"S1.SS2.p1\" class=\"ltx_para\">\n<p id=\"S1.SS2.p1.1\" class=\"ltx_p\">Despite intensive research on system-level agent security—including goal alignment <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib4\" title=\"\" class=\"ltx_ref\">Kirk et al. (2024)</a>; <a href=\"#bib.bib5\" title=\"\" class=\"ltx_ref\">Huang et al. (2024)</a>; <a href=\"#bib.bib6\" title=\"\" class=\"ltx_ref\">OpenAI (2024)</a></cite>, adversarial robustness <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib7\" title=\"\" class=\"ltx_ref\">Zou et al. (2024)</a>; <a href=\"#bib.bib8\" title=\"\" class=\"ltx_ref\">Anil et al. (2024)</a>; <a href=\"#bib.bib9\" title=\"\" class=\"ltx_ref\">Wallace et al. (2024)</a></cite>, and multi-agent coordination <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib10\" title=\"\" class=\"ltx_ref\">Yan et al. (2024)</a>; <a href=\"#bib.bib11\" title=\"\" class=\"ltx_ref\">Chen and Parker (2024)</a>; <a href=\"#bib.bib12\" title=\"\" class=\"ltx_ref\">Tran et al. (2025)</a></cite>—a fundamental infrastructure gap remains: the lack of verifiable identity and accountability. Existing approaches typically assume unified trust boundaries, overlooking critical questions of “who is operating” and “who bears responsibility” in open ecosystems.</p>\n</div>\n<div id=\"S1.SS2.p2\" class=\"ltx_para\">\n<p id=\"S1.SS2.p2.1\" class=\"ltx_p\">Addressing this deficit requires a clear definition of responsibility. Theoretical models primarily distinguish between: (1) the <span id=\"S1.SS2.p2.1.1\" class=\"ltx_text ltx_font_italic\">Autonomous Responsibility Model</span>, where agents independently bear liability (implying legal personhood); and (2) the <span id=\"S1.SS2.p2.1.2\" class=\"ltx_text ltx_font_italic\">Binding Agent Model</span>, where agents act as accountable tools bound to specific human or organizational principals. We argue that the Binding Agent Model is the only practicable approach under current technological and legal constraints, as AI lacks legal subject status and agency law attributes actions to principals.</p>\n</div>\n<div id=\"S1.SS2.p3\" class=\"ltx_para\">\n<p id=\"S1.SS2.p3.1\" class=\"ltx_p\">However, realizing the Binding Agent paradigm introduces a fundamental challenge stemming from the distinction between autonomous agents and standard software. Unlike passive tools, autonomous agents possess the capacity for independent decision-making and real-world interactions. This autonomy necessitates a stricter form of binding: the agent must not only serve its owner securely but also ensure that all consequences are irrefutably traceable to that principal. Consequently, mere local user authentication—which provides only service exclusivity—is insufficient. Instead, a <span id=\"S1.SS2.p3.1.1\" class=\"ltx_text ltx_font_italic\">third-party verifiable proof</span> is required to confirm that critical actions were explicitly authorized by the user. This obligation is absent in traditional software models, which typically rely on implicit local trust.</p>\n</div>\n<div id=\"S1.SS2.p4\" class=\"ltx_para\">\n<p id=\"S1.SS2.p4.1\" class=\"ltx_p\">Emerging Agent Identity systems have laid meaningful foundations for naming and discovery: ANS <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">Huang et al. (2025)</a></cite> provides DNS-like resolution, AgentFacts <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">Raskar et al. (2025b)</a></cite> enables verifiable capability metadata, and works by Chan et al. <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib18\" title=\"\" class=\"ltx_ref\">Chan et al. (2024)</a></cite> and Raskar et al. <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">Raskar et al. (2025a)</a></cite> integrate identity markers into existing infrastructure. Recently, decentralized frameworks like LOKA <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">ranjan2025loka</span></cite> and ERC-8004 <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">erc8004</span></cite> have further advanced this field by addressing ethical alignment and on-chain validation. However, while these advancements successfully establish “agent-to-system” trust—ensuring agents are locatable, valid, and compliant entities—they fall short of establishing “human-to-agent” liability binding. They lack the mechanism to cryptographically anchor agent actions to a liable human principal. By relying on traditional key-based authentication, they inherit the semantic gap of standard software security: keys prove possession but neither authenticate the operator’s physical identity nor guarantee the execution logic’s integrity. In open environments, third-party verifiers require cryptographic assurance that an agent’s actions are authorized by its bound user—a mechanism absent in existing systems, leaving them vulnerable to code substitution and accountability evasion. To address this, we innovatively employ Zero-Knowledge Proofs (ZKP) to generate verifiable proofs of the authentication process itself, effectively bridging the gap between local authorization and global accountability.</p>\n</div>\n</section>\n<section id=\"S1.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">1.3 </span>Our Contributions</h3>\n\n<div id=\"S1.SS3.p1\" class=\"ltx_para\">\n<p id=\"S1.SS3.p1.1\" class=\"ltx_p\">To address these challenges and implement the Binding Agent responsibility paradigm, we propose the BAID (Binding Agent ID) framework. Our specific contributions are as follows:</p>\n</div>\n<div id=\"S1.SS3.p2\" class=\"ltx_para\">\n<ul id=\"S1.I2\" class=\"ltx_itemize\">\n<li id=\"S1.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i1.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">We propose the BAID framework</span>, a comprehensive identity infrastructure that integrates local biometric binding, decentralized on-chain identity management, and verifiable agent authentication. This framework provides a unified solution for identity verification, trusted discovery, and accountability tracking, ensuring “the correct agent is operated by the binding user executing committed code”.</p>\n</div></li>\n<li id=\"S1.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i2.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">We introduce a zkVM-based agent authentication protocol</span> to establish verifiable user-code binding. By leveraging code-level authentication and recursive zero-knowledge proofs, this mechanism cryptographically binds the agent’s execution to its registered identity and authorized user, effectively preventing code substitution attacks and ensuring execution integrity without revealing sensitive operational details.</p>\n</div></li>\n<li id=\"S1.I2.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S1.I2.i3.p1\" class=\"ltx_para\">\n<p id=\"S1.I2.i3.p1.1\" class=\"ltx_p\"><span id=\"S1.I2.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">We implement a complete prototype and provide extensive evaluation</span>. We develop the full system architecture including the identity management smart contracts, and zkVM verification circuits. Our experimental results demonstrate the practical feasibility of the system, with gas-efficient on-chain operations and millisecond-level verification latency suitable for real-world deployment.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"S1.SS3.p3\" class=\"ltx_para\">\n<p id=\"S1.SS3.p3.1\" class=\"ltx_p\">The rest of this paper is organized as follows. Section <a href=\"#S2\" title=\"2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> introduces the technical\npreliminaries. Section <a href=\"#S3\" title=\"3 BAID System Overview ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> presents the BAID system architecture and technical overviews. Section <a href=\"#S4\" title=\"4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a> describes the detailed technical\ndesign of the binding mechanisms. Section <a href=\"#S5\" title=\"5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a> evaluates the system’s security properties, performance\ncharacteristics, and deployment feasibility across multiple dimensions. Section <a href=\"#S6\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6</span></a> surveys related work. Section <a href=\"#S7\" title=\"7 Conclusion ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">7</span></a> concludes the paper.</p>\n</div>\n</section>\n</section>\n<section id=\"S2\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">2 </span>Technical Preliminaries</h2>\n\n<div id=\"S2.p1\" class=\"ltx_para\">\n<p id=\"S2.p1.1\" class=\"ltx_p\">This section introduces the fundamental technologies underlying our BAID framework.</p>\n</div>\n<section id=\"S2.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">2.1 </span>Blockchain</h3>\n\n<div id=\"S2.SS1.p1\" class=\"ltx_para\">\n<p id=\"S2.SS1.p1.1\" class=\"ltx_p\">Blockchain represents a <span id=\"S2.SS1.p1.1.1\" class=\"ltx_text ltx_font_italic\">decentralized</span>, append-only ledger characterized by three fundamental properties essential for agent identity systems: <span id=\"S2.SS1.p1.1.2\" class=\"ltx_text ltx_font_italic\">decentralization</span>, <span id=\"S2.SS1.p1.1.3\" class=\"ltx_text ltx_font_italic\">immutability</span>, and <span id=\"S2.SS1.p1.1.4\" class=\"ltx_text ltx_font_italic\">public transparency</span> <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib33\" title=\"\" class=\"ltx_ref\">Nakamoto (2008)</a></cite>.\nThrough distributed consensus protocols (e.g., Proof-of-Work, Proof-of-Stake), all state transitions are cryptographically linked and verifiable by any participant, eliminating reliance on centralized authorities while ensuring that identity credential registrations, delegations, and revocations remain fully auditable.\nSmart contracts—deterministic programs deployed on blockchains such as Ethereum <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib34\" title=\"\" class=\"ltx_ref\">Buterin (2014)</a></cite>—extend this foundation by enabling Turing-complete logic execution within the Ethereum Virtual Machine (EVM).\nUpon transaction triggers, contract code and state modifications are validated by all consensus participants, guaranteeing that identity lifecycle operations (issuance, verification, revocation) exhibit both <span id=\"S2.SS1.p1.1.5\" class=\"ltx_text ltx_font_italic\">tamper-evidence</span> and <span id=\"S2.SS1.p1.1.6\" class=\"ltx_text ltx_font_italic\">public verifiability</span>.\nThese properties collectively establish blockchain as a trust anchor for credential provenance and delegation chains in decentralized agent identity frameworks.</p>\n</div>\n</section>\n<section id=\"S2.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">2.2 </span>Zero-Knowledge Virtual Machine</h3>\n\n<div id=\"S2.SS2.p1\" class=\"ltx_para\">\n<p id=\"S2.SS2.p1.1\" class=\"ltx_p\">The emergence of blockchain technology, distributed ledgers, and multi-party computation has created an increasing demand for efficient, scalable, and composable verification of arbitrary computation results while preserving input privacy. Zero-Knowledge Proof (ZKP) technology establishes the cryptographic foundation for achieving both computational integrity and privacy <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib23\" title=\"\" class=\"ltx_ref\">Goldwasser et al. (1985)</a></cite>. Nevertheless, traditional approaches based on circuit-level or arithmetic descriptions, such as Rank-1 Constraint System and Quadratic Arithmetic Programs, present significant challenges for developers and require substantial effort to integrate with existing software ecosystems.</p>\n</div>\n<div id=\"S2.SS2.p2\" class=\"ltx_para\">\n<p id=\"S2.SS2.p2.1\" class=\"ltx_p\">Zero-Knowledge Virtual Machine (zkVM) addresses this challenge by bridging the semantic gap between general-purpose programs and provable instances. By introducing an abstraction layer that encompasses an instruction set architecture (typically resembling traditional CPU designs or optimized RISC-style instructions) and a corresponding execution environment, zkVM automatically transforms program execution into verifiable constraints and proof generation procedures. This transformation enables proof-carrying execution while maintaining high degrees of development reusability and ecosystem compatibility.</p>\n</div>\n<div id=\"S2.SS2.p3\" class=\"ltx_para\">\n<p id=\"S2.SS2.p3.1\" class=\"ltx_p\">Formally, let <math id=\"S2.SS2.p3.m1\" class=\"ltx_Math\" alttext=\"\\lambda\" display=\"inline\" intent=\":literal\"><semantics><mi>λ</mi><annotation encoding=\"application/x-tex\">\\lambda</annotation></semantics></math> denote the security parameter and let <math id=\"S2.SS2.p3.m2\" class=\"ltx_Math\" alttext=\"\\mathbb{F}_{p}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝔽</mi><mi>p</mi></msub><annotation encoding=\"application/x-tex\">\\mathbb{F}_{p}</annotation></semantics></math> be the base field where <math id=\"S2.SS2.p3.m3\" class=\"ltx_Math\" alttext=\"p\" display=\"inline\" intent=\":literal\"><semantics><mi>p</mi><annotation encoding=\"application/x-tex\">p</annotation></semantics></math> is a large prime. We model zkVM as a five-tuple:</p>\n<table id=\"S2.Ex1\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S2.Ex1.m1\" class=\"ltx_Math\" alttext=\"\\Pi=(\\text{Setup},\\text{CommitProg},\\text{Compile},\\text{Prove},\\text{Verify})\" display=\"block\" intent=\":literal\"><semantics><mrow><mi mathvariant=\"normal\">Π</mi><mo>=</mo><mrow><mo stretchy=\"false\">(</mo><mtext>Setup</mtext><mo>,</mo><mtext>CommitProg</mtext><mo>,</mo><mtext>Compile</mtext><mo>,</mo><mtext>Prove</mtext><mo>,</mo><mtext>Verify</mtext><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\Pi=(\\text{Setup},\\text{CommitProg},\\text{Compile},\\text{Prove},\\text{Verify})</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"S2.SS2.p3.2\" class=\"ltx_p\">consisting of the following algorithms:</p>\n</div>\n<div id=\"S2.SS2.p4\" class=\"ltx_para\">\n<ol id=\"S2.I1\" class=\"ltx_enumerate\">\n<li id=\"S2.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S2.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i1.p1.1\" class=\"ltx_p\"><math id=\"S2.I1.i1.p1.m1\" class=\"ltx_Math\" alttext=\"(pp,vk)\\leftarrow\\text{Setup}(1^{\\lambda},param)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mo stretchy=\"false\">(</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo stretchy=\"false\">)</mo></mrow><mo stretchy=\"false\">←</mo><mrow><mtext>Setup</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo>,</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>m</mi></mrow><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">(pp,vk)\\leftarrow\\text{Setup}(1^{\\lambda},param)</annotation></semantics></math>: A setup algorithm that generates public parameters and verification key, where <math id=\"S2.I1.i1.p1.m2\" class=\"ltx_Math\" alttext=\"param\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>m</mi></mrow><annotation encoding=\"application/x-tex\">param</annotation></semantics></math> encompasses system parameters including the maximum step bound <math id=\"S2.I1.i1.p1.m3\" class=\"ltx_Math\" alttext=\"T_{max}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>T</mi><mrow><mi>m</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>x</mi></mrow></msub><annotation encoding=\"application/x-tex\">T_{max}</annotation></semantics></math>, field specifications, and commitment scheme parameters.</p>\n</div></li>\n<li id=\"S2.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S2.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i2.p1.1\" class=\"ltx_p\"><math id=\"S2.I1.i2.p1.m1\" class=\"ltx_Math\" alttext=\"C_{P}\\leftarrow\\text{CommitProg}(P)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>C</mi><mi>P</mi></msub><mo stretchy=\"false\">←</mo><mrow><mtext>CommitProg</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">C_{P}\\leftarrow\\text{CommitProg}(P)</annotation></semantics></math>: A commitment algorithm that produces a cryptographic commitment <math id=\"S2.I1.i2.p1.m2\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math> to the program code <math id=\"S2.I1.i2.p1.m3\" class=\"ltx_Math\" alttext=\"P\" display=\"inline\" intent=\":literal\"><semantics><mi>P</mi><annotation encoding=\"application/x-tex\">P</annotation></semantics></math> using either hash-based, vector, or KZG commitment schemes.</p>\n</div></li>\n<li id=\"S2.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S2.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i3.p1.1\" class=\"ltx_p\"><math id=\"S2.I1.i3.p1.m1\" class=\"ltx_Math\" alttext=\"(\\text{ArithDesc},\\text{MapIO})\\leftarrow\\text{Compile}(pp,P)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mo stretchy=\"false\">(</mo><mtext>ArithDesc</mtext><mo>,</mo><mtext>MapIO</mtext><mo stretchy=\"false\">)</mo></mrow><mo stretchy=\"false\">←</mo><mrow><mtext>Compile</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">(\\text{ArithDesc},\\text{MapIO})\\leftarrow\\text{Compile}(pp,P)</annotation></semantics></math>: A compilation algorithm that performs static analysis and transforms the instruction set into constraint templates, yielding both arithmetic descriptions (constraint skeletons) and I/O mapping specifications. These outputs serve as static intermediates for subsequent proof generation, enabling the transformation of program logic into verifiable constraints.</p>\n</div></li>\n<li id=\"S2.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"S2.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i4.p1.1\" class=\"ltx_p\"><math id=\"S2.I1.i4.p1.m1\" class=\"ltx_Math\" alttext=\"\\pi\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc},\\text{MapIO},x_{pub},x_{prv},y)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>π</mi><mo stretchy=\"false\">←</mo><mrow><mtext>Prove</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><mtext>ArithDesc</mtext><mo>,</mo><mtext>MapIO</mtext><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><mo>,</mo><mi>y</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\pi\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc},\\text{MapIO},x_{pub},x_{prv},y)</annotation></semantics></math>: A proving algorithm that:</p>\n<ul id=\"S2.I1.i4.I1\" class=\"ltx_itemize\">\n<li id=\"S2.I1.i4.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S2.I1.i4.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i4.I1.i1.p1.1\" class=\"ltx_p\">Constructs the execution trace</p>\n<table id=\"S2.Ex2\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S2.Ex2.m1\" class=\"ltx_Math\" alttext=\"\\text{Trace}(P,x_{pub},x_{prv})=(s_{0},\\ldots,s_{T}),\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mrow><mtext>Trace</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>s</mi><mn>0</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>s</mi><mi>T</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>,</mo></mrow><annotation encoding=\"application/x-tex\">\\text{Trace}(P,x_{pub},x_{prv})=(s_{0},\\ldots,s_{T}),</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"S2.I1.i4.I1.i1.p1.2\" class=\"ltx_p\">utilizing <span id=\"S2.I1.i4.I1.i1.p1.2.1\" class=\"ltx_text ltx_markedasmath\">MapIO</span> to map public inputs <math id=\"S2.I1.i4.I1.i1.p1.m2\" class=\"ltx_Math\" alttext=\"x_{pub}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub}</annotation></semantics></math> and private inputs <math id=\"S2.I1.i4.I1.i1.p1.m3\" class=\"ltx_Math\" alttext=\"x_{prv}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{prv}</annotation></semantics></math> into the initial state and ensure output <math id=\"S2.I1.i4.I1.i1.p1.m4\" class=\"ltx_Math\" alttext=\"y\" display=\"inline\" intent=\":literal\"><semantics><mi>y</mi><annotation encoding=\"application/x-tex\">y</annotation></semantics></math> consistency in the final state.</p>\n</div></li>\n<li id=\"S2.I1.i4.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S2.I1.i4.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i4.I1.i2.p1.1\" class=\"ltx_p\">Generates the constraint representation by instantiating <span id=\"S2.I1.i4.I1.i2.p1.1.1\" class=\"ltx_text ltx_markedasmath\">ArithDesc</span>’s constraint templates with the execution trace (utilizing R1CS, AIR, or PLONKish frameworks), incorporating <span id=\"S2.I1.i4.I1.i2.p1.1.2\" class=\"ltx_text ltx_markedasmath\">MapIO</span> for I/O constraints.</p>\n</div></li>\n<li id=\"S2.I1.i4.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"S2.I1.i4.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i4.I1.i3.p1.1\" class=\"ltx_p\">Executes the underlying proof system to produce the proof <math id=\"S2.I1.i4.I1.i3.p1.m1\" class=\"ltx_Math\" alttext=\"\\pi\" display=\"inline\" intent=\":literal\"><semantics><mi>π</mi><annotation encoding=\"application/x-tex\">\\pi</annotation></semantics></math>.</p>\n</div></li>\n</ul>\n</div></li>\n<li id=\"S2.I1.i5\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">5.</span> \n<div id=\"S2.I1.i5.p1\" class=\"ltx_para\">\n<p id=\"S2.I1.i5.p1.1\" class=\"ltx_p\"><math id=\"S2.I1.i5.p1.m1\" class=\"ltx_Math\" alttext=\"b\\leftarrow\\text{Verify}(vk,C_{P},x_{pub},y,\\pi)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>b</mi><mo stretchy=\"false\">←</mo><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><mi>y</mi><mo>,</mo><mi>π</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">b\\leftarrow\\text{Verify}(vk,C_{P},x_{pub},y,\\pi)</annotation></semantics></math>: A verification algorithm that outputs a binary decision: accept (1) or reject (0). The verification implicitly relies on the constraint structure derived from <span id=\"S2.I1.i5.p1.1.1\" class=\"ltx_text ltx_markedasmath\">ArithDesc</span> and <span id=\"S2.I1.i5.p1.1.2\" class=\"ltx_text ltx_markedasmath\">MapIO</span> (embedded in <math id=\"S2.I1.i5.p1.m4\" class=\"ltx_Math\" alttext=\"vk\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><annotation encoding=\"application/x-tex\">vk</annotation></semantics></math> or <math id=\"S2.I1.i5.p1.m5\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math>), ensuring the proof <math id=\"S2.I1.i5.p1.m6\" class=\"ltx_Math\" alttext=\"\\pi\" display=\"inline\" intent=\":literal\"><semantics><mi>π</mi><annotation encoding=\"application/x-tex\">\\pi</annotation></semantics></math> attests to correct program execution and I/O mapping without revealing private inputs.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S2.SS2.p5\" class=\"ltx_para\">\n<p id=\"S2.SS2.p5.1\" class=\"ltx_p\">In the BAID framework, zkVM enables agents to generate <span id=\"S2.SS2.p5.1.1\" class=\"ltx_text ltx_font_italic\">verifiable execution proofs</span> demonstrating identity authenticity and operational compliance without revealing sensitive configurations or proprietary code.\nThese proofs cryptographically establish that agents operate under certified configurations, authenticated operators, and committed program logic, thereby achieving accountability through <span id=\"S2.SS2.p5.1.2\" class=\"ltx_text ltx_font_italic\">computational verification</span> rather than <span id=\"S2.SS2.p5.1.3\" class=\"ltx_text ltx_font_italic\">data disclosure</span>.</p>\n</div>\n</section>\n<section id=\"S2.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">2.3 </span>Verifiable Credentials</h3>\n\n<div id=\"S2.SS3.p1\" class=\"ltx_para\">\n<p id=\"S2.SS3.p1.1\" class=\"ltx_p\">Verifiable Credentials (VC) and Decentralized Identifiers (DID) constitute the foundational standards for <span id=\"S2.SS3.p1.1.1\" class=\"ltx_text ltx_font_italic\">decentralized</span>, <span id=\"S2.SS3.p1.1.2\" class=\"ltx_text ltx_font_italic\">privacy-preserving</span>, and <span id=\"S2.SS3.p1.1.3\" class=\"ltx_text ltx_font_italic\">interoperable</span> digital identity systems <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib36\" title=\"\" class=\"ltx_ref\">Sporny and others (2025)</a>; <a href=\"#bib.bib35\" title=\"\" class=\"ltx_ref\">Sporny et al. (2022)</a></cite>.\nThe trust model involves four key entities: <span id=\"S2.SS3.p1.1.4\" class=\"ltx_text ltx_font_italic\">Issuers</span> make cryptographically signed claims about subjects; <span id=\"S2.SS3.p1.1.5\" class=\"ltx_text ltx_font_italic\">Holders</span> store VCs and generate selective-disclosure Verifiable Presentations (VPs); <span id=\"S2.SS3.p1.1.6\" class=\"ltx_text ltx_font_italic\">Verifiers</span> authenticate credentials by resolving issuer and holder public keys through <span id=\"S2.SS3.p1.1.7\" class=\"ltx_text ltx_font_italic\">Registry Authorities</span>, which maintain immutable trust anchors recording entity identities, associated keys, and revocation lists.\nThis architecture enables privacy-preserving identity verification: holders can prove specific attributes (e.g., “age <math id=\"S2.SS3.p1.m1\" class=\"ltx_Math\" alttext=\"\\geq\" display=\"inline\" intent=\":literal\"><semantics><mo>≥</mo><annotation encoding=\"application/x-tex\">\\geq</annotation></semantics></math> 18”, “KYC approved”) without revealing underlying personal data.</p>\n</div>\n<div id=\"S2.SS3.p2\" class=\"ltx_para\">\n<p id=\"S2.SS3.p2.1\" class=\"ltx_p\">Integration with zero-knowledge proofs strengthens privacy guarantees <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">Pauwels (2021)</a></cite>.\nIn zkKYC scenarios, approved institutions (Issuers) generate signed VCs with cryptographic field commitments using privacy-preserving signature schemes such as BBS+ or CL-Signature.\nHolders then generate Selective-Disclosure Proofs through local ZKP circuits, cryptographically demonstrating compliance with regulatory requirements (e.g., “not sanctioned”, “credential unexpired”, “age <math id=\"S2.SS3.p2.m1\" class=\"ltx_Math\" alttext=\"\\geq\" display=\"inline\" intent=\":literal\"><semantics><mo>≥</mo><annotation encoding=\"application/x-tex\">\\geq</annotation></semantics></math> 18”) while concealing sensitive personal identifiers.\nVerifiers validate only the VC signature chain and ZKP correctness, confirming regulatory compliance without accessing underlying personal data.\nThis cryptographic separation of <span id=\"S2.SS3.p2.1.1\" class=\"ltx_text ltx_font_italic\">authentication</span> (proving credential validity) from <span id=\"S2.SS3.p2.1.2\" class=\"ltx_text ltx_font_italic\">disclosure</span> (revealing specific attributes) establishes VCs as the privacy-preserving credential substrate for BAID framework.</p>\n</div>\n</section>\n</section>\n<section id=\"S3\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">3 </span>BAID System Overview</h2>\n\n<figure id=\"S3.F2\" class=\"ltx_figure\"><img src=\"2512.17538v1/Baidarchitecture.png\" id=\"S3.F2.g1\" class=\"ltx_graphics ltx_centering ltx_img_landscape\" style=\"aspect-ratio:310/196;\" width=\"310\" height=\"196\" alt=\"Refer to caption\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 2: </span>BAID system architecture: 1. Local User-Agent Binding mechanism; 2. On-Chain Identity Management; 3. Agents Authentication and Authorization Protocol.</figcaption>\n</figure>\n<div id=\"S3.p1\" class=\"ltx_para\">\n<p id=\"S3.p1.1\" class=\"ltx_p\">The BAID (Binding Agent ID) system establishes verifiable, traceable, and accountable digital identity chains for autonomous AI agents, addressing the fundamental challenge of agent trustworthiness and cross-system collaboration. As illustrated in Figure <a href=\"#S3.F2\" title=\"Figure 2 ‣ 3 BAID System Overview ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a>, the system workflow proceeds through three integrated stages: (1) users establish local biometric binding with agents through the Biometric Authentication Module (BAM), anchoring agent identity to its human owners; (2) users register Agent Identifiers on-chain via blockchain smart contracts, creating publicly queryable user-agent binding declarations that enable trusted agent discovery; (3) agents authenticate to third-party verifiers through zkVM execution proofs combined with Verifiable Credentials, establishing cryptographically verified identity and permission scope for secure collaboration.\nTo implement this workflow, the BAID system architecture comprises three principal technical modules:</p>\n</div>\n<div id=\"S3.p2\" class=\"ltx_para\">\n<p id=\"S3.p2.1\" class=\"ltx_p\"><span id=\"S3.p2.1.1\" class=\"ltx_text ltx_font_bold\">(1) Local User-Agent Binding.</span> To support local binding and subsequent Agent ID management, we design an extended agent framework that enhances the Profile module and introduces an Identity Management module supporting biometric authentication and cryptographic operations. Users establish local binding by storing their biometric identity features in the agent’s Profile security configurations file. Subsequently, the agent continuously validates operators against stored biometric templates through the Biometric Authentication Module (BAM), ensuring only the legitimate owner can activate the agent—this corresponds to Phase 2 (Operator Biometric Authentication) in the verification pipeline, thereby implementing the security property “agent serves only its owner.”</p>\n</div>\n<div id=\"S3.p3\" class=\"ltx_para\">\n<p id=\"S3.p3.1\" class=\"ltx_p\"><span id=\"S3.p3.1.1\" class=\"ltx_text ltx_font_bold\">(2) On-Chain Identity Management.</span> Building upon this local foundation, leveraging blockchain’s transparency, immutability, and decentralization, BAID constructs a globally unified trusted identity system supporting user/agent registration, on-chain binding, and agent discovery. Users complete real-person verification through zkKYC (see Section <a href=\"#S2.SS3\" title=\"2.3 Verifiable Credentials ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2.3</span></a>) without revealing identity privacy, creating User Identity Contracts that establish legal entity attributes. Based on the User Identity Contract, users can subsequently create Agent Identity Contracts for locally-bound agents, making binding relationships publicly queryable. The Agent Identity Contract records agent attributes (user identity contract address, Agent Identifier, capabilities, roles) and communication metadata (protocols, endpoints, domains), thereby enabling agent discovery functionality that allows other agents to rapidly identify and locate collaboration channels. The on-chain Agent Identifier serves as the canonical reference for Phase 1 (Agent Configuration Integrity) verification, ensuring local configurations match blockchain-anchored versions.</p>\n</div>\n<div id=\"S3.p4\" class=\"ltx_para\">\n<p id=\"S3.p4.1\" class=\"ltx_p\"><span id=\"S3.p4.1.1\" class=\"ltx_text ltx_font_bold\">(3) Agents Authentication and Authorization Protocol.</span> With the identity infrastructure established, the authentication mechanism enables verifiers to validate agent identities and permission boundaries, establishing trust channels. As shown in Figure <a href=\"#S3.F2\" title=\"Figure 2 ‣ 3 BAID System Overview ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a>, agents initially establish communication through the blockchain identity system’s discovery functionality, but further collaboration requires mutual identity and permission verification. As software entities, agents’ program commitments serve as their “biometric identity features.” We use program commitments as Agent Identifiers and employ zkVM proofs to verify consistency between currently executing programs and Agent Identifiers—this authentication mechanism transcends traditional key-based authentication limitations by simultaneously verifying the operator’s physical identity and the agent’s computational identity, effectively preventing both unauthorized operation and malicious program impersonation. Moreover, BAID implements verifiable permission authorization through Verifiable Credentials (VC), enabling users to perform fine-grained authorization combining agent attributes and target task contexts. Consequently, during agent authentication, agents must provide two proofs to verifiers: zkVM execution proof and user permission authorization proof (VC).</p>\n</div>\n</section>\n<section id=\"S4\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">4 </span>BAID System Designs</h2>\n\n<div id=\"S4.p1\" class=\"ltx_para\">\n<p id=\"S4.p1.1\" class=\"ltx_p\">Having outlined the overall BAID architecture, we now provide detailed system designs for the framework’s three core pillars. This section first presents the local binding infrastructure that establishes the foundational trust relationship between agents and their human owners (Section 4.1). It then details the blockchain-based identity registration and discovery mechanisms that enable global agent interoperability (Section 4.2). Finally, it describes the zkVM-based agent identity authentication protocol that facilitates verifiable and privacy-preserving interactions through code-level proofs (Section 4.3).