Internet-Draft draft-reilly-sentinel-protocol-02.txt is now available.
Title: Reilly Sentinel Protocol (RSP): Blockchain-Anchored Integrity for AI Datasets, Training, Fine-Tuning, and Inference Provenance
Author: Lawrence John Reilly Jr.
Name: draft-reilly-sentinel-protocol-02.txt
Pages: 44
Dates: 2026-08-24
Abstract:
The Reilly Sentinel Protocol (RSP) specifies an interoperable,
multi-layer method for establishing integrity, provenance, and
auditability across the artificial intelligence (AI) lifecycle.
RSP defines a Sentinel Evidence Package (SEP) that binds payload
digests, provenance metadata, signatures, blockchain timestamp
proofs, and resolvable identifiers. This enables tamper-evident,
independently verifiable receipts for datasets, data
transformations, training jobs, checkpoints, fine-tuning runs,
evaluations, inference outputs, and agentic AI action logs.
This revision (-02) supersedes draft-reilly-sentinel-protocol-01
and corrects defects in it. The cross-chain binding hash of -01
was computed under SHA3-512 alone over an unframed concatenation
of hex strings, which made a single algorithm the point of failure
for a construction whose stated purpose was to survive the failure
of any single algorithm, and which admitted field-boundary
ambiguity. It is replaced by an entangled link construction over
a fixed-length framed input, with a concatenated braid that
privileges no algorithm. The post-quantum analysis of -01 applied
Grover's algorithm to collision resistance, a property Grover does
not meaningfully reduce, and stated SHA-256's collision resistance
as 256 bits when it is 128 bits classically. The claim that
combining three hash functions requires an adversary to break all
three is replaced, following [JOUX], by a hedging claim. Merkle
tree construction, left unspecified in -01 while relied upon by
three separate extensions, is now normatively specified per
[RFC6962]. Digest-only selective disclosure is replaced by salted
commitments. Automated repair of chain integrity violations is
prohibited.
RSP is transport-agnostic and serializable in JSON and CBOR. It
leverages existing IETF building blocks including COSE signatures,
CBOR, CDDL, JSON, and NTS-secured time. Anchoring is done via
append-only blockchain receipts and identity is stabilized with
persistent identifiers.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-reilly-sentinel-protocol/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-reilly-sentinel-protocol-02
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-reilly-sentinel-protocol-02
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.