I-D Action: draft-das-hardware-enforced-execution-finality-00.txt

[email protected]
Newsgroups gmane.ietf.announce
Message-ID <178776548526.798776.6305593526603340462@dt-datatracker-786f84c586-97d96>
Internet-Draft draft-das-hardware-enforced-execution-finality-00.txt is now
available.

   Title:   Hardware-Rooted National Control to Prevent Covert Intelligence Data Export and Unauthorized Frontier and Neural AI/Autonomous Acts in Critical Infrastructure
   Author:  Sangam Das
   Name:    draft-das-hardware-enforced-execution-finality-00.txt
   Pages:   93
   Dates:   2026-08-26

Abstract:

   Modern security architecture has traditionally focused on who or what
   may access a system, data object, network, device, application, or
   service.  Authentication, authorization, sandboxing, access control,
   encryption, application permissions, network policy, identity
   management, and audit logging were generally sufficient when most
   consequential operations were initiated, reviewed, or completed
   through relatively predictable human-directed software flows.

   That assumption is changing.

   Ten years ago, there was substantially less need for a distinct
   execution-finality security layer because most artificial-
   intelligence systems were primarily analytical, classificatory,
   predictive, or advisory.  A model could classify an image, rank
   search results, recommend content, detect patterns, translate text,
   or generate a prediction, but it generally could not autonomously
   discover external tools, recruit other agents, operate browsers,
   invoke APIs, modify persistent memory, initiate payments, reconfigure
   networks, control accelerators, export sensitive information,
   communicate directly with machines, or cause physical and
   communications effects at machine speed.  The human operator,
   application workflow, operating system, or another conventional
   software boundary often remained the practical final boundary between
   computation and consequence.

   In contemporary agentic and autonomous systems, that boundary is
   increasingly disappearing.  A model output may become a tool call; a
   tool call may become an API transaction; an autonomous agent may
   delegate to another agent; an application with location access may
   automatically transmit precise coordinates; an AI-controlled network
   function may modify routing or resource allocation; and an AI-
   generated instruction may become a payment, RF emission, satellite
   command, memory write, database commit, network transmission, or
   actuator signal without a separate technical decision immediately
   before the consequence occurs.

   This creates a different class of security problem:

   successful computation, authentication, data access, application
   permission, model approval, or upstream authorization does not
   necessarily establish authority for the resulting consequence.

   Precise geolocation provides a particularly important example.

   Traditional mobile-security models frequently treat location
   permission as an application-level access question: whether an
   application may obtain location information.  In the AI era, however,
   precise latitude and longitude should increasingly be treated as
   high-value inference material rather than as ordinary application
   metadata.

   A single GPS coordinate may reveal little.  Thousands or millions of
   coordinates, timestamps, movement traces, device observations,
   proximity records, public-map information, telemetry signals,
   communications metadata, and other apparently low-sensitivity
   fragments can be correlated by modern AI systems to infer information
   that was never explicitly contained in any individual record.

   Such inference may reveal movement patterns, home and workplace
   relationships, protected-person movements, operational routines,
   sensitive infrastructure, military activity, research facilities,
   industrial sites, or other strategically significant information.

   The important security problem is therefore no longer limited to:

   "Was the secret database breached?"

   A future attacker or intelligence system may instead ask:

   "Can the secret be reconstructed from ordinary data that many
   applications were permitted to collect?"

   This distinction becomes increasingly important because contemporary
   machine-learning systems can perform correlation, clustering, anomaly
   detection, temporal analysis, multimodal fusion, relationship
   inference, and large-scale pattern recognition far more rapidly and
   economically than was practical for routine use a decade ago.

   The inference itself was not impossible ten years ago.  What has
   changed is its scale, automation, cost, speed, and accessibility.

   Accordingly, not every application, SDK, analytics component,
   advertising library, AI agent, browser process, cloud service, or
   external endpoint should automatically receive precise GPS
   coordinates merely because some component of the application stack
   possesses location permission.

   A weather application may need only a city.

   A local-search application may need only an approximate area.

   A recommendation service may require a regional location.

   An emergency, navigation, rescue, or safety-critical application may
   legitimately require exact coordinates.

   An unrelated analytics or advertising component may require no
   location at all.