</p>\n</div>\n<section id=\"S4.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.1 </span>Local User-Agent Binding via Biometric Authentication</h3>\n\n<div id=\"S4.SS1.p1\" class=\"ltx_para\">\n<p id=\"S4.SS1.p1.1\" class=\"ltx_p\">The local binding mechanism ensures that agents serve exclusively their designated owners by embedding user biometric identity directly into agent configurations. This mechanism is implemented through an enhanced agent architecture that integrates biometric authentication capabilities within the Identity Management module.</p>\n</div>\n<section id=\"S4.SS1.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">4.1.1 </span>Agent Architecture</h4>\n\n<div id=\"S4.SS1.SSS1.p1\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS1.p1.1\" class=\"ltx_p\">Contemporary agent frameworks typically consist of Profile (configuration), Memory (knowledge retention), Planning (decision-making), and Action (task execution) modules <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib25\" title=\"\" class=\"ltx_ref\">Wang et al. (2024b)</a></cite>. However, to support autonomous identity management and cryptographic operations, we extend this architecture with an Identity Management module and augment the Profile module with identity-binding capabilities.</p>\n</div>\n<div id=\"S4.SS1.SSS1.p2\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS1.p2.1\" class=\"ltx_p\"><span id=\"S4.SS1.SSS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Profile Module.</span> Beyond recording agent attributes (capabilities, behavioral constraints, operational parameters), the Configuration Document within the Profile module stores the owner’s Human Identifier and Biometric Authentication Credential. These identity anchors provide the foundation for deep binding and local user authentication mechanisms.</p>\n</div>\n<div id=\"S4.SS1.SSS1.p3\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS1.p3.1\" class=\"ltx_p\"><span id=\"S4.SS1.SSS1.p3.1.1\" class=\"ltx_text ltx_font_bold\">Identity Module.</span> This module manages all Agent ID-related operations, consisting of two subcomponents: (1) Cryptographic module\n(e.g., zkVM) for generating authentication proofs and managing Verifiable Credentials; (2) BAM integration for real-time operator identity verification. The module interfaces with both local biometric sensors and blockchain identity contracts to enforce the security property “agent serves only its owner.”</p>\n</div>\n<div id=\"S4.SS1.SSS1.p4\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS1.p4.1\" class=\"ltx_p\">Figure <a href=\"#S4.F3\" title=\"Figure 3 ‣ 4.1.1 Agent Architecture ‣ 4.1 Local User-Agent Binding via Biometric Authentication ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> illustrates the enhanced agent architecture with identity management capabilities integrated into the standard agent framework.</p>\n</div>\n<figure id=\"S4.F3\" class=\"ltx_figure\"><img src=\"2512.17538v1/agent-architecture.png\" id=\"S4.F3.g1\" class=\"ltx_graphics ltx_centering ltx_img_landscape\" style=\"aspect-ratio:381/96;\" width=\"381\" height=\"96\" alt=\"Refer to caption\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 3: </span>Extended agent architecture with Identity module: integrating biometric authentication, cryptographic operations, and identity binding capabilities into the standard agent framework (Profile, Memory, Planning, Action).</figcaption>\n</figure>\n</section>\n<section id=\"S4.SS1.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">4.1.2 </span>Biometric Template Registration and Verification</h4>\n\n<div id=\"S4.SS1.SSS2.p1\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS2.p1.1\" class=\"ltx_p\">The local binding mechanism establishes a cryptographically secure association between user biometric identity and agent configuration, operating through two distinct phases: registration and verification.</p>\n</div>\n<div id=\"S4.SS1.SSS2.p2\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS2.p2.1\" class=\"ltx_p\"><span id=\"S4.SS1.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Registration Phase.</span> During the initial binding establishment, the system performs the following steps as illustrated in Figure <a href=\"#S4.F4\" title=\"Figure 4 ‣ 4.1.2 Biometric Template Registration and Verification ‣ 4.1 Local User-Agent Binding via Biometric Authentication ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a>:</p>\n</div>\n<div id=\"S4.SS1.SSS2.p3\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS2.p3.1\" class=\"ltx_p\"><span id=\"S4.SS1.SSS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Step1: Biometric Capture and Template Generation.</span> The user invokes the device’s local Biometric Authentication Module (BAM), which captures biometric data via facial recognition camera, fingerprint sensor, or iris scanner. BAM applies feature extraction algorithms to generate a Biometric Template—a compact mathematical representation of distinctive biological traits.</p>\n</div>\n<div id=\"S4.SS1.SSS2.p4\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS2.p4.1\" class=\"ltx_p\"><span id=\"S4.SS1.SSS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Step2: Configuration Binding.</span> The system writes both the User Identifier and Biometric Template (designated as Registered Template) into the agent’s Configuration Document within the Profile module, creating an immutable binding record that anchors the agent to its designated owner.</p>\n</div>\n<figure id=\"S4.F4\" class=\"ltx_figure\"><img src=\"2512.17538v1/local-binding.png\" id=\"S4.F4.g1\" class=\"ltx_graphics ltx_centering ltx_img_landscape\" style=\"aspect-ratio:476/80;\" width=\"476\" height=\"80\" alt=\"Refer to caption\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 4: </span>Local binding registration workflow: biometric template generation and configuration document binding.</figcaption>\n</figure>\n<div id=\"S4.SS1.SSS2.p5\" class=\"ltx_para\">\n<p id=\"S4.SS1.SSS2.p5.1\" class=\"ltx_p\"><span id=\"S4.SS1.SSS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Verification Phase.</span> Once bound, the Identity Module enforces continuous operator verification before executing sensitive operations. BAM captures fresh biometric samples, generates temporary templates, and performs similarity matching against the registered template to confirm identity. If verification fails, the agent immediately terminates or refuses service, ensuring that only the legitimate bound user can control agent actions.</p>\n</div>\n</section>\n</section>\n<section id=\"S4.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.2 </span>On-Chain Identity Management</h3>\n\n<div id=\"S4.SS2.p1\" class=\"ltx_para\">\n<p id=\"S4.SS2.p1.1\" class=\"ltx_p\">Building upon the local binding infrastructure, we construct a globally unified, decentralized on-chain identity system based on blockchain technology to support trusted identity management and secure collaboration across the agent ecosystem. This identity system not only strengthens user sovereignty over agents but also provides critical infrastructure for building secure, trustworthy, multi-party collaborative agent networks.</p>\n</div>\n<section id=\"S4.SS2.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">4.2.1 </span>Identity Management Smart Contract Framework</h4>\n\n<div id=\"S4.SS2.SSS1.p1\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS1.p1.1\" class=\"ltx_p\">The decentralized identity system comprises three primary architectural components:</p>\n</div>\n<div id=\"S4.SS2.SSS1.p2\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS1.p2.1\" class=\"ltx_p\"><span id=\"S4.SS2.SSS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Entrypoint Contract.</span> Drawing inspiration from the ERC-4337 account abstraction protocol, we employ an Entrypoint Contract as the user-contract interaction gateway. The ERC-4337 protocol enables user accounts to execute complex programmable logic including gas sponsorship for agents (users pay transaction fees on behalf of their agents), delegated payment authorization (granting agents specific payment permissions within defined limits), and subordinate account binding (establishing agent identity accounts as dependent sub-accounts under user accounts). The Entrypoint Contract leverages these capabilities to verify and execute user transactions while invoking target identity contracts, enabling flexible identity management operations without requiring agents to hold native blockchain tokens for transaction fees.</p>\n</div>\n<div id=\"S4.SS2.SSS1.p3\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS1.p3.1\" class=\"ltx_p\"><span id=\"S4.SS2.SSS1.p3.1.1\" class=\"ltx_text ltx_font_bold\">Identity Contracts.</span> The User Identity Contract and Agent Identity Contract serve as the respective account contracts for users and agents within the identity system, both instantiated by the Entrypoint using predefined templates. The User Identity Contract template contains variables including <span id=\"S4.SS2.SSS1.p3.1.2\" class=\"ltx_text ltx_font_typewriter\">Owner</span>, <span id=\"S4.SS2.SSS1.p3.1.3\" class=\"ltx_text ltx_font_typewriter\">userID</span>, and <span id=\"S4.SS2.SSS1.p3.1.4\" class=\"ltx_text ltx_font_typewriter\">Agent_Binding_List</span>, storing the user’s public key, user identifier, and the list of <math id=\"S4.SS2.SSS1.p3.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math>s bound to the user, respectively. The Agent Identity Contract template contains variables including <span id=\"S4.SS2.SSS1.p3.1.5\" class=\"ltx_text ltx_font_typewriter\">Owner_User</span>, <span id=\"S4.SS2.SSS1.p3.1.6\" class=\"ltx_text ltx_font_typewriter\">OperationalStatus</span>, <span id=\"S4.SS2.SSS1.p3.1.7\" class=\"ltx_text ltx_font_typewriter\">Attribute</span>, and <span id=\"S4.SS2.SSS1.p3.1.8\" class=\"ltx_text ltx_font_typewriter\">AgentFactsURL</span>. These variables store: (1) the owner’s contract address; (2) the agent’s operational status (Running/Stopped/Deregistered); (3) agent attributes (including agent name, program commitment <math id=\"S4.SS2.SSS1.p3.m2\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math>, configuration hash, <math id=\"S4.SS2.SSS1.p3.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{userID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝗎𝗌𝖾𝗋𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{userID}</annotation></semantics></math>, <math id=\"S4.SS2.SSS1.p3.m4\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math>, capabilities, and roles); and (4) the Uniform Resource Locator pointing to the agent’s verifiable metadata (AgentFacts).</p>\n</div>\n<div id=\"S4.SS2.SSS1.p4\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS1.p4.1\" class=\"ltx_p\">AgentFacts is a lightweight dynamic metadata document published by the agent, employing JSON-LD format with Verifiable Credential signatures to describe an AI agent’s identity, capabilities, endpoints, routing, and trust status. It decouples stable index records from high-frequency changing information, supporting rapid updates, verifiable trust, and privacy-friendly resolution <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">Raskar et al. (2025b)</a></cite>. The complete AgentFacts document supports multiple flexible storage options including agent self-hosting, IPFS decentralized storage, third-party hosting, CDN distribution, and storage within the BAID Agent Identity Contract itself. Only the <span id=\"S4.SS2.SSS1.p4.1.1\" class=\"ltx_text ltx_font_typewriter\">AgentFactsURL</span> needs to be published in the Agent Identity Contract to enable BAID’s Agent Discovery functionality.</p>\n</div>\n<div id=\"S4.SS2.SSS1.p5\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS1.p5.1\" class=\"ltx_p\">The identity system implements three core functions for lifecycle management, as detailed in Table <a href=\"#S4.T1\" title=\"Table 1 ‣ 4.2.1 Identity Management Smart Contract Framework ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a>.</p>\n</div>\n<figure id=\"S4.T1\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\">Table 1: </span>Core Functions for Agent Identity Lifecycle Management</figcaption>\n<table id=\"S4.T1.2\" class=\"ltx_tabular ltx_centering ltx_align_middle\">\n<tr id=\"S4.T1.2.1\" class=\"ltx_tr\">\n<td id=\"S4.T1.2.1.1\" class=\"ltx_td ltx_align_left ltx_border_tt\"><span id=\"S4.T1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Function</span></td>\n<td id=\"S4.T1.2.1.2\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S4.T1.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T1.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S4.T1.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Description</span></span>\n</span></td></tr>\n<tr id=\"S4.T1.2.2\" class=\"ltx_tr\">\n<td id=\"S4.T1.2.2.1\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S4.T1.2.2.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">addAgent(...)</span></td>\n<td id=\"S4.T1.2.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S4.T1.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T1.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S4.T1.2.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Creates Agent Identity Contract through Entrypoint, adds AgentID to </span><span id=\"S4.T1.2.2.2.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">Agent_Binding_List</span><span id=\"S4.T1.2.2.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">, establishing on-chain User-Agent binding for discovery and accountability.</span></span>\n</span></td></tr>\n<tr id=\"S4.T1.2.3\" class=\"ltx_tr\">\n<td id=\"S4.T1.2.3.1\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S4.T1.2.3.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">updateAgent(...)</span></td>\n<td id=\"S4.T1.2.3.2\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S4.T1.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T1.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S4.T1.2.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Modifies agent attributes after verifying caller authorization (</span><span id=\"S4.T1.2.3.2.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">Owner_User</span><span id=\"S4.T1.2.3.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\">), recording timestamps and versions for capability evolution tracking.</span></span>\n</span></td></tr>\n<tr id=\"S4.T1.2.4\" class=\"ltx_tr\">\n<td id=\"S4.T1.2.4.1\" class=\"ltx_td ltx_align_left ltx_border_bb ltx_border_t\"><span id=\"S4.T1.2.4.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">removeAgent(...)</span></td>\n<td id=\"S4.T1.2.4.2\" class=\"ltx_td ltx_align_left ltx_border_bb ltx_border_t\">\n<span id=\"S4.T1.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S4.T1.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S4.T1.2.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Sets </span><span id=\"S4.T1.2.4.2.1.1.2\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">OperationalStatus</span><span id=\"S4.T1.2.4.2.1.1.3\" class=\"ltx_text\" style=\"font-size:90%;\"> to Deregistered, removes AgentID from binding list while preserving audit trails for compliance.</span></span>\n</span></td></tr>\n</table>\n</figure>\n</section>\n<section id=\"S4.SS2.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">4.2.2 </span>On-Chain Identity Registration and Binding Workflow</h4>\n\n<div id=\"S4.SS2.SSS2.p1\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS2.p1.1\" class=\"ltx_p\">As illustrated in Figure <a href=\"#S4.F5\" title=\"Figure 5 ‣ 4.2.2 On-Chain Identity Registration and Binding Workflow ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">5</span></a>, the registration and binding workflow covers the complete agent lifecycle from user identity establishment to agent on-chain registration:</p>\n</div>\n<div id=\"S4.SS2.SSS2.p2\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS2.p2.1\" class=\"ltx_p\"><span id=\"S4.SS2.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Step1: UserID Registration.</span> Based on the principle of legal entity binding with optional anonymity, we leverage real-person zkKYC technology to confirm users’ legal entity attributes and complete UserID registration without exposing users’ real identities. After users pass zkKYC verification, the Entrypoint Contract creates a User Identity Contract and initializes the <span id=\"S4.SS2.SSS2.p2.1.2\" class=\"ltx_text ltx_font_typewriter\">userID</span> and <span id=\"S4.SS2.SSS2.p2.1.3\" class=\"ltx_text ltx_font_typewriter\">Owner</span> variables (<span id=\"S4.SS2.SSS2.p2.1.4\" class=\"ltx_text ltx_font_typewriter\">Owner = Pkey_A</span>, where <span id=\"S4.SS2.SSS2.p2.1.5\" class=\"ltx_text ltx_font_typewriter\">Pkey_A</span> is the user’s blockchain account public key).</p>\n</div>\n<div id=\"S4.SS2.SSS2.p3\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS2.p3.1\" class=\"ltx_p\"><span id=\"S4.SS2.SSS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Step2: AgentID Generation.</span> In BAID, the Agent Identifier follows the structure:</p>\n<table id=\"S4.E1\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S4.E1.m1\" class=\"ltx_Math\" alttext=\"\\begin{split}\\mathsf{AgentID}=\\text{agentid}:H(&amp;\\text{name}\\|C_{P}\\|\\\\\n&amp;H(\\text{profile})\\|\\text{userID}\\|\\text{others})\\end{split}\" display=\"block\" intent=\":literal\"><semantics><mtable columnspacing=\"0pt\" displaystyle=\"true\" rowspacing=\"0pt\"><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><mo>=</mo><mtext>agentid</mtext><mo lspace=\"0.278em\" rspace=\"0.278em\">:</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mo fence=\"true\" lspace=\"0em\">CLOSE</mo></mrow></mrow></mrow></mtd><mtd class=\"ltx_align_left\" columnalign=\"left\"><mrow><mtext>name</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">‖</mo><msub><mi>C</mi><mi>P</mi></msub><mo stretchy=\"false\">‖</mo></mrow></mrow></mtd></mtr><mtr><mtd></mtd><mtd class=\"ltx_align_left\" columnalign=\"left\"><mrow><mo fence=\"true\" rspace=\"0em\">OPEN</mo><mrow><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mtext>profile</mtext><mo stretchy=\"false\">)</mo></mrow></mrow><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">‖</mo><mtext>userID</mtext><mo stretchy=\"false\">‖</mo></mrow><mo lspace=\"0em\" rspace=\"0em\">​</mo><mtext>others</mtext></mrow><mo stretchy=\"false\">)</mo></mrow></mtd></mtr></mtable><annotation encoding=\"application/x-tex\">\\begin{split}\\mathsf{AgentID}=\\text{agentid}:H(&amp;\\text{name}\\|C_{P}\\|\\\\\n&amp;H(\\text{profile})\\|\\text{userID}\\|\\text{others})\\end{split}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(1)</span></td></tr></tbody>\n</table>\n</div>\n<div id=\"S4.SS2.SSS2.p4\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS2.p4.1\" class=\"ltx_p\">where <math id=\"S4.SS2.SSS2.p4.m1\" class=\"ltx_Math\" alttext=\"C_{P}=\\text{CommitProg}(P)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>C</mi><mi>P</mi></msub><mo>=</mo><mrow><mtext>CommitProg</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">C_{P}=\\text{CommitProg}(P)</annotation></semantics></math> is the program commitment,\n<math id=\"S4.SS2.SSS2.p4.m2\" class=\"ltx_Math\" alttext=\"H(\\text{profile})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mtext>profile</mtext><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">H(\\text{profile})</annotation></semantics></math> hashes the security configuration (user identity, policy constraints),\n<math id=\"S4.SS2.SSS2.p4.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{userID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝗎𝗌𝖾𝗋𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{userID}</annotation></semantics></math> identifies the bound user, and <span id=\"S4.SS2.SSS2.p4.1.1\" class=\"ltx_text ltx_markedasmath\">name</span> provides human readability. The <math id=\"S4.SS2.SSS2.p4.m5\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> is generated locally by the user, preparing for subsequent on-chain identity registration. Table <a href=\"#S4.T2\" title=\"Table 2 ‣ 4.2.2 On-Chain Identity Registration and Binding Workflow ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">2</span></a> presents an <math id=\"S4.SS2.SSS2.p4.m6\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> for a laptop retail sales advisor agent, demonstrating how these identity components are instantiated in practice.</p>\n</div>\n<div id=\"S4.SS2.SSS2.p5\" class=\"ltx_para\">\n<p id=\"S4.SS2.SSS2.p5.1\" class=\"ltx_p\"><span id=\"S4.SS2.SSS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Step3: AgentID Registration and Binding.</span> The user generates variable data <span id=\"S4.SS2.SSS2.p5.1.2\" class=\"ltx_text ltx_font_typewriter\">Attribute</span>, <span id=\"S4.SS2.SSS2.p5.1.3\" class=\"ltx_text ltx_font_typewriter\">AgentFactsURL</span>, and a signature <math id=\"S4.SS2.SSS2.p5.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{Sig}_{A}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝖲𝗂𝗀</mi><mi>A</mi></msub><annotation encoding=\"application/x-tex\">\\mathsf{Sig}_{A}</annotation></semantics></math> using the owner’s public key, then invokes the Entrypoint Contract to execute the User Identity Contract’s <span id=\"S4.SS2.SSS2.p5.1.4\" class=\"ltx_text ltx_font_typewriter\">addAgent(AgentID, Name, Attribute, AgentFactsURL)</span> function (see Table <a href=\"#S4.T1\" title=\"Table 1 ‣ 4.2.1 Identity Management Smart Contract Framework ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a>), adding the newly bound agent’s information and creating the Agent Identity Contract. After signature verification passes, the Entrypoint Contract creates an Agent Identity Contract and initializes the <span id=\"S4.SS2.SSS2.p5.1.5\" class=\"ltx_text ltx_font_typewriter\">Owner_User</span>, <span id=\"S4.SS2.SSS2.p5.1.6\" class=\"ltx_text ltx_font_typewriter\">Attribute</span>, and <span id=\"S4.SS2.SSS2.p5.1.7\" class=\"ltx_text ltx_font_typewriter\">AgentFactsURL</span> variables. The <span id=\"S4.SS2.SSS2.p5.1.8\" class=\"ltx_text ltx_font_typewriter\">Owner_User</span> is set to the User Identity Contract’s address, declaring the binding relationship between the user and agent and ownership of the Agent Identity Contract.</p>\n</div>\n<figure id=\"S4.F5\" class=\"ltx_figure\"><img src=\"2512.17538v1/registration-binding.png\" id=\"S4.F5.g1\" class=\"ltx_graphics ltx_centering ltx_img_landscape\" style=\"aspect-ratio:476/223;\" width=\"476\" height=\"223\" alt=\"Refer to caption\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 5: </span>Registration and binding workflow showing UserID registration via zkKYC, AgentID generation, and on-chain AgentID registration.</figcaption>\n</figure>\n<figure id=\"S4.T2\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\">Table 2: </span>Example AgentID for Laptop Retail Sales Advisor Agent</figcaption>\n<table id=\"S4.T2.2\" class=\"ltx_tabular ltx_centering ltx_align_middle\">\n<tr id=\"S4.T2.2.1\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.1.1\" class=\"ltx_td ltx_align_left ltx_border_tt\"><span id=\"S4.T2.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Field</span></td>\n<td id=\"S4.T2.2.1.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_tt\">\n<span id=\"S4.T2.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Value</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.2.2\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.2.1\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S4.T2.2.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">name</span></td>\n<td id=\"S4.T2.2.2.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_t\">\n<span id=\"S4.T2.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.2.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">baid:agent:laptopretail:salesadvisor</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.2.3\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S4.T2.2.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">code_hash</span></td>\n<td id=\"S4.T2.2.3.2\" class=\"ltx_td ltx_align_left ltx_align_top\">\n<span id=\"S4.T2.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.3.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">sha256:2c1d7fa9c5b84d6f9a1e3d...</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.2.4\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S4.T2.2.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">profile_hash</span></td>\n<td id=\"S4.T2.2.4.2\" class=\"ltx_td ltx_align_left ltx_align_top\">\n<span id=\"S4.T2.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.4.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">sha256:8af4c61bd0b9e2a7d17f...</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.2.5\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S4.T2.2.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">UserID</span></td>\n<td id=\"S4.T2.2.5.2\" class=\"ltx_td ltx_align_left ltx_align_top\">\n<span id=\"S4.T2.2.5.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.5.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.5.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">org:laptopretail:cn:sales-division</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.2.6\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S4.T2.2.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Other</span></td>\n<td id=\"S4.T2.2.6.2\" class=\"ltx_td ltx_align_left ltx_align_top\">\n<span id=\"S4.T2.2.6.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.6.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.6.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">‘‘agent_version’’: ‘‘1.0.0’’</span></span>\n</span></td></tr>\n<tr id=\"S4.T2.2.7\" class=\"ltx_tr\">\n<td id=\"S4.T2.2.7.1\" class=\"ltx_td ltx_align_left ltx_border_bb\"><span id=\"S4.T2.2.7.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">AgentID</span></td>\n<td id=\"S4.T2.2.7.2\" class=\"ltx_td ltx_align_left ltx_align_top ltx_border_bb\">\n<span id=\"S4.T2.2.7.2.1\" class=\"ltx_inline-block ltx_align_top\" style=\"width:207.0pt;\">\n<span id=\"S4.T2.2.7.2.1.1\" class=\"ltx_p\"><span id=\"S4.T2.2.7.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\" style=\"font-size:90%;\">agentid:5f04cf173a987be6a98e...</span></span>\n</span></td></tr>\n</table>\n</figure>\n</section>\n</section>\n<section id=\"S4.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">4.3 </span>zkVM-Based Agent Identity Authentication Protocol</h3>\n\n<div id=\"S4.SS3.p1\" class=\"ltx_para\">\n<p id=\"S4.SS3.p1.1\" class=\"ltx_p\">Having established the local binding and on-chain registration mechanisms, we now present the zkVM-based agent identity authentication protocol that enables secure agent interactions with third-party verifiers through cryptographically verifiable identity and permission proofs. This protocol addresses the fundamental challenge of establishing trust when agents interact with external entities—including other agents, service providers, and regulatory authorities. Verifiers must authenticate both the agent’s identity integrity and its delegated permission scope to establish a cryptographic trust foundation.</p>\n</div>\n<div id=\"S4.SS3.p2\" class=\"ltx_para\">\n<p id=\"S4.SS3.p2.1\" class=\"ltx_p\">The authentication protocol comprises two complementary components: user-to-agent authorization through Verifiable Credentials, and agent identity authentication through zkVM proofs. The authorization mechanism enables users to delegate fine-grained permissions to agents, while the authentication mechanism enables agents to prove their identity and authorization scope to any third-party verifier without revealing sensitive information. Agent-to-agent interaction represents a primary application scenario, where mutual authentication enables trustworthy collaboration between autonomous systems.</p>\n</div>\n<section id=\"S4.SS3.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">4.3.1 </span>User-to-Agent Authorization</h4>\n\n<div id=\"S4.SS3.SSS1.p1\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS1.p1.1\" class=\"ltx_p\">Authorization establishes the permission delegation chain from users to agents, enabling agents to access user data, invoke resources, or act on behalf of users within explicitly defined boundaries. Our authorization mechanism features context-aware permission control that combines agent attributes with target task contexts, thereby preventing permission over-provisioning and protecting user data privacy.</p>\n</div>\n<div id=\"S4.SS3.SSS1.p2\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS1.p2.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Authorization Workflow.</span> As illustrated in Figure <a href=\"#S4.F6\" title=\"Figure 6 ‣ 4.3.1 User-to-Agent Authorization ‣ 4.3 zkVM-Based Agent Identity Authentication Protocol ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">6</span></a>, the authorization process comprises three steps:</p>\n</div>\n<div id=\"S4.SS3.SSS1.p3\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS1.p3.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS1.p3.1.1\" class=\"ltx_text ltx_font_bold\">Step1: Verifiable Credential Generation.</span> The agent’s Identity Module generates a Verifiable Credential (VC) based on the agent’s role, capabilities, and target task context. The VC contains: (1) Identity information (agent’s <math id=\"S4.SS3.SSS1.p3.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> and user’s <math id=\"S4.SS3.SSS1.p3.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{UserID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖴𝗌𝖾𝗋𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{UserID}</annotation></semantics></math>); (2) Task information (Task ID, Task definition); and (3) Permission information (security level, authorization scope, and credential validity period).</p>\n</div>\n<div id=\"S4.SS3.SSS1.p4\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS1.p4.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS1.p4.1.1\" class=\"ltx_text ltx_font_bold\">Step2: Local User Authentication.</span> The Identity Module initiates local user authentication to verify that the current operator is the legitimate owner, following the biometric verification procedure described in Section 5.1.</p>\n</div>\n<div id=\"S4.SS3.SSS1.p5\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS1.p5.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS1.p5.1.1\" class=\"ltx_text ltx_font_bold\">Step3: Credential Signing and Storage.</span> After passing local user authentication, the Identity Module signs the VC using the Owner’s private key and attaches the signature to the VC. The signed VC is then stored in the agent’s Identity Module. When necessary, the VC can be published to the AgentFactsURL, for example, VCs that can demonstrate the agent’s capabilities or harmlessness.</p>\n</div>\n<figure id=\"S4.F6\" class=\"ltx_figure\"><img src=\"2512.17538v1/authorization-workflow.png\" id=\"S4.F6.g1\" class=\"ltx_graphics ltx_centering ltx_img_landscape\" style=\"aspect-ratio:476/143;\" width=\"476\" height=\"143\" alt=\"Refer to caption\">\n<figcaption class=\"ltx_caption ltx_centering\"><span class=\"ltx_tag ltx_tag_figure\">Figure 6: </span>Authorization workflow showing VC generation, biometric authentication, and credential signing.</figcaption>\n</figure>\n</section>\n<section id=\"S4.SS3.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">4.3.2 </span>zkVM-Based Agent Identity Authentication</h4>\n\n<div id=\"S4.SS3.SSS2.p1\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p1.1\" class=\"ltx_p\">Building upon the user-to-agent authorization foundation, the agent identity authentication protocol implements a dual-layer verifiable computation framework leveraging zkVM technology. This protocol addresses three fundamental technical challenges inherent to autonomous agent systems to establish cryptographic guarantees for agent identity integrity, operator legitimacy, and execution provenance.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p2\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p2.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Challenge 1: Identity-Execution Binding.