Skip to main content

The model_attestation Block for Agent Action Capsules: Model, Runtime, and Hardware Claims
draft-palanisamy-scitt-aac-runtime-00

Document Type Active Internet-Draft (individual)
Authors Govindaraj Palanisamy , Steven Mih
Last updated 2026-10-02
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state I-D Exists
Telechat date (None)
Responsible AD (None)
Send notices to (None)
draft-palanisamy-scitt-aac-runtime-00
Network Working Group                                      G. Palanisamy
Internet-Draft                                               Independent
Intended status: Standards Track                                  S. Mih
Expires: 5 April 2027                           Action State Group, Inc.
                                                          2 October 2026

 The model_attestation Block for Agent Action Capsules: Model, Runtime,
                          and Hardware Claims
                 draft-palanisamy-scitt-aac-runtime-00

Abstract

   This document defines the model_attestation block of the Agent Action
   Capsule (AAC) profile — referenced twice by the base profile but
   never defined there — and, within it, the compute_attestation
   container that already carries runtime extensions in the field: the
   model-serving runtime, the agent's own execution environment
   (architectural pattern, orchestration framework, sandbox confinement,
   invoked tool version), and host hardware, together with model and
   weights claims.  Every claim carries an explicitly declared source; a
   verifier grades claims by how they were observed and never infers a
   stronger grade than the evidence supports.  Hardware or platform
   attestation, when present, is cited by content-addressed reference to
   a foreign attestation record and verified with that record's own
   verifier.

Status of This Memo

   This Internet-Draft is submitted in full conformance with the
   provisions of BCP 78 and BCP 79.

   Internet-Drafts are working documents of the Internet Engineering
   Task Force (IETF).  Note that other groups may also distribute
   working documents as Internet-Drafts.  The list of current Internet-
   Drafts is at https://datatracker.ietf.org/drafts/current/.

   Internet-Drafts are draft documents valid for a maximum of six months
   and may be updated, replaced, or obsoleted by other documents at any
   time.  It is inappropriate to use Internet-Drafts as reference
   material or to cite them other than as "work in progress."

   This Internet-Draft will expire on 5 April 2027.

Copyright Notice

   Copyright (c) 2026 IETF Trust and the persons identified as the
   document authors.  All rights reserved.

Palanisamy & Mih          Expires 5 April 2027                  [Page 1]
Internet-Draft            AAC model_attestation             October 2026

   This document is subject to BCP 78 and the IETF Trust's Legal
   Provisions Relating to IETF Documents (https://trustee.ietf.org/
   license-info) in effect on the date of publication of this document.
   Please review these documents carefully, as they describe your rights
   and restrictions with respect to this document.  Code Components
   extracted from this document must include Revised BSD License text as
   described in Section 4.e of the Trust Legal Provisions and are
   provided without warranty as described in the Revised BSD License.