   Precise location should therefore be treated not merely as readable
   data, but as a consequence-bearing disclosure whose permitted
   precision can be independently verified before release.

   This document describes a hardware-rooted execution-finality
   architecture in which a proposed consequence-bearing operation is
   represented as a Candidate Act and maintained in a Non-Effective
   State until protected validation and independent Finality Sink
   verification succeed.

   A Protected Enforcement Domain evaluates act-specific conditions that
   may include authority, purpose, instruction provenance, requesting
   application or agent identity, permitted scope, recipient,
   destination, jurisdiction, data class, data precision, policy epoch,
   revocation state, protected state, runtime behavior, permitted
   consequence class, and Finality Sink identity.

   Protected validation evidence is committed before, or atomically
   with, release of scoped non-bearer finality authority.

   The applicable Finality Sink independently verifies that authority
   immediately before the operation becomes externally or operationally
   effective.

   For a location-data Candidate Act, the result may therefore be:

   exact location permitted;

   coarse location permitted;

   city-level or regional location permitted;

   delayed, randomized, grid-based, or otherwise reduced location
   permitted; or

   location disclosure denied.

   If exact coordinates are not authorized, possession of exact
   coordinates inside the application or protected environment does not
   itself authorize those coordinates to cross the relevant data-egress
   boundary.

   The architecture is jurisdiction-neutral.  It does not prescribe
   whether the governing rule originates in the United States, the
   European Union, China, India, another sovereign jurisdiction, an
   enterprise policy, a telecommunications operator, or a user-
   controlled privacy policy.

   Instead, it provides a technical mechanism by which the applicable
   regulatory, sovereign, organizational, contractual, or user-
   authorized policy can be evaluated before a protected consequence
   becomes effective.

   Thus, a system may determine:

   "This application is allowed to use exact GPS locally, but this
   destination is authorized to receive only city-level location."

   or:

   "This recipient is authorized to receive exact coordinates for
   emergency response."

   or:

   "This foreign destination is not authorized to receive this location
   information."

   The same architectural principle applies beyond location information
   to agentic AI, sovereign data export, AI-native 5G and 6G, O-RAN, GPU
   and accelerator egress, confidential computing, satellite and non-
   terrestrial networks, financial settlement, and cyber-physical
   infrastructure.

   This requirement becomes still more important as 6G develops.

   The International Telecommunication Union's IMT-2030 framework for 6G
   includes Artificial Intelligence and Communication and Integrated
   Sensing and Communication as distinct usage scenarios.  Current
   IMT-2030 work also anticipates substantially enhanced positioning and
   sensing capabilities, including object detection, localization,
   mapping, AI-enabled processing, ubiquitous intelligence, and very
   high precision positioning.

   This means that the future security problem will not simply involve
   more applications connected to a faster network.

   The network environment itself is expected to become more
   intelligent, more sensing-aware, more densely connected, more
   autonomous, and more capable of combining communications,
   computation, positioning, and environmental information.

   Without a corresponding consequence-control boundary, the combination
   of AI, precise location, integrated sensing, ubiquitous connectivity,
   autonomous agents, cloud and edge computation, and machine-speed
   communication risks undermining traditional assumptions on which both
   cybersecurity and privacy have relied.

   The result could be a collapse of the conventional distinction
   between harmless metadata and sensitive intelligence:

   data that is individually ordinary may become strategically sensitive
   after AI inference.

   It could also collapse the traditional distinction between software
   permission and real-world authority:

   an application may be authorized to read information while being
   unauthorized to disclose it;

   an AI may be authorized to compute while being unauthorized to act;

   a network function may be authenticated while being unauthorized to
   cause a particular network consequence.

   The security boundary must therefore move closer to the consequence
   itself.

   If required finality authority is absent, stale, replayed, revoked,
   consumed, act-mismatched, scope-mismatched, precision-mismatched,
   jurisdiction-mismatched, policy-mismatched, or sink-mismatched, the
   Candidate Act remains non-effective and the protected consequence
   fails closed.

   The central security principle is:

   COMPUTATION IS NOT AUTHORITY.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-das-hardware-enforced-execution-finality/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-das-hardware-enforced-execution-finality-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.