</span> Traditional key-based authentication is insufficient for autonomous agents, as possession of a signing key guarantees neither the integrity of the executing code nor the authenticity of the operator. An adversary with a compromised key could therefore execute malicious logic or impersonate the legitimate operator while masquerading as the authorized agent. To resolve this semantic gap, we introduce <span id=\"S4.SS3.SSS2.p2.1.2\" class=\"ltx_text ltx_font_italic\">Code-Level Authentication</span> using zkVM. By establishing the program binary as the agent’s identity and generating cryptographic proofs of execution, we bind the agent’s identity directly to its computational behavior and operator authorization, ensuring that only the committed code executed by the bound user can generate valid authentication proofs.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p3\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p3.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Challenge 2: Execution Continuity.</span> Agents operate through multi-turn interactions where state transitions must be sequentially valid. Standard verifiable computation proofs verify individual steps but lack mechanisms to enforce the correct ordering of a sequence, leaving systems vulnerable to replay or reordering attacks. We address this by leveraging zkVM’s <span id=\"S4.SS3.SSS2.p3.1.2\" class=\"ltx_text ltx_font_italic\">Recursive Verification</span> capability. Each execution step generates a proof that recursively verifies the validity of the previous step’s proof, constructing an unbreakable cryptographic chain that guarantees the integrity and continuity of the entire interaction history.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p4\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p4.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Challenge 3: Data Provenance.</span> Agents frequently interact with external environments (e.g., calling LLM APIs or accessing web data), but the zkVM cannot inherently verify the authenticity of external data. This creates a trust gap where an attacker could feed fabricated data to the agent. We bridge this gap by integrating <span id=\"S4.SS3.SSS2.p4.1.2\" class=\"ltx_text ltx_font_italic\">zkTLS</span> (Zero-Knowledge Transport Layer Security). This allows the agent to generate proofs attesting that specific data originated from a trusted TLS-authenticated server (e.g., OpenAI), ensuring end-to-end provenance from external data sources to internal computation.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p5\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p5.1\" class=\"ltx_p\">To systematically resolve these challenges, we propose a <span id=\"S4.SS3.SSS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Dual-Layer Verification Framework</span> (detailed technical specifications including mathematical proofs, security properties, and protocol formalization are provided in Appendix A). The protocol orchestrates verification through two integrated layers:</p>\n</div>\n<div id=\"S4.SS3.SSS2.p6\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p6.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p6.1.1\" class=\"ltx_text ltx_font_bold\">Layer 1: Three-Phase Verifiable Computation Pipeline.</span> This layer implements end-to-end cryptographic guarantees through recursive proof algorithm across three sequential phases:</p>\n</div>\n<div id=\"S4.SS3.SSS2.p7\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p7.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p7.1.1\" class=\"ltx_text ltx_font_italic\">Phase 1—Operator Biometric Authentication.</span> To address the unique security requirements of autonomous agents, this phase validates operator legitimacy through privacy-preserving facial recognition. This mechanism fulfills two critical security objectives: it strictly enforces that the agent serves <span id=\"S4.SS3.SSS2.p7.1.2\" class=\"ltx_text ltx_font_italic\">exclusively its designated owner</span>, and simultaneously generates a <span id=\"S4.SS3.SSS2.p7.1.3\" class=\"ltx_text ltx_font_italic\">third-party verifiable proof</span> of this authorization—a mandatory condition for irrefutable traceability that overcomes the limitations of mere local authentication. The protocol captures operator face via device camera, extracts normalized 128-dimensional embedding <math id=\"S4.SS3.SSS2.p7.m1\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{capture}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝐯</mi><mtext>capture</mtext></msub><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{capture}}</annotation></semantics></math> using pre-trained neural networks (FaceNet, ArcFace), and loads stored template <math id=\"S4.SS3.SSS2.p7.m2\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{stored}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝐯</mi><mtext>stored</mtext></msub><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{stored}}</annotation></semantics></math> from the verified configuration. zkVM similarity computation receives public inputs (threshold <math id=\"S4.SS3.SSS2.p7.m3\" class=\"ltx_Math\" alttext=\"\\tau\" display=\"inline\" intent=\":literal\"><semantics><mi>τ</mi><annotation encoding=\"application/x-tex\">\\tau</annotation></semantics></math>, user identifier) and private witness (<math id=\"S4.SS3.SSS2.p7.m4\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{capture}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝐯</mi><mtext>capture</mtext></msub><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{capture}}</annotation></semantics></math>, <math id=\"S4.SS3.SSS2.p7.m5\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{stored}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝐯</mi><mtext>stored</mtext></msub><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{stored}}</annotation></semantics></math>), generating proof <math id=\"S4.SS3.SSS2.p7.m6\" class=\"ltx_Math\" alttext=\"\\pi_{1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>1</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{1}</annotation></semantics></math> asserting:</p>\n<table id=\"S4.E2\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S4.E2.m1\" class=\"ltx_Math\" alttext=\"\\exists\\mathbf{v}_{\\text{capture}},\\mathbf{v}_{\\text{stored}}:\\frac{\\mathbf{v}_{\\text{capture}}\\cdot\\mathbf{v}_{\\text{stored}}}{\\|\\mathbf{v}_{\\text{capture}}\\|\\|\\mathbf{v}_{\\text{stored}}\\|}\\geq\\tau\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mo rspace=\"0.167em\">∃</mo><msub><mi>𝐯</mi><mtext>capture</mtext></msub></mrow><mo>,</mo><mrow><msub><mi>𝐯</mi><mtext>stored</mtext></msub><mo lspace=\"0.278em\" rspace=\"0.278em\">:</mo><mrow><mfrac><mrow><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo lspace=\"0.222em\" rspace=\"0.222em\">⋅</mo><msub><mi>𝐯</mi><mtext>stored</mtext></msub></mrow><mrow><mrow><mo stretchy=\"false\">‖</mo><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo stretchy=\"false\">‖</mo></mrow><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">‖</mo><msub><mi>𝐯</mi><mtext>stored</mtext></msub><mo stretchy=\"false\">‖</mo></mrow></mrow></mfrac><mo>≥</mo><mi>τ</mi></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\exists\\mathbf{v}_{\\text{capture}},\\mathbf{v}_{\\text{stored}}:\\frac{\\mathbf{v}_{\\text{capture}}\\cdot\\mathbf{v}_{\\text{stored}}}{\\|\\mathbf{v}_{\\text{capture}}\\|\\|\\mathbf{v}_{\\text{stored}}\\|}\\geq\\tau</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(2)</span></td></tr></tbody>\n</table>\n<p id=\"S4.SS3.SSS2.p7.2\" class=\"ltx_p\">without revealing embedding vectors, ensuring only authorized users activate agent services.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p8\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p8.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p8.1.1\" class=\"ltx_text ltx_font_italic\">Phase 2—Agent Configuration Integrity.</span> Building upon operator verification, the protocol verifies that the agent’s local configuration matches the blockchain-anchored canonical version. The on-chain <math id=\"S4.SS3.SSS2.p8.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> stores <math id=\"S4.SS3.SSS2.p8.m2\" class=\"ltx_Math\" alttext=\"\\text{profile\\_hash}=H(\\text{Config})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mtext>profile_hash</mtext><mo>=</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mtext>Config</mtext><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{profile\\_hash}=H(\\text{Config})</annotation></semantics></math> in an Ethereum smart contract at storage slot <math id=\"S4.SS3.SSS2.p8.m3\" class=\"ltx_Math\" alttext=\"s\" display=\"inline\" intent=\":literal\"><semantics><mi>s</mi><annotation encoding=\"application/x-tex\">s</annotation></semantics></math>. The protocol invokes <span id=\"S4.SS3.SSS2.p8.1.2\" class=\"ltx_text ltx_font_typewriter\">eth_getProof(contractAddr, [s], blockNumber)</span> to retrieve Merkle proofs linking the <math id=\"S4.SS3.SSS2.p8.m4\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> to blockchain state. zkVM verification receives public inputs (<math id=\"S4.SS3.SSS2.p8.m5\" class=\"ltx_Math\" alttext=\"r_{\\text{storage}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>r</mi><mtext>storage</mtext></msub><annotation encoding=\"application/x-tex\">r_{\\text{storage}}</annotation></semantics></math>, expected profile hash) and private witness (local configuration <math id=\"S4.SS3.SSS2.p8.m6\" class=\"ltx_Math\" alttext=\"\\text{Config}_{\\text{local}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mtext>Config</mtext><mtext>local</mtext></msub><annotation encoding=\"application/x-tex\">\\text{Config}_{\\text{local}}</annotation></semantics></math>, Merkle proof <math id=\"S4.SS3.SSS2.p8.m7\" class=\"ltx_Math\" alttext=\"\\pi_{\\text{merkle}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mtext>merkle</mtext></msub><annotation encoding=\"application/x-tex\">\\pi_{\\text{merkle}}</annotation></semantics></math>), then proves:</p>\n<table id=\"S4.E3\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"S4.E3.m1\" class=\"ltx_Math\" alttext=\"H(\\text{Config}_{\\text{local}})=\\text{profile\\_hash in }\\mathsf{AgentID}\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mtext>Config</mtext><mtext>local</mtext></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mrow><mtext>profile_hash in </mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi></mrow></mrow><annotation encoding=\"application/x-tex\">H(\\text{Config}_{\\text{local}})=\\text{profile\\_hash in }\\mathsf{AgentID}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(3)</span></td></tr></tbody>\n</table>\n<p id=\"S4.SS3.SSS2.p8.2\" class=\"ltx_p\">Leveraging blockchain’s tamper-proof storage establishes a cryptographic anchor for agent identity, generating proof <math id=\"S4.SS3.SSS2.p8.m8\" class=\"ltx_Math\" alttext=\"\\pi_{2}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>2</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{2}</annotation></semantics></math> that binds storage root and Merkle proof verification without revealing configuration contents.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p9\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p9.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p9.1.1\" class=\"ltx_text ltx_font_italic\">Phase 3—Iterative Execution with Communication Provenance.</span> The system generates cryptographic proofs for complete execution traces across conversational turns. Each turn <math id=\"S4.SS3.SSS2.p9.m1\" class=\"ltx_Math\" alttext=\"t\" display=\"inline\" intent=\":literal\"><semantics><mi>t</mi><annotation encoding=\"application/x-tex\">t</annotation></semantics></math> involves: (1) input reception (user query <math id=\"S4.SS3.SSS2.p9.m2\" class=\"ltx_Math\" alttext=\"q_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>q</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">q_{t}</annotation></semantics></math>, previous state commitment <math id=\"S4.SS3.SSS2.p9.m3\" class=\"ltx_Math\" alttext=\"h_{t-1}=H(S_{t-1})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>h</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>=</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">h_{t-1}=H(S_{t-1})</annotation></semantics></math>); (2) LLM invocation (remote service response <math id=\"S4.SS3.SSS2.p9.m4\" class=\"ltx_Math\" alttext=\"a_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>a</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">a_{t}</annotation></semantics></math>); (3) tool execution (<math id=\"S4.SS3.SSS2.p9.m5\" class=\"ltx_Math\" alttext=\"o_{t}=f_{a_{t}}(\\text{params})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>o</mi><mi>t</mi></msub><mo>=</mo><mrow><msub><mi>f</mi><msub><mi>a</mi><mi>t</mi></msub></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mtext>params</mtext><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">o_{t}=f_{a_{t}}(\\text{params})</annotation></semantics></math>); (4) state update (<math id=\"S4.SS3.SSS2.p9.m6\" class=\"ltx_Math\" alttext=\"S_{t}=(S_{t-1},q_{t},a_{t},o_{t})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mi>t</mi></msub><mo>=</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>q</mi><mi>t</mi></msub><mo>,</mo><msub><mi>a</mi><mi>t</mi></msub><mo>,</mo><msub><mi>o</mi><mi>t</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">S_{t}=(S_{t-1},q_{t},a_{t},o_{t})</annotation></semantics></math>). The integrated execution proof <math id=\"S4.SS3.SSS2.p9.m7\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> combines three verification stages within one zkVM execution:</p>\n<ol id=\"S4.I1\" class=\"ltx_enumerate\">\n<li id=\"S4.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"S4.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_italic\">Recursive Verification.</span> For <math id=\"S4.I1.i1.p1.m1\" class=\"ltx_Math\" alttext=\"t&gt;1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>t</mi><mo>&gt;</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">t&gt;1</annotation></semantics></math>, verify parent proof <math id=\"S4.I1.i1.p1.m2\" class=\"ltx_Math\" alttext=\"\\pi_{t-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{t-1}</annotation></semantics></math> validity through zkVM’s recursive verification capability—where Prove algorithm verifies another zkVM proof within its execution—preventing broken proof chains from extending. This constructs proof chains with cryptographically enforced sequential dependencies: proof <math id=\"S4.I1.i1.p1.m3\" class=\"ltx_Math\" alttext=\"\\pi_{k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>k</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{k}</annotation></semantics></math> embeds complete previous proof <math id=\"S4.I1.i1.p1.m4\" class=\"ltx_Math\" alttext=\"\\pi_{k-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{k-1}</annotation></semantics></math> in public inputs <math id=\"S4.I1.i1.p1.m5\" class=\"ltx_Math\" alttext=\"x_{pub,k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub,k}</annotation></semantics></math>, and constraint template includes recursive verification program <math id=\"S4.I1.i1.p1.m6\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>P</mi><mtext>rec</mtext></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">P_{\\text{rec}}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})</annotation></semantics></math>. Successful verification of final proof <math id=\"S4.I1.i1.p1.m7\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> implies the entire execution sequence <math id=\"S4.I1.i1.p1.m8\" class=\"ltx_Math\" alttext=\"S_{0}\\to S_{1}\\to\\cdots\\to S_{T}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><msub><mi>S</mi><mn>1</mn></msub><mo rspace=\"0.1389em\" stretchy=\"false\">→</mo><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mo lspace=\"0.1389em\" stretchy=\"false\">→</mo><msub><mi>S</mi><mi>T</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\to S_{1}\\to\\cdots\\to S_{T}</annotation></semantics></math> validates in order with no permutation or substitution.</p>\n</div></li>\n<li id=\"S4.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"S4.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_italic\">zkTLS Verification.</span> Execute TLS session validation within zkVM to ensure authenticity of external communications. zkVM operates in isolated environments that cannot verify external data sources—an adversary controlling execution environment can replace genuine API responses with fabricated data. We adopt zkTLS (Zero-Knowledge Transport Layer Security) to establish cryptographic provenance for HTTPS communications. The unified verification circuit validates: (a) certificate validity (verify signature chain to trusted root CA, check certificate matches server identity); (b) session key derivation (compute Pre-Master Secret, derive <math id=\"S4.I1.i2.p1.m1\" class=\"ltx_Math\" alttext=\"K_{\\text{session}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mtext>session</mtext></msub><annotation encoding=\"application/x-tex\">K_{\\text{session}}</annotation></semantics></math> via PRF); (c) data integrity (decrypt response <math id=\"S4.I1.i2.p1.m2\" class=\"ltx_Math\" alttext=\"d=\\text{D}_{K_{\\text{session}}}(c)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>d</mi><mo>=</mo><mrow><msub><mtext>D</mtext><msub><mi>K</mi><mtext>session</mtext></msub></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>c</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">d=\\text{D}_{K_{\\text{session}}}(c)</annotation></semantics></math>, verify AEAD authentication tag); and (d) commitment binding (<math id=\"S4.I1.i2.p1.m3\" class=\"ltx_Math\" alttext=\"\\text{commit}(d)=H(d)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mtext>commit</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mrow><mi>H</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{commit}(d)=H(d)</annotation></semantics></math> matches public input). The unified proof <math id=\"S4.I1.i2.p1.m4\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> cryptographically attests: <span id=\"S4.I1.i2.p1.1.2\" class=\"ltx_text ltx_font_italic\">there exists a valid TLS session with server <math id=\"S4.I1.i2.p1.m5\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math> that decrypts to data <math id=\"S4.I1.i2.p1.m6\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> (matching commitment <math id=\"S4.I1.i2.p1.m7\" class=\"ltx_Math\" alttext=\"H(d)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">H(d)</annotation></semantics></math>), and program <math id=\"S4.I1.i2.p1.m8\" class=\"ltx_Math\" alttext=\"P\" display=\"inline\" intent=\":literal\"><semantics><mi>P</mi><annotation encoding=\"application/x-tex\">P</annotation></semantics></math> correctly processed <math id=\"S4.I1.i2.p1.m9\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> to produce claimed output</span>—binding TLS communication provenance with computation correctness.</p>\n</div></li>\n<li id=\"S4.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"S4.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"S4.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"S4.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_italic\">Agent Computation Verification.</span> Verify agent correctly executes tasks using verified responses: parse action, execute tool call, update state, compute state commitment <math id=\"S4.I1.i3.p1.m1\" class=\"ltx_Math\" alttext=\"h_{S_{t}}=H(S_{t})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>h</mi><msub><mi>S</mi><mi>t</mi></msub></msub><mo>=</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mi>t</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">h_{S_{t}}=H(S_{t})</annotation></semantics></math>.</p>\n</div></li>\n</ol>\n</div>\n<div id=\"S4.SS3.SSS2.p10\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p10.1\" class=\"ltx_p\">After <math id=\"S4.SS3.SSS2.p10.m1\" class=\"ltx_Math\" alttext=\"T\" display=\"inline\" intent=\":literal\"><semantics><mi>T</mi><annotation encoding=\"application/x-tex\">T</annotation></semantics></math> conversational turns, final proof <math id=\"S4.SS3.SSS2.p10.m2\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> cryptographically attests to: (1) initial authentication validity (Phase 1 configuration integrity, Phase 2 operator biometric verification); (2) complete execution trace across all turns: <math id=\"S4.SS3.SSS2.p10.m3\" class=\"ltx_Math\" alttext=\"S_{0}\\to S_{1}\\to\\cdots\\to S_{T}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><msub><mi>S</mi><mn>1</mn></msub><mo rspace=\"0.1389em\" stretchy=\"false\">→</mo><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mo lspace=\"0.1389em\" stretchy=\"false\">→</mo><msub><mi>S</mi><mi>T</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\to S_{1}\\to\\cdots\\to S_{T}</annotation></semantics></math>; (3) verified provenance of all external service responses: <math id=\"S4.SS3.SSS2.p10.m4\" class=\"ltx_Math\" alttext=\"\\{a_{1},\\ldots,a_{T}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>a</mi><mn>1</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>a</mi><mi>T</mi></msub><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{a_{1},\\ldots,a_{T}\\}</annotation></semantics></math> via zkTLS; (4) correct agent computation for all tool executions: <math id=\"S4.SS3.SSS2.p10.m5\" class=\"ltx_Math\" alttext=\"\\{o_{1},\\ldots,o_{T}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>o</mi><mn>1</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>o</mi><mi>T</mi></msub><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{o_{1},\\ldots,o_{T}\\}</annotation></semantics></math> following code <math id=\"S4.SS3.SSS2.p10.m6\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math>.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p11\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p11.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p11.1.1\" class=\"ltx_text ltx_font_bold\">Layer 2: Permission Validation.</span> After establishing identity and execution integrity through Layer 1, the system validates authorization scope using Verifiable Credentials. The verifier validates agent’s VC to confirm permission scope matches requested operation: (a) signature verification using user’s public key from User Identity Contract; (b) credential validity period checking; (c) permission scope matching against target task context; (d) revocation status checking. This layer ensures authenticated agents operate within explicitly delegated permission boundaries, preventing privilege escalation.</p>\n</div>\n<div id=\"S4.SS3.SSS2.p12\" class=\"ltx_para\">\n<p id=\"S4.SS3.SSS2.p12.1\" class=\"ltx_p\"><span id=\"S4.SS3.SSS2.p12.1.1\" class=\"ltx_text ltx_font_bold\">Authentication Output.</span> Upon successful completion, the protocol outputs: (1) unified proof <math id=\"S4.SS3.SSS2.p12.m1\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> demonstrating agent configuration integrity, operator biometric verification, and complete execution trace; (2) validated Verifiable Credential with verified permission scope. Verifiers (counterpart agents, service providers, regulators) independently verify by checking <math id=\"S4.SS3.SSS2.p12.m2\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> using zkVM’s Verify algorithm against on-chain <math id=\"S4.SS3.SSS2.p12.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> and validating VC signature and scope, establishing cryptographic guarantees for trustworthy agent interactions without centralized trust infrastructure.</p>\n</div>\n</section>\n</section>\n</section>\n<section id=\"S5\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">5 </span>Implementation and Performance Evaluation</h2>\n\n<div id=\"S5.p1\" class=\"ltx_para\">\n<p id=\"S5.p1.1\" class=\"ltx_p\">We evaluate the BAID system across two critical dimensions: (1) on-chain identity management smart contracts performance focusing on gas consumption efficiency for on-chain identity management operations, and (2) verifiable agent system performance focusing on zkVM-based authentication protocol efficiency. These evaluations address distinct but complementary aspects of the BAID architecture, demonstrating practical deployability across both on-chain and off-chain components.</p>\n</div>\n<section id=\"S5.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.1 </span>Identity Management Smart Contracts Performance</h3>\n\n<div id=\"S5.SS1.p1\" class=\"ltx_para\">\n<p id=\"S5.SS1.p1.1\" class=\"ltx_p\">To evaluate the gas consumption efficiency of the BAID on-chain identity management system, we deployed the complete smart contract architecture on the Ethereum Virtual Machine (EVM) testnet and conducted comprehensive performance testing using the Hardhat framework <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib32\" title=\"\" class=\"ltx_ref\">Nomic Foundation (2024)</a></cite>, a development environment that provides deterministic gas metering consistent with mainnet behavior. We deployed the complete BAID contract suite including IdentityFactory, UserIdentityContract template, AgentIdentityContract template, and all zkKYC verification contracts. Gas measurements were collected using Hardhat’s built-in gas reporter, which instruments the EVM to track computational costs for each transaction. The evaluation focused on gas consumption for core identity management operations, as gas costs directly impact the economic feasibility and scalability of blockchain-based identity systems.</p>\n</div>\n<div id=\"S5.SS1.p2\" class=\"ltx_para\">\n<p id=\"S5.SS1.p2.1\" class=\"ltx_p\">Table <a href=\"#S5.T3\" title=\"Table 3 ‣ 5.1 Identity Management Smart Contracts Performance ‣ 5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">3</span></a> presents the gas consumption statistics for the four core BAID system operations. The measurements represent average values across multiple test executions, demonstrating consistent performance characteristics.</p>\n</div>\n<figure id=\"S5.T3\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\">Table 3: </span>Gas Consumption for Core BAID System Operations</figcaption>\n<table id=\"S5.T3.2\" class=\"ltx_tabular ltx_centering ltx_align_middle\">\n<tr id=\"S5.T3.2.1\" class=\"ltx_tr\">\n<td id=\"S5.T3.2.1.1\" class=\"ltx_td ltx_align_left ltx_border_tt\"><span id=\"S5.T3.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Operation</span></td>\n<td id=\"S5.T3.2.1.2\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S5.T3.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T3.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S5.T3.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Gas Consumption</span></span>\n</span></td></tr>\n<tr id=\"S5.T3.2.2\" class=\"ltx_tr\">\n<td id=\"S5.T3.2.2.1\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S5.T3.2.2.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">User Registration (<span id=\"S5.T3.2.2.1.1.1\" class=\"ltx_text ltx_font_typewriter\">registerUser</span>)</span></td>\n<td id=\"S5.T3.2.2.2\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S5.T3.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T3.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S5.T3.2.2.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">390,325 gas</span></span>\n</span></td></tr>\n<tr id=\"S5.T3.2.3\" class=\"ltx_tr\">\n<td id=\"S5.T3.2.3.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.T3.2.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent Registration (<span id=\"S5.T3.2.3.1.1.1\" class=\"ltx_text ltx_font_typewriter\">registerAgent</span>)</span></td>\n<td id=\"S5.T3.2.3.2\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T3.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T3.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S5.T3.2.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">507,763 gas</span></span>\n</span></td></tr>\n<tr id=\"S5.T3.2.4\" class=\"ltx_tr\">\n<td id=\"S5.T3.2.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.T3.2.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent Deregistration (<span id=\"S5.T3.2.4.1.1.1\" class=\"ltx_text ltx_font_typewriter\">deregisterAgent</span>)</span></td>\n<td id=\"S5.T3.2.4.2\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T3.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T3.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S5.T3.2.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">124,117 gas</span></span>\n</span></td></tr>\n<tr id=\"S5.T3.2.5\" class=\"ltx_tr\">\n<td id=\"S5.T3.2.5.1\" class=\"ltx_td ltx_align_left ltx_border_bb\"><span id=\"S5.T3.2.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Agent Update (<span id=\"S5.T3.2.5.1.1.1\" class=\"ltx_text ltx_font_typewriter\">updateAgent</span>)</span></td>\n<td id=\"S5.T3.2.5.2\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S5.T3.2.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T3.2.5.2.1.1\" class=\"ltx_p\"><span id=\"S5.T3.2.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">128,837 gas</span></span>\n</span></td></tr>\n</table>\n</figure>\n<div id=\"S5.SS1.p3\" class=\"ltx_para\">\n<p id=\"S5.SS1.p3.1\" class=\"ltx_p\">The experimental results demonstrate two fundamental characteristics of the BAID blockchain system’s gas consumption profile:</p>\n</div>\n<div id=\"S5.SS1.p4\" class=\"ltx_para\">\n<p id=\"S5.SS1.p4.1\" class=\"ltx_p\"><span id=\"S5.SS1.p4.1.1\" class=\"ltx_text ltx_font_bold\">(1) Registration Cost Composition.</span> Registration operations exhibit high gas consumption driven by two factors: cryptographic verification overhead and storage allocation costs. User registration (<math id=\"S5.SS1.p4.m1\" class=\"ltx_Math\" alttext=\"\\sim\" display=\"inline\" intent=\":literal\"><semantics><mo>∼</mo><annotation encoding=\"application/x-tex\">\\sim</annotation></semantics></math>390K gas) performs zkKYC verification for privacy-preserving identity validation, consuming substantial gas for on-chain zero-knowledge proof verification. Agent registration (<math id=\"S5.SS1.p4.m2\" class=\"ltx_Math\" alttext=\"\\sim\" display=\"inline\" intent=\":literal\"><semantics><mo>∼</mo><annotation encoding=\"application/x-tex\">\\sim</annotation></semantics></math>508K gas) adds 30% overhead through Clone-pattern contract instantiation and user-agent binding establishment. The fundamental storage cost asymmetry—SSTORE from zero to non-zero requires 20,000 gas per slot versus 5,000 gas for modifications—explains why registration operations dominate gas consumption.</p>\n</div>\n<div id=\"S5.SS1.p5\" class=\"ltx_para\">\n<p id=\"S5.SS1.p5.1\" class=\"ltx_p\"><span id=\"S5.SS1.p5.1.1\" class=\"ltx_text ltx_font_bold\">(2) Efficient State Modification.</span> Update (<math id=\"S5.SS1.p5.m1\" class=\"ltx_Math\" alttext=\"\\sim\" display=\"inline\" intent=\":literal\"><semantics><mo>∼</mo><annotation encoding=\"application/x-tex\">\\sim</annotation></semantics></math>129K gas) and deregistration (<math id=\"S5.SS1.p5.m2\" class=\"ltx_Math\" alttext=\"\\sim\" display=\"inline\" intent=\":literal\"><semantics><mo>∼</mo><annotation encoding=\"application/x-tex\">\\sim</annotation></semantics></math>124K gas) operations consume approximately 75% less gas than registrations by avoiding expensive contract creation and leveraging existing storage slots. These operations achieve consistent performance through minimal state modifications and event emission, demonstrating the efficiency of the BAID contract architecture for routine identity management operations.</p>\n</div>\n<div id=\"S5.SS1.p6\" class=\"ltx_para\">\n<p id=\"S5.SS1.p6.1\" class=\"ltx_p\">Overall, the BAID blockchain system achieves gas-efficient identity management through three design choices: zkKYC for privacy-preserving user registration, Clone pattern for agent contract deployment, and minimal storage footprint for affordable routine operations.</p>\n</div>\n</section>\n<section id=\"S5.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">5.2 </span>Verifiable Agent System Performance</h3>\n\n<div id=\"S5.SS2.p1\" class=\"ltx_para\">\n<p id=\"S5.SS2.p1.1\" class=\"ltx_p\">To evaluate the performance and scalability of the BAID authentication protocol, we implemented a complete Verifiable Agent System using RISC Zero’s zkVM framework <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib31\" title=\"\" class=\"ltx_ref\">RISC Zero (2024)</a></cite> and conducted comprehensive performance testing on the recursive proof generation pipeline. The testing environment consisted of a Rust-based zkVM execution framework implementing the complete BAID authentication pipeline described in Section 5.3, deployed on a standard development machine (Apple M1 chip, 16GB RAM) using RISC Zero zkVM version 1.0 with the composite proof system.