%% You should probably cite draft-hawkins-scitt-attested-agent-payment-02 instead of this revision. @techreport{hawkins-scitt-attested-agent-payment-01, number = {draft-hawkins-scitt-attested-agent-payment-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hawkins-scitt-attested-agent-payment/01/}, author = {Walter Hawkins}, title = {{Attested Payment Authorization for Autonomous Agents}}, pagetotal = 21, year = , month = , day = , abstract = {Autonomous software agents increasingly initiate payments on behalf of principals. Existing agent-payment mechanisms authenticate the human principal, the operator, or possession of a key; none of them establishes that the software authorized to spend is the software that was reviewed. A key held by a compromised or silently modified agent authenticates exactly as well as one held by an honest agent. This document defines a payment authorization scope bound to a key whose protection properties are attested by hardware, and registers the resulting authorization as a Signed Statement on an SCITT Transparency Service. The binding reuses the EAT confirmation and key-attributes claims without modification; the contribution is the authorization scope, the verification procedure a payment executor performs before settlement, the transparency record that makes the authorization artifact and its registration auditable independently of the agent and of the executor, and an execution-record mechanism that makes the executor's aggregate accounting auditable on challenge. What is registered evidences the authorization; it does not evidence that the verification procedure was performed for any given settlement.}, }