Hardware-rooted attestation for AI-agent evidence: composing IETF RATS with action evidence packages
arXiv SecurityArchived Aug 04, 2026✓ Full text saved
arXiv:2608.00801v1 Announce Type: new Abstract: An action evidence package (AEP) is a signed, append-only record of what an AI agent did, who or what authorised the action, and what the outcome was. It is a software-layer artefact: it tells a verifier the story of an action as the agent's own runtime reports it. This note argues that software attestation of this kind is necessary but not sufficient. When a verifier's question shifts from "what does the agent claim it did?" to "did the specific m
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Cryptography and Security
[Submitted on 1 Aug 2026]
Hardware-rooted attestation for AI-agent evidence: composing IETF RATS with action evidence packages
Anton Sokolov
An action evidence package (AEP) is a signed, append-only record of what an AI agent did, who or what authorised the action, and what the outcome was. It is a software-layer artefact: it tells a verifier the story of an action as the agent's own runtime reports it. This note argues that software attestation of this kind is necessary but not sufficient. When a verifier's question shifts from "what does the agent claim it did?" to "did the specific model version the operator claims to have deployed actually produce this output, on unmodified hardware?", the AEP alone cannot answer. The missing element is a hardware root of trust: an attestation that the measured boot and runtime state of the platform match an endorsed reference. The IETF Remote Attestation Procedures (RATS) architecture (RFC 9334) and Veraison, an open-source RATS Verifier implementation (Confidential Computing Consortium / Linux Foundation), supply exactly this. We propose a composite attestation: hardware Evidence appraised under RATS, bound to a software AEP. We map a small verifier vocabulary (Authorised / Unauthorised / Indeterminate / Attested / Contested / Expired) onto RATS appraisal outcomes, and demonstrate feasibility with a small executed experiment: on a software Trusted Platform Module (TPM; the swtpm emulator), an output-binding protocol folds the hash of an AEP outcome and a fresh appraiser nonce into an attestation-key-signed quote, with a model-artefact measurement carried in a platform register. A minimal RATS-Verifier stand-in resolves the three platform outcomes as designed -- Attested for a good, fresh quote; Contested when the model measurement is swapped; Expired when a stale quote is replayed -- and rejects a forged AEP outcome bound to a valid quote. The result is a feasibility demonstration on emulated hardware, not a hardware-rooted guarantee.
Comments: 9 pages, 1 figure, 1 table. Technical note. Also deposited at Zenodo: doi:https://doi.org/10.5281/zenodo.20818671
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2608.00801 [cs.CR]
(or arXiv:2608.00801v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.00801
Focus to learn more
Submission history
From: Anton Sokolov [view email]
[v1] Sat, 1 Aug 2026 18:01:36 UTC (13 KB)
Access Paper:
HTML (experimental)
view license
Current browse context:
cs.CR
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)