</p>\n</div>\n<div id=\"S5.SS2.p2\" class=\"ltx_para\">\n<p id=\"S5.SS2.p2.1\" class=\"ltx_p\">The implementation follows a fully recursive verification pipeline spanning five sequential phases: (1) Phase 1 (Operator Biometric Authentication) establishes the baseline proof; (2) Phase 2 (Agent Configuration Integrity) recursively verifies Phase 1; (3) Phase 3 comprises three iterations of Iterative Task Execution, where Turn 1 recursively verifies Phases 1-2, Turn 2 recursively verifies Phases 1-2 and Turn 1, and Turn 3 recursively verifies the complete execution history from Phase 1 through Turn 2. The evaluation focused on execution efficiency, proof generation overhead, verification costs, and proof size characteristics across this multi-phase recursive authentication workflow, as these metrics directly impact the practical deployability and scalability of zkVM-based agent identity systems.</p>\n</div>\n<div id=\"S5.SS2.p3\" class=\"ltx_para\">\n<p id=\"S5.SS2.p3.1\" class=\"ltx_p\">Table <a href=\"#S5.T4\" title=\"Table 4 ‣ 5.2 Verifiable Agent System Performance ‣ 5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">4</span></a> presents the performance characteristics for each phase of the BAID authentication protocol. The measurements represent average values across multiple test executions, demonstrating consistent performance patterns.</p>\n</div>\n<figure id=\"S5.T4\" class=\"ltx_table\">\n<figcaption class=\"ltx_caption\"><span class=\"ltx_tag ltx_tag_table\">Table 4: </span>zkVM Performance Metrics for BAID Authentication Protocol</figcaption>\n<table id=\"S5.T4.2\" class=\"ltx_tabular ltx_centering ltx_align_middle\">\n<tr id=\"S5.T4.2.1\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.1.1\" class=\"ltx_td ltx_align_left ltx_border_tt\"><span id=\"S5.T4.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Phase</span></td>\n<td id=\"S5.T4.2.1.2\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S5.T4.2.1.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.1.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.1.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Exec</span></span>\n</span></td>\n<td id=\"S5.T4.2.1.3\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S5.T4.2.1.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.1.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.1.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Prove</span></span>\n</span></td>\n<td id=\"S5.T4.2.1.4\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S5.T4.2.1.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.1.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.1.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Total</span></span>\n</span></td>\n<td id=\"S5.T4.2.1.5\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S5.T4.2.1.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.1.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.1.5.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Proof</span></span>\n</span></td>\n<td id=\"S5.T4.2.1.6\" class=\"ltx_td ltx_align_left ltx_border_tt\">\n<span id=\"S5.T4.2.1.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.1.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.1.6.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">Verify</span></span>\n</span></td></tr>\n<tr id=\"S5.T4.2.2\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.2.1\" class=\"ltx_td\"></td>\n<td id=\"S5.T4.2.2.2\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.2.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.2.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.2.2.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">(ms)</span></span>\n</span></td>\n<td id=\"S5.T4.2.2.3\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.2.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.2.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.2.3.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">(s)</span></span>\n</span></td>\n<td id=\"S5.T4.2.2.4\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.2.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.2.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.2.4.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">(s)</span></span>\n</span></td>\n<td id=\"S5.T4.2.2.5\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.2.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.2.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.2.5.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">(KB)</span></span>\n</span></td>\n<td id=\"S5.T4.2.2.6\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.2.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.2.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.2.6.1.1.1\" class=\"ltx_text ltx_font_bold\" style=\"font-size:90%;\">(ms)</span></span>\n</span></td></tr>\n<tr id=\"S5.T4.2.3\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.3.1\" class=\"ltx_td ltx_align_left ltx_border_t\"><span id=\"S5.T4.2.3.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Phase 1: Bio Auth</span></td>\n<td id=\"S5.T4.2.3.2\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S5.T4.2.3.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.3.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.3.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">9</span></span>\n</span></td>\n<td id=\"S5.T4.2.3.3\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S5.T4.2.3.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.3.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.3.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">15.00</span></span>\n</span></td>\n<td id=\"S5.T4.2.3.4\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S5.T4.2.3.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.3.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.3.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">15.01</span></span>\n</span></td>\n<td id=\"S5.T4.2.3.5\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S5.T4.2.3.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.3.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.3.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">238</span></span>\n</span></td>\n<td id=\"S5.T4.2.3.6\" class=\"ltx_td ltx_align_left ltx_border_t\">\n<span id=\"S5.T4.2.3.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.3.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.3.6.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">14</span></span>\n</span></td></tr>\n<tr id=\"S5.T4.2.4\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.4.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.T4.2.4.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Phase 2: Config Veri</span></td>\n<td id=\"S5.T4.2.4.2\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.4.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.4.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.4.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">13</span></span>\n</span></td>\n<td id=\"S5.T4.2.4.3\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.4.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.4.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.4.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">31.35</span></span>\n</span></td>\n<td id=\"S5.T4.2.4.4\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.4.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.4.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.4.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">31.36</span></span>\n</span></td>\n<td id=\"S5.T4.2.4.5\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.4.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.4.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.4.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">488</span></span>\n</span></td>\n<td id=\"S5.T4.2.4.6\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.4.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.4.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.4.6.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">28</span></span>\n</span></td></tr>\n<tr id=\"S5.T4.2.5\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.5.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.T4.2.5.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Phase 3 (Turn 1)</span></td>\n<td id=\"S5.T4.2.5.2\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.5.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.5.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.5.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">17</span></span>\n</span></td>\n<td id=\"S5.T4.2.5.3\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.5.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.5.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.5.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">40.14</span></span>\n</span></td>\n<td id=\"S5.T4.2.5.4\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.5.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.5.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.5.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">40.16</span></span>\n</span></td>\n<td id=\"S5.T4.2.5.5\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.5.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.5.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.5.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">737</span></span>\n</span></td>\n<td id=\"S5.T4.2.5.6\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.5.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.5.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.5.6.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">43</span></span>\n</span></td></tr>\n<tr id=\"S5.T4.2.6\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.6.1\" class=\"ltx_td ltx_align_left\"><span id=\"S5.T4.2.6.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Phase 3 (Turn 2)</span></td>\n<td id=\"S5.T4.2.6.2\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.6.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.6.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.6.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">19</span></span>\n</span></td>\n<td id=\"S5.T4.2.6.3\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.6.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.6.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.6.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">37.68</span></span>\n</span></td>\n<td id=\"S5.T4.2.6.4\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.6.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.6.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.6.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">37.70</span></span>\n</span></td>\n<td id=\"S5.T4.2.6.5\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.6.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.6.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.6.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">987</span></span>\n</span></td>\n<td id=\"S5.T4.2.6.6\" class=\"ltx_td ltx_align_left\">\n<span id=\"S5.T4.2.6.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.6.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.6.6.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">74</span></span>\n</span></td></tr>\n<tr id=\"S5.T4.2.7\" class=\"ltx_tr\">\n<td id=\"S5.T4.2.7.1\" class=\"ltx_td ltx_align_left ltx_border_bb\"><span id=\"S5.T4.2.7.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">Phase 3 (Turn 3)</span></td>\n<td id=\"S5.T4.2.7.2\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S5.T4.2.7.2.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.7.2.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.7.2.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">15</span></span>\n</span></td>\n<td id=\"S5.T4.2.7.3\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S5.T4.2.7.3.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.7.3.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.7.3.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">38.29</span></span>\n</span></td>\n<td id=\"S5.T4.2.7.4\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S5.T4.2.7.4.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.7.4.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.7.4.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">38.31</span></span>\n</span></td>\n<td id=\"S5.T4.2.7.5\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S5.T4.2.7.5.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.7.5.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.7.5.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">1236</span></span>\n</span></td>\n<td id=\"S5.T4.2.7.6\" class=\"ltx_td ltx_align_left ltx_border_bb\">\n<span id=\"S5.T4.2.7.6.1\" class=\"ltx_inline-block ltx_align_top\">\n<span id=\"S5.T4.2.7.6.1.1\" class=\"ltx_p\"><span id=\"S5.T4.2.7.6.1.1.1\" class=\"ltx_text\" style=\"font-size:90%;\">93</span></span>\n</span></td></tr>\n</table>\n</figure>\n<div id=\"S5.SS2.p4\" class=\"ltx_para\">\n<p id=\"S5.SS2.p4.1\" class=\"ltx_p\"><span id=\"S5.SS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Proof Generation Overhead.</span> Proof generation dominates the computational cost, constituting 99.9% of total processing time across all phases. For instance, Phase 1 requires only 9ms for program execution but 15.00s for proof generation, demonstrating that cryptographic proof construction overhead far exceeds the program execution itself. This asymmetry aligns with fundamental zkVM architecture where constraint satisfaction and polynomial commitment schemes require intensive computation, while program execution remains lightweight. Notably, proof generation time scales polylogarithmically with program size but exhibits near-constant complexity with respect to recursive depth—the 15-40 second generation latency remains consistent across phases despite accumulating recursive verification steps. This property makes the protocol suitable for high-security authentication scenarios where cryptographic guarantees justify computational overhead.</p>\n</div>\n<div id=\"S5.SS2.p5\" class=\"ltx_para\">\n<p id=\"S5.SS2.p5.1\" class=\"ltx_p\"><span id=\"S5.SS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Verification Overhead.</span> In contrast to proof generation, verification exhibits succinct characteristics with logarithmic complexity relative to program size. Verification time demonstrates linear growth with recursive depth—Phase 3 (Turn 1) requires 43ms, Phase 3 (Turn 2) (with one recursive verification) increases to 74ms, and Phase 3 (Turn 3) (with two recursive verifications) reaches 93ms. This linear scaling in recursive depth is the fundamental cost of ensuring execution sequence integrity: each additional turn cryptographically validates all previous computation, preventing proof chain manipulation or execution reordering attacks. The proof size similarly scales linearly with recursive depth (737KB for Turn 1, 987KB for Turn 2, 1236KB for Turn 3), reflecting the embedded verification history. Despite this linear growth, millisecond-level verification times remain practical for real-world deployment scenarios where cryptographic execution ordering guarantees are critical security requirements. This asymmetric cost structure—expensive proof generation concentrated at the prover, with efficient verification distributed to multiple verifiers—enables scalable multi-party verification in decentralized agent ecosystems without requiring verifiers to re-execute the complete agent workflow.</p>\n</div>\n<div id=\"S5.SS2.p6\" class=\"ltx_para\">\n<p id=\"S5.SS2.p6.1\" class=\"ltx_p\">Overall, the zkVM evaluation demonstrates that the BAID authentication protocol achieves practical performance characteristics suitable for real-world deployment, with asymmetric costs favoring verifiers over provers in high-security authentication scenarios.</p>\n</div>\n</section>\n</section>\n<section id=\"S6\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">6 </span>Related Work</h2>\n\n<div id=\"S6.p1\" class=\"ltx_para\">\n<p id=\"S6.p1.1\" class=\"ltx_p\">Trustworthy AI agent collaboration requires three interconnected capabilities: standardized communication protocols, robust identity authentication, and operator accountability mechanisms. While existing research has advanced each dimension independently, a critical gap remains: no unified system simultaneously ensures agent identity integrity, operator accountability, and cross-protocol interoperability. We organize related work along these dimensions and identify limitations motivating our approach.</p>\n</div>\n<div id=\"S6.p2\" class=\"ltx_para\">\n<p id=\"S6.p2.1\" class=\"ltx_p\"><span id=\"S6.p2.1.1\" class=\"ltx_text ltx_font_bold\">Agent Communication Protocols.</span> The field of agent communication protocols has witnessed significant developments with several sophisticated frameworks emerging. Model Context Protocol (MCP) introduced by Anthropic <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib28\" title=\"\" class=\"ltx_ref\">Anthropic (2024)</a>; <a href=\"#bib.bib29\" title=\"\" class=\"ltx_ref\">Model Context Protocol Specification Authors (2025)</a>; <a href=\"#bib.bib30\" title=\"\" class=\"ltx_ref\">Schmid (2025)</a></cite> establishes a comprehensive framework for contextual information exchange. Agent-to-Agent (A2A) Protocol <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib26\" title=\"\" class=\"ltx_ref\">Surapaneni et al. (2025)</a>; <a href=\"#bib.bib27\" title=\"\" class=\"ltx_ref\">Agent2Agent Protocol Specification Authors (2025)</a></cite>, developed by Google, represents a breakthrough in opaque agent interoperability. Agent Communication Protocol (ACP) <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib15\" title=\"\" class=\"ltx_ref\">LF AI &amp; Data Foundation (2025)</a></cite> focuses on local network-prioritized communication. Additionally, several novel frameworks have been proposed: ANP (Agent Network Protocol) <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">lin2025anp</span></cite> facilitates large-scale agent networking; LMOS (Language Model Operating System) <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">lmos2025</span></cite> by Eclipse integrates LLMs into system-level operations; and the Agent Protocol <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">agentprotocol2025</span></cite> offers an open-source, framework-agnostic standard based on OpenAPI v3 for managing agent lifecycles (start, stop, monitor). Despite their technical sophistication, these protocols share a fundamental limitation: the absence of a unified, trusted layer for agent registration and discovery, creating significant barriers to cross-protocol identity verification and trusted collaboration environments.</p>\n</div>\n<div id=\"S6.p3\" class=\"ltx_para\">\n<p id=\"S6.p3.1\" class=\"ltx_p\"><span id=\"S6.p3.1.1\" class=\"ltx_text ltx_font_bold\">Identity Authentication Frameworks.</span> Identity authentication frameworks, serving as fundamental infrastructure for trusted agent collaboration, have achieved significant advancements. Contemporary frameworks predominantly build upon OAuth 2.0 <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib16\" title=\"\" class=\"ltx_ref\">Hardt (2012)</a></cite> and OpenID Connect <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib17\" title=\"\" class=\"ltx_ref\">Sakimura et al. (2014)</a></cite>. While OAuth 2.0’s Client Credentials flow theoretically enables agent authentication, its implementation reveals substantial limitations: the client_id mechanism lacks cross-platform universality, and existing ID Tokens exclusively identify human users while Access Tokens fail to encapsulate agent capabilities. To address these limitations, South et al. <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib22\" title=\"\" class=\"ltx_ref\">South et al. (2025)</a></cite> proposed the Authenticated Delegation framework, extending OAuth 2.0 and OpenID Connect with Agent-ID Tokens incorporating unique agent identifiers, capability manifests, and delegation metadata. However, this approach faces three key limitations: centralization dependencies limiting cross-domain agent identification; domain boundaries restricting system integration; and security vulnerabilities arising from centralized identity data management creating single points of failure. Moreover, these traditional frameworks fundamentally rely on key-based authentication, where identity is proven by possession of a private key rather than the integrity of the executing code. This creates a semantic gap for autonomous agents: proving “who holds the key” does not guarantee “what code is running,” leaving systems vulnerable to code substitution attacks where malicious agents generate valid signatures. While emerging Verifiable Computation paradigms, particularly Zero-Knowledge Virtual Machines (zkVM) and zkTLS, offer theoretical foundations for code-level authentication and communication provenance, they have yet to be integrated into a unified, practical agent identity framework that simultaneously ensures execution integrity and privacy.</p>\n</div>\n<div id=\"S6.p4\" class=\"ltx_para\">\n<p id=\"S6.p4.1\" class=\"ltx_p\"><span id=\"S6.p4.1.1\" class=\"ltx_text ltx_font_bold\">Agent Identity Management Systems.</span> Academic research has produced several groundbreaking approaches to agent identity management, which can be categorized into foundational identity infrastructures and decentralized trust frameworks. In the first category, Chan et al. <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib18\" title=\"\" class=\"ltx_ref\">Chan et al. (2024)</a></cite> pioneered the conceptual framework for AI system identity markers, creating criteria for accessibility and verifiability. This was further operationalized by Huang et al. with the Agent Name Service (ANS) <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib21\" title=\"\" class=\"ltx_ref\">Huang et al. (2025)</a></cite>, which implements unified registration and resolution through DNS-style naming and PKI. Advancing this further, Raskar et al. <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib20\" title=\"\" class=\"ltx_ref\">Raskar et al. (2025a)</a></cite> proposed hybrid indexing approaches that integrate with existing DNS/PKI, leading to the NANDA (Beyond DNS) <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib19\" title=\"\" class=\"ltx_ref\">Raskar et al. (2025b)</a></cite> framework. NANDA combines a global Core Index with a verifiable AgentFact framework to enable trusted discovery.</p>\n</div>\n<div id=\"S6.p5\" class=\"ltx_para\">\n<p id=\"S6.p5.1\" class=\"ltx_p\">Complementing these foundational layers, emerging decentralized trust frameworks address the specifics of agent autonomy and ethics. The LOKA protocol <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">ranjan2025loka</span></cite> serves as a decentralized identity framework specifically targeting accountability and ethical consistency, implementing a blockchain-based trust layer to govern agent interactions. Similarly, ERC-8004 <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">erc8004</span></cite> introduces “Trustless Agents” via an on-chain validation registry, allowing agents to submit verifiable proofs of their work. However, while these systems successfully implement technical registration and discovery mechanisms, they predominantly focus on “agent-to-system” trust—verifying that the agent is a technically valid and recognizable entity within the network. They largely overlook the critical “human-to-agent” liability binding—cryptographically anchoring the agent’s actions to a specific natural person to ensure legal accountability. This omission makes it difficult to establish the comprehensive responsibility chains necessary for autonomous deployment.</p>\n</div>\n<div id=\"S6.p6\" class=\"ltx_para\">\n<p id=\"S6.p6.1\" class=\"ltx_p\">To address these critical gaps, we propose the BAID (Binding Agent ID) framework, which implements an innovative dual-mechanism approach combining local binding and on-chain identity verification. This comprehensive solution not only bridges the technical gaps in responsibility binding but also establishes a robust foundation for secure AI agent operations in complex social collaboration environments. Our framework represents a significant advancement in reconciling technical identification requirements with legal traceability demands, offering a practical path forward for responsible AI agent deployment.</p>\n</div>\n</section>\n<section id=\"S7\" class=\"ltx_section\">\n<h2 class=\"ltx_title ltx_title_section\"><span class=\"ltx_tag ltx_tag_section\">7 </span>Conclusion</h2>\n\n<div id=\"S7.p1\" class=\"ltx_para\">\n<p id=\"S7.p1.1\" class=\"ltx_p\">This paper presents BAID (Binding Agent ID), a comprehensive identity infrastructure addressing the fundamental challenge of autonomous AI agents: the absence of traceable and accountable responsibility chains. BAID implements the Binding Agent Model through three integrated mechanisms: (1) local binding via biometric authentication ensures agents serve only their designated owners, preventing command injection attacks; (2) on-chain identity registration via blockchain smart contracts enables trusted agent discovery and establishes publicly auditable user-agent binding declarations; (3) zkVM-based authentication protocol provides cryptographic guarantees for operator identity verification, agent configuration integrity, and complete execution provenance through recursive proof composition. This unified framework addresses the five critical security requirements identified in cross-organizational agent interactions: user identity verification, trusted discovery, mutual authentication, permission control, and accountability tracking. Our implementation and evaluation demonstrate practical deployability: blockchain identity management achieves viable gas consumption for real-world Ethereum deployment, while zkVM authentication exhibits millisecond-level verification latency suitable for security-prioritized scenarios despite proof generation overhead. Future work should address performance optimization to enable broader adoption beyond specialized high-security use cases.</p>\n</div>\n</section>\n<section id=\"bib\" class=\"ltx_bibliography\">\n<h2 class=\"ltx_title ltx_title_bibliography\">References</h2>\n\n<ul id=\"bib.L1\" class=\"ltx_biblist\">\n<li id=\"bib.bib27\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Agent2Agent Protocol Specification Authors (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Agent2Agent Protocol Specification Authors</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent2Agent (a2a) protocol specification</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/google/A2A\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/google/A2A</a>accessed: 2025-10-31</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p2.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib8\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Anil <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Anil, E. Durmus, N. Rimsky, M. Sharma, J. Benton, S. Kundu, J. Batson, M. Tong, J. Mu, D. J. Ford, F. Mosconi, R. Agrawal, R. Schaeffer, N. Bashkansky, S. Svenningsen, M. Lambert, A. Radhakrishnan, C. Denison, E. J. Hubinger, Y. Bai, T. Bricken, T. Maxwell, N. Schiefer, J. Sully, A. Tamkin, T. Lanham, K. Nguyen, T. Korbak, J. Kaplan, D. Ganguli, S. R. Bowman, E. Perez, R. B. Grosse, and D. Duvenaud</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Many-shot jailbreaking</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">NeurIPS 2024</span>,\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">(OpenReview preprint)</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib28\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Anthropic (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Anthropic</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Model context protocol (mcp)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://www.anthropic.com/news/model-context-protocol\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://www.anthropic.com/news/model-context-protocol</a>accessed: 2025-10-31</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p2.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib34\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Buterin (2014)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">V. Buterin</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Ethereum: a next-generation smart contract and decentralized application platform</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://ethereum.org/en/whitepaper\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://ethereum.org/en/whitepaper</a>accessed: 2025-11-18</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Blockchain ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib18\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Chan <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Chan, N. Kolt, P. Wills, U. Anwar, C. Schroeder de Witt, N. Rajkumar, L. Hammond, D. Krueger, L. Heim, and M. Anderljung</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">IDs for ai systems</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2406.12137</span>,\n<a href=\"https://dx.doi.org/10.48550/arXiv.2406.12137\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a>,\n<a href=\"https://arxiv.org/abs/2406.12137\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#A2.SS2.SSS4.p2.1\" title=\"B.2.4 Defense Against Sybil and Impersonation Attacks ‣ B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§B.2.4</span></a>,\n<a href=\"#S1.SS2.p4.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>,\n<a href=\"#S6.p4.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib24\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Chan <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2023)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Chan, R. Salganik, A. Markelius, C. Pang, N. Rajkumar, D. Krasheninnikov, L. Langosco, Z. He, Y. Duan, M. Carroll, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Harms from increasingly agentic algorithmic systems</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency</span>,\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_pages\">pp. 651–666</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib11\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Chen and Parker (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">C. Chen and L. Parker</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Composable contracts for multi-agent coordination</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">Agentic Markets Workshop at ICML 2024</span>,\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Workshop (Poster)</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://openreview.net/forum?id=hq0lZ9u68G\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib23\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Goldwasser <span class=\"ltx_text ltx_bib_etal\">et al.</span> (1985)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Goldwasser, S. Micali, and C. Rackoff</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The knowledge complexity of interactive proof systems</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">STOC ’85</span>,\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_pages\">pp. 291–304</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.1145/22145.22178\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS2.p1.1\" title=\"2.2 Zero-Knowledge Virtual Machine ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.2</span></a>.\n</span></li>\n<li id=\"bib.bib13\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Guo <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">T. Guo, X. Chen, Y. Wang, R. Chang, S. Pei, N. V. Chawla, O. Wiest, and X. Zhang</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Large language model based multi-agents: a survey of progress and challenges</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2402.01680</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib16\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Hardt (2012)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">D. Hardt</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The oauth 2.0 authorization framework</span>.