Network Working Group G. Palanisamy Internet-Draft Independent Intended status: Standards Track S. Mih Expires: 5 April 2027 Action State Group, Inc. 2 October 2026 The model_attestation Block for Agent Action Capsules: Model, Runtime, and Hardware Claims draft-palanisamy-scitt-aac-runtime-00 Abstract This document defines the model_attestation block of the Agent Action Capsule (AAC) profile — referenced twice by the base profile but never defined there — and, within it, the compute_attestation container that already carries runtime extensions in the field: the model-serving runtime, the agent's own execution environment (architectural pattern, orchestration framework, sandbox confinement, invoked tool version), and host hardware, together with model and weights claims. Every claim carries an explicitly declared source; a verifier grades claims by how they were observed and never infers a stronger grade than the evidence supports. Hardware or platform attestation, when present, is cited by content-addressed reference to a foreign attestation record and verified with that record's own verifier. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 5 April 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. Palanisamy & Mih Expires 5 April 2027 [Page 1] Internet-Draft AAC model_attestation October 2026 This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 2. Conventions and Definitions . . . . . . . . . . . . . . . . . 4 3. The model_attestation Block . . . . . . . . . . . . . . . . . 5 3.1. Model Members . . . . . . . . . . . . . . . . . . . . . . 6 3.1.1. Verification Grade Semantics . . . . . . . . . . . . 6 4. The compute_attestation Container . . . . . . . . . . . . . . 7 4.1. compute_attestation.runtime . . . . . . . . . . . . . . . 8 4.2. compute_attestation.agent_runtime . . . . . . . . . . . . 9 4.3. compute_attestation.invocation . . . . . . . . . . . . . 11 4.4. compute_attestation.hardware . . . . . . . . . . . . . . 13 4.5. compute_attestation.attestation_refs . . . . . . . . . . 14 5. Formal CDDL Specification . . . . . . . . . . . . . . . . . . 15 6. Relationship to Epochs . . . . . . . . . . . . . . . . . . . 17 7. Verification . . . . . . . . . . . . . . . . . . . . . . . . 17 8. Relationship to evidence stores and epistemic typing . . . . 18 9. Security Considerations . . . . . . . . . . . . . . . . . . . 18 10. Privacy Considerations . . . . . . . . . . . . . . . . . . . 19 11. Implementation Status . . . . . . . . . . . . . . . . . . . . 20 12. Conformance Vectors . . . . . . . . . . . . . . . . . . . . . 20 13. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 22 14. References . . . . . . . . . . . . . . . . . . . . . . . . . 22 14.1. Normative References . . . . . . . . . . . . . . . . . . 22 14.2. Informative References . . . . . . . . . . . . . . . . . 23 Appendix A. Fix to the base profile . . . . . . . . . . . . . . 24 Appendix B. Complete Example . . . . . . . . . . . . . . . . . . 24 Appendix C. Acknowledgments . . . . . . . . . . . . . . . . . . 26 Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 26 1. Introduction An agent action recorded in an Agent Action Capsule (AAC) is executed by a model running within a specific model-serving runtime, itself invoked by an agent process in a specific execution environment, on host hardware. Two capsules recording nominally identical actions can differ in what actually happened depending on model checkpoint, quantization, sandbox confinement, or the version of a tool package the agent invoked; without a record of that environment, a forensic Palanisamy & Mih Expires 5 April 2027 [Page 2] Internet-Draft AAC model_attestation October 2026 reviewer cannot tell a model-drift event from a compromised tool from an unconfined sandbox. The base profile [I-D.mih-scitt-agent-action-capsule] records the action, seals it under canonicalization [RFC8785], and MAY register its Capsule ID as independently transparent to a SCITT [RFC9943] Transparency Service; the agent-domain checks defined by the base profile are verified independently of that registration, by a Class 1 or Class 2 verifier, from the record's own bytes. Its epoch mechanism records baseline configuration shifts across actions. Although the base profile references a model_attestation block, it does not supply a formal definition. Two constraints matter. First, this extension is payload-extension- only: model_attestation lives in the Capsule JSON like every other payload member — the base profile's Section "Extensibility" states that all Capsule extension points are in the Capsule JSON — and it does not touch the Producer Envelope's protected header, which the base profile's Section "Producer Envelope wire profile" holds closed to exactly three entries (Section 3.1). Second, this extension MUST NOT change the base profile's Class 1 or Class 2 verification model (Sections 6 and 8.2); a verifier that does not implement it treats the block as informational (Section 3). This extension also imposes no mandatory transport dependency; it is silent on how a Capsule is delivered. model_attestation is a bare top-level payload member name, not a namespaced one. This follows from a fact specific to this field: the base profile already refers to model_attestation by that exact bare name, twice, without defining it (in its epoch-boundary Capsule section and in its Security Considerations), so the name is already reserved by the base profile itself rather than being minted here. This document supplies the definition for a name the base profile already uses, rather than introducing a new namespaced member. This document defines the model_attestation block, generalizes it to per-action use, and formalizes the model-serving runtime, agent execution environment, and hardware facts producers observe — all within the compute_attestation container (Section 4). The block is sealed directly inside the Capsule payload and participates in derived identifier generation (capsule_id). Palanisamy & Mih Expires 5 April 2027 [Page 3] Internet-Draft AAC model_attestation October 2026 The core design principle is honesty of source. A model name reported by the runtime is a claim; a weights digest computed over a loaded file is a stronger claim; a measurement signed by a hardware root of trust is stronger still. They represent distinct facts, and the record states which one it holds. A verifier that cannot resolve a claim to its stated source MUST report it as unresolved, MUST NOT report it as verified, and MUST NOT upgrade an unknown grade to a known one. This block complements rather than replaces the base profile's epoch machinery: it records per-action claims in force for an action while remaining scoped to the active epoch and prevailing epoch-boundary Capsule. model_id is RECOMMENDED, not REQUIRED, in Section 3.1: the epoch-boundary Capsule already records the model transition, and an extension MUST NOT out-mandate its base. 2. Conventions and Definitions The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. Capsule, Producer Envelope, epoch, epoch-boundary Capsule, epoch_id, derived identifier, typed digest reference, and data-admission tiers are used as defined in [I-D.mih-scitt-agent-action-capsule] and [I-D.mih-sokolov-scitt-payload-binding]. Attester, Verifier, and Evidence are used in the sense of [RFC9334] where foreign platform attestation is discussed. Source label: A standardized vocabulary declaring how a claim's value was obtained: self_reported (asserted by executing software), provider_reported (returned by a remote model provider or serving API and preserved by the producer without alteration), os_reported (reported by the host operating system), computed (calculated by the producer from bytes it held), or attested (cryptographically bound inside a verifiable foreign attestation record). Additional labels MUST be namespaced. Every source map in this document (at the model_attestation level and within each compute_attestation sub-object) follows the same default: if the map is omitted, or a field has no entry in it, a verifier MUST treat that field's source as self_reported. This rule is stated once here and applies wherever a source field appears below; it is not restated per sub-object. Palanisamy & Mih Expires 5 April 2027 [Page 4] Internet-Draft AAC model_attestation October 2026 3. The model_attestation Block A Capsule payload MAY carry a member named model_attestation. The block participates in the derived identifier like every payload member: it is canonicalized under JCS [RFC8785] and covered by capsule_id. A verifier that does not implement this extension MUST ignore it for verification and MUST NOT fail a Capsule solely because it is present. +=====================+========+=============+=================+ | Field | Type | Req | Meaning | +=====================+========+=============+=================+ | model_id | string | RECOMMENDED | See | | | | | Section 3.1. | +---------------------+--------+-------------+-----------------+ | provider | string | OPTIONAL | See | | | | | Section 3.1. | +---------------------+--------+-------------+-----------------+ | model_revision | string | OPTIONAL | See | | | | | Section 3.1. | +---------------------+--------+-------------+-----------------+ | weights_digest | object | OPTIONAL | See | | | | | Section 3.1. | +---------------------+--------+-------------+-----------------+ | quantization | string | OPTIONAL | See | | | | | Section 3.1. | +---------------------+--------+-------------+-----------------+ | decoding | object | OPTIONAL | See | | | | | Section 3.1. | +---------------------+--------+-------------+-----------------+ | source | object | OPTIONAL | Field to source | | | | | label mapping; | | | | | see above for | | | | | the omitted- | | | | | entry default. | +---------------------+--------+-------------+-----------------+ | compute_attestation | object | OPTIONAL | Container for | | | | | runtime/compute | | | | | facts | | | | | (Section 4). | +---------------------+--------+-------------+-----------------+ | epoch_consistency | string | OPTIONAL | consistent, | | | | | inconsistent, | | | | | or unknown | | | | | (Section 6). | +---------------------+--------+-------------+-----------------+ Table 1 Palanisamy & Mih Expires 5 April 2027 [Page 5] Internet-Draft AAC model_attestation October 2026 3.1. Model Members These members define the core model assertions referenced by the base profile's epoch section. They MAY appear in any Capsule and SHOULD appear in every epoch-boundary Capsule. +==============+======+===========+==============+=================+ |Field |Type |Req |Permitted | Meaning | | | | |Sources | | +==============+======+===========+==============+=================+ |model_id |string|RECOMMENDED|self_reported,| Model name as | | | | |os_reported, | reported by the | | | | |attested | runtime. | +--------------+------+-----------+--------------+-----------------+ |provider |string|OPTIONAL |self_reported,| Model provider | | | | |attested | or serving | | | | | | system. | +--------------+------+-----------+--------------+-----------------+ |model_revision|string|OPTIONAL |self_reported,| Provider- or | | | | |attested | repo-assigned | | | | | | revision. | +--------------+------+-----------+--------------+-----------------+ |weights_digest|object|OPTIONAL |computed, | {digest_alg, | | | | |attested | digest, scope} | | | | | | over loaded | | | | | | weights. | +--------------+------+-----------+--------------+-----------------+ |quantization |string|OPTIONAL |self_reported,| Quantization | | | | |computed, | label (e.g., | | | | |attested | Q4_K_M). | +--------------+------+-----------+--------------+-----------------+ |decoding |object|OPTIONAL |self_reported | Hyperparameters | | | | | | {temperature, | | | | | | top_p, seed}. | +--------------+------+-----------+--------------+-----------------+ Table 2 For weights_digest, scope MUST be either file (digest over serialized model bytes as loaded from storage) or tensors (digest over