This work presents a task-bound lifecycle and state model instantiated by a quantum-safe task passport (QTP) that binds purpose, scope, computation type, participants, validity, evidence-key metadata, and an initial governed-resource profile.
Abstract
Trusted data spaces support privacy-preserving computation, but existing credentials leave an execution-time gap when task parameters or cumulative resources change. We present a task-bound lifecycle and state model instantiated by a quantum-safe task passport (QTP). Its signed schema binds purpose, scope, computation type, participants, validity, evidence-key metadata, and an initial governed-resource profile. At admission, QTP matches an independently reconstructed request, queries authoritative state, and atomically reserves units before mediated execution; Commit/Result evidence is bound to the admitted version. ML-DSA protects the credential, and ML-KEM establishes an off-chain evidence key. ML-DSA-44 signing and verification averaged 0.295 and 0.079 ms; a complete QTP occupied 4150 B. Fifteen field-correctness cases and ten additive-resource checks passed. In a four-node FISCO BCOS deployment co-located with one sequential client in a single virtual machine, state queries averaged 0.737 ms for 100 synthetic tasks, and all 71 negative transactions were rejected without state changes. The experiments do not characterize concurrent contention or an operational FL, PSI, or MPC runtime. Merkle-path measurements assume a supplied authenticated root; checkpoint authentication and finality verification remain deployment requirements. The quantum-safe claim covers credential and evidence-key layers; the ledger remains conventionally authenticated.
Post-quantum migration increases WebPKI authentication cost, but authenticating a compressed certificate object does not by itself preserve the mutable authorization context under which a relying party accepts it. We formalize \emph{context closure}: the authenticated projection accepted by a verifier must determine th...
Autonomous LLM agents can turn untrusted content into effectful actions such as payments and permission changes. If the same process interprets this content and controls a reusable signing credential, prompt injection can cross the judgment boundary and reach execution authority. We present KITA, a review-to-authorizat...
Blockchain-Cyber-Physical Systems (BCPSs) use sensor-generated IoT events to update ledger representations of physical assets. Authenticating individual reports does not by itself establish an admissible trajectory from the canonical predecessor or authenticate a selected historical interval. We formulate Verifiable St...
Ning-Yuan Chen, Yi-Bei Lin, Siu-Yeung Cho et al.· Italian National Conference...· 0 citations
Security analysis demonstrates that SecuAudit can effectively resist data forgery, metadata tampering, and sub-threshold collusion attacks under the defined threat model, and establishes a feasible framework for secure data circulation under the evaluated deployment assumptions.
Yufa Shi, Jia-Xing Hu, Li-Peng Wang et al.· Computers, Materials & C...· 0 citations
A correctly governed LLM agent can reach a state in which neither continuing execution nor automatically halting is admissible: the system has detected a persistent failure of its observability or drift-detection layer, but cannot itself decide who has the authority to resume, deny, or recalibrate the deployment. We ca...
We present an architecture that enables data owners to combine private data into data pools using Trusted Execution Environments (TEEs) and manage these pools by issuing narrowly scoped computational rights, encoded as Digital Rights Tokens (DRTs), to third-party data analysts. Each DRT binds specific open-source code...
B. Kruger, Co-Pierre Georg· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.