\n</span>\n<span class=\"ltx_bibblock\"> <span class=\"ltx_text ltx_bib_publisher\">Internet Engineering Task Force</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">RFC 6749Section 4.4: Client Credentials Grant</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.rfc-editor.org/rfc/rfc6749\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a>,\n<a href=\"https://dx.doi.org/10.17487/RFC6749\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p3.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib21\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Huang <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Huang, V. S. Narajala, I. Habler, and A. Sheriff</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Agent name service (ans): a universal directory for secure ai agent discovery and interoperability</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2505.10609</span>,\n<a href=\"https://dx.doi.org/10.48550/arXiv.2505.10609\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a>,\n<a href=\"https://arxiv.org/abs/2505.10609\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p4.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>,\n<a href=\"#S6.p4.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib5\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Huang <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Huang, D. Siddarth, L. Lovitt, T. I. Liao, E. Durmus, A. Tamkin, and D. Ganguli</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Collective constitutional AI: aligning a language model with public input</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency (FAccT ’24)</span>,\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_pages\">pp. 1395–1417</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.1145/3630106.3658979\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib4\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Kirk <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">H. R. Kirk, A. Whitefield, P. R”ottger, A. Bean, K. Margatina, J. Ciro, R. Mosquera, M. Bartolo, A. Williams, H. He, B. Vidgen, and S. A. Hale</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The prism alignment project: what participatory, representative and individualised human feedback reveals about the subjective and multicultural alignment of large language models</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2404.16019</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib15\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">LF AI &amp; Data Foundation (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">LF AI &amp; Data Foundation</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">ACP joins forces with a2a under the linux foundation</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Community blogAccessed: 2025-09-24</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://lfaidata.foundation/communityblog/2025/08/29/acp-joins-forces-with-a2a-under-the-linux-foundations-lf-ai-data/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p2.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib29\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Model Context Protocol Specification Authors (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Model Context Protocol Specification Authors</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Model context protocol (mcp) specification</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://modelcontextprotocol.io/specification/2025-03-26\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://modelcontextprotocol.io/specification/2025-03-26</a>accessed: 2025-10-31</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p2.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib33\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Nakamoto (2008)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">S. Nakamoto</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Bitcoin: a peer-to-peer electronic cash system</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://bitcoin.org/bitcoin.pdf\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://bitcoin.org/bitcoin.pdf</a>accessed: 2025-11-18</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS1.p1.1\" title=\"2.1 Blockchain ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.1</span></a>.\n</span></li>\n<li id=\"bib.bib32\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Nomic Foundation (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Nomic Foundation</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Hardhat: ethereum development environment for professionals</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/NomicFoundation/hardhat\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/NomicFoundation/hardhat</a>accessed: 2025-11-08</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S5.SS1.p1.1\" title=\"5.1 Identity Management Smart Contracts Performance ‣ 5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.1</span></a>.\n</span></li>\n<li id=\"bib.bib6\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">OpenAI (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">OpenAI</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Model Spec</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://cdn.openai.com/spec/model-spec-2024-05-08.html\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://cdn.openai.com/spec/model-spec-2024-05-08.html</a>Accessed: 2024-09</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib37\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Pauwels (2021)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. Pauwels</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">zkKYC: a solution concept for KYC without knowing your customer, leveraging self-sovereign identity and zero-knowledge proofs</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Cryptology ePrint Archive, Paper 2021/907accessed: 2025-11-18</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://eprint.iacr.org/2021/907\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#A2.SS2.SSS4.p2.1\" title=\"B.2.4 Defense Against Sybil and Impersonation Attacks ‣ B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§B.2.4</span></a>,\n<a href=\"#S2.SS3.p2.1\" title=\"2.3 Verifiable Credentials ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib20\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Raskar <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025a)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">R. Raskar, P. Chari, J. J. Grogan, M. Lambe, R. Lincourt, R. Bala, A. Joshi, A. Singh, A. Chopra, R. Ranjan, S. Gupta, D. Stripelis, M. Gorskikh, and S. Wang</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Upgrade or switch: do we need a next-gen trusted architecture for the internet of ai agents?</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2506.12003</span>,\n<a href=\"https://arxiv.org/abs/2506.12003\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p4.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>,\n<a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>,\n<a href=\"#S6.p4.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib19\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Raskar <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025b)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">R. Raskar, P. Chari, J. Zinky, M. Lambe, J. J. Grogan, S. Wang, R. Ranjan, R. Singhal, S. Gupta, R. Lincourt, R. Bala, A. Joshi, A. Singh, A. Chopra, D. Stripelis, B. B, S. Kumar, and M. Gorskikh</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Beyond dns: unlocking the internet of ai agents via the nanda index and verified agentfacts</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><span class=\"ltx_text ltx_bib_external\">2507.14263</span>,\n<a href=\"https://arxiv.org/abs/2507.14263\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p4.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>,\n<a href=\"#S4.SS2.SSS1.p4.1\" title=\"4.2.1 Identity Management Smart Contract Framework ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.2.1</span></a>,\n<a href=\"#S6.p4.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib31\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">RISC Zero (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">RISC Zero</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">RISC zero: a zero-knowledge verifiable general computing platform based on zk-starks and the risc-v microarchitecture</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://github.com/risc0/risc0\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://github.com/risc0/risc0</a>accessed: 2025-11-08</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#A2.SS2.SSS1.p2.1\" title=\"B.2.1 Defense Against Code Substitution Attacks ‣ B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§B.2.1</span></a>,\n<a href=\"#A2.SS2.SSS2.p2.1\" title=\"B.2.2 Defense Against Replay and Reordering Attacks ‣ B.2 Security Properties and Defenses ‣ Appendix B Security Analysis ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§B.2.2</span></a>,\n<a href=\"#S5.SS2.p1.1\" title=\"5.2 Verifiable Agent System Performance ‣ 5 Implementation and Performance Evaluation ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§5.2</span></a>.\n</span></li>\n<li id=\"bib.bib17\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Sakimura <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2014)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">N. Sakimura, J. Bradley, M. Jones, B. de Medeiros, and C. Mortimore</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">OpenID connect core 1.0 (incorporating errata set 1)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">OpenID Foundation SpecificationOriginal publication: 26 Feb 2014; updated with Errata Set 1 Nov 2014</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://openid.net/specs/openid-connect-core-1_0.html\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p3.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib30\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Schmid (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. Schmid</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">MCP introduction</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\"><a href=\"https://www.philschmid.de/mcp-introduction\" title=\"\" class=\"ltx_ref ltx_url ltx_font_typewriter\">https://www.philschmid.de/mcp-introduction</a>accessed: 2025-10-31</span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p2.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib22\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">South <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">T. South, S. Marro, T. Hardjono, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Authenticated delegation and authorized ai agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2501.09674</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p3.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib35\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Sporny <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2022)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">M. Sporny, A. Guy, M. Sabadello, and D. Reed</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Decentralized identifiers (dids) v1.0</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">W3C Recommendationaccessed: 2025-11-18</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.w3.org/TR/did-core/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p1.1\" title=\"2.3 Verifiable Credentials ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib36\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Sporny <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">M. Sporny <span class=\"ltx_text ltx_bib_etal\">et al.</span></span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Verifiable credentials data model v2.0</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">W3C Recommendationaccessed: 2025-11-18</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://www.w3.org/TR/vc-data-model-2.0/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S2.SS3.p1.1\" title=\"2.3 Verifiable Credentials ‣ 2 Technical Preliminaries ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§2.3</span></a>.\n</span></li>\n<li id=\"bib.bib26\" class=\"ltx_bibitem ltx_bib_misc\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Surapaneni <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">R. Surapaneni, M. Jha, M. Vakoc, and T. Segal</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Announcing the agent2agent protocol (a2a)</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Google for Developers Blogaccessed: 2025-10-31</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S6.p2.1\" title=\"6 Related Work ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§6</span></a>.\n</span></li>\n<li id=\"bib.bib12\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Tran <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">K. Tran, D. Dao, M. Nguyen, Q. Pham, B. O’Sullivan, and H. D. Nguyen</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Multi-agent collaboration mechanisms: a survey of llms</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2501.06322</span>.\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://arxiv.org/abs/2501.06322\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib2\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Verma (2023a)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. Verma</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The rise of ai fake news is creating a ’misinformation superspreader’</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Washington Post</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib3\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Verma (2023b)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">P. Verma</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">They thought loved ones were calling for help. it was an ai scam</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Washington Post</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib9\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Wallace <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">E. Wallace, K. Xiao, R. Leike, L. Weng, J. Heidecke, and A. Beutel</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The instruction hierarchy: training llms to prioritize privileged instructions</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2404.13208</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib1\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Wang <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024a)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">L. Wang, C. Ma, X. Feng, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A survey on large language model based autonomous agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Frontiers of Computer Science</span> <span class=\"ltx_text ltx_bib_volume\">18</span> (<span class=\"ltx_text ltx_bib_number\">6</span>), <span class=\"ltx_text ltx_bib_pages\">pp. 186345</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib25\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Wang <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024b)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">L. Wang, C. Ma, X. Feng, Z. Zhang, H. Yang, J. Zhang, Z. Chen, J. Tang, X. Chen, Y. Lin, <span class=\"ltx_text ltx_bib_etal\">et al.</span></span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">A survey on large language model based autonomous agents</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Frontiers of Computer Science</span> <span class=\"ltx_text ltx_bib_volume\">18</span> (<span class=\"ltx_text ltx_bib_number\">6</span>), <span class=\"ltx_text ltx_bib_pages\">pp. 186345</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S4.SS1.SSS1.p1.1\" title=\"4.1.1 Agent Architecture ‣ 4.1 Local User-Agent Binding via Biometric Authentication ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§4.1.1</span></a>.\n</span></li>\n<li id=\"bib.bib14\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Xi <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2025)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">Z. Xi, W. Chen, X. Guo, W. He, Y. Ding, B. Hong, M. Zhang, J. Wang, S. Jin, E. Zhou, R. Zheng, X. Fan, X. Wang, L. Xiong, Y. Zhou, W. Wang, C. Jiang, Y. Zou, X. Liu, Z. Yin, S. Dou, R. Weng, W. Qin, Y. Zheng, X. Qiu, X. Huang, Q. Zhang, and T. Gui</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">The rise and potential of large language model based agents: a survey</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">Science China Information Sciences</span> <span class=\"ltx_text ltx_bib_volume\">68</span>, <span class=\"ltx_text ltx_bib_pages\">pp. 121101</span>.\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Review article</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://dx.doi.org/10.1007/s11432-024-4222-0\" title=\"\" class=\"ltx_ref doi ltx_bib_external\">Document</a>,\n<a href=\"https://link.springer.com/article/10.1007/s11432-024-4222-0\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.p1.1\" title=\"1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1</span></a>.\n</span></li>\n<li id=\"bib.bib10\" class=\"ltx_bibitem ltx_bib_inproceedings\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Yan <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">F. Yan, Q. J. Hu, N. Jiang, and X. Sun</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Get it cooperating: enhancing generative agent cooperation with commitment devices</span>.\n</span>\n<span class=\"ltx_bibblock\">In <span class=\"ltx_text ltx_bib_inbook\">Agentic Markets Workshop at ICML 2024</span>,\n</span>\n<span class=\"ltx_bibblock\">Note: <span class=\"ltx_text ltx_bib_note\">Workshop (Oral)</span>\n</span>\n<span class=\"ltx_bibblock\">External Links: <span class=\"ltx_text ltx_bib_links\"><a href=\"https://openreview.net/forum?id=J39bW48ipI\" title=\"\" class=\"ltx_ref ltx_bib_external\">Link</a></span>\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n<li id=\"bib.bib7\" class=\"ltx_bibitem ltx_bib_article\"><span class=\"ltx_tag ltx_bib_author-year ltx_role_refnum ltx_tag_bibitem\">Zou <span class=\"ltx_text ltx_bib_etal\">et al.</span> (2024)</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_author\">A. Zou, L. Phan, J. Wang, D. Duenas, M. Lin, M. Andriushchenko, R. Wang, Z. Kolter, M. Fredrikson, and D. Hendrycks</span>\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_title\">Improving alignment and robustness with circuit breakers</span>.\n</span>\n<span class=\"ltx_bibblock\"><span class=\"ltx_text ltx_bib_journal\">arXiv preprint arXiv:2406.04313</span>.\n</span>\n<span class=\"ltx_bibblock ltx_bib_cited\">Cited by: <a href=\"#S1.SS2.p1.1\" title=\"1.2 The Gap: Autonomous Capabilities Without Identity Infrastructure ‣ 1 Introduction ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">§1.2</span></a>.\n</span></li>\n</ul>\n</section>\n<section id=\"A1\" class=\"ltx_appendix\">\n<h2 class=\"ltx_title ltx_title_appendix\"><span class=\"ltx_tag ltx_tag_appendix\">Appendix A </span>zkVM-based Authentication Protocol Technical Specifications</h2>\n\n<div id=\"A1.p1\" class=\"ltx_para\">\n<p id=\"A1.p1.1\" class=\"ltx_p\">This appendix provides comprehensive technical specifications for the zkVM-based verifiable computation protocol that establishes cryptographic guarantees for agent identity integrity, operator authentication, and execution provenance. The protocol addresses the fundamental challenge in autonomous AI systems—ensuring the correct agent is used by the correct user in the correct manner—thereby constructing an end-to-end trust chain from identity validation to execution auditing.</p>\n</div>\n<section id=\"A1.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">A.1 </span>Limitations of Key-Based Authentication</h3>\n\n<div id=\"A1.SS1.p1\" class=\"ltx_para\">\n<p id=\"A1.SS1.p1.1\" class=\"ltx_p\">Traditional software authentication relies on digital signature schemes where possession of private key <math id=\"A1.SS1.p1.m1\" class=\"ltx_Math\" alttext=\"sk\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>s</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><annotation encoding=\"application/x-tex\">sk</annotation></semantics></math> enables signing operations that prove ownership. While effective for human-controlled systems, this paradigm exhibits a critical vulnerability when applied to autonomous agents: key compromise enables arbitrary code substitution.</p>\n</div>\n<div id=\"A1.SS1.p2\" class=\"ltx_para\">\n<p id=\"A1.SS1.p2.1\" class=\"ltx_p\">An adversary obtaining the agent’s signing key <math id=\"A1.SS1.p2.m1\" class=\"ltx_Math\" alttext=\"sk\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>s</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><annotation encoding=\"application/x-tex\">sk</annotation></semantics></math> can: (1) execute malicious code <math id=\"A1.SS1.p2.m2\" class=\"ltx_Math\" alttext=\"P_{\\text{malicious}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>malicious</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{malicious}}</annotation></semantics></math> instead of legitimate program <math id=\"A1.SS1.p2.m3\" class=\"ltx_Math\" alttext=\"P_{\\text{legitimate}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>legitimate</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{legitimate}}</annotation></semantics></math>; (2) generate valid signatures <math id=\"A1.SS1.p2.m4\" class=\"ltx_Math\" alttext=\"\\sigma=\\text{Sign}_{sk}(\\text{output})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>σ</mi><mo>=</mo><mrow><msub><mtext>Sign</mtext><mrow><mi>s</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mtext>output</mtext><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\sigma=\\text{Sign}_{sk}(\\text{output})</annotation></semantics></math> over malicious outputs; (3) present outputs as originating from the legitimate agent. Verification <math id=\"A1.SS1.p2.m5\" class=\"ltx_Math\" alttext=\"\\text{Verify}_{pk}(\\text{output},\\sigma)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mtext>Verify</mtext><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mtext>output</mtext><mo>,</mo><mi>σ</mi><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{Verify}_{pk}(\\text{output},\\sigma)</annotation></semantics></math> succeeds, yet computation violates intended behavior, breaking the assumption that cryptographic authenticity implies behavioral integrity.</p>\n</div>\n<div id=\"A1.SS1.p3\" class=\"ltx_para\">\n<p id=\"A1.SS1.p3.1\" class=\"ltx_p\">Unlike human users, software agents lack physical embodiment amenable to conventional biometric authentication. The agent’s identity is inherently tied to its computational behavior—the code it executes. Traditional authentication verifies the credential holder, not the executing code, creating a semantic gap between “who holds the key” and “what code is running.”</p>\n</div>\n</section>\n<section id=\"A1.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">A.2 </span>Code-Level Authentication</h3>\n\n<div id=\"A1.SS2.p1\" class=\"ltx_para\">\n<p id=\"A1.SS2.p1.1\" class=\"ltx_p\">We introduce code-level authentication, a cryptographic identity model where the program binary serves as the agent’s unique identity marker, shifting authentication from key-based ownership proofs to code-based execution verification.</p>\n</div>\n<div id=\"A1.SS2.p2\" class=\"ltx_para\">\n<p id=\"A1.SS2.p2.1\" class=\"ltx_p\">Based on the zkVM five-tuple from Section 2:</p>\n<table id=\"A1.Ex3\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex3.m1\" class=\"ltx_Math\" alttext=\"\\Pi=(\\text{Setup},\\text{CommitProg},\\text{Compile},\\text{Prove},\\text{Verify}),\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mi mathvariant=\"normal\">Π</mi><mo>=</mo><mrow><mo stretchy=\"false\">(</mo><mtext>Setup</mtext><mo>,</mo><mtext>CommitProg</mtext><mo>,</mo><mtext>Compile</mtext><mo>,</mo><mtext>Prove</mtext><mo>,</mo><mtext>Verify</mtext><mo stretchy=\"false\">)</mo></mrow></mrow><mo>,</mo></mrow><annotation encoding=\"application/x-tex\">\\Pi=(\\text{Setup},\\text{CommitProg},\\text{Compile},\\text{Prove},\\text{Verify}),</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n</div>\n<div id=\"A1.SS2.p3\" class=\"ltx_para\">\n<p id=\"A1.SS2.p3.1\" class=\"ltx_p\"><span id=\"A1.SS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">Definition 1 (Execution Integrity Relation).</span> The protocol proves:</p>\n<table id=\"A1.E4\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.E4.m1\" class=\"ltx_Math\" alttext=\"\\begin{split}\\mathcal{R}_{\\text{exec}}=\\{(P,x_{pub},x_{prv},y):P(x_{pub},x_{prv})=y\\\\\n\\land\\text{CommitProg}(P)=C_{P}\\}\\end{split}\" display=\"block\" intent=\":literal\"><semantics><mtable displaystyle=\"true\" rowspacing=\"0pt\"><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mi class=\"ltx_font_mathcaligraphic\">ℛ</mi><msub><mrow></mrow><mtext>exec</mtext></msub><mo>=</mo><mo stretchy=\"false\">{</mo><mo stretchy=\"false\">(</mo><mi>P</mi><mo>,</mo><mi>x</mi><msub><mrow></mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><mi>x</mi><msub><mrow></mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><mo>,</mo><mi>y</mi><mo rspace=\"0.278em\" stretchy=\"false\">)</mo><mo rspace=\"0.278em\">:</mo><mi>P</mi><mo stretchy=\"false\">(</mo><mi>x</mi><msub><mrow></mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><mi>x</mi><msub><mrow></mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><mo stretchy=\"false\">)</mo><mo>=</mo><mi>y</mi></mrow></mtd></mtr><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mo>∧</mo><mtext>CommitProg</mtext><mo stretchy=\"false\">(</mo><mi>P</mi><mo stretchy=\"false\">)</mo><mo>=</mo><mi>C</mi><msub><mrow></mrow><mi>P</mi></msub><mo stretchy=\"false\">}</mo></mrow></mtd></mtr></mtable><annotation encoding=\"application/x-tex\">\\begin{split}\\mathcal{R}_{\\text{exec}}=\\{(P,x_{pub},x_{prv},y):P(x_{pub},x_{prv})=y\\\\\n\\land\\text{CommitProg}(P)=C_{P}\\}\\end{split}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(4)</span></td></tr></tbody>\n</table>\n<p id=\"A1.SS2.p3.2\" class=\"ltx_p\">where <math id=\"A1.SS2.p3.m1\" class=\"ltx_Math\" alttext=\"P\" display=\"inline\" intent=\":literal\"><semantics><mi>P</mi><annotation encoding=\"application/x-tex\">P</annotation></semantics></math> is the agent program, <math id=\"A1.SS2.p3.m2\" class=\"ltx_Math\" alttext=\"x_{pub}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub}</annotation></semantics></math> are public inputs,\n<math id=\"A1.SS2.p3.m3\" class=\"ltx_Math\" alttext=\"x_{prv}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{prv}</annotation></semantics></math> are private inputs, and <math id=\"A1.SS2.p3.m4\" class=\"ltx_Math\" alttext=\"y\" display=\"inline\" intent=\":literal\"><semantics><mi>y</mi><annotation encoding=\"application/x-tex\">y</annotation></semantics></math> is the public output.</p>\n</div>\n<div id=\"A1.SS2.p4\" class=\"ltx_para\">\n<p id=\"A1.SS2.p4.1\" class=\"ltx_p\"><span id=\"A1.SS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Property 1 (Code Substitution Resistance).</span> Any modification to <math id=\"A1.SS2.p4.m1\" class=\"ltx_Math\" alttext=\"P\" display=\"inline\" intent=\":literal\"><semantics><mi>P</mi><annotation encoding=\"application/x-tex\">P</annotation></semantics></math> yields\n<math id=\"A1.SS2.p4.m2\" class=\"ltx_Math\" alttext=\"\\text{CommitProg}(P^{\\prime})\\neq C_{P}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mtext>CommitProg</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><msup><mi>P</mi><mo>′</mo></msup><mo stretchy=\"false\">)</mo></mrow></mrow><mo>≠</mo><msub><mi>C</mi><mi>P</mi></msub></mrow><annotation encoding=\"application/x-tex\">\\text{CommitProg}(P^{\\prime})\\neq C_{P}</annotation></semantics></math>, causing proof construction to fail during zkVM constraint verification.</p>\n</div>\n<div id=\"A1.SS2.p5\" class=\"ltx_para\">\n<p id=\"A1.SS2.p5.1\" class=\"ltx_p\"><span id=\"A1.SS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Security Framework.</span> The security framework of zkVM encompasses three fundamental guarantees:</p>\n<ul id=\"A1.I1\" class=\"ltx_itemize\">\n<li id=\"A1.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"A1.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Completeness:</span> For any valid statement, an honest prover can consistently generate proofs that are accepted by the verification algorithm with probability 1.</p>\n</div></li>\n<li id=\"A1.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"A1.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Soundness:</span> For any invalid statement, no computationally bounded adversarial prover can generate an accepting proof, except with negligible probability in the security parameter. The verification algorithm systematically rejects proofs of false statements.</p>\n</div></li>\n<li id=\"A1.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"A1.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Zero-Knowledge:</span> For any valid statement, the proof reveals no information beyond its validity. Specifically, the verifier gains no computational advantage in deriving any additional knowledge about the private inputs or intermediate computation states.</p>\n</div></li>\n</ul>\n</div>\n</section>\n<section id=\"A1.SS3\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">A.3 </span>zkVM-Based Agent Authentication Protocol Workflow</h3>\n\n<div id=\"A1.SS3.p1\" class=\"ltx_para\">\n<p id=\"A1.SS3.p1.1\" class=\"ltx_p\">The protocol workflow comprises four phases:</p>\n</div>\n<div id=\"A1.SS3.p2\" class=\"ltx_para\">\n<p id=\"A1.SS3.p2.1\" class=\"ltx_p\"><span id=\"A1.SS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">Initialization:</span> <math id=\"A1.SS3.p2.m1\" class=\"ltx_Math\" alttext=\"(pp,vk)\\leftarrow\\text{Setup}(1^{\\lambda},param)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mo stretchy=\"false\">(</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo stretchy=\"false\">)</mo></mrow><mo stretchy=\"false\">←</mo><mrow><mtext>Setup</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><msup><mn>1</mn><mi>λ</mi></msup><mo>,</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>a</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>m</mi></mrow><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">(pp,vk)\\leftarrow\\text{Setup}(1^{\\lambda},param)</annotation></semantics></math> generates system parameters.</p>\n</div>\n<div id=\"A1.SS3.p3\" class=\"ltx_para\">\n<p id=\"A1.SS3.p3.1\" class=\"ltx_p\"><span id=\"A1.SS3.p3.1.1\" class=\"ltx_text ltx_font_bold\">Registration:</span> Compile agent code to obtain</p>\n<table id=\"A1.Ex4\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex4.m1\" class=\"ltx_Math\" alttext=\"(\\text{ArithDesc},\\text{MapIO})\\leftarrow\\text{Compile}(pp,P);\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mrow><mo stretchy=\"false\">(</mo><mtext>ArithDesc</mtext><mo>,</mo><mtext>MapIO</mtext><mo stretchy=\"false\">)</mo></mrow><mo stretchy=\"false\">←</mo><mrow><mtext>Compile</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><mo>;</mo></mrow><annotation encoding=\"application/x-tex\">(\\text{ArithDesc},\\text{MapIO})\\leftarrow\\text{Compile}(pp,P);</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.SS3.p3.2\" class=\"ltx_p\">generate commitment</p>\n<table id=\"A1.Ex5\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex5.m1\" class=\"ltx_Math\" alttext=\"C_{P}\\leftarrow\\text{CommitProg}(P);\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><msub><mi>C</mi><mi>P</mi></msub><mo stretchy=\"false\">←</mo><mrow><mtext>CommitProg</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><mo>;</mo></mrow><annotation encoding=\"application/x-tex\">C_{P}\\leftarrow\\text{CommitProg}(P);</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.SS3.p3.3\" class=\"ltx_p\">construct <math id=\"A1.SS3.p3.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> following Equation (<a href=\"#S4.E1\" title=\"In 4.2.2 On-Chain Identity Registration and Binding Workflow ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a>); anchor <math id=\"A1.SS3.p3.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> to blockchain smart contract.