Table of Contents

   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   2
   2.  Conventions and Definitions . . . . . . . . . . . . . . . . .   4
   3.  The model_attestation Block . . . . . . . . . . . . . . . . .   5
     3.1.  Model Members . . . . . . . . . . . . . . . . . . . . . .   6
       3.1.1.  Verification Grade Semantics  . . . . . . . . . . . .   6
   4.  The compute_attestation Container . . . . . . . . . . . . . .   7
     4.1.  compute_attestation.runtime . . . . . . . . . . . . . . .   8
     4.2.  compute_attestation.agent_runtime . . . . . . . . . . . .   9
     4.3.  compute_attestation.invocation  . . . . . . . . . . . . .  11
     4.4.  compute_attestation.hardware  . . . . . . . . . . . . . .  13
     4.5.  compute_attestation.attestation_refs  . . . . . . . . . .  14
   5.  Formal CDDL Specification . . . . . . . . . . . . . . . . . .  15
   6.  Relationship to Epochs  . . . . . . . . . . . . . . . . . . .  17
   7.  Verification  . . . . . . . . . . . . . . . . . . . . . . . .  17
   8.  Relationship to evidence stores and epistemic typing  . . . .  18
   9.  Security Considerations . . . . . . . . . . . . . . . . . . .  18
   10. Privacy Considerations  . . . . . . . . . . . . . . . . . . .  19
   11. Implementation Status . . . . . . . . . . . . . . . . . . . .  20
   12. Conformance Vectors . . . . . . . . . . . . . . . . . . . . .  20
   13. IANA Considerations . . . . . . . . . . . . . . . . . . . . .  22
   14. References  . . . . . . . . . . . . . . . . . . . . . . . . .  22
     14.1.  Normative References . . . . . . . . . . . . . . . . . .  22
     14.2.  Informative References . . . . . . . . . . . . . . . . .  23
   Appendix A.  Fix to the base profile  . . . . . . . . . . . . . .  24
   Appendix B.  Complete Example . . . . . . . . . . . . . . . . . .  24
   Appendix C.  Acknowledgments  . . . . . . . . . . . . . . . . . .  26
   Authors' Addresses  . . . . . . . . . . . . . . . . . . . . . . .  26

1.  Introduction

   An agent action recorded in an Agent Action Capsule (AAC) is executed
   by a model running within a specific model-serving runtime, itself
   invoked by an agent process in a specific execution environment, on
   host hardware.  Two capsules recording nominally identical actions
   can differ in what actually happened depending on model checkpoint,
   quantization, sandbox confinement, or the version of a tool package
   the agent invoked; without a record of that environment, a forensic

Palanisamy & Mih          Expires 5 April 2027                  [Page 2]
Internet-Draft            AAC model_attestation             October 2026

   reviewer cannot tell a model-drift event from a compromised tool from
   an unconfined sandbox.  The base profile
   [I-D.mih-scitt-agent-action-capsule] records the action, seals it
   under canonicalization [RFC8785], and MAY register its Capsule ID as
   independently transparent to a SCITT [RFC9943] Transparency Service;
   the agent-domain checks defined by the base profile are verified
   independently of that registration, by a Class 1 or Class 2 verifier,
   from the record's own bytes.  Its epoch mechanism records baseline
   configuration shifts across actions.  Although the base profile
   references a model_attestation block, it does not supply a formal
   definition.

   Two constraints matter.  First, this extension is payload-extension-
   only: model_attestation lives in the Capsule JSON like every other
   payload member — the base profile's Section "Extensibility" states
   that all Capsule extension points are in the Capsule JSON — and it
   does not touch the Producer Envelope's protected header, which the
   base profile's Section "Producer Envelope wire profile" holds closed
   to exactly three entries (Section 3.1).  Second, this extension MUST
   NOT change the base profile's Class 1 or Class 2 verification model
   (Sections 6 and 8.2); a verifier that does not implement it treats
   the block as informational (Section 3).  This extension also imposes
   no mandatory transport dependency; it is silent on how a Capsule is
   delivered.

   model_attestation is a bare top-level payload member name, not a
   namespaced one.  This follows from a fact specific to this field: the
   base profile already refers to model_attestation by that exact bare
   name, twice, without defining it (in its epoch-boundary Capsule
   section and in its Security Considerations), so the name is already
   reserved by the base profile itself rather than being minted here.
   This document supplies the definition for a name the base profile
   already uses, rather than introducing a new namespaced member.

   This document defines the model_attestation block, generalizes it to
   per-action use, and formalizes the model-serving runtime, agent
   execution environment, and hardware facts producers observe — all
   within the compute_attestation container (Section 4).  The block is
   sealed directly inside the Capsule payload and participates in
   derived identifier generation (capsule_id).

Palanisamy & Mih          Expires 5 April 2027                  [Page 3]
Internet-Draft            AAC model_attestation             October 2026

   The core design principle is honesty of source.  A model name
   reported by the runtime is a claim; a weights digest computed over a
   loaded file is a stronger claim; a measurement signed by a hardware
   root of trust is stronger still.  They represent distinct facts, and
   the record states which one it holds.  A verifier that cannot resolve
   a claim to its stated source MUST report it as unresolved, MUST NOT
   report it as verified, and MUST NOT upgrade an unknown grade to a
   known one.