in-memory tensor structures, admissible only under attested). A digest of a reference string (e.g., a HuggingFace URI) MUST NOT be carried in weights_digest; such identifiers belong in model_id. 3.1.1. Verification Grade Semantics A verifier MAY derive grades according to the following matrix, never exceeding what source and accompanying evidence substantiate: Palanisamy & Mih Expires 5 April 2027 [Page 6] Internet-Draft AAC model_attestation October 2026 +==========================+===========================+ | Record Fact | Verifier May Report | +==========================+===========================+ | model_id only | model: self-reported name | +--------------------------+---------------------------+ | weights_digest (scope: | model: file-identified | | file, computed) | (recomputable) | +--------------------------+---------------------------+ | weights_digest (attested | model: attested at | | via Section 4.5) | declared scope | +--------------------------+---------------------------+ | quantization | quantization: claimed | | (self_reported) | | +--------------------------+---------------------------+ Table 3 A verifier MUST NOT report "model attested" from model_id alone, and MUST NOT report "quantization verified" from any field in this block, as none of these fields establish which underlying arithmetic was executed. Detection of substituted models or quantizations is out of scope for this record and belongs to redundancy or referee mechanisms at the system level. 4. The compute_attestation Container compute_attestation groups environment observations into five sub- objects: runtime (Section 4.1, the model-serving runtime), agent_runtime (Section 4.2, the agent's own execution environment), invocation (Section 4.3, what the model provider or serving API reported about this call), hardware (Section 4.4), and attestation_refs (Section 4.5), plus any namespaced member owned by another specification (for example x-mesh-lifecycle-v1, host_binding). runtime and agent_runtime are deliberately distinct: runtime describes the process that served the model's inference (for example, a local inference server or hosted serving stack); agent_runtime describes the process that orchestrated the action — the agent loop, its sandbox, and the tool it invoked — which may be a different process, on different infrastructure, than the one that served the model. A verifier MUST ignore members it does not recognize. A member MUST be absent rather than null when its fact is unavailable. Palanisamy & Mih Expires 5 April 2027 [Page 7] Internet-Draft AAC model_attestation October 2026 4.1. compute_attestation.runtime +====================+========+==============+=================+ | Field | Type | Req | Meaning | +====================+========+==============+=================+ | name | string | RECOMMENDED | Serving binary | | | | | name and | | | | | version. | +--------------------+--------+--------------+-----------------+ | runtime_digest | string | OPTIONAL | Digest of the | | | | | serving binary | | | | | as measured. | +--------------------+--------+--------------+-----------------+ | measurement_class | string | RECOMMENDED* | Class of | | | | | measurement | | | | | (*when digest | | | | | present). | +--------------------+--------+--------------+-----------------+ | platform_integrity | object | OPTIONAL | OS integrity | | | | | bits (e.g., | | | | | SIP, Secure | | | | | Boot). | +--------------------+--------+--------------+-----------------+ | source | object | OPTIONAL | Field to source | | | | | label mapping; | | | | | see above for | | | | | the omitted- | | | | | entry default. | +--------------------+--------+--------------+-----------------+ Table 4 Standard measurement_class values include self_measured, os_measured, tpm_measured, app_attested, mda_measured, and tee_measured. Field status at the time of writing: self_measured and os_measured are produced by shipping code; tee_measured has a record shape and verifier with real Intel TDX vectors; tpm_measured, app_attested, and mda_measured are named here so that the vocabulary is fixed before their producers exist. Unknown classes MUST be treated as unrecognized, never ordered above known classes; the classes are sibling roots of trust and the ordering above is meaningful only within a single root. Palanisamy & Mih Expires 5 April 2027 [Page 8] Internet-Draft AAC model_attestation October 2026 4.2. compute_attestation.agent_runtime Where runtime (Section 4.1) describes the process that served the model, agent_runtime describes the process that orchestrated the action: the agent loop or orchestration framework, the environment and confinement it ran in, and the version of any tool package it invoked to perform this specific action. This is the environment- blindness gap: two Capsules recording the same nominal action can behave differently depending on sandbox confinement or a tool package's version, and without this record a forensic reviewer cannot distinguish a compromised tool from an unconfined sandbox from a model-drift event. Palanisamy & Mih Expires 5 April 2027 [Page 9] Internet-Draft AAC model_attestation October 2026 +==============+========+==========+===============================+ | Field | Type | Req | Meaning | +==============+========+==========+===============================+ | agent_type | string | OPTIONAL | The agent's architectural | | | | | pattern (e.g., single_agent, | | | | | multi_agent_orchestrator, | | | | | react, plan_execute, | | | | | supervisor_worker). | +--------------+--------+----------+-------------------------------+ | framework | string | OPTIONAL | Agent orchestration framework | | | | | or agent-loop implementation, | | | | | name and version (e.g., | | | | | langchain 0.3.1, custom- | | | | | agent-loop 1.4.0). | +--------------+--------+----------+-------------------------------+ | runtime_env | string | OPTIONAL | Execution environment the | | | | | agent process ran in, name | | | | | and version (e.g., | | | | | python:3.11-slim, | | | | | node:20-alpine). | +--------------+--------+----------+-------------------------------+ | sandbox_type | string | OPTIONAL | Confinement mechanism | | | | | isolating the agent process | | | | | (e.g., gvisor, firecracker, | | | | | wasm, unconfined). | +--------------+--------+----------+-------------------------------+ | tool_version | string | OPTIONAL | Version or content digest of | | | | | the tool package this action | | | | | invoked, when the action | | | | | involved a specific tool. | +--------------+--------+----------+-------------------------------+ | source | object | OPTIONAL | Field to source label | | | | | mapping; see above for the | | | | | omitted-entry default. | +--------------+--------+----------+-------------------------------+ Table 5 agent_type names the architectural pattern the agent process implements for this action, not the specific framework instance (that is framework's job) or a claim about correctness. The seeded values above are illustrative, not exhaustive or registry-governed: single_agent (one model, one decision loop), multi_agent_orchestrator (a coordinating process dispatching to one or more sub-agents for this action), react (interleaved reasoning-and-acting loop), plan_execute (a separate planning phase precedes execution), and supervisor_worker (a supervisor process dispatches to worker processes it does not itself execute as). A value outside this list Palanisamy & Mih Expires 5 April 2027 [Page 10] Internet-Draft AAC model_attestation October 2026 follows the same namespacing discipline as constraint id/check_type in the base profile's Section "Namespacing convention": bare names are reserved for the values seeded here, and a party introducing a new value MUST namespace it with a URI or reverse-DNS prefix. A verifier treats an unrecognized agent_type value as informational, never as a validation failure — this field is descriptive metadata, not a graded claim, and carries no source-grading matrix of its own beyond the standard self-reported default. sandbox_type: "unconfined" is itself an informative claim, not an absent field: a producer that knows its agent process runs unconfined SHOULD say so rather than omit the field, since the omission and the honest disclosure of no confinement are otherwise indistinguishable to a verifier. As with every field in this document, sandbox_type and framework are self-reported unless graded otherwise by source or corroborated by an attestation_refs entry (Section 4.5); a verifier MUST NOT infer actual confinement strength from the label alone; gvisor and firecracker name mechanisms with different isolation properties, and this document does not rank them. 4.3. compute_attestation.invocation Commercial and self-hosted model APIs commonly return invocation metadata in addition to the text or tool output. This sub-object preserves such provider or runtime facts without standardizing any provider-specific response object. Every value here is a claim about what the serving side reported for this call; none of it is a measurement of the serving environment, which is what Section 4.1 and Section 4.4 carry. All fields below are OPTIONAL. +===================+======+==================+=====================+ |Field |Type |Permitted Sources |Meaning | +===================+======+==================+=====================+ |requested_model_id |string|self_reported |Model identifier the | | | | |caller asked for. | +-------------------+------+------------------+---------------------+ |resolved_model_id |string|provider_reported,|Model identifier | | | |self_reported, |reported as actually | | | |attested |serving the call. | +-------------------+------+------------------+---------------------+ |service_class |string|provider_reported,|Provider or runtime | | | |self_reported |processing tier. | | | | |Values are provider- | | | | |defined unless | | | | |registered by | | | | |another profile. | Palanisamy & Mih Expires 5 April 2027 [Page 11] Internet-Draft AAC model_attestation October 2026 +-------------------+------+------------------+---------------------+ |backend_fingerprint|string|provider_reported |Opaque provider- | | | | |issued deployment or | | | | |configuration | | | | |identifier. A | | | | |change-detection | | | | |value, not a | | | | |hardware | | | | |attestation. | +-------------------+------+------------------+---------------------+ |reasoning |object|provider_reported,|Declared reasoning | | | |self_reported |configuration (mode, | | | | |effort, summary | | | | |policy). Raw chain- | | | | |of-thought MUST NOT | | | | |appear here. | +-------------------+------+------------------+---------------------+ |usage |object|provider_reported,|Non-content | | | |self_reported |counters: input, | | | | |output, cached, and | | | | |reasoning tokens. | +-------------------+------+------------------+---------------------+ |finish_status |string|provider_reported,|Termination status: | | | |self_reported |completed, | | | | |incomplete, failed, | | | | |or a provider- | | | | |namespaced finish | | | | |reason. | +-------------------+------+------------------+---------------------+ |response_ref |object|provider_reported |Digest-only or | | | | |pairwise reference | | | | |to a provider | | | | |response identifier, | | | | |for later | | | | |correlation. Raw | | | | |provider request and | | | | |response identifiers | | | | |SHOULD NOT be | | | | |disclosed across | | | | |parties by default. | +-------------------+------+------------------+---------------------+ |reasoning_state_ref|object|provider_reported |Typed reference or | | | | |digest of an opaque | | | | |provider-issued | | | | |reasoning-continuity | | | | |artifact, when one | | | | |is returned. | | | | |Treated as opaque; | Palanisamy & Mih Expires 5 April 2027 [Page 12] Internet-Draft AAC model_attestation October 2026 | | | |this document | | | | |neither defines nor | | | | |requires disclosure | | | | |of internal | | | | |reasoning. | +-------------------+------+------------------+---------------------+ |source |object|— |Field to source | | | | |label mapping; see | | | | |Conventions for the | | | | |omitted-entry | | | | |default. | +-------------------+------+------------------+---------------------+ Table 6 reasoning MAY carry configuration metadata such as mode, effort, summary, or a provider-namespaced equivalent. It MUST NOT carry hidden chain-of-thought text, and a verifier MUST treat any text- valued member of reasoning as a profile violation of the base profile's data-admission tiers. A provider-issued opaque reasoning or thought signature MAY be referenced through reasoning_state_ref when the producer needs to bind the exact state token that was returned. The field names describe semantics, not a vendor API. An adapter MAY preserve additional provider fields under a provider-controlled namespace, subject to the base profile's data-admission rules. resolved_model_id complements, and never replaces, model_id at the model_attestation level: the former is what the provider said it served on this call, the latter is the identity the producer records for the epoch. 4.4. compute_attestation.hardware +==============+=========+==========+==============================+ | Field | Type | Req | Meaning | +==============+=========+==========+==============================+ | platform | string | OPTIONAL | Platform enum (e.g., intel- | | | | | tdx, amd-sev-snp, apple- | | | | | silicon). | +--------------+---------+----------+------------------------------+ | accelerator | string | OPTIONAL | Accelerator or GPU name as | | | | | reported. | +--------------+---------+----------+------------------------------+ | memory_bytes | integer | OPTIONAL | Unified or accelerator | | | | | memory in bytes. | +--------------+---------+----------+------------------------------+ | inventory | object | OPTIONAL | Coarse CPU/firmware topology | Palanisamy & Mih Expires 5 April 2027 [Page 13] Internet-Draft AAC model_attestation October 2026 | | | | details. | +--------------+---------+----------+------------------------------+ | source | object | OPTIONAL | Field to source label | | | | | mapping; see above for the | | | | | omitted-entry default. | | | | | Hardware is os_reported at | | | | | best without a corroborating | | | | | attestation_refs entry. | +--------------+---------+----------+------------------------------+ Table 7 *Never-enters.* Device serial numbers, platform UUIDs, MAC addresses, and other stable device identifiers MUST NOT appear in hardware, in clear or as a digest: they are stable identifiers of small effective entropy and re-identify a person's machine (base profile, "Data- Admission Tiers"). A producer that must later show "this was my machine" MAY carry a salted digest of such an identifier under an explicitly opt-in, namespaced field whose salt the producer retains; this document does not define that field. 4.5. compute_attestation.attestation_refs This document defines no attestation format. Where hardware or platform attestation exists, the Capsule cites it by a typed digest reference [I-D.mih-sokolov-scitt-payload-binding] — {type, purpose, digest_alg, digest} — where type resolves in the shared Artifact Type Registry to the foreign record's declared digest context: { "type": "example.tdx-quote-v1", "purpose": "hardware", "digest_alg": "SHA-256", "digest": "e3b0c442…b7852b855" } Verification of a cited attestation record is performed by the verifier that record's issuer publishes, never by a re-implementation in this profile's verifier. The result feeds this block as follows: * If the cited record verifies and binds weights_digest, runtime_digest, or platform measurement values equal to those carried here, the verifier MAY report those fields at source attested, at the grade the foreign verifier reports. A foreign verifier's intermediate grades MUST be carried through, not collapsed to a boolean. Palanisamy & Mih Expires 5 April 2027 [Page 14] Internet-Draft AAC model_attestation October 2026 * If the cited record does not verify, is absent, or binds different values, no field in this block is upgraded, and the verifier SHOULD report the citation as present-but-not-verified with the reason. * A cited record MUST be carried byte-identically; it is never re- minted or re-signed by the Capsule producer. 5. Formal CDDL Specification The following CDDL [RFC8610] grammar formally specifies the payload schema: model-attestation-block = { ? "model_id" => tstr, ? "provider" => tstr, ? "model_revision" => tstr, ? "weights_digest" => weights-digest-claim, ? "quantization" => tstr, ? "decoding" => decoding-params, ? "source" => source-map, ? "compute_attestation" => compute-attestation-container, ? "epoch_consistency" => "consistent" / "inconsistent" / "unknown", * tstr => any } source-label = "self_reported" / "provider_reported" / "os_reported" / "computed" / "attested" / tstr source-map = { * tstr => source-label } weights-digest-claim = { "digest_alg" => tstr, "digest" => tstr, "scope" => "file" / "tensors" / tstr } decoding-params = { ? "temperature" => float / int, ? "top_p" => float / int, ? "seed" => int, * tstr => any } compute-attestation-container = { Palanisamy & Mih Expires 5 April 2027 [Page 15] Internet-Draft AAC model_attestation October 2026 ? "runtime" => runtime-claims, ? "agent_runtime" => agent-runtime-claims, ? "invocation" => invocation-claims, ? "hardware" => hardware-claims, ? "attestation_refs" => [* foreign-attestation-ref], * tstr => any } runtime-claims = { ? "name" => tstr, ? "runtime_digest" => tstr, ? "measurement_class" => measurement-class-label, ? "platform_integrity" => { * tstr => any }, ? "source" => source-map } agent-runtime-claims = { ? "agent_type" => tstr, ? "framework" => tstr, ? "runtime_env" => tstr, ? "sandbox_type" => tstr, ? "tool_version" => tstr, ? "source" => source-map } invocation-claims = { ? "requested_model_id" => tstr, ? "resolved_model_id" => tstr, ? "service_class" => tstr, ? "backend_fingerprint" => tstr, ? "reasoning" => { * tstr => tstr / int / float / bool }, ? "usage" => { * tstr => uint }, ? "finish_status" => tstr, ? "response_ref" => { * tstr => any }, ? "reasoning_state_ref" => { * tstr => any }, ? "source" => source-map } measurement-class-label = "self_measured" / "os_measured" / "tpm_measured" / "app_attested" / "mda_measured" / "tee_measured" / tstr hardware-claims = { ? "platform" => tstr, ? "accelerator" => tstr, ? "memory_bytes" => uint, ? "inventory" => { * tstr => any }, Palanisamy & Mih Expires 5 April 2027 [Page 16] Internet-Draft AAC model_attestation October 2026 ? "source" => source-map } foreign-attestation-ref = { "type" => tstr, "purpose" => tstr, "digest_alg" => tstr, "digest" => tstr } 6. Relationship to Epochs The base profile's epoch-boundary Capsule records a macroscopic configuration shift across a registry or agent lifecycle. This block records the configuration in force for one action. The two MUST NOT contradict: a Capsule whose model_attestation names a model different from the one the prevailing epoch-boundary Capsule opened is either a producer defect or an unrecorded epoch change, and a verifier SHOULD report epoch_consistency: inconsistent regardless of what the producer stated. A producer that populates epoch_id SHOULD carry this block in the epoch-boundary Capsule with source labels, so the transition is commit-addressed as the base profile intends. 7. Verification This extension adds no additional verification semantics beyond the base profile's Class 1 and Class 2 verifier checks (Sections 6 and 8.2 of [I-D.mih-scitt-agent-action-capsule]) on the sealed AAC record. When this extension is implemented, a verifier MAY apply the checks below. 1. Validate field shapes against Section 5 and the source map; a field without a source entry is self_reported per Section 3. 2. For each entry in attestation_refs, resolve type per [I-D.mih-sokolov-scitt-payload-binding]; if resolvable and the record is available, invoke the issuer's verifier and record its result and grade. 3. Derive per-field grades per Section 3.1, never exceeding the stated source and the foreign verifier's result. 4. Report epoch_consistency from the ledger context when available. 5. Report unknown measurement_class or source labels as unrecognized, never as equal to or higher than a known class or label. Palanisamy & Mih Expires 5 April 2027 [Page 17] Internet-Draft AAC model_attestation October 2026 6. Treat agent_runtime fields (Section 4.2) as self-reported by default and never infer confinement strength from sandbox_type's value; this document ranks no sandbox mechanism against another. 7. Treat invocation fields (Section 4.3) labelled provider_reported as the provider's claim preserved by the producer: a verifier MUST NOT report a provider_reported value as computed or attested, and MUST NOT report resolved_model_id as establishing model identity on its own. 8. Relationship to evidence stores and epistemic typing A local evidence store MAY preserve these fields as evidence about the execution environment. The source labels in this document describe how a specific field value was obtained and are intentionally narrower than a general evidence taxonomy. An implementation that maps them onto a wider taxonomy SHOULD do so without silently upgrading them, for example: * self_reported: a producer claim; * provider_reported: a claim returned by a remote provider or API and preserved by the producer; * os_reported: an observation attributed to an operating-system source; * computed: a deterministic derivation over identified bytes; and * attested: a claim supported by a separately verified attestation record. Tool-call content, tool-call result content, prompt and context material, intentionally emitted rationale artifacts, human reports, semantic judgments, outcome adjudications, and regulatory obligation results are outside this block even when they concern the same action. They belong to separate records or extensions and may be linked by typed references. 9. Security Considerations All claims in this block outside of an independently validated attestation_refs record are assertions made by the Capsule producer. The function of this profile is not to make those claims true but to make them specific, signed, and non-repudiable under the AAC verifier acceptance path. A producer that later serves a different model than it claimed has signed the discrepancy. Claims about which arithmetic ran (quantization, precision) cannot be verified from any record the Palanisamy & Mih Expires 5 April 2027 [Page 18] Internet-Draft AAC model_attestation October 2026 producer alone signs; systems that need that assurance obtain it by redundancy or hardware attestation, outside this document. The same honesty-of-source discipline applies to agent_runtime (Section 4.2): sandbox_type: "unconfined" is exactly as signed and non-repudiable as any other value, which is what lets a forensic reviewer later distinguish an unconfined sandbox that was disclosed from one that was silently omitted. A verifier MUST NOT round up: an unknown measurement_class, an unresolvable attestation_refs.type, or a source label it does not know is reported as unrecognized, never treated as the highest grade the verifier knows. This rule exists because the failure it prevents — a forged grade string accepted by an old verifier — is otherwise cheap. 