Binding an agent action back to the vouch credential that authorized it #428
Replies: 1 comment
|
I would keep the credential as standing authority, but make the action carry an independently verifiable authorization receipt. It should bind the credential ID and immutable version/digest, capability reference, action hash, target, parameter hash, audience, time, nonce, and the policy decision that admitted it. Sign that envelope with the acting key, and retain the verifier/runtime attestation only when it actually mediated the call.\n\nFor offline review after rotation, verification should resolve the credential and DID document as of the action time, then check the historical key and any time-bounded revocation/status evidence. Requiring the old key to remain live turns key rotation into evidence loss. The hard part is making the policy snapshot explicit too; otherwise you can prove who signed but not whether that action was within the allowance that applied then. |
Uh oh!
There was an error while loading. Please reload this page.
v1.0’s move to Verifiable Credentials + Data Integrity (
eddsa-jcs-2022, Multikey, ML-DSA-ready) makes the credential cleanly verifiable. The seam I can’t resolve from the docs is the binding to the act.A vouch credential asserts identity/provenance of an agent (or artifact). But the thing a relying party usually needs to check is narrower: that this action was performed under that credential, within its allowance. Where does that binding live?
Two shapes:
Related: during a post-quantum migration the signing key rotates. If a verifier validates an old action offline later, does it check against the key that was current at action time (DID doc versioning / key history), or must the signer key still be live? The first makes provenance durable; the second makes it decay on rotation.
Which shape does Vouch take for the action→credential binding, and does that binding survive key rotation?
All reactions