   This block complements rather than replaces the base profile's epoch
   machinery: it records per-action claims in force for an action while
   remaining scoped to the active epoch and prevailing epoch-boundary
   Capsule. model_id is RECOMMENDED, not REQUIRED, in Section 3.1: the
   epoch-boundary Capsule already records the model transition, and an
   extension MUST NOT out-mandate its base.

2.  Conventions and Definitions

   The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
   "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
   "OPTIONAL" in this document are to be interpreted as described in
   BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all
   capitals, as shown here.

   Capsule, Producer Envelope, epoch, epoch-boundary Capsule, epoch_id,
   derived identifier, typed digest reference, and data-admission tiers
   are used as defined in [I-D.mih-scitt-agent-action-capsule] and
   [I-D.mih-sokolov-scitt-payload-binding].  Attester, Verifier, and
   Evidence are used in the sense of [RFC9334] where foreign platform
   attestation is discussed.

   Source label:  A standardized vocabulary declaring how a claim's
      value was obtained: self_reported (asserted by executing
      software), provider_reported (returned by a remote model provider
      or serving API and preserved by the producer without alteration),
      os_reported (reported by the host operating system), computed
      (calculated by the producer from bytes it held), or attested
      (cryptographically bound inside a verifiable foreign attestation
      record).  Additional labels MUST be namespaced.

   Every source map in this document (at the model_attestation level and
   within each compute_attestation sub-object) follows the same default:
   if the map is omitted, or a field has no entry in it, a verifier MUST
   treat that field's source as self_reported.  This rule is stated once
   here and applies wherever a source field appears below; it is not
   restated per sub-object.

Palanisamy & Mih          Expires 5 April 2027                  [Page 4]
Internet-Draft            AAC model_attestation             October 2026

3.  The model_attestation Block

   A Capsule payload MAY carry a member named model_attestation.  The
   block participates in the derived identifier like every payload
   member: it is canonicalized under JCS [RFC8785] and covered by
   capsule_id.  A verifier that does not implement this extension MUST
   ignore it for verification and MUST NOT fail a Capsule solely because
   it is present.

     +=====================+========+=============+=================+
     | Field               | Type   | Req         | Meaning         |
     +=====================+========+=============+=================+
     | model_id            | string | RECOMMENDED | See             |
     |                     |        |             | Section 3.1.    |
     +---------------------+--------+-------------+-----------------+
     | provider            | string | OPTIONAL    | See             |
     |                     |        |             | Section 3.1.    |
     +---------------------+--------+-------------+-----------------+
     | model_revision      | string | OPTIONAL    | See             |
     |                     |        |             | Section 3.1.    |
     +---------------------+--------+-------------+-----------------+
     | weights_digest      | object | OPTIONAL    | See             |
     |                     |        |             | Section 3.1.    |
     +---------------------+--------+-------------+-----------------+
     | quantization        | string | OPTIONAL    | See             |
     |                     |        |             | Section 3.1.    |
     +---------------------+--------+-------------+-----------------+
     | decoding            | object | OPTIONAL    | See             |
     |                     |        |             | Section 3.1.    |
     +---------------------+--------+-------------+-----------------+
     | source              | object | OPTIONAL    | Field to source |
     |                     |        |             | label mapping;  |
     |                     |        |             | see above for   |
     |                     |        |             | the omitted-    |
     |                     |        |             | entry default.  |
     +---------------------+--------+-------------+-----------------+
     | compute_attestation | object | OPTIONAL    | Container for   |
     |                     |        |             | runtime/compute |
     |                     |        |             | facts           |
     |                     |        |             | (Section 4).    |
     +---------------------+--------+-------------+-----------------+
     | epoch_consistency   | string | OPTIONAL    | consistent,     |
     |                     |        |             | inconsistent,   |
     |                     |        |             | or unknown      |
     |                     |        |             | (Section 6).    |
     +---------------------+--------+-------------+-----------------+

                                 Table 1

Palanisamy & Mih          Expires 5 April 2027                  [Page 5]
Internet-Draft            AAC model_attestation             October 2026

3.1.  Model Members

   These members define the core model assertions referenced by the base
   profile's epoch section.  They MAY appear in any Capsule and SHOULD
   appear in every epoch-boundary Capsule.