</p>\n</div>\n<div id=\"A1.SS3.p4\" class=\"ltx_para\">\n<p id=\"A1.SS3.p4.1\" class=\"ltx_p\"><span id=\"A1.SS3.p4.1.1\" class=\"ltx_text ltx_font_bold\">Execution:</span> For each step <math id=\"A1.SS3.p4.m1\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi>k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math>, generate proof\n<math id=\"A1.SS3.p4.m2\" class=\"ltx_Math\" alttext=\"\\pi_{k}\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc},\\text{MapIO},x_{pub},x_{prv},y)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>π</mi><mi>k</mi></msub><mo stretchy=\"false\">←</mo><mrow><mtext>Prove</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><mtext>ArithDesc</mtext><mo>,</mo><mtext>MapIO</mtext><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><mo>,</mo><mi>y</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\pi_{k}\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc},\\text{MapIO},x_{pub},x_{prv},y)</annotation></semantics></math>\nwhere execution trace <math id=\"A1.SS3.p4.m3\" class=\"ltx_Math\" alttext=\"\\text{Trace}(P,x_{pub},x_{prv})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mtext>Trace</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{Trace}(P,x_{pub},x_{prv})</annotation></semantics></math> is validated through constraint templates.</p>\n</div>\n<div id=\"A1.SS3.p5\" class=\"ltx_para\">\n<p id=\"A1.SS3.p5.1\" class=\"ltx_p\"><span id=\"A1.SS3.p5.1.1\" class=\"ltx_text ltx_font_bold\">Verification:</span> Compute <math id=\"A1.SS3.p5.m1\" class=\"ltx_Math\" alttext=\"b\\leftarrow\\text{Verify}(vk,C_{P},x_{pub},y,\\pi)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>b</mi><mo stretchy=\"false\">←</mo><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><mi>y</mi><mo>,</mo><mi>π</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">b\\leftarrow\\text{Verify}(vk,C_{P},x_{pub},y,\\pi)</annotation></semantics></math>,\nconfirming proof validity and code commitment <math id=\"A1.SS3.p5.m2\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math> matches the registered <math id=\"A1.SS3.p5.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> value.</p>\n</div>\n</section>\n<section id=\"A1.SS4\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">A.4 </span>Execution Continuity Across Conversational Turns</h3>\n\n<section id=\"A1.SS4.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.4.1 </span>Problem Statement</h4>\n\n<div id=\"A1.SS4.SSS1.p1\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS1.p1.1\" class=\"ltx_p\">LLM-based agents operate through conversational state transitions involving user input reception,\nremote LLM API invocation, tool execution, and state updates.\nA fundamental zkVM constraint is that while individual proofs can certify that a computation\ncorrectly transforms a given input to its output, they do not verify the provenance of inputs.</p>\n</div>\n<div id=\"A1.SS4.SSS1.p2\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS1.p2.1\" class=\"ltx_p\">Given execution sequence:</p>\n<table id=\"A1.E5\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.E5.m1\" class=\"ltx_Math\" alttext=\"S_{0}\\xrightarrow{a_{1},f_{1}}S_{1}\\xrightarrow{a_{2},f_{2}}S_{2}\\xrightarrow{a_{3},f_{3}}\\cdots\\xrightarrow{a_{n},f_{n}}S_{n}\" display=\"block\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mover accent=\"true\"><mo>→</mo><mrow><msub><mi mathsize=\"0.700em\">a</mi><mn mathsize=\"0.710em\">1</mn></msub><mo mathsize=\"0.700em\">,</mo><msub><mi mathsize=\"0.700em\">f</mi><mn mathsize=\"0.710em\">1</mn></msub></mrow></mover><msub><mi>S</mi><mn>1</mn></msub><mover accent=\"true\"><mo>→</mo><mrow><msub><mi mathsize=\"0.700em\">a</mi><mn mathsize=\"0.710em\">2</mn></msub><mo mathsize=\"0.700em\">,</mo><msub><mi mathsize=\"0.700em\">f</mi><mn mathsize=\"0.710em\">2</mn></msub></mrow></mover><msub><mi>S</mi><mn>2</mn></msub><mover accent=\"true\"><mo rspace=\"0.1389em\">→</mo><mrow><msub><mi mathsize=\"0.700em\">a</mi><mn mathsize=\"0.710em\">3</mn></msub><mo mathsize=\"0.700em\">,</mo><msub><mi mathsize=\"0.700em\">f</mi><mn mathsize=\"0.710em\">3</mn></msub></mrow></mover><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mover accent=\"true\"><mo lspace=\"0.1389em\">→</mo><mrow><msub><mi mathsize=\"0.700em\">a</mi><mi mathsize=\"0.710em\">n</mi></msub><mo mathsize=\"0.700em\">,</mo><msub><mi mathsize=\"0.700em\">f</mi><mi mathsize=\"0.710em\">n</mi></msub></mrow></mover><msub><mi>S</mi><mi>n</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\xrightarrow{a_{1},f_{1}}S_{1}\\xrightarrow{a_{2},f_{2}}S_{2}\\xrightarrow{a_{3},f_{3}}\\cdots\\xrightarrow{a_{n},f_{n}}S_{n}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(5)</span></td></tr></tbody>\n</table>\n<p id=\"A1.SS4.SSS1.p2.2\" class=\"ltx_p\">where <math id=\"A1.SS4.SSS1.p2.m1\" class=\"ltx_Math\" alttext=\"a_{i}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>a</mi><mi>i</mi></msub><annotation encoding=\"application/x-tex\">a_{i}</annotation></semantics></math> are actions and <math id=\"A1.SS4.SSS1.p2.m2\" class=\"ltx_Math\" alttext=\"f_{i}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>f</mi><mi>i</mi></msub><annotation encoding=\"application/x-tex\">f_{i}</annotation></semantics></math> are transition functions,\nstandard zkVM can generate independent proofs <math id=\"A1.SS4.SSS1.p2.m3\" class=\"ltx_Math\" alttext=\"\\{\\pi_{1},\\pi_{2},\\ldots,\\pi_{n}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><mrow><msub><mi>π</mi><mn>1</mn></msub><mo>,</mo><msub><mi>π</mi><mn>2</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>π</mi><mi>n</mi></msub></mrow><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{\\pi_{1},\\pi_{2},\\ldots,\\pi_{n}\\}</annotation></semantics></math>.\nEach <math id=\"A1.SS4.SSS1.p2.m4\" class=\"ltx_Math\" alttext=\"\\pi_{i}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>i</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{i}</annotation></semantics></math> proves: “given some value claimed to be <math id=\"A1.SS4.SSS1.p2.m5\" class=\"ltx_Math\" alttext=\"S_{i-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mrow><mi>i</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">S_{i-1}</annotation></semantics></math>, the computation\n<math id=\"A1.SS4.SSS1.p2.m6\" class=\"ltx_Math\" alttext=\"f_{i}(S_{i-1},a_{i})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>f</mi><mi>i</mi></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mrow><mi>i</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>a</mi><mi>i</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">f_{i}(S_{i-1},a_{i})</annotation></semantics></math> correctly produces <math id=\"A1.SS4.SSS1.p2.m7\" class=\"ltx_Math\" alttext=\"S_{i}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mi>i</mi></msub><annotation encoding=\"application/x-tex\">S_{i}</annotation></semantics></math>.”\nHowever, <math id=\"A1.SS4.SSS1.p2.m8\" class=\"ltx_Math\" alttext=\"\\pi_{i}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>i</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{i}</annotation></semantics></math> does not verify that this <math id=\"A1.SS4.SSS1.p2.m9\" class=\"ltx_Math\" alttext=\"S_{i-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>S</mi><mrow><mi>i</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">S_{i-1}</annotation></semantics></math> is actually the output from <math id=\"A1.SS4.SSS1.p2.m10\" class=\"ltx_Math\" alttext=\"\\pi_{i-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>i</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{i-1}</annotation></semantics></math>.</p>\n</div>\n<div id=\"A1.SS4.SSS1.p3\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS1.p3.1\" class=\"ltx_p\">Without cryptographic binding between proofs, a verifier receiving <math id=\"A1.SS4.SSS1.p3.m1\" class=\"ltx_Math\" alttext=\"\\{\\pi_{1},\\pi_{2}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>π</mi><mn>1</mn></msub><mo>,</mo><msub><mi>π</mi><mn>2</mn></msub><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{\\pi_{1},\\pi_{2}\\}</annotation></semantics></math> cannot distinguish:\nvalid sequence <math id=\"A1.SS4.SSS1.p3.m2\" class=\"ltx_Math\" alttext=\"S_{0}\\xrightarrow{\\pi_{1}}S_{1}\\xrightarrow{\\pi_{2}}S_{2}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mover accent=\"true\"><mo>→</mo><msub><mi mathsize=\"0.700em\">π</mi><mn mathsize=\"0.710em\">1</mn></msub></mover><msub><mi>S</mi><mn>1</mn></msub><mover accent=\"true\"><mo>→</mo><msub><mi mathsize=\"0.700em\">π</mi><mn mathsize=\"0.710em\">2</mn></msub></mover><msub><mi>S</mi><mn>2</mn></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\xrightarrow{\\pi_{1}}S_{1}\\xrightarrow{\\pi_{2}}S_{2}</annotation></semantics></math>;\ninvalid permutation <math id=\"A1.SS4.SSS1.p3.m3\" class=\"ltx_Math\" alttext=\"S_{0}\\xrightarrow{\\pi_{2}}S_{2}^{\\prime}\\xrightarrow{\\pi_{1}}S_{1}^{\\prime}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mover accent=\"true\"><mo>→</mo><msub><mi mathsize=\"0.700em\">π</mi><mn mathsize=\"0.710em\">2</mn></msub></mover><msubsup><mi>S</mi><mn>2</mn><mo>′</mo></msubsup><mover accent=\"true\"><mo>→</mo><msub><mi mathsize=\"0.700em\">π</mi><mn mathsize=\"0.710em\">1</mn></msub></mover><msubsup><mi>S</mi><mn>1</mn><mo>′</mo></msubsup></mrow><annotation encoding=\"application/x-tex\">S_{0}\\xrightarrow{\\pi_{2}}S_{2}^{\\prime}\\xrightarrow{\\pi_{1}}S_{1}^{\\prime}</annotation></semantics></math>;\nor invalid replay <math id=\"A1.SS4.SSS1.p3.m4\" class=\"ltx_Math\" alttext=\"S_{0}\\xrightarrow{\\pi_{1}}S_{1}\\xrightarrow{\\pi_{1}}S_{1}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mover accent=\"true\"><mo>→</mo><msub><mi mathsize=\"0.700em\">π</mi><mn mathsize=\"0.710em\">1</mn></msub></mover><msub><mi>S</mi><mn>1</mn></msub><mover accent=\"true\"><mo>→</mo><msub><mi mathsize=\"0.700em\">π</mi><mn mathsize=\"0.710em\">1</mn></msub></mover><msub><mi>S</mi><mn>1</mn></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\xrightarrow{\\pi_{1}}S_{1}\\xrightarrow{\\pi_{1}}S_{1}</annotation></semantics></math>.\nInput provenance independence breaks execution ordering guarantees.</p>\n</div>\n</section>\n<section id=\"A1.SS4.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.4.2 </span>Recursive Proof Algorithm</h4>\n\n<div id=\"A1.SS4.SSS2.p1\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p1.1\" class=\"ltx_p\">We leverage zkVM’s recursive verification capability—where the zkVM’s Prove algorithm\ncan verify another zkVM proof within its execution—to construct proof chains with cryptographically\nenforced sequential dependencies.</p>\n</div>\n<div id=\"A1.SS4.SSS2.p2\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p2.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Recursive Verification Program.</span> Define special program <math id=\"A1.SS4.SSS2.p2.m1\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math> with functionality:</p>\n<table id=\"A1.E6\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.E6.m1\" class=\"ltx_Math\" alttext=\"\\begin{split}P_{\\text{rec}}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})\\to\\{0,1\\}\\end{split}\" display=\"block\" intent=\":literal\"><semantics><mtable displaystyle=\"true\"><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mrow><msub><mi>P</mi><mtext>rec</mtext></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo stretchy=\"false\">→</mo><mrow><mo stretchy=\"false\">{</mo><mn>0</mn><mo>,</mo><mn>1</mn><mo stretchy=\"false\">}</mo></mrow></mrow></mtd></mtr></mtable><annotation encoding=\"application/x-tex\">\\begin{split}P_{\\text{rec}}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})\\to\\{0,1\\}\\end{split}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(6)</span></td></tr></tbody>\n</table>\n</div>\n<div id=\"A1.SS4.SSS2.p3\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p3.1\" class=\"ltx_p\">This program executes</p>\n<table id=\"A1.Ex6\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex6.m1\" class=\"ltx_Math\" alttext=\"\\text{Verify}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})\" display=\"block\" intent=\":literal\"><semantics><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{Verify}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.SS4.SSS2.p3.2\" class=\"ltx_p\">within the zkVM, outputting the verification result.</p>\n</div>\n<div id=\"A1.SS4.SSS2.p4\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p4.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Proof Chain Construction.</span> For execution sequence <math id=\"A1.SS4.SSS2.p4.m1\" class=\"ltx_Math\" alttext=\"S_{0}\\to S_{1}\\to\\cdots\\to S_{T}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><msub><mi>S</mi><mn>1</mn></msub><mo rspace=\"0.1389em\" stretchy=\"false\">→</mo><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mo lspace=\"0.1389em\" stretchy=\"false\">→</mo><msub><mi>S</mi><mi>T</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\to S_{1}\\to\\cdots\\to S_{T}</annotation></semantics></math>, step <math id=\"A1.SS4.SSS2.p4.m2\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi>k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math> generates compound proof:</p>\n<table id=\"A1.E7\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.E7.m1\" class=\"ltx_Math\" alttext=\"\\begin{split}\\pi_{k}\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc}_{k},\\\\\n\\text{MapIO}_{k},x_{pub,k},x_{prv,k},y_{k})\\end{split}\" display=\"block\" intent=\":literal\"><semantics><mtable displaystyle=\"true\" rowspacing=\"0pt\"><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mi>π</mi><msub><mrow></mrow><mi>k</mi></msub><mo stretchy=\"false\">←</mo><mtext>Prove</mtext><mo stretchy=\"false\">(</mo><mi>p</mi><mi>p</mi><mo>,</mo><mi>C</mi><msub><mrow></mrow><mi>P</mi></msub><mo>,</mo><mtext>ArithDesc</mtext><msub><mrow></mrow><mi>k</mi></msub><mo>,</mo></mrow></mtd></mtr><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mo fence=\"true\" rspace=\"0em\">OPEN</mo><mrow><msub><mtext>MapIO</mtext><mi>k</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><mo>,</mo><msub><mi>y</mi><mi>k</mi></msub></mrow><mo stretchy=\"false\">)</mo></mrow></mtd></mtr></mtable><annotation encoding=\"application/x-tex\">\\begin{split}\\pi_{k}\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc}_{k},\\\\\n\\text{MapIO}_{k},x_{pub,k},x_{prv,k},y_{k})\\end{split}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(7)</span></td></tr></tbody>\n</table>\n</div>\n<div id=\"A1.SS4.SSS2.p5\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p5.1\" class=\"ltx_p\">where:</p>\n<ul id=\"A1.I2\" class=\"ltx_itemize\">\n<li id=\"A1.I2.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I2.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I2.i1.p1.1\" class=\"ltx_p\"><math id=\"A1.I2.i1.p1.m1\" class=\"ltx_Math\" alttext=\"x_{pub,k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub,k}</annotation></semantics></math> contains complete previous proof <math id=\"A1.I2.i1.p1.m2\" class=\"ltx_Math\" alttext=\"\\pi_{k-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{k-1}</annotation></semantics></math>, program commitment <math id=\"A1.I2.i1.p1.m3\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math>, verification key <math id=\"A1.I2.i1.p1.m4\" class=\"ltx_Math\" alttext=\"vk\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><annotation encoding=\"application/x-tex\">vk</annotation></semantics></math>, previous output <math id=\"A1.I2.i1.p1.m5\" class=\"ltx_Math\" alttext=\"y_{k-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">y_{k-1}</annotation></semantics></math>, and previous claim <math id=\"A1.I2.i1.p1.m6\" class=\"ltx_Math\" alttext=\"x_{pub,k-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub,k-1}</annotation></semantics></math></p>\n</div></li>\n<li id=\"A1.I2.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I2.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I2.i2.p1.1\" class=\"ltx_p\"><math id=\"A1.I2.i2.p1.m1\" class=\"ltx_Math\" alttext=\"x_{prv,k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{prv,k}</annotation></semantics></math> contains current witness data</p>\n</div></li>\n<li id=\"A1.I2.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I2.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I2.i3.p1.1\" class=\"ltx_p\">Constraint template <math id=\"A1.I2.i3.p1.m1\" class=\"ltx_Math\" alttext=\"\\text{ArithDesc}_{k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mtext>ArithDesc</mtext><mi>k</mi></msub><annotation encoding=\"application/x-tex\">\\text{ArithDesc}_{k}</annotation></semantics></math> includes call to <math id=\"A1.I2.i3.p1.m2\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>P</mi><mtext>rec</mtext></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">P_{\\text{rec}}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})</annotation></semantics></math></p>\n</div></li>\n</ul>\n</div>\n<div id=\"A1.SS4.SSS2.p6\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p6.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p6.1.1\" class=\"ltx_text ltx_font_bold\">Security Properties.</span></p>\n</div>\n<div id=\"A1.SS4.SSS2.p7\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p7.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p7.1.1\" class=\"ltx_text ltx_font_italic\">Property 2 (Unforgeability of Execution Order).</span> For proof chain <math id=\"A1.SS4.SSS2.p7.m1\" class=\"ltx_Math\" alttext=\"\\{\\pi_{1},\\pi_{2},\\ldots,\\pi_{T}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><mrow><msub><mi>π</mi><mn>1</mn></msub><mo>,</mo><msub><mi>π</mi><mn>2</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>π</mi><mi>T</mi></msub></mrow><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{\\pi_{1},\\pi_{2},\\ldots,\\pi_{T}\\}</annotation></semantics></math>, by induction on <math id=\"A1.SS4.SSS2.p7.m2\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi>k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math>:</p>\n<ul id=\"A1.I3\" class=\"ltx_itemize\">\n<li id=\"A1.I3.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I3.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I3.i1.p1.1\" class=\"ltx_p\">Base case (<math id=\"A1.I3.i1.p1.m1\" class=\"ltx_Math\" alttext=\"k=1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>k</mi><mo>=</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">k=1</annotation></semantics></math>):</p>\n<table id=\"A1.EGx1\" class=\"ltx_equationgroup ltx_eqn_align ltx_eqn_table\">\n\n<tbody id=\"A1.Ex7\"><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_td ltx_align_right ltx_eqn_cell\"><math id=\"A1.Ex7.m1\" class=\"ltx_Math\" alttext=\"\\displaystyle\\pi_{1}\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc}_{1},\\text{MapIO}_{1},\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><msub><mi>π</mi><mn>1</mn></msub><mo stretchy=\"false\">←</mo><mrow><mtext>Prove</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>p</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mtext>ArithDesc</mtext><mn>1</mn></msub><mo>,</mo><msub><mtext>MapIO</mtext><mn>1</mn></msub></mrow><mo fence=\"true\" lspace=\"0em\" rspace=\"0em\">CLOSE</mo></mrow></mrow></mrow><mo>,</mo></mrow><annotation encoding=\"application/x-tex\">\\displaystyle\\pi_{1}\\leftarrow\\text{Prove}(pp,C_{P},\\text{ArithDesc}_{1},\\text{MapIO}_{1},</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n<tbody id=\"A1.Ex8\"><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_td ltx_align_right ltx_eqn_cell\"><math id=\"A1.Ex8.m1\" class=\"ltx_Math\" alttext=\"\\displaystyle x_{pub,1},x_{prv,1},y_{1})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo fence=\"true\" rspace=\"0em\">OPEN</mo><mrow><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>r</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>v</mi></mrow><mo>,</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>y</mi><mn>1</mn></msub></mrow><mo stretchy=\"false\">)</mo></mrow><annotation encoding=\"application/x-tex\">\\displaystyle x_{pub,1},x_{prv,1},y_{1})</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.I3.i1.p1.2\" class=\"ltx_p\">where <math id=\"A1.I3.i1.p1.m2\" class=\"ltx_Math\" alttext=\"x_{pub,1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub,1}</annotation></semantics></math> contains no dependencies (initial step),\n<math id=\"A1.I3.i1.p1.m3\" class=\"ltx_Math\" alttext=\"\\text{Verify}(vk,C_{P},x_{pub,1},y_{1},\\pi_{1})=1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>y</mi><mn>1</mn></msub><mo>,</mo><msub><mi>π</mi><mn>1</mn></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">\\text{Verify}(vk,C_{P},x_{pub,1},y_{1},\\pi_{1})=1</annotation></semantics></math> validates directly.</p>\n</div></li>\n<li id=\"A1.I3.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I3.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I3.i2.p1.1\" class=\"ltx_p\">Inductive step: Assume for <math id=\"A1.I3.i2.p1.m1\" class=\"ltx_Math\" alttext=\"k-1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">k-1</annotation></semantics></math>,</p>\n<table id=\"A1.Ex9\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex9.m1\" class=\"ltx_Math\" alttext=\"\\text{Verify}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})=1.\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mn>1</mn></mrow><mo lspace=\"0em\">.</mo></mrow><annotation encoding=\"application/x-tex\">\\text{Verify}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})=1.</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.I3.i2.p1.2\" class=\"ltx_p\">For step <math id=\"A1.I3.i2.p1.m2\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi>k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math>, recursive verification program <math id=\"A1.I3.i2.p1.m3\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math> executes within zkVM: (1) Extract previous proof <math id=\"A1.I3.i2.p1.m4\" class=\"ltx_Math\" alttext=\"\\pi_{k-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{k-1}</annotation></semantics></math> from <math id=\"A1.I3.i2.p1.m5\" class=\"ltx_Math\" alttext=\"x_{pub,k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub,k}</annotation></semantics></math>; (2) Verify parent proof:</p>\n<table id=\"A1.Ex10\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex10.m1\" class=\"ltx_Math\" alttext=\"b_{k-1}\\leftarrow\\text{Verify}(vk,C_{P_{k-1}},x_{pub,k-1},y_{k-1},\\pi_{k-1});\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><msub><mi>b</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">←</mo><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><msub><mi>P</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><mo>;</mo></mrow><annotation encoding=\"application/x-tex\">b_{k-1}\\leftarrow\\text{Verify}(vk,C_{P_{k-1}},x_{pub,k-1},y_{k-1},\\pi_{k-1});</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.I3.i2.p1.3\" class=\"ltx_p\">(3) If <math id=\"A1.I3.i2.p1.m6\" class=\"ltx_Math\" alttext=\"b_{k-1}=0\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>b</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>=</mo><mn>0</mn></mrow><annotation encoding=\"application/x-tex\">b_{k-1}=0</annotation></semantics></math>, <math id=\"A1.I3.i2.p1.m7\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math> fails, cannot generate <math id=\"A1.I3.i2.p1.m8\" class=\"ltx_Math\" alttext=\"\\pi_{k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>k</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{k}</annotation></semantics></math>; (4) If <math id=\"A1.I3.i2.p1.m9\" class=\"ltx_Math\" alttext=\"b_{k-1}=1\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>b</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>=</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">b_{k-1}=1</annotation></semantics></math>, generate integrated proof <math id=\"A1.I3.i2.p1.m10\" class=\"ltx_Math\" alttext=\"\\pi_{k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>k</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{k}</annotation></semantics></math>, whose verification implies validity of <math id=\"A1.I3.i2.p1.m11\" class=\"ltx_Math\" alttext=\"\\pi_{k-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{k-1}</annotation></semantics></math>.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"A1.SS4.SSS2.p8\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p8.1\" class=\"ltx_p\">Therefore:</p>\n<table id=\"A1.Ex11\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex11.m1\" class=\"ltx_Math\" alttext=\"\\begin{split}\\text{Verify}(vk,C_{P},x_{pub,k},y_{k},\\pi_{k})=1\\\\\n\\implies\\text{Verify}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})=1.\\end{split}\" display=\"block\" intent=\":literal\"><semantics><mtable displaystyle=\"true\" rowspacing=\"0pt\"><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>k</mi></mrow></msub><mo>,</mo><msub><mi>y</mi><mi>k</mi></msub><mo>,</mo><msub><mi>π</mi><mi>k</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mn>1</mn></mrow></mtd></mtr><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mrow><mphantom></mphantom><mo stretchy=\"false\">⟹</mo><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></mrow></msub><mo>,</mo><msub><mi>y</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>π</mi><mrow><mi>k</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mn>1</mn></mrow><mo lspace=\"0em\">.</mo></mrow></mtd></mtr></mtable><annotation encoding=\"application/x-tex\">\\begin{split}\\text{Verify}(vk,C_{P},x_{pub,k},y_{k},\\pi_{k})=1\\\\\n\\implies\\text{Verify}(vk,C_{P},x_{pub,k-1},y_{k-1},\\pi_{k-1})=1.\\end{split}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n</div>\n<div id=\"A1.SS4.SSS2.p9\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p9.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p9.1.1\" class=\"ltx_text ltx_font_italic\">Corollary.</span> Successful verification of final proof <math id=\"A1.SS4.SSS2.p9.m1\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> implies the entire execution sequence <math id=\"A1.SS4.SSS2.p9.m2\" class=\"ltx_Math\" alttext=\"S_{0}\\to S_{1}\\to\\cdots\\to S_{T}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><msub><mi>S</mi><mn>1</mn></msub><mo rspace=\"0.1389em\" stretchy=\"false\">→</mo><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mo lspace=\"0.1389em\" stretchy=\"false\">→</mo><msub><mi>S</mi><mi>T</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\to S_{1}\\to\\cdots\\to S_{T}</annotation></semantics></math> validates in order, with no permutation or substitution.</p>\n</div>\n<div id=\"A1.SS4.SSS2.p10\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p10.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p10.1.1\" class=\"ltx_text ltx_font_italic\">Property 3 (Fail-Stop Security).</span> If any intermediate step <math id=\"A1.SS4.SSS2.p10.m1\" class=\"ltx_Math\" alttext=\"t&lt;T\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>t</mi><mo>&lt;</mo><mi>T</mi></mrow><annotation encoding=\"application/x-tex\">t&lt;T</annotation></semantics></math> verification fails, i.e.,</p>\n<table id=\"A1.Ex12\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex12.m1\" class=\"ltx_Math\" alttext=\"\\text{Verify}(vk,C_{P},x_{pub,t},y_{t},\\pi_{t})=0,\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>t</mi></mrow></msub><mo>,</mo><msub><mi>y</mi><mi>t</mi></msub><mo>,</mo><msub><mi>π</mi><mi>t</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mn>0</mn></mrow><mo>,</mo></mrow><annotation encoding=\"application/x-tex\">\\text{Verify}(vk,C_{P},x_{pub,t},y_{t},\\pi_{t})=0,</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.SS4.SSS2.p10.2\" class=\"ltx_p\">then: (1) Step <math id=\"A1.SS4.SSS2.p10.m2\" class=\"ltx_Math\" alttext=\"t+1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">t+1</annotation></semantics></math>’s recursive verification program <math id=\"A1.SS4.SSS2.p10.m3\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math> detects failure\nwhen verifying <math id=\"A1.SS4.SSS2.p10.m4\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> (condition C2 unsatisfied); (2) <math id=\"A1.SS4.SSS2.p10.m5\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math> execution fails,\ntriggering constraint violation; (3) zkVM cannot generate valid proof <math id=\"A1.SS4.SSS2.p10.m6\" class=\"ltx_Math\" alttext=\"\\pi_{t+1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{t+1}</annotation></semantics></math> for step <math id=\"A1.SS4.SSS2.p10.m7\" class=\"ltx_Math\" alttext=\"t+1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">t+1</annotation></semantics></math>;\n(4) All subsequent steps <math id=\"A1.SS4.SSS2.p10.m8\" class=\"ltx_Math\" alttext=\"t+2,t+3,\\ldots,T\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mi>t</mi><mo>+</mo><mn>2</mn></mrow><mo>,</mo><mrow><mi>t</mi><mo>+</mo><mn>3</mn></mrow><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><mi>T</mi></mrow><annotation encoding=\"application/x-tex\">t+2,t+3,\\ldots,T</annotation></semantics></math> likewise cannot generate proofs.</p>\n</div>\n<div id=\"A1.SS4.SSS2.p11\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p11.1\" class=\"ltx_p\">Broken proof chains cannot be extended. Attackers cannot “skip over” failed steps—each\nproof <math id=\"A1.SS4.SSS2.p11.m1\" class=\"ltx_Math\" alttext=\"\\pi_{t+1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>t</mi><mo>+</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{t+1}</annotation></semantics></math> cryptographically embeds verification of <math id=\"A1.SS4.SSS2.p11.m2\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> within its recursive proof;\nmissing or invalid <math id=\"A1.SS4.SSS2.p11.m3\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> causes verification failure inside <math id=\"A1.SS4.SSS2.p11.m4\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math>.</p>\n</div>\n<div id=\"A1.SS4.SSS2.p12\" class=\"ltx_para\">\n<p id=\"A1.SS4.SSS2.p12.1\" class=\"ltx_p\"><span id=\"A1.SS4.SSS2.p12.1.1\" class=\"ltx_text ltx_font_italic\">Property 4 (Compact Verification).</span> External verifiers need only check the final proof <math id=\"A1.SS4.SSS2.p12.m1\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math>:</p>\n<ul id=\"A1.I4\" class=\"ltx_itemize\">\n<li id=\"A1.I4.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I4.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I4.i1.p1.1\" class=\"ltx_p\">Verification complexity:\n<math id=\"A1.I4.i1.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{O}(\\log T)\\cdot|\\text{ArithDesc}|\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mi class=\"ltx_font_mathcaligraphic\">𝒪</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>log</mi><mo lspace=\"0.167em\">⁡</mo><mi>T</mi></mrow><mo rspace=\"0.055em\" stretchy=\"false\">)</mo></mrow></mrow><mo rspace=\"0.222em\">⋅</mo><mrow><mo stretchy=\"false\">|</mo><mtext>ArithDesc</mtext><mo stretchy=\"false\">|</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\mathcal{O}(\\log T)\\cdot|\\text{ArithDesc}|</annotation></semantics></math>\n<br class=\"ltx_break\">(STARK verification scales logarithmically;\n<br class=\"ltx_break\"><math id=\"A1.I4.i1.p1.m2\" class=\"ltx_Math\" alttext=\"|\\text{ArithDesc}|\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">|</mo><mtext>ArithDesc</mtext><mo stretchy=\"false\">|</mo></mrow><annotation encoding=\"application/x-tex\">|\\text{ArithDesc}|</annotation></semantics></math> is constant)</p>\n</div></li>\n<li id=\"A1.I4.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I4.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I4.i2.p1.1\" class=\"ltx_p\">Proof size: <math id=\"A1.I4.i2.p1.m1\" class=\"ltx_Math\" alttext=\"|\\pi_{T}|=\\mathcal{O}(1)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mo stretchy=\"false\">|</mo><msub><mi>π</mi><mi>T</mi></msub><mo stretchy=\"false\">|</mo></mrow><mo>=</mo><mrow><mi class=\"ltx_font_mathcaligraphic\">𝒪</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mn>1</mn><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">|\\pi_{T}|=\\mathcal{O}(1)</annotation></semantics></math> (constant size  150-250 KB,\nindependent of execution length <math id=\"A1.I4.i2.p1.m2\" class=\"ltx_Math\" alttext=\"T\" display=\"inline\" intent=\":literal\"><semantics><mi>T</mi><annotation encoding=\"application/x-tex\">T</annotation></semantics></math>)</p>\n</div></li>\n<li id=\"A1.I4.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I4.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I4.i3.p1.1\" class=\"ltx_p\">Recursive embedding: All historical validations <math id=\"A1.I4.i3.p1.m1\" class=\"ltx_Math\" alttext=\"\\{\\pi_{1},\\ldots,\\pi_{T-1}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>π</mi><mn>1</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>π</mi><mrow><mi>T</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{\\pi_{1},\\ldots,\\pi_{T-1}\\}</annotation></semantics></math>\nare recursively verified and embedded into <math id=\"A1.I4.i3.p1.m2\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> through the public input <math id=\"A1.I4.i3.p1.m3\" class=\"ltx_Math\" alttext=\"x_{pub,T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>x</mi><mrow><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow><mo>,</mo><mi>T</mi></mrow></msub><annotation encoding=\"application/x-tex\">x_{pub,T}</annotation></semantics></math></p>\n</div></li>\n</ul>\n</div>\n</section>\n</section>\n<section id=\"A1.SS5\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">A.5 </span>External Communication Provenance</h3>\n\n<section id=\"A1.SS5.