10. Privacy Considerations Every field in this block is subject to the base profile's data- admission tiers (clear-safe, digest-only, never-enters) and its default-deny posture: producers and adapters MUST classify each candidate field before admission, and MUST NOT admit a field merely because this document does not mention it. model_id, provider, and decoding.seed are deployment or run parameters and clear-safe: they describe the model and its configuration, not a person. weights_digest and runtime_digest are digests of software artifacts and carry no end-user privacy exposure on their own; a producer MUST still ensure the artifact digested does not itself embed tenant- or user-identifying material — a model fine- tuned on a single tenant's private corpus is itself a sensitive artifact, and digesting it does not launder that sensitivity, so model_id and weights_digest for such a model are tier-appropriate to the tenant's own data, not automatically clear-safe. agent_runtime.agent_type, .framework, .runtime_env, and .sandbox_type are ordinarily deployment constants and clear-safe. agent_runtime.tool_version is clear-safe only when the tool package identifier or digest does not itself encode end-user or tenant- identifying information (for example, a tenant-named internal tool, or a per-tenant container image tag); a producer whose tool naming does so MUST treat the field as digest-only or omit it. A producer for whom agent_type, framework, runtime_env, or sandbox_type varies per end-user request or per tenant (for example, per-tenant sandbox images keyed to a customer) MUST re-evaluate that field's tier rather than relying on the clear-safe default stated here, since a per- tenant value is then itself a tenant-correlation handle. Palanisamy & Mih Expires 5 April 2027 [Page 19] Internet-Draft AAC model_attestation October 2026 hardware.inventory is intentionally constrained to prevent device fingerprinting: device serial numbers, MAC addresses, platform UUIDs, and other persistent hardware identifiers MUST NOT appear in compute_attestation, in clear or as a digest, per Section 4.4. No field defined in this block is an end-user or session identifier at any tier; none should be added without also updating this section. 11. Implementation Status This section records the status of known implementations of this block at the time of posting, per [RFC7942]. It is to be removed before publication as an RFC. Mesh-LLM capsule plugin (Apache-2.0, Rust and Python): a producer at the inference boundary of a peer-to-peer model-serving network. It writes compute_attestation.runtime with a SHA-256 digest of the serving binary and a measurement_class of os_measured where the host operating system can report it and self_measured otherwise, and records serving provenance (serving node, requesting party, token usage, generation parameters) under a namespaced member of compute_attestation. Quantization and hardware facts the host does not expose are recorded as absent, never fabricated. A name hash is recorded under a field name that says it is a name hash, after an earlier field name that overclaimed a weights binding was renamed. Its reference library reads model_attestation in its verifier, ledger, disclosure, and viewer paths. capsule-emit (Apache-2.0, Python): the reference emitter and verifier treats model_attestation.compute_attestation as the extension container for runtime and compute facts, and other extensions (for example the OpenTelemetry correlation block of draft-palanisamy- scitt-aac-otel) are placed there today. 12. Conformance Vectors This is a tier-2 (per-profile) extension in the sense of [I-D.mih-agent-accountability-conformance]: it defines its own semantics and must-fail cases on top of the tier-1 binding conformance that [I-D.mih-sokolov-scitt-payload-binding] (CPB) defines for every AAC payload member. This document is not itself a binding-layer artifact and does not register a type in the CPB Artifact Type Registry; that registry governs the type field of a typed digest reference — used here only by attestation_refs entries (Section 4.5) — a different and narrower thing than a named payload extension like model_attestation itself. Palanisamy & Mih Expires 5 April 2027 [Page 20] Internet-Draft AAC model_attestation October 2026 As of this writing, the registry structure for tier-2 (per-profile) conformance artifacts is explicitly not yet specified — [I-D.mih-agent-accountability-conformance] states plainly that this is "TBD in a future revision." This document therefore cannot cite a settled registration procedure for itself, and does not assert one. What it does provide now, so that registration is a formality once the tier-2 registry exists rather than a rewrite, is the two-sided conformance-vector set that document's discipline (Section 5) requires of any record profile: positive vectors with pinned values, and must-fail vectors that a conformant implementation MUST refuse rather than merely mismatch. Positive vector (MUST be accepted, and graded per Section 3.1 and Section 4.5 without exceeding the stated source): { "model_attestation": { "model_id": "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M", "weights_digest": { "digest_alg": "SHA-256", "digest": "1993f98e…", "scope": "file" }, "source": { "model_id": "self_reported", "weights_digest": "computed" }, "compute_attestation": { "runtime": { "name": "mesh-llm-host-runtime 0.76.0", "measurement_class": "os_measured" }, "agent_runtime": { "agent_type": "react", "sandbox_type": "gvisor", "tool_version": "sha256:9b7412f8…" }, "attestation_refs": [] } } } MUST-FAIL vectors (a conformant verifier MUST NOT grade the field above what these rules permit): Palanisamy & Mih Expires 5 April 2027 [Page 21] Internet-Draft AAC model_attestation October 2026 // (a) weights_digest present with no "source" entry: MUST default // to self_reported, MUST NOT be treated as "computed" or "attested". { "model_attestation": { "weights_digest": { "digest_alg": "SHA-256", "digest": "1993f98e…", "scope": "file" } } } // (b) unrecognized measurement_class: MUST be reported as // unrecognized, MUST NOT be treated as equal to or higher than any // known class. { "model_attestation": { "compute_attestation": { "runtime": { "name": "custom-runtime 1.0", "measurement_class": "quantum_measured" } } } } // (c) attestation_refs entry whose cited record does not verify: no // field in the block may be upgraded to "attested" on account of the // citation. { "model_attestation": { "weights_digest": { "digest_alg": "SHA-256", "digest": "1993f98e…", "scope": "file" }, "source": { "weights_digest": "attested" }, "compute_attestation": { "attestation_refs": [ { "type": "example.invalid-attestation-v1", "purpose": "hardware", "digest_alg": "SHA-256", "digest": "0000…" } ] } } } // (d) agent_runtime.tool_version present with no "source" entry: // MUST default to self_reported, MUST NOT be treated as "computed". { "model_attestation": { "compute_attestation": { "agent_runtime": { "tool_version": "sha256:9b7412f8…" } } } } 13. IANA Considerations This document has no IANA actions. model_attestation is a bare payload member name seeded by the base profile itself (Section 3), not a namespaced extension, so the base profile's namespacing convention does not apply to the member name. Source labels and measurement classes are closed vocabularies of this document (Conventions and Section 4.1); a future revision may request IANA registries for either if independent extensions appear. Registration of this document as a conforming tier-2 profile awaits the registry work noted in Section 12. 14. References 14.1. Normative References Palanisamy & Mih Expires 5 April 2027 [Page 22] Internet-Draft AAC model_attestation October 2026 [I-D.mih-scitt-agent-action-capsule] Mih, S., "An Agent Action Capsule Profile for SCITT", Work in Progress, Internet-Draft, draft-mih-scitt-agent-action- capsule-05, 26 September 2026, . [I-D.mih-sokolov-scitt-payload-binding] Mih, S. and A. Sokolov, "Canonicalization Declaration for SCITT Signed Statements", Work in Progress, Internet- Draft, draft-mih-sokolov-scitt-payload-binding-05, 12 September 2026, . [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . [RFC8610] Birkholz, H., Vigano, C., and C. Bormann, "Concise Data Definition Language (CDDL): A Notational Convention to Express Concise Binary Object Representation (CBOR) and JSON Data Structures", RFC 8610, DOI 10.17487/RFC8610, June 2019, . [RFC8785] Rundgren, A., Jordan, B., and S. Erdtman, "JSON Canonicalization Scheme (JCS)", RFC 8785, DOI 10.17487/RFC8785, June 2020, . 14.2. Informative References [I-D.mih-agent-accountability-conformance] Mih, S., "Agent Accountability: A Conformance and Verification Method", Work in Progress, Internet-Draft, draft-mih-agent-accountability-conformance-00, 31 July 2026, . [RFC7942] Sheffer, Y. and A. Farrel, "Improving Awareness of Running Code: The Implementation Status Section", BCP 205, RFC 7942, DOI 10.17487/RFC7942, July 2016, . Palanisamy & Mih Expires 5 April 2027 [Page 23] Internet-Draft AAC model_attestation October 2026 [RFC9334] Birkholz, H., Thaler, D., Richardson, M., Smith, N., and W. Pan, "Remote ATtestation procedureS (RATS) Architecture", RFC 9334, DOI 10.17487/RFC9334, January 2023, . [RFC9943] Birkholz, H., Delignat-Lavaud, A., Fournet, C., Deshpande, Y., and S. Lasker, "An Architecture for Trustworthy and Transparent Digital Supply Chains", RFC 9943, DOI 10.17487/RFC9943, June 2026, . Appendix A. Fix to the base profile Revisions -04 and -05 of draft-mih-scitt-agent-action-capsule reference model_attestation in their epoch-boundary section and their security considerations without defining it, while producers and a registry entry already use the block. This document supplies the definition (Section 3, Section 3.1). The authors recommend that -06 of the base profile (a) cite this document for the definition or fold Section 3 in, and (b) name the two extension containers explicitly: namespaced top-level members for correlation/provenance extensions, and model_attestation.compute_attestation for runtime and compute extensions. Until (b) lands, implementations place namespaced extensions under model_attestation.compute_attestation as well (see Section 11). Appendix B. Complete Example The following is an example of a complete model_attestation object: { "model_attestation": { "model_id": "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M", "provider": "mesh-llm", "weights_digest": { "digest_alg": "SHA-256", "digest": "1993f98e…04724b12", "scope": "file" }, "quantization": "Q4_K_M", "decoding": { "temperature": 0.0, "seed": 42 }, "source": { "model_id": "self_reported", "weights_digest": "computed", Palanisamy & Mih Expires 5 April 2027 [Page 24] Internet-Draft AAC model_attestation October 2026 "quantization": "self_reported" }, "compute_attestation": { "runtime": { "name": "mesh-llm-host-runtime 0.76.0", "runtime_digest": "c204ac76…4f23b723", "measurement_class": "os_measured", "platform_integrity": { "sip_enabled": true }, "source": { "sip_enabled": "os_reported" } }, "agent_runtime": { "agent_type": "react", "framework": "custom-agent-loop 1.4.0", "runtime_env": "python:3.11-slim", "sandbox_type": "gvisor", "tool_version": "sha256:9b7412f8…12345678", "source": { "agent_type": "self_reported", "framework": "self_reported", "runtime_env": "self_reported", "sandbox_type": "os_reported", "tool_version": "computed" } }, "invocation": { "requested_model_id": "hermes-2-pro-7b", "resolved_model_id": "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M", "usage": { "input_tokens": 412, "output_tokens": 88 }, "finish_status": "completed", "source": { "requested_model_id": "self_reported", "resolved_model_id": "provider_reported", "usage": "provider_reported", "finish_status": "provider_reported" } }, "hardware": { "platform": "apple-silicon", "accelerator": "Apple M4 Max", "memory_bytes": 28991029248, "source": { "platform": "os_reported", "accelerator": "os_reported", Palanisamy & Mih Expires 5 April 2027 [Page 25] Internet-Draft AAC model_attestation October 2026 "memory_bytes": "os_reported" } }, "attestation_refs": [] }, "epoch_consistency": "consistent" } } Appendix C. Acknowledgments The authors thank the maintainers of the Mesh-LLM capsule plugin, whose shipping runtime measurements fixed the first two measurement classes, and the reviewers of the RATS architecture whose grading discipline Section 4.5 follows. Authors' Addresses Govindaraj Palanisamy Independent Email: npgovintarajan@gmail.com Steven Mih Action State Group, Inc. Email: steven@actionstate.ai Palanisamy & Mih Expires 5 April 2027 [Page 26]