   +==============+======+===========+==============+=================+
   |Field         |Type  |Req        |Permitted     | Meaning         |
   |              |      |           |Sources       |                 |
   +==============+======+===========+==============+=================+
   |model_id      |string|RECOMMENDED|self_reported,| Model name as   |
   |              |      |           |os_reported,  | reported by the |
   |              |      |           |attested      | runtime.        |
   +--------------+------+-----------+--------------+-----------------+
   |provider      |string|OPTIONAL   |self_reported,| Model provider  |
   |              |      |           |attested      | or serving      |
   |              |      |           |              | system.         |
   +--------------+------+-----------+--------------+-----------------+
   |model_revision|string|OPTIONAL   |self_reported,| Provider- or    |
   |              |      |           |attested      | repo-assigned   |
   |              |      |           |              | revision.       |
   +--------------+------+-----------+--------------+-----------------+
   |weights_digest|object|OPTIONAL   |computed,     | {digest_alg,    |
   |              |      |           |attested      | digest, scope}  |
   |              |      |           |              | over loaded     |
   |              |      |           |              | weights.        |
   +--------------+------+-----------+--------------+-----------------+
   |quantization  |string|OPTIONAL   |self_reported,| Quantization    |
   |              |      |           |computed,     | label (e.g.,    |
   |              |      |           |attested      | Q4_K_M).        |
   +--------------+------+-----------+--------------+-----------------+
   |decoding      |object|OPTIONAL   |self_reported | Hyperparameters |
   |              |      |           |              | {temperature,   |
   |              |      |           |              | top_p, seed}.   |
   +--------------+------+-----------+--------------+-----------------+

                                 Table 2

   For weights_digest, scope MUST be either file (digest over serialized
   model bytes as loaded from storage) or tensors (digest over in-memory
   tensor structures, admissible only under attested).  A digest of a
   reference string (e.g., a HuggingFace URI) MUST NOT be carried in
   weights_digest; such identifiers belong in model_id.

3.1.1.  Verification Grade Semantics

   A verifier MAY derive grades according to the following matrix, never
   exceeding what source and accompanying evidence substantiate:

Palanisamy & Mih          Expires 5 April 2027                  [Page 6]
Internet-Draft            AAC model_attestation             October 2026

         +==========================+===========================+
         | Record Fact              | Verifier May Report       |
         +==========================+===========================+
         | model_id only            | model: self-reported name |
         +--------------------------+---------------------------+
         | weights_digest (scope:   | model: file-identified    |
         | file, computed)          | (recomputable)            |
         +--------------------------+---------------------------+
         | weights_digest (attested | model: attested at        |
         | via Section 4.5)         | declared scope            |
         +--------------------------+---------------------------+
         | quantization             | quantization: claimed     |
         | (self_reported)          |                           |
         +--------------------------+---------------------------+

                                 Table 3

   A verifier MUST NOT report "model attested" from model_id alone, and
   MUST NOT report "quantization verified" from any field in this block,
   as none of these fields establish which underlying arithmetic was
   executed.  Detection of substituted models or quantizations is out of
   scope for this record and belongs to redundancy or referee mechanisms
   at the system level.

4.  The compute_attestation Container

   compute_attestation groups environment observations into five sub-
   objects: runtime (Section 4.1, the model-serving runtime),
   agent_runtime (Section 4.2, the agent's own execution environment),
   invocation (Section 4.3, what the