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.5.1 </span>Problem Statement</h4>\n\n<div id=\"A1.SS5.SSS1.p1\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS1.p1.1\" class=\"ltx_p\">zkVM operates within an isolated execution environment that cannot directly access network resources or verify external data sources. When an agent invokes external tools (e.g., web search APIs, databases), remote LLM services (e.g., OpenAI GPT-4, Anthropic Claude), or other agents (in multi-agent systems), <span id=\"A1.SS5.SSS1.p1.1.1\" class=\"ltx_text ltx_font_bold\">the zkVM cannot distinguish authentic API responses from fabricated data provided by the external environment</span>.</p>\n</div>\n<div id=\"A1.SS5.SSS1.p2\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS1.p2.1\" class=\"ltx_p\">An adversary controlling the execution environment can: (1) Intercept the agent’s intended API call (e.g., query to LLM service); (2) Replace the genuine response with attacker-controlled content; (3) Feed the fabricated data to the zkVM’s Prove algorithm. The zkVM generates a valid proof <math id=\"A1.SS5.SSS1.p2.m1\" class=\"ltx_Math\" alttext=\"\\pi\" display=\"inline\" intent=\":literal\"><semantics><mi>π</mi><annotation encoding=\"application/x-tex\">\\pi</annotation></semantics></math> over the tampered input, yet the computation violates the agent’s declared behavior. The proof attests to computational correctness, not data provenance.</p>\n</div>\n</section>\n<section id=\"A1.SS5.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.5.2 </span>zkTLS Integration for Verifiable HTTPS Communications</h4>\n\n<div id=\"A1.SS5.SSS2.p1\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p1.1\" class=\"ltx_p\">We adopt <span id=\"A1.SS5.SSS2.p1.1.1\" class=\"ltx_text ltx_font_bold\">zkTLS (Zero-Knowledge Transport Layer Security)</span> to establish cryptographic provenance for external communications. zkTLS extends TLS with zero-knowledge proofs, enabling an agent to prove properties about HTTPS sessions (e.g., “I received data <math id=\"A1.SS5.SSS2.p1.m1\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> from server <math id=\"A1.SS5.SSS2.p1.m2\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math>”) without revealing the session contents to third parties.</p>\n</div>\n<div id=\"A1.SS5.SSS2.p2\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p2.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Standard TLS Workflow:</span></p>\n<ol id=\"A1.I5\" class=\"ltx_enumerate\">\n<li id=\"A1.I5.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"A1.I5.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I5.i1.p1.1\" class=\"ltx_p\">Handshake: Client and server exchange certificates, negotiate cipher suite, derive session keys</p>\n</div></li>\n<li id=\"A1.I5.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"A1.I5.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I5.i2.p1.1\" class=\"ltx_p\">Data Transfer: Application data is encrypted with session keys, authenticated with AEAD (e.g., AES-GCM)</p>\n</div></li>\n</ol>\n</div>\n<div id=\"A1.SS5.SSS2.p3\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p3.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p3.1.1\" class=\"ltx_text ltx_font_bold\">zkTLS Extension:</span></p>\n<ol id=\"A1.I6\" class=\"ltx_enumerate\">\n<li id=\"A1.I6.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"A1.I6.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I6.i1.p1.1\" class=\"ltx_p\">Transcript Recording: The client (agent) records the complete TLS transcript, including handshake messages and encrypted data</p>\n</div></li>\n<li id=\"A1.I6.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"A1.I6.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I6.i2.p1.1\" class=\"ltx_p\">Zero-Knowledge Proof Generation: The client generates a proof asserting that:</p>\n<ul id=\"A1.I6.i2.I1\" class=\"ltx_itemize\">\n<li id=\"A1.I6.i2.I1.ix1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">(a)</span> \n<div id=\"A1.I6.i2.I1.ix1.p1\" class=\"ltx_para\">\n<p id=\"A1.I6.i2.I1.ix1.p1.1\" class=\"ltx_p\">The TLS handshake is valid (certificate chain verified, session keys correctly derived)</p>\n</div></li>\n<li id=\"A1.I6.i2.I1.ix2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">(b)</span> \n<div id=\"A1.I6.i2.I1.ix2.p1\" class=\"ltx_para\">\n<p id=\"A1.I6.i2.I1.ix2.p1.1\" class=\"ltx_p\">Specific data fields <math id=\"A1.I6.i2.I1.ix2.p1.m1\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> were present in the server’s response</p>\n</div></li>\n<li id=\"A1.I6.i2.I1.ix3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">(c)</span> \n<div id=\"A1.I6.i2.I1.ix3.p1\" class=\"ltx_para\">\n<p id=\"A1.I6.i2.I1.ix3.p1.1\" class=\"ltx_p\">The proof reveals no information about the full response content or session keys</p>\n</div></li>\n</ul>\n</div></li>\n</ol>\n</div>\n<div id=\"A1.SS5.SSS2.p4\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p4.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p4.1.1\" class=\"ltx_text ltx_font_bold\">Protocol Integration with zkVM.</span> For each external communication at step <math id=\"A1.SS5.SSS2.p4.m1\" class=\"ltx_Math\" alttext=\"k\" display=\"inline\" intent=\":literal\"><semantics><mi>k</mi><annotation encoding=\"application/x-tex\">k</annotation></semantics></math>:</p>\n</div>\n<div id=\"A1.SS5.SSS2.p5\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p5.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p5.1.1\" class=\"ltx_text ltx_font_bold\">Step1: TLS Session Execution (External Environment).</span> The execution environment:\n(1) Initiates TLS connection to target server <math id=\"A1.SS5.SSS2.p5.m1\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math> (e.g., <span id=\"A1.SS5.SSS2.p5.1.2\" class=\"ltx_text ltx_font_typewriter\">api.openai.com</span>);\n(2) Sends API request (e.g., LLM prompt);\n(3) Receives encrypted response <math id=\"A1.SS5.SSS2.p5.m2\" class=\"ltx_Math\" alttext=\"c=\\text{E}_{K_{\\text{session}}}(d)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>c</mi><mo>=</mo><mrow><msub><mtext>E</mtext><msub><mi>K</mi><mtext>session</mtext></msub></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">c=\\text{E}_{K_{\\text{session}}}(d)</annotation></semantics></math>;\n(4) Records full TLS transcript:</p>\n<table id=\"A1.Ex13\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex13.m1\" class=\"ltx_Math\" alttext=\"T=(\\text{ClientHello},\\text{ServerHello},\\text{Certificate},c,\\ldots).\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mi>T</mi><mo>=</mo><mrow><mo stretchy=\"false\">(</mo><mtext>ClientHello</mtext><mo>,</mo><mtext>ServerHello</mtext><mo>,</mo><mtext>Certificate</mtext><mo>,</mo><mi>c</mi><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo stretchy=\"false\">)</mo></mrow></mrow><mo lspace=\"0em\">.</mo></mrow><annotation encoding=\"application/x-tex\">T=(\\text{ClientHello},\\text{ServerHello},\\text{Certificate},c,\\ldots).</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n</div>\n<div id=\"A1.SS5.SSS2.p6\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p6.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p6.1.1\" class=\"ltx_text ltx_font_bold\">Step2: Integrated zkVM Execution (Inside zkVM).</span> The zkVM’s Prove algorithm receives:</p>\n<ul id=\"A1.I7\" class=\"ltx_itemize\">\n<li id=\"A1.I7.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I7.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I7.i1.p1.1\" class=\"ltx_p\">Public inputs: server identity <math id=\"A1.I7.i1.p1.m1\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math>, data commitment <math id=\"A1.I7.i1.p1.m2\" class=\"ltx_Math\" alttext=\"\\text{commit}(d)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mtext>commit</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{commit}(d)</annotation></semantics></math></p>\n</div></li>\n<li id=\"A1.I7.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I7.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I7.i2.p1.1\" class=\"ltx_p\">Private witness: TLS transcript <math id=\"A1.I7.i2.p1.m1\" class=\"ltx_Math\" alttext=\"T\" display=\"inline\" intent=\":literal\"><semantics><mi>T</mi><annotation encoding=\"application/x-tex\">T</annotation></semantics></math>, session keys <math id=\"A1.I7.i2.p1.m2\" class=\"ltx_Math\" alttext=\"K_{\\text{session}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>K</mi><mtext>session</mtext></msub><annotation encoding=\"application/x-tex\">K_{\\text{session}}</annotation></semantics></math></p>\n</div></li>\n</ul>\n</div>\n<div id=\"A1.SS5.SSS2.p7\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p7.1\" class=\"ltx_p\">The zkVM executes a unified verification and computation circuit that:</p>\n</div>\n<div id=\"A1.SS5.SSS2.p8\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p8.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p8.1.1\" class=\"ltx_text ltx_font_bold\">(a) Validates TLS Communication Provenance:</span></p>\n<ol id=\"A1.I8\" class=\"ltx_enumerate\">\n<li id=\"A1.I8.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"A1.I8.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I8.i1.p1.1\" class=\"ltx_p\"><span id=\"A1.I8.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Certificate Validity:</span> Parse X.509 certificate from <math id=\"A1.I8.i1.p1.m1\" class=\"ltx_Math\" alttext=\"T\" display=\"inline\" intent=\":literal\"><semantics><mi>T</mi><annotation encoding=\"application/x-tex\">T</annotation></semantics></math>, verify signature chain up to trusted root CA, and check certificate matches server identity <math id=\"A1.I8.i1.p1.m2\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math> (DNS name in Subject Alternative Name field)</p>\n</div></li>\n<li id=\"A1.I8.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"A1.I8.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I8.i2.p1.1\" class=\"ltx_p\"><span id=\"A1.I8.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Session Key Derivation:</span> Extract client/server random nonces from ClientHello/ServerHello, compute Pre-Master Secret (from RSA/ECDHE key exchange), and derive session keys via PRF:</p>\n<table id=\"A1.Ex14\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex14.m1\" class=\"ltx_Math\" alttext=\"K_{\\text{session}}=\\text{PRF}(\\text{PMS},\\text{nonces},\\text{``key expansion''})\" display=\"block\" intent=\":literal\"><semantics><mrow><msub><mi>K</mi><mtext>session</mtext></msub><mo>=</mo><mrow><mtext>PRF</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mtext>PMS</mtext><mo>,</mo><mtext>nonces</mtext><mo>,</mo><mtext>“key expansion”</mtext><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">K_{\\text{session}}=\\text{PRF}(\\text{PMS},\\text{nonces},\\text{``key expansion''})</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n</div></li>\n<li id=\"A1.I8.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"A1.I8.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I8.i3.p1.1\" class=\"ltx_p\"><span id=\"A1.I8.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Data Integrity:</span> Decrypt response <math id=\"A1.I8.i3.p1.m1\" class=\"ltx_Math\" alttext=\"d=\\text{D}_{K_{\\text{session}}}(c)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>d</mi><mo>=</mo><mrow><msub><mtext>D</mtext><msub><mi>K</mi><mtext>session</mtext></msub></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>c</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">d=\\text{D}_{K_{\\text{session}}}(c)</annotation></semantics></math>, and verify AEAD authentication tag (e.g., GCM tag) to ensure <math id=\"A1.I8.i3.p1.m2\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> was not tampered</p>\n</div></li>\n<li id=\"A1.I8.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"A1.I8.i4.p1\" class=\"ltx_para\">\n<p id=\"A1.I8.i4.p1.1\" class=\"ltx_p\"><span id=\"A1.I8.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Commitment Binding:</span> Compute <math id=\"A1.I8.i4.p1.m1\" class=\"ltx_Math\" alttext=\"\\text{commit}(d)=H(d)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mtext>commit</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mrow><mi>H</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\text{commit}(d)=H(d)</annotation></semantics></math> and check commitment matches the public input</p>\n</div></li>\n</ol>\n</div>\n<div id=\"A1.SS5.SSS2.p9\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p9.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p9.1.1\" class=\"ltx_text ltx_font_bold\">(b) Proves Agent Computation with Verified Data:</span> The zkVM proves that the agent’s computation correctly uses the verified data <math id=\"A1.SS5.SSS2.p9.m1\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math>: parsing the data, performing business logic operations, and generating computational outputs.</p>\n</div>\n<div id=\"A1.SS5.SSS2.p10\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p10.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p10.1.1\" class=\"ltx_text ltx_font_bold\">Output:</span> The zkVM generates a single unified proof <math id=\"A1.SS5.SSS2.p10.m1\" class=\"ltx_Math\" alttext=\"\\pi_{k}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>k</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{k}</annotation></semantics></math> that cryptographically attests: <span id=\"A1.SS5.SSS2.p10.1.2\" class=\"ltx_text ltx_font_italic\">there exists a valid TLS session with server <math id=\"A1.SS5.SSS2.p10.m2\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math> that decrypts to data <math id=\"A1.SS5.SSS2.p10.m3\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> (matching the public commitment <math id=\"A1.SS5.SSS2.p10.m4\" class=\"ltx_Math\" alttext=\"H(d)\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">H(d)</annotation></semantics></math>), and the agent program <math id=\"A1.SS5.SSS2.p10.m5\" class=\"ltx_Math\" alttext=\"P\" display=\"inline\" intent=\":literal\"><semantics><mi>P</mi><annotation encoding=\"application/x-tex\">P</annotation></semantics></math> correctly processed <math id=\"A1.SS5.SSS2.p10.m6\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> to produce the claimed output</span>. This proof binds TLS communication provenance with computation correctness without revealing the private TLS transcript, session keys, or decrypted data.</p>\n</div>\n<div id=\"A1.SS5.SSS2.p11\" class=\"ltx_para\">\n<p id=\"A1.SS5.SSS2.p11.1\" class=\"ltx_p\"><span id=\"A1.SS5.SSS2.p11.1.1\" class=\"ltx_text ltx_font_bold\">Security Guarantee:</span> An attacker cannot: (1) substitute <math id=\"A1.SS5.SSS2.p11.m1\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> with fabricated data <math id=\"A1.SS5.SSS2.p11.m2\" class=\"ltx_Math\" alttext=\"d^{\\prime}\" display=\"inline\" intent=\":literal\"><semantics><msup><mi>d</mi><mo>′</mo></msup><annotation encoding=\"application/x-tex\">d^{\\prime}</annotation></semantics></math> (breaks hash binding <math id=\"A1.SS5.SSS2.p11.m3\" class=\"ltx_Math\" alttext=\"H(d)\\neq H(d^{\\prime})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mi>d</mi><mo stretchy=\"false\">)</mo></mrow></mrow><mo>≠</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msup><mi>d</mi><mo>′</mo></msup><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">H(d)\\neq H(d^{\\prime})</annotation></semantics></math>); (2) claim <math id=\"A1.SS5.SSS2.p11.m4\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> came from different server <math id=\"A1.SS5.SSS2.p11.m5\" class=\"ltx_Math\" alttext=\"S^{\\prime}\" display=\"inline\" intent=\":literal\"><semantics><msup><mi>S</mi><mo>′</mo></msup><annotation encoding=\"application/x-tex\">S^{\\prime}</annotation></semantics></math> (breaks TLS certificate verification); (3) modify <math id=\"A1.SS5.SSS2.p11.m6\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> after TLS decryption (breaks AEAD authentication tag); or (4) manipulate computation with incorrect data (breaks unified proof integrity).</p>\n</div>\n</section>\n</section>\n<section id=\"A1.SS6\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">A.6 </span>Three-Phase Verification Pipeline</h3>\n\n<div id=\"A1.SS6.p1\" class=\"ltx_para\">\n<p id=\"A1.SS6.p1.1\" class=\"ltx_p\">The BAID protocol orchestrates agent authentication through three sequential phases,\neach enforcing specific security invariants:</p>\n<table id=\"A1.Ex15\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex15.m1\" class=\"ltx_Math\" alttext=\"\\begin{split}\\text{Phase 1 (Operator)}\\to\\text{Phase 2 (Config)}\\\\\n\\to\\text{Phase 3 (Execution)}\\end{split}\" display=\"block\" intent=\":literal\"><semantics><mtable displaystyle=\"true\" rowspacing=\"0pt\"><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mtext>Phase 1 (Operator)</mtext><mo stretchy=\"false\">→</mo><mtext>Phase 2 (Config)</mtext></mrow></mtd></mtr><mtr><mtd class=\"ltx_align_right\" columnalign=\"right\"><mrow><mphantom></mphantom><mo stretchy=\"false\">→</mo><mtext>Phase 3 (Execution)</mtext></mrow></mtd></mtr></mtable><annotation encoding=\"application/x-tex\">\\begin{split}\\text{Phase 1 (Operator)}\\to\\text{Phase 2 (Config)}\\\\\n\\to\\text{Phase 3 (Execution)}\\end{split}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n</div>\n<div id=\"A1.SS6.p2\" class=\"ltx_para\">\n<p id=\"A1.SS6.p2.1\" class=\"ltx_p\">Each phase generates a proof <math id=\"A1.SS6.p2.m1\" class=\"ltx_Math\" alttext=\"\\pi_{i}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>i</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{i}</annotation></semantics></math> that feeds into the next phase via recursive proof algorithm,\nensuring end-to-end verification.</p>\n</div>\n<section id=\"A1.SS6.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.6.1 </span>Phase 1: Operator Biometric Authentication</h4>\n\n<div id=\"A1.SS6.SSS1.p1\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS1.p1.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Objective:</span> Verify the operator’s identity without revealing biometric templates, ensuring only authorized users can activate the agent.</p>\n</div>\n<div id=\"A1.SS6.SSS1.p2\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS1.p2.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Privacy-Preserving Facial Recognition:</span></p>\n<ol id=\"A1.I9\" class=\"ltx_enumerate\">\n<li id=\"A1.I9.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"A1.I9.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I9.i1.p1.1\" class=\"ltx_p\">Feature Extraction: Capture operator’s face via device camera;\nextract 128-dimensional embedding <math id=\"A1.I9.i1.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{capture}}\\in\\mathbb{R}^{128}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo>∈</mo><msup><mi>ℝ</mi><mn>128</mn></msup></mrow><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{capture}}\\in\\mathbb{R}^{128}</annotation></semantics></math>\nusing a pre-trained neural network (e.g., FaceNet, ArcFace);\nnormalize: <math id=\"A1.I9.i1.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{capture}}\\leftarrow\\frac{\\mathbf{v}_{\\text{capture}}}{\\|\\mathbf{v}_{\\text{capture}}\\|}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo stretchy=\"false\">←</mo><mfrac><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mrow><mo stretchy=\"false\">‖</mo><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo stretchy=\"false\">‖</mo></mrow></mfrac></mrow><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{capture}}\\leftarrow\\frac{\\mathbf{v}_{\\text{capture}}}{\\|\\mathbf{v}_{\\text{capture}}\\|}</annotation></semantics></math>.</p>\n</div></li>\n<li id=\"A1.I9.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"A1.I9.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I9.i2.p1.1\" class=\"ltx_p\">Reference Template Retrieval: Load stored template <math id=\"A1.I9.i2.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{stored}}\\in\\mathbb{R}^{128}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>𝐯</mi><mtext>stored</mtext></msub><mo>∈</mo><msup><mi>ℝ</mi><mn>128</mn></msup></mrow><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{stored}}\\in\\mathbb{R}^{128}</annotation></semantics></math>\nfrom the agent’s security configurations file.</p>\n</div></li>\n<li id=\"A1.I9.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"A1.I9.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I9.i3.p1.1\" class=\"ltx_p\">zkVM Similarity Computation: Public inputs (similarity threshold <math id=\"A1.I9.i3.p1.m1\" class=\"ltx_Math\" alttext=\"\\tau\" display=\"inline\" intent=\":literal\"><semantics><mi>τ</mi><annotation encoding=\"application/x-tex\">\\tau</annotation></semantics></math>, user identifier <math id=\"A1.I9.i3.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{UserID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖴𝗌𝖾𝗋𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{UserID}</annotation></semantics></math>);\nPrivate witness (<math id=\"A1.I9.i3.p1.m3\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{capture}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝐯</mi><mtext>capture</mtext></msub><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{capture}}</annotation></semantics></math>, <math id=\"A1.I9.i3.p1.m4\" class=\"ltx_Math\" alttext=\"\\mathbf{v}_{\\text{stored}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>𝐯</mi><mtext>stored</mtext></msub><annotation encoding=\"application/x-tex\">\\mathbf{v}_{\\text{stored}}</annotation></semantics></math>).\nVerification logic computes cosine similarity and performs threshold comparison.</p>\n</div></li>\n<li id=\"A1.I9.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"A1.I9.i4.p1\" class=\"ltx_para\">\n<p id=\"A1.I9.i4.p1.1\" class=\"ltx_p\">Output: Proof <math id=\"A1.I9.i4.p1.m1\" class=\"ltx_Math\" alttext=\"\\pi_{1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>1</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{1}</annotation></semantics></math> where the zkVM generates proof asserting:</p>\n<table id=\"A1.E8\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.E8.m1\" class=\"ltx_Math\" alttext=\"\\exists\\mathbf{v}_{\\text{capture}},\\mathbf{v}_{\\text{stored}}:\\frac{\\mathbf{v}_{\\text{capture}}\\cdot\\mathbf{v}_{\\text{stored}}}{\\|\\mathbf{v}_{\\text{capture}}\\|\\|\\mathbf{v}_{\\text{stored}}\\|}\\geq\\tau\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mo rspace=\"0.167em\">∃</mo><msub><mi>𝐯</mi><mtext>capture</mtext></msub></mrow><mo>,</mo><mrow><msub><mi>𝐯</mi><mtext>stored</mtext></msub><mo lspace=\"0.278em\" rspace=\"0.278em\">:</mo><mrow><mfrac><mrow><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo lspace=\"0.222em\" rspace=\"0.222em\">⋅</mo><msub><mi>𝐯</mi><mtext>stored</mtext></msub></mrow><mrow><mrow><mo stretchy=\"false\">‖</mo><msub><mi>𝐯</mi><mtext>capture</mtext></msub><mo stretchy=\"false\">‖</mo></mrow><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">‖</mo><msub><mi>𝐯</mi><mtext>stored</mtext></msub><mo stretchy=\"false\">‖</mo></mrow></mrow></mfrac><mo>≥</mo><mi>τ</mi></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">\\exists\\mathbf{v}_{\\text{capture}},\\mathbf{v}_{\\text{stored}}:\\frac{\\mathbf{v}_{\\text{capture}}\\cdot\\mathbf{v}_{\\text{stored}}}{\\|\\mathbf{v}_{\\text{capture}}\\|\\|\\mathbf{v}_{\\text{stored}}\\|}\\geq\\tau</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td>\n<td rowspan=\"1\" class=\"ltx_eqn_cell ltx_eqn_eqno ltx_align_middle ltx_align_right\"><span class=\"ltx_tag ltx_tag_equation ltx_align_right\">(8)</span></td></tr></tbody>\n</table>\n<p id=\"A1.I9.i4.p1.2\" class=\"ltx_p\">Public output indicates authentication result (true/false), without revealing the actual embedding vectors.\nThe proof <math id=\"A1.I9.i4.p1.m2\" class=\"ltx_Math\" alttext=\"\\pi_{1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>1</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{1}</annotation></semantics></math> establishes operator authentication as the foundation for subsequent phases.</p>\n</div></li>\n</ol>\n</div>\n</section>\n<section id=\"A1.SS6.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.6.2 </span>Phase 2: Agent Configuration Integrity</h4>\n\n<div id=\"A1.SS6.SSS2.p1\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS2.p1.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Objective:</span> Prove that the agent’s local configuration matches\nthe blockchain-anchored canonical version.</p>\n</div>\n<div id=\"A1.SS6.SSS2.p2\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS2.p2.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Protocol Steps:</span></p>\n<ol id=\"A1.I10\" class=\"ltx_enumerate\">\n<li id=\"A1.I10.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">1.</span> \n<div id=\"A1.I10.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i1.p1.1\" class=\"ltx_p\">On-Chain Anchor: The Agent Identifier, defined in Equation (<a href=\"#S4.E1\" title=\"In 4.2.2 On-Chain Identity Registration and Binding Workflow ‣ 4.2 On-Chain Identity Management ‣ 4 BAID System Designs ‣ Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility\" class=\"ltx_ref\"><span class=\"ltx_text ltx_ref_tag\">1</span></a>), is stored in an Ethereum smart contract, where <math id=\"A1.I10.i1.p1.m1\" class=\"ltx_Math\" alttext=\"C_{P}=\\text{CommitProg}(P)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>C</mi><mi>P</mi></msub><mo>=</mo><mrow><mtext>CommitProg</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">C_{P}=\\text{CommitProg}(P)</annotation></semantics></math> is the program commitment and <math id=\"A1.I10.i1.p1.m2\" class=\"ltx_Math\" alttext=\"H(\\text{profile})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><mtext>profile</mtext><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">H(\\text{profile})</annotation></semantics></math> represents the hash of the agent’s security configurations file (containing biometric features, behavioral rules, and security policies). The <math id=\"A1.I10.i1.p1.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> is anchored at a specific storage slot <math id=\"A1.I10.i1.p1.m4\" class=\"ltx_Math\" alttext=\"s\" display=\"inline\" intent=\":literal\"><semantics><mi>s</mi><annotation encoding=\"application/x-tex\">s</annotation></semantics></math> within the contract’s state trie.</p>\n</div></li>\n<li id=\"A1.I10.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">2.</span> \n<div id=\"A1.I10.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i2.p1.1\" class=\"ltx_p\">Merkle Proof Retrieval: The protocol invokes the Ethereum JSON-RPC method\n<span id=\"A1.I10.i2.p1.1.1\" class=\"ltx_text ltx_font_typewriter\">eth_getProof( \n<br class=\"ltx_break\">contractAddr, [storageSlot], blockNumber)</span> to retrieve cryptographic proofs\nlinking the on-chain <math id=\"A1.I10.i2.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> to the blockchain state. The method returns three components:</p>\n<ul id=\"A1.I10.i2.I1\" class=\"ltx_itemize\">\n<li id=\"A1.I10.i2.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I10.i2.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i2.I1.i1.p1.1\" class=\"ltx_p\">Account proof: Merkle branch proving the contract account’s existence in the state trie</p>\n</div></li>\n<li id=\"A1.I10.i2.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I10.i2.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i2.I1.i2.p1.1\" class=\"ltx_p\">Storage proof: Merkle branch proving that <math id=\"A1.I10.i2.I1.i2.p1.m1\" class=\"ltx_Math\" alttext=\"(s,\\mathsf{AgentID})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">(</mo><mi>s</mi><mo>,</mo><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><mo stretchy=\"false\">)</mo></mrow><annotation encoding=\"application/x-tex\">(s,\\mathsf{AgentID})</annotation></semantics></math> is stored in the contract’s storage trie</p>\n</div></li>\n<li id=\"A1.I10.i2.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A1.I10.i2.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i2.I1.i3.p1.1\" class=\"ltx_p\">Storage root: <math id=\"A1.I10.i2.I1.i3.p1.m1\" class=\"ltx_Math\" alttext=\"r_{\\text{storage}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>r</mi><mtext>storage</mtext></msub><annotation encoding=\"application/x-tex\">r_{\\text{storage}}</annotation></semantics></math> from the account state, serving as the verification anchor</p>\n</div></li>\n</ul>\n</div></li>\n<li id=\"A1.I10.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">3.</span> \n<div id=\"A1.I10.i3.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i3.p1.1\" class=\"ltx_p\">zkVM Verification: Public inputs (<math id=\"A1.I10.i3.p1.m1\" class=\"ltx_Math\" alttext=\"r_{\\text{storage}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>r</mi><mtext>storage</mtext></msub><annotation encoding=\"application/x-tex\">r_{\\text{storage}}</annotation></semantics></math>, expected profile hash from <math id=\"A1.I10.i3.p1.m2\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math>);\nPrivate witness (local security configurations file <math id=\"A1.I10.i3.p1.m3\" class=\"ltx_Math\" alttext=\"\\text{Config}_{\\text{local}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mtext>Config</mtext><mtext>local</mtext></msub><annotation encoding=\"application/x-tex\">\\text{Config}_{\\text{local}}</annotation></semantics></math>, Merkle proof <math id=\"A1.I10.i3.p1.m4\" class=\"ltx_Math\" alttext=\"\\pi_{\\text{merkle}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mtext>merkle</mtext></msub><annotation encoding=\"application/x-tex\">\\pi_{\\text{merkle}}</annotation></semantics></math>).\nVerification logic computes <math id=\"A1.I10.i3.p1.m5\" class=\"ltx_Math\" alttext=\"H(\\text{Config}_{\\text{local}})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mtext>Config</mtext><mtext>local</mtext></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">H(\\text{Config}_{\\text{local}})</annotation></semantics></math>, verifies it matches <span id=\"A1.I10.i3.p1.1.1\" class=\"ltx_text ltx_markedasmath\">profile_hash</span> in <math id=\"A1.I10.i3.p1.m7\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math>,\nreconstructs storage root from leaf, and checks consistency.</p>\n</div></li>\n<li id=\"A1.I10.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">4.</span> \n<div id=\"A1.I10.i4.p1\" class=\"ltx_para\">\n<p id=\"A1.I10.i4.p1.1\" class=\"ltx_p\">Output: Proof <math id=\"A1.I10.i4.p1.m1\" class=\"ltx_Math\" alttext=\"\\pi_{2}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>2</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{2}</annotation></semantics></math> asserting that the local configuration matches the blockchain-anchored version:</p>\n<table id=\"A1.Ex16\" class=\"ltx_equation ltx_eqn_table\">\n\n<tbody><tr class=\"ltx_equation ltx_eqn_row ltx_align_baseline\">\n<td class=\"ltx_eqn_cell ltx_eqn_center_padleft\"></td>\n<td class=\"ltx_eqn_cell ltx_align_center\"><math id=\"A1.Ex16.m1\" class=\"ltx_Math\" alttext=\"H(\\text{Config}_{\\text{local}})=\\text{profile\\_hash in $\\mathsf{AgentID}$}\" display=\"block\" intent=\":literal\"><semantics><mrow><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mtext>Config</mtext><mtext>local</mtext></msub><mo stretchy=\"false\">)</mo></mrow></mrow><mo>=</mo><mrow><mtext>profile_hash in </mtext><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi></mrow></mrow><annotation encoding=\"application/x-tex\">H(\\text{Config}_{\\text{local}})=\\text{profile\\_hash in $\\mathsf{AgentID}$}</annotation></semantics></math></td>\n<td class=\"ltx_eqn_cell ltx_eqn_center_padright\"></td></tr></tbody>\n</table>\n<p id=\"A1.I10.i4.p1.2\" class=\"ltx_p\">The proof binds the storage root <math id=\"A1.I10.i4.p1.m2\" class=\"ltx_Math\" alttext=\"r_{\\text{storage}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>r</mi><mtext>storage</mtext></msub><annotation encoding=\"application/x-tex\">r_{\\text{storage}}</annotation></semantics></math> and Merkle proof verification without revealing the configuration contents.