Internet-Draft draft-das-protocols-enterprise-ai-00.txt is now available.
Title: Architecting Resilience for Enterprise AI: Preventing Data Reconstruction, Exfiltration, and Unauthorized Consequence in Compromised AI Environments (DAS Protocols)
Author: Sangam Das
Name: draft-das-protocols-enterprise-ai-00.txt
Pages: 36
Dates: 2026-08-27
Abstract:
A compromised enterprise AI server is no longer just a data-breach
risk. It can become a continuously updated reconstruction engine of
the enterprise’s future — correlating customer records, engineering
defects, financial systems, and internal communications into
competitive intelligence and then externalizing that intelligence.
Conventional security concentrates the powers of data access,
semantic joining, and external effectuation inside the same workload.
When that workload is compromised through prompt injection, model
substitution, credential theft, or full server takeover, existing
access-control, sandbox, TEE, DLP, and clean-room approaches do not
structurally stop the escalation from computation to real-world
consequence.
This document presents the DAS Protocols enterprise-AI architecture,
a focused embodiment of the broader execution-finality framework
disclosed in PCT/IB2026/055615 (“THE DAS PROTOCOLS”). It introduces
Execution–Consequence Decoupling enforced by three pillars:
Decomposition of Authority (Technical Non-Joinability) across
independently controlled identity, content, relationship-mapping, and
cryptographic vaults; Mandatory Mediation of every consequence-
bearing Candidate Output; and Technical Non-Completability so that
computation can finish without the ability to complete external
consequence.
Reconstruction is governed by a non-bearer Reconstruction
Authorization Object bound to attested execution context, session,
purpose, and Permitted Association Scope. Candidate Outputs are
sealed. Live output-time re-verification and constitutive Protected
Output Validation Receipt commitment are required before an output-
specific Release Capability can be issued and exercised only at a
designated Output Release Boundary. Compromise of the AI computation
plane therefore cannot automatically escalate into unrestricted
enterprise-knowledge reconstruction or unauthorized external
consequence.
The document elaborates the full problem space, compares the
architecture against representative conventional technologies,
provides a detailed technical description, and supplies JSON Schema
definitions for the core protected objects (Reconstruction
Authorization Object, Protected Output Validation Receipt, and Output
Release Capability). Intellectual-property disclosures of related
Indian provisional applications and PCT filings appear in the final
appendix.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-das-protocols-enterprise-ai/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-das-protocols-enterprise-ai-00.html
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.