MachineMandate: Real-Phone Evidence Bundle — Bounded SD-JWT VC Delegation to an Autonomous LLM Agent in an EUDI Reference-Wallet Build, with Attested Four-Gate Enforcement
收藏资源简介:
Version 1.2 (11 August 2026) — correction notice added. The offline reproduction accompanying this evidence derived its session challenge from the TPM quote it was checking, so its freshness comparison was circular and a literal replay passed; the published seven-row gate ablation's replay row was denied on appraisal status, not freshness. The 2026-07-06 real-phone evidence in this bundle is unaffected and every v1.1 file remains byte-identical under the previously signed MANIFEST.sha256 and RFC-3161 token; what changes is the interpretation of the offline replay validation. Full statement: CORRECTION-NOTICE.md in this version; corrected preprint under concept DOI 10.5281/zenodo.21229864; corrected artifact at github.com/tyche-institute/machine-mandate. A new MANIFEST-v1.2.sha256 covers all files of this version including the notice. v1.1 (2026-07-07) correction. The demonstration date is corrected to 2026-07-06 (v1.0 mislabelled it 2026-07-04; the SD-JWT/KB-JWT iat and capture metadata in the bundle show 2026-07-06). The hackathon field-scan denominator is 8 distinct agentic projects (not 9), and the human-in-the-loop transaction_data finding is scoped to the wallet application layer, after an adversarial claim-verification pass. No cryptographic evidence changed. Primary evidence bundle for a demonstration (2026-07-04, capture over public rails 2026-07-06) in which a MachineMandate — an SD-JWT verifiable credential expressing a bounded, machine-readable grant of authority to an autonomous AI agent — is issued over OpenID4VCI into a commit-pinned build of the EU Digital Identity reference wallet, presented over OpenID4VP from a physical Android phone, and enforced by a verifier that actively denies out-of-mandate actions. Claim (composition, to our knowledge, as of 2026-07-04): first demonstration of a verifier that actively denies a live LLM agent's out-of-mandate actions — over-budget, off-allow-list tool, and post-approval action-hash mismatch — with RATS platform attestation in the same loop, driven by a MachineMandate SD-JWT VC issued via OpenID4VCI into a build of the EUDI reference wallet on a physical phone. Wallet-issued bounded agent delegation itself is prior art (EY «EUDICATION», German EUDI-Wallet Hackathon, June 2026) and is not claimed. Payment-rail VC mandates (Google AP2, Mastercard Verifiable Intent), cloud agent credential wallets (Talao), production machine-mandate VCs (DOME), and phone KYA delegation (Vouched/Dock) exist; none compose an identity-rail mandate in the regulated EUDI reference wallet on a physical phone with attested, constraint-gated LLM execution. Contents: the actual vp_token (SD-JWT VC + KB-JWT) captured from the physical device; decoded payloads (principal, scope payments:<=500EUR, action_hash tamper-seal, cnf.jwk holder binding, x509_hash audience binding, anti-replay nonce); four-gate verifier verdicts (1 ACCEPT / 3 DENY: over-limit, poisoned-instruction tool call, payee swapped after approval); published action-seal badges from the live agent playground; wallet screenshots (consent → PIN → success); full demonstration write-up; adversarial novelty verification. Honest scope: the platform-attestation root is a software TPM (swtpm), not hardware-rooted — the RATS/Veraison protocol is complete and cryptographically real, only the hardware root is emulated; the wallet is a commit-pinned rebuild of the EU reference wallet, not an official published release; the verifier's trust decision is trusted-list membership, not full PKIX path + revocation; no real money moves. Integrity anchor: MANIFEST.sha256 covers all 14 files; MANIFEST.sha256.tsr is an RFC 3161 timestamp over the manifest (freetsa.org, 2026-07-06 21:28:13 UTC). vp_token SHA-256: 4790e07f34ff35c5bfb751cb955d7785aa1d1b9363e81dc12ffc972729f8be6f. Live agent playground: agent.eatf.eu.