\nThe proof <math id=\"A1.I10.i4.p1.m3\" class=\"ltx_Math\" alttext=\"\\pi_{2}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>2</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{2}</annotation></semantics></math> depends on <math id=\"A1.I10.i4.p1.m4\" class=\"ltx_Math\" alttext=\"\\pi_{1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mn>1</mn></msub><annotation encoding=\"application/x-tex\">\\pi_{1}</annotation></semantics></math> through recursive proof algorithm.</p>\n</div></li>\n</ol>\n</div>\n</section>\n<section id=\"A1.SS6.SSS3\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">A.6.3 </span>Phase 3: Iterative Task Execution</h4>\n\n<div id=\"A1.SS6.SSS3.p1\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p1.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Objective:</span> Prove correct execution of agent tasks across multiple conversational turns\n<math id=\"A1.SS6.SSS3.p1.m1\" class=\"ltx_Math\" alttext=\"t=1,2,\\ldots,T\" display=\"inline\" intent=\":literal\"><semantics><mrow><mrow><mi>t</mi><mo>=</mo><mn>1</mn></mrow><mo>,</mo><mn>2</mn><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><mi>T</mi></mrow><annotation encoding=\"application/x-tex\">t=1,2,\\ldots,T</annotation></semantics></math>, with verified provenance for all external communications.</p>\n</div>\n<div id=\"A1.SS6.SSS3.p2\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p2.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">Execution Model per Turn <math id=\"A1.SS6.SSS3.p2.m1\" class=\"ltx_Math\" alttext=\"t\" display=\"inline\" intent=\":literal\"><semantics><mi>t</mi><annotation encoding=\"application/x-tex\">t</annotation></semantics></math>:</span> Each conversational turn <math id=\"A1.SS6.SSS3.p2.m2\" class=\"ltx_Math\" alttext=\"t\" display=\"inline\" intent=\":literal\"><semantics><mi>t</mi><annotation encoding=\"application/x-tex\">t</annotation></semantics></math> involves:\n(1) Input Reception (user query <math id=\"A1.SS6.SSS3.p2.m3\" class=\"ltx_Math\" alttext=\"q_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>q</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">q_{t}</annotation></semantics></math> or tool response <math id=\"A1.SS6.SSS3.p2.m4\" class=\"ltx_Math\" alttext=\"r_{t-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>r</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">r_{t-1}</annotation></semantics></math>, previous state commitment <math id=\"A1.SS6.SSS3.p2.m5\" class=\"ltx_Math\" alttext=\"h_{t-1}=H(S_{t-1})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>h</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>=</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">h_{t-1}=H(S_{t-1})</annotation></semantics></math>);\n(2) LLM Invocation (send prompt to remote LLM service, receive response <math id=\"A1.SS6.SSS3.p2.m6\" class=\"ltx_Math\" alttext=\"a_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>a</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">a_{t}</annotation></semantics></math>);\n(3) Tool Execution (execute tool function: <math id=\"A1.SS6.SSS3.p2.m7\" class=\"ltx_Math\" alttext=\"o_{t}=f_{a_{t}}(\\text{params})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>o</mi><mi>t</mi></msub><mo>=</mo><mrow><msub><mi>f</mi><msub><mi>a</mi><mi>t</mi></msub></msub><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mtext>params</mtext><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">o_{t}=f_{a_{t}}(\\text{params})</annotation></semantics></math>);\n(4) State Update (compute new state: <math id=\"A1.SS6.SSS3.p2.m8\" class=\"ltx_Math\" alttext=\"S_{t}=(S_{t-1},q_{t},a_{t},o_{t})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mi>t</mi></msub><mo>=</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><mo>,</mo><msub><mi>q</mi><mi>t</mi></msub><mo>,</mo><msub><mi>a</mi><mi>t</mi></msub><mo>,</mo><msub><mi>o</mi><mi>t</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow><annotation encoding=\"application/x-tex\">S_{t}=(S_{t-1},q_{t},a_{t},o_{t})</annotation></semantics></math>).</p>\n</div>\n<div id=\"A1.SS6.SSS3.p3\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p3.1\" class=\"ltx_p\"><span id=\"A1.SS6.SSS3.p3.1.1\" class=\"ltx_text ltx_font_bold\">Integrated Execution Proof per Turn <math id=\"A1.SS6.SSS3.p3.m1\" class=\"ltx_Math\" alttext=\"t\" display=\"inline\" intent=\":literal\"><semantics><mi>t</mi><annotation encoding=\"application/x-tex\">t</annotation></semantics></math>:</span> For each conversational turn <math id=\"A1.SS6.SSS3.p3.m2\" class=\"ltx_Math\" alttext=\"t\" display=\"inline\" intent=\":literal\"><semantics><mi>t</mi><annotation encoding=\"application/x-tex\">t</annotation></semantics></math>,\ngenerate a single execution proof <math id=\"A1.SS6.SSS3.p3.m3\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> that integrates zkTLS verification, agent computation,\nand recursive proof algorithm within one zkVM execution. The proof generation proceeds in three stages:</p>\n</div>\n<div id=\"A1.SS6.SSS3.p4\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p4.1\" class=\"ltx_p\">1. Recursive Verification and Dependency Checking:\nFor <math id=\"A1.SS6.SSS3.p4.m1\" class=\"ltx_Math\" alttext=\"t&gt;1\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>t</mi><mo>&gt;</mo><mn>1</mn></mrow><annotation encoding=\"application/x-tex\">t&gt;1</annotation></semantics></math>, first verify parent proof <math id=\"A1.SS6.SSS3.p4.m2\" class=\"ltx_Math\" alttext=\"\\pi_{t-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{t-1}</annotation></semantics></math> validity through zkVM’s recursive verification.\nThis ensures the current turn builds on a verified historical foundation,\npreventing broken proof chains from extending.</p>\n</div>\n<div id=\"A1.SS6.SSS3.p5\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p5.1\" class=\"ltx_p\">2. zkTLS Verification (Communication Provenance):\nExecute TLS session validation within zkVM to ensure authenticity of responses from LLM services and remote third-party APIs:\nverify certificate chain, session key derivation, AEAD authentication,\nand compute data commitment <math id=\"A1.SS6.SSS3.p5.m1\" class=\"ltx_Math\" alttext=\"h_{a_{t}}=H(a_{t})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>h</mi><msub><mi>a</mi><mi>t</mi></msub></msub><mo>=</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>a</mi><mi>t</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">h_{a_{t}}=H(a_{t})</annotation></semantics></math>.</p>\n</div>\n<div id=\"A1.SS6.SSS3.p6\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p6.1\" class=\"ltx_p\">3. Agent Computation Verification (Execution Correctness):\nVerify the agent correctly executes tasks using verified responses from external services:\nparse action, execute tool call, update state, and compute state commitment <math id=\"A1.SS6.SSS3.p6.m1\" class=\"ltx_Math\" alttext=\"h_{S_{t}}=H(S_{t})\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>h</mi><msub><mi>S</mi><mi>t</mi></msub></msub><mo>=</mo><mrow><mi>H</mi><mo>⁡</mo><mrow><mo stretchy=\"false\">(</mo><msub><mi>S</mi><mi>t</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">h_{S_{t}}=H(S_{t})</annotation></semantics></math>.</p>\n</div>\n<div id=\"A1.SS6.SSS3.p7\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p7.1\" class=\"ltx_p\">4. Final Proof after <math id=\"A1.SS6.SSS3.p7.m1\" class=\"ltx_Math\" alttext=\"T\" display=\"inline\" intent=\":literal\"><semantics><mi>T</mi><annotation encoding=\"application/x-tex\">T</annotation></semantics></math> Turns: After <math id=\"A1.SS6.SSS3.p7.m2\" class=\"ltx_Math\" alttext=\"T\" display=\"inline\" intent=\":literal\"><semantics><mi>T</mi><annotation encoding=\"application/x-tex\">T</annotation></semantics></math> conversational turns,\nthe final proof <math id=\"A1.SS6.SSS3.p7.m3\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math> cryptographically attests to:\n(1) Initial authentication validity (Phase 1 configuration integrity and Phase 2 operator biometric verification);\n(2) Complete execution trace across all turns: <math id=\"A1.SS6.SSS3.p7.m4\" class=\"ltx_Math\" alttext=\"S_{0}\\to S_{1}\\to\\cdots\\to S_{T}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><msub><mi>S</mi><mn>1</mn></msub><mo rspace=\"0.1389em\" stretchy=\"false\">→</mo><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mo lspace=\"0.1389em\" stretchy=\"false\">→</mo><msub><mi>S</mi><mi>T</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\to S_{1}\\to\\cdots\\to S_{T}</annotation></semantics></math>;\n(3) Verified provenance of all external service responses: <math id=\"A1.SS6.SSS3.p7.m5\" class=\"ltx_Math\" alttext=\"\\{a_{1},\\ldots,a_{T}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>a</mi><mn>1</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>a</mi><mi>T</mi></msub><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{a_{1},\\ldots,a_{T}\\}</annotation></semantics></math> via zkTLS;\n(4) Correct agent computation for all tool executions: <math id=\"A1.SS6.SSS3.p7.m6\" class=\"ltx_Math\" alttext=\"\\{o_{1},\\ldots,o_{T}\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>o</mi><mn>1</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo>,</mo><msub><mi>o</mi><mi>T</mi></msub><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{o_{1},\\ldots,o_{T}\\}</annotation></semantics></math> following code <math id=\"A1.SS6.SSS3.p7.m7\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math>.</p>\n</div>\n<div id=\"A1.SS6.SSS3.p8\" class=\"ltx_para\">\n<p id=\"A1.SS6.SSS3.p8.1\" class=\"ltx_p\">External verifiers (eg. counterpart agents, service providers, or regulators) only need to:\n(1) Receive the final proof <math id=\"A1.SS6.SSS3.p8.m1\" class=\"ltx_Math\" alttext=\"\\pi_{T}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>T</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{T}</annotation></semantics></math>;\n(2) Verify using zkVM’s Verify algorithm: <math id=\"A1.SS6.SSS3.p8.m2\" class=\"ltx_Math\" alttext=\"b\\leftarrow\\text{Verify}(vk,C_{P},x_{pub},y_{T},\\pi_{T})\" display=\"inline\" intent=\":literal\"><semantics><mrow><mi>b</mi><mo stretchy=\"false\">←</mo><mrow><mtext>Verify</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mrow><mi>v</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>k</mi></mrow><mo>,</mo><msub><mi>C</mi><mi>P</mi></msub><mo>,</mo><msub><mi>x</mi><mrow><mi>p</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>u</mi><mo lspace=\"0em\" rspace=\"0em\">​</mo><mi>b</mi></mrow></msub><mo>,</mo><msub><mi>y</mi><mi>T</mi></msub><mo>,</mo><msub><mi>π</mi><mi>T</mi></msub><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">b\\leftarrow\\text{Verify}(vk,C_{P},x_{pub},y_{T},\\pi_{T})</annotation></semantics></math>;\n(3) Check the public outputs match expected values.</p>\n</div>\n</section>\n</section>\n</section>\n<section id=\"A2\" class=\"ltx_appendix\">\n<h2 class=\"ltx_title ltx_title_appendix\"><span class=\"ltx_tag ltx_tag_appendix\">Appendix B </span>Security Analysis</h2>\n\n<div id=\"A2.p1\" class=\"ltx_para\">\n<p id=\"A2.p1.1\" class=\"ltx_p\">This section analyzes the security properties of the BAID framework, defining the threat model and demonstrating how the proposed protocols defend against critical attacks targeting autonomous agent systems.</p>\n</div>\n<section id=\"A2.SS1\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">B.1 </span>Threat Model</h3>\n\n<div id=\"A2.SS1.p1\" class=\"ltx_para\">\n<p id=\"A2.SS1.p1.1\" class=\"ltx_p\">We consider an adversary <math id=\"A2.SS1.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> with the following capabilities:</p>\n<ul id=\"A2.I1\" class=\"ltx_itemize\">\n<li id=\"A2.I1.i1\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A2.I1.i1.p1\" class=\"ltx_para\">\n<p id=\"A2.I1.i1.p1.1\" class=\"ltx_p\"><span id=\"A2.I1.i1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Key Compromise:</span> <math id=\"A2.I1.i1.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> may obtain the private signing keys of legitimate users or agents.</p>\n</div></li>\n<li id=\"A2.I1.i2\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A2.I1.i2.p1\" class=\"ltx_para\">\n<p id=\"A2.I1.i2.p1.1\" class=\"ltx_p\"><span id=\"A2.I1.i2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Network Control:</span> <math id=\"A2.I1.i2.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> can intercept, modify, replay, or reorder network messages between agents, users, and external services.</p>\n</div></li>\n<li id=\"A2.I1.i3\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A2.I1.i3.p1\" class=\"ltx_para\">\n<p id=\"A2.I1.i3.p1.1\" class=\"ltx_p\"><span id=\"A2.I1.i3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Malicious Execution Environment:</span> <math id=\"A2.I1.i3.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> may control the computational environment where the agent executes, enabling manipulation of I/O or substitution of program binaries.</p>\n</div></li>\n<li id=\"A2.I1.i4\" class=\"ltx_item\" style=\"list-style-type:none;\"><span class=\"ltx_tag ltx_tag_item\">•</span> \n<div id=\"A2.I1.i4.p1\" class=\"ltx_para\">\n<p id=\"A2.I1.i4.p1.1\" class=\"ltx_p\"><span id=\"A2.I1.i4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Data Fabrication:</span> <math id=\"A2.I1.i4.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> can forge responses from external APIs (e.g., LLMs, web services) to mislead agent execution.</p>\n</div></li>\n</ul>\n</div>\n<div id=\"A2.SS1.p2\" class=\"ltx_para\">\n<p id=\"A2.SS1.p2.1\" class=\"ltx_p\">We assume the underlying cryptographic primitives (zkVM proof system, hash functions, digital signatures, TLS) are secure.</p>\n</div>\n</section>\n<section id=\"A2.SS2\" class=\"ltx_subsection\">\n<h3 class=\"ltx_title ltx_title_subsection\"><span class=\"ltx_tag ltx_tag_subsection\">B.2 </span>Security Properties and Defenses</h3>\n\n<section id=\"A2.SS2.SSS1\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">B.2.1 </span>Defense Against Code Substitution Attacks</h4>\n\n<div id=\"A2.SS2.SSS1.p1\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS1.p1.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS1.p1.1.1\" class=\"ltx_text ltx_font_bold\">Attack:</span> An adversary with a compromised agent private key replaces the legitimate agent program <math id=\"A2.SS2.SSS1.p1.m1\" class=\"ltx_Math\" alttext=\"P\" display=\"inline\" intent=\":literal\"><semantics><mi>P</mi><annotation encoding=\"application/x-tex\">P</annotation></semantics></math> with malicious code <math id=\"A2.SS2.SSS1.p1.m2\" class=\"ltx_Math\" alttext=\"P^{\\prime}\" display=\"inline\" intent=\":literal\"><semantics><msup><mi>P</mi><mo>′</mo></msup><annotation encoding=\"application/x-tex\">P^{\\prime}</annotation></semantics></math> to execute unauthorized actions while signing them as the legitimate agent.</p>\n</div>\n<div id=\"A2.SS2.SSS1.p2\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS1.p2.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS1.p2.1.1\" class=\"ltx_text ltx_font_bold\">Defense:</span> BAID implements <span id=\"A2.SS2.SSS1.p2.1.2\" class=\"ltx_text ltx_font_italic\">Code-Level Authentication</span>. The agent’s identity is cryptographically bound to the program commitment <math id=\"A2.SS2.SSS1.p2.m1\" class=\"ltx_Math\" alttext=\"C_{P}=\\text{CommitProg}(P)\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>C</mi><mi>P</mi></msub><mo>=</mo><mrow><mtext>CommitProg</mtext><mo lspace=\"0em\" rspace=\"0em\">​</mo><mrow><mo stretchy=\"false\">(</mo><mi>P</mi><mo stretchy=\"false\">)</mo></mrow></mrow></mrow><annotation encoding=\"application/x-tex\">C_{P}=\\text{CommitProg}(P)</annotation></semantics></math>. Any modification to the code results in <math id=\"A2.SS2.SSS1.p2.m2\" class=\"ltx_Math\" alttext=\"C_{P^{\\prime}}\\neq C_{P}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>C</mi><msup><mi>P</mi><mo>′</mo></msup></msub><mo>≠</mo><msub><mi>C</mi><mi>P</mi></msub></mrow><annotation encoding=\"application/x-tex\">C_{P^{\\prime}}\\neq C_{P}</annotation></semantics></math>. The zkVM proof generation requires the execution trace to satisfy constraints derived from <math id=\"A2.SS2.SSS1.p2.m3\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math> <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib31\" title=\"\" class=\"ltx_ref\">RISC Zero (2024)</a></cite>. Therefore, <math id=\"A2.SS2.SSS1.p2.m4\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> cannot generate a valid proof <math id=\"A2.SS2.SSS1.p2.m5\" class=\"ltx_Math\" alttext=\"\\pi\" display=\"inline\" intent=\":literal\"><semantics><mi>π</mi><annotation encoding=\"application/x-tex\">\\pi</annotation></semantics></math> for <math id=\"A2.SS2.SSS1.p2.m6\" class=\"ltx_Math\" alttext=\"P^{\\prime}\" display=\"inline\" intent=\":literal\"><semantics><msup><mi>P</mi><mo>′</mo></msup><annotation encoding=\"application/x-tex\">P^{\\prime}</annotation></semantics></math> that verifies against the legitimate <math id=\"A2.SS2.SSS1.p2.m7\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> (which contains <math id=\"A2.SS2.SSS1.p2.m8\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math>), effectively preventing code substitution even if keys are compromised.</p>\n</div>\n</section>\n<section id=\"A2.SS2.SSS2\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">B.2.2 </span>Defense Against Replay and Reordering Attacks</h4>\n\n<div id=\"A2.SS2.SSS2.p1\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS2.p1.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS2.p1.1.1\" class=\"ltx_text ltx_font_bold\">Attack:</span> <math id=\"A2.SS2.SSS2.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> intercepts valid proofs <math id=\"A2.SS2.SSS2.p1.m2\" class=\"ltx_Math\" alttext=\"\\{\\pi_{1},\\pi_{2},\\ldots\\}\" display=\"inline\" intent=\":literal\"><semantics><mrow><mo stretchy=\"false\">{</mo><msub><mi>π</mi><mn>1</mn></msub><mo>,</mo><msub><mi>π</mi><mn>2</mn></msub><mo>,</mo><mi mathvariant=\"normal\">…</mi><mo stretchy=\"false\">}</mo></mrow><annotation encoding=\"application/x-tex\">\\{\\pi_{1},\\pi_{2},\\ldots\\}</annotation></semantics></math> from a session and replays them or reorders them (e.g., skipping a payment authorization step) to manipulate the agent’s state transition.</p>\n</div>\n<div id=\"A2.SS2.SSS2.p2\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS2.p2.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS2.p2.1.1\" class=\"ltx_text ltx_font_bold\">Defense:</span> BAID employs <span id=\"A2.SS2.SSS2.p2.1.2\" class=\"ltx_text ltx_font_italic\">Recursive Verification</span> to enforce <span id=\"A2.SS2.SSS2.p2.1.3\" class=\"ltx_text ltx_font_italic\">Execution Continuity</span>. Each proof <math id=\"A2.SS2.SSS2.p2.m1\" class=\"ltx_Math\" alttext=\"\\pi_{t}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mi>t</mi></msub><annotation encoding=\"application/x-tex\">\\pi_{t}</annotation></semantics></math> cryptographically embeds the verification of the previous proof <math id=\"A2.SS2.SSS2.p2.m2\" class=\"ltx_Math\" alttext=\"\\pi_{t-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>π</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">\\pi_{t-1}</annotation></semantics></math> as a public input. This creates an immutable, ordered hash chain <math id=\"A2.SS2.SSS2.p2.m3\" class=\"ltx_Math\" alttext=\"S_{0}\\to S_{1}\\to\\cdots\\to S_{t}\" display=\"inline\" intent=\":literal\"><semantics><mrow><msub><mi>S</mi><mn>0</mn></msub><mo stretchy=\"false\">→</mo><msub><mi>S</mi><mn>1</mn></msub><mo rspace=\"0.1389em\" stretchy=\"false\">→</mo><mo lspace=\"0.1389em\" rspace=\"0.1389em\">⋯</mo><mo lspace=\"0.1389em\" stretchy=\"false\">→</mo><msub><mi>S</mi><mi>t</mi></msub></mrow><annotation encoding=\"application/x-tex\">S_{0}\\to S_{1}\\to\\cdots\\to S_{t}</annotation></semantics></math>. A replayed or reordered proof will fail the recursive verification check <math id=\"A2.SS2.SSS2.p2.m4\" class=\"ltx_Math\" alttext=\"P_{\\text{rec}}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>P</mi><mtext>rec</mtext></msub><annotation encoding=\"application/x-tex\">P_{\\text{rec}}</annotation></semantics></math> inside the zkVM <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib31\" title=\"\" class=\"ltx_ref\">RISC Zero (2024)</a></cite>, as the input state commitment <math id=\"A2.SS2.SSS2.p2.m5\" class=\"ltx_Math\" alttext=\"h_{t-1}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>h</mi><mrow><mi>t</mi><mo>−</mo><mn>1</mn></mrow></msub><annotation encoding=\"application/x-tex\">h_{t-1}</annotation></semantics></math> will not match the output of the previous valid step.</p>\n</div>\n</section>\n<section id=\"A2.SS2.SSS3\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">B.2.3 </span>Defense Against Data Fabrication (Man-in-the-Middle)</h4>\n\n<div id=\"A2.SS2.SSS3.p1\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS3.p1.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS3.p1.1.1\" class=\"ltx_text ltx_font_bold\">Attack:</span> <math id=\"A2.SS2.SSS3.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> controls the network or execution environment and feeds fabricated LLM responses or market data to the agent to trigger incorrect decisions.</p>\n</div>\n<div id=\"A2.SS2.SSS3.p2\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS3.p2.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS3.p2.1.1\" class=\"ltx_text ltx_font_bold\">Defense:</span> BAID integrates <span id=\"A2.SS2.SSS3.p2.1.2\" class=\"ltx_text ltx_font_italic\">zkTLS</span> to ensure <span id=\"A2.SS2.SSS3.p2.1.3\" class=\"ltx_text ltx_font_italic\">Data Provenance</span>. The zkVM circuit verifies the TLS handshake and server signatures within the zero-knowledge environment. It proves that the data <math id=\"A2.SS2.SSS3.p2.m1\" class=\"ltx_Math\" alttext=\"d\" display=\"inline\" intent=\":literal\"><semantics><mi>d</mi><annotation encoding=\"application/x-tex\">d</annotation></semantics></math> processed by the agent originated from a specific, authenticated server <math id=\"A2.SS2.SSS3.p2.m2\" class=\"ltx_Math\" alttext=\"S\" display=\"inline\" intent=\":literal\"><semantics><mi>S</mi><annotation encoding=\"application/x-tex\">S</annotation></semantics></math> (e.g., <span id=\"A2.SS2.SSS3.p2.1.4\" class=\"ltx_text ltx_font_typewriter\">api.openai.com</span>) and has not been tampered with <cite class=\"ltx_cite ltx_citemacro_cite\"><span class=\"ltx_ref ltx_missing_citation ltx_ref_self\">Zhang2020DECO</span></cite>. <math id=\"A2.SS2.SSS3.p2.m3\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> cannot forge a valid TLS transcript and corresponding zkVM proof without breaking the underlying TLS cryptography.</p>\n</div>\n</section>\n<section id=\"A2.SS2.SSS4\" class=\"ltx_subsubsection\">\n<h4 class=\"ltx_title ltx_title_subsubsection\"><span class=\"ltx_tag ltx_tag_subsubsection\">B.2.4 </span>Defense Against Sybil and Impersonation Attacks</h4>\n\n<div id=\"A2.SS2.SSS4.p1\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS4.p1.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS4.p1.1.1\" class=\"ltx_text ltx_font_bold\">Attack:</span> <math id=\"A2.SS2.SSS4.p1.m1\" class=\"ltx_Math\" alttext=\"\\mathcal{A}\" display=\"inline\" intent=\":literal\"><semantics><mi class=\"ltx_font_mathcaligraphic\">𝒜</mi><annotation encoding=\"application/x-tex\">\\mathcal{A}</annotation></semantics></math> creates multiple fake agent identities to flood the network or impersonates a reputable agent.</p>\n</div>\n<div id=\"A2.SS2.SSS4.p2\" class=\"ltx_para\">\n<p id=\"A2.SS2.SSS4.p2.1\" class=\"ltx_p\"><span id=\"A2.SS2.SSS4.p2.1.1\" class=\"ltx_text ltx_font_bold\">Defense:</span> BAID relies on <span id=\"A2.SS2.SSS4.p2.1.2\" class=\"ltx_text ltx_font_italic\">On-Chain Identity Management</span> and <span id=\"A2.SS2.SSS4.p2.1.3\" class=\"ltx_text ltx_font_italic\">zkKYC</span>. Agent identities must be bound to a valid User Identity Contract, which requires zkKYC verification of the legal entity <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib37\" title=\"\" class=\"ltx_ref\">Pauwels (2021)</a></cite>. This imposes a real-world cost and accountability on identity creation, mitigating Sybil attacks. Furthermore, the on-chain binding of <math id=\"A2.SS2.SSS4.p2.m1\" class=\"ltx_Math\" alttext=\"\\mathsf{AgentID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖠𝗀𝖾𝗇𝗍𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{AgentID}</annotation></semantics></math> to <math id=\"A2.SS2.SSS4.p2.m2\" class=\"ltx_Math\" alttext=\"C_{P}\" display=\"inline\" intent=\":literal\"><semantics><msub><mi>C</mi><mi>P</mi></msub><annotation encoding=\"application/x-tex\">C_{P}</annotation></semantics></math> and <math id=\"A2.SS2.SSS4.p2.m3\" class=\"ltx_Math\" alttext=\"\\mathsf{UserID}\" display=\"inline\" intent=\":literal\"><semantics><mi>𝖴𝗌𝖾𝗋𝖨𝖣</mi><annotation encoding=\"application/x-tex\">\\mathsf{UserID}</annotation></semantics></math> ensures that any impersonation attempt is detectable by verifying the agent’s proofs against the immutable blockchain registry <cite class=\"ltx_cite ltx_citemacro_cite\"><a href=\"#bib.bib18\" title=\"\" class=\"ltx_ref\">Chan et al. (2024)</a></cite>.</p>\n</div>\n</section>\n</section>\n</section>\n</article>\n</div>\n</div>\n<footer class=\"arxiv-html-footer\">\n  <div class=\"ltx_page_logo\">\n    Experimental support, please\n    <a href=\"./2512.17538v1/__stdout.txt\" class=\"ltx_ref\"\n    target=\"_blank\" rel=\"nofollow\">view the build logs</a>\n    for errors. Generated by\n    <a href=\"https://math.nist.gov/~BMiller/LaTeXML/\" target=\"_blank\" class=\"ltx_ref ltx_LaTeXML_logo\">\n      <span style=\"letter-spacing: -0.2em; margin-right: 0.1em;\">\n        L\n        <span style=\"font-size: 70%; position: relative; bottom: 2.2pt;\">A</span>\n        T\n        <span style=\"position: relative; bottom: -0.4ex;\">E</span>\n      </span>\n      <span class=\"ltx_font_smallcaps\">xml</span>\n      <img alt=\"[LOGO]\"\n        src=\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAsAAAAOCAYAAAD5YeaVAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9wKExQZLWTEaOUAAAAddEVYdENvbW1lbnQAQ3JlYXRlZCB3aXRoIFRoZSBHSU1Q72QlbgAAAdpJREFUKM9tkL+L2nAARz9fPZNCKFapUn8kyI0e4iRHSR1Kb8ng0lJw6FYHFwv2LwhOpcWxTjeUunYqOmqd6hEoRDhtDWdA8ApRYsSUCDHNt5ul13vz4w0vWCgUnnEc975arX6ORqN3VqtVZbfbTQC4uEHANM3jSqXymFI6yWazP2KxWAXAL9zCUa1Wy2tXVxheKA9YNoR8Pt+aTqe4FVVVvz05O6MBhqUIBGk8Hn8HAOVy+T+XLJfLS4ZhTiRJgqIoVBRFIoric47jPnmeB1mW/9rr9ZpSSn3Lsmir1fJZlqWlUonKsvwWwD8ymc/nXwVBeLjf7xEKhdBut9Hr9WgmkyGEkJwsy5eHG5vN5g0AKIoCAEgkEkin0wQAfN9/cXPdheu6P33fBwB4ngcAcByHJpPJl+fn54mD3Gg0NrquXxeLRQAAwzAYj8cwTZPwPH9/sVg8PXweDAauqqr2cDjEer1GJBLBZDJBs9mE4zjwfZ85lAGg2+06hmGgXq+j3+/DsixYlgVN03a9Xu8jgCNCyIegIAgx13Vfd7vdu+FweG8YRkjXdWy329+dTgeSJD3ieZ7RNO0VAXAPwDEAO5VKndi2fWrb9jWl9Esul6PZbDY9Go1OZ7PZ9z/lyuD3OozU2wAAAABJRU5ErkJggg==\">\n    </a>.\n  </div>\n  <div class=\"keyboard-glossary\">\n    <h2>Instructions for reporting errors</h2>\n    <p>We are continuing to improve HTML versions of papers, and your feedback helps enhance accessibility and mobile\n      support. To report errors in the HTML that will help us improve conversion and rendering, choose any of the\n      methods listed below:</p>\n    <ul>\n      <li>Click the \"Report Issue\" <span class=\"mobile-only\">(<svg role=\"presentation\"\n            style=\"display: inline-block; vertical-align: middle; fill: var(--text-color);\" aria-hidden=\"true\"\n            height=\"1em\" viewBox=\"0 0 640 640\">\n            <path\n              d=\"M224 160C224 107 267 64 320 64C373 64 416 107 416 160L416 163.6C416 179.3 403.3 192 387.6 192L252.5 192C236.8 192 224.1 179.3 224.1 163.6L224.1 160zM569.6 172.8C580.2 186.9 577.3 207 563.2 217.6L465.4 290.9C470.7 299.8 474.7 309.6 477.2 320L576 320C593.7 320 608 334.3 608 352C608 369.7 593.7 384 576 384L480 384L480 416C480 418.6 479.9 421.3 479.8 423.9L563.2 486.4C577.3 497 580.2 517.1 569.6 531.2C559 545.3 538.9 548.2 524.8 537.6L461.7 490.3C438.5 534.5 395.2 566.5 344 574.2L344 344C344 330.7 333.3 320 320 320C306.7 320 296 330.7 296 344L296 574.2C244.8 566.5 201.5 534.5 178.3 490.3L115.2 537.6C101.1 548.2 81 545.3 70.4 531.2C59.8 517.1 62.7 497 76.8 486.4L160.2 423.9C160.1 421.3 160 418.7 160 416L160 384L64 384C46.3 384 32 369.7 32 352C32 334.3 46.3 320 64 320L162.8 320C165.3 309.6 169.3 299.8 174.6 290.9L76.8 217.6C62.7 207 59.8 186.9 70.4 172.8C81 158.7 101.1 155.8 115.2 166.4L224 248C236.3 242.9 249.8 240 264 240L376 240C390.2 240 403.7 242.8 416 248L524.8 166.4C538.9 155.8 559 158.7 569.6 172.8z\" />\n          </svg>)</span> button, located in the page header.</li>\n    </ul>\n    <p><strong>Tip:</strong> You can select the relevant text first, to include it in your report.</p>\n    <p>Our team has already identified <a class=\"ltx_ref\" href=\"https://github.com/arXiv/html_feedback/issues\"\n        target=\"_blank\">the following issues</a>. We appreciate your time reviewing and reporting rendering errors we\n      may not have found yet. Your efforts will help us improve the HTML versions for all readers, because disability\n      should not be a barrier to accessing research. Thank you for your continued support in championing open access for\n      all.</p>\n    <p>Have a free development cycle? Help support accessibility at arXiv! Our collaborators at LaTeXML maintain a <a\n        class=\"ltx_ref\" href=\"https://github.com/brucemiller/LaTeXML/wiki/Porting-LaTeX-packages-for-LaTeXML\"\n        target=\"_blank\">list of packages that need conversion</a>, and welcome <a class=\"ltx_ref\"\n        href=\"https://github.com/brucemiller/LaTeXML/issues\" target=\"_blank\">developer contributions</a>.</p>\n  </div>\n</footer><footer class=\"ds-site-footer\">\n  <div class=\"ds-site-footer-grid\">\n    <div class=\"ds-site-footer-main\">\n      <div class=\"ds-site-footer-ack\">\n        We gratefully acknowledge support from\n        our <strong>major funders</strong>,\n        <a href=\"https://info.arxiv.org/about/ourmembers.html\"><strong>member institutions</strong></a><span class=\"ack-member-inline\" hidden>, <strong></strong></span>,\n        and all contributors.\n      </div>\n      <nav class=\"ds-site-footer-links\" aria-label=\"Site navigation\">\n        <a href=\"https://info.arxiv.org/about\">About</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help\">Help</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/contact.html\">Contact</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/subscribe\">Subscribe</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/license/index.html\">Copyright</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/policies/privacy_policy.html\">Privacy</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://info.arxiv.org/help/web_accessibility.html\">Accessibility</a>\n        <span class=\"ds-site-footer-sep\" aria-hidden=\"true\">&middot;</span>\n        <a href=\"https://status.arxiv.org\" target=\"_blank\" rel=\"noopener noreferrer\">Operational Status<span class=\"is-sr-only\"> (opens in new tab)</span></a>\n      </nav>\n    </div>\n\n    <div class=\"ds-site-footer-funders\" aria-label=\"Major funders\">\n      <div class=\"ds-site-footer-funders-label\">Major funding support from</div>\n      <div class=\"ds-site-footer-funders-logos\">\n        <a class=\"ds-funder-link\" href=\"https://www.simonsfoundation.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation.png\" alt=\"Simons Foundation\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.sfi.org.bm/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/simons-foundation-international.png\" alt=\"Simons Foundation International\">\n        </a>\n        <a class=\"ds-funder-link\" href=\"https://www.schmidtsciences.org/\" target=\"_blank\" rel=\"noopener noreferrer\">\n          <img class=\"ds-funder-logo\" src=\"/static/base/1.0.1/images/funders/schmidt-sciences.png\" alt=\"Schmidt Sciences\">\n        </a>\n      </div>\n    </div>\n  </div>\n</footer><div id=\"fixed-buttons-container\">\n  <a id=\"disable-reading-mode-btn\" class=\"header-button\" href=\"javascript:toggleReadingMode();\"\n    title=\"Disable reading mode, show header and footer\">\n    <svg role=\"presentation\" height=\"1.25rem\"\n      viewBox=\"0 0 448 512\"><!--!Font Awesome Free v7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.-->\n      <path\n        d=\"M0 96C0 78.3 14.3 64 32 64l384 0c17.7 0 32 14.3 32 32s-14.3 32-32 32L32 128C14.3 128 0 113.7 0 96zM0 256c0-17.7 14.3-32 32-32l384 0c17.7 0 32 14.3 32 32s-14.3 32-32 32L32 288c-17.7 0-32-14.3-32-32zM448 416c0 17.7-14.3 32-32 32L32 448c-17.7 0-32-14.3-32-32s14.3-32 32-32l384 0c17.7 0 32 14.3 32 32z\" />\n    </svg>\n  </a>\n</div></body>\n</html>\n","snapshot_chars":355593,"live_check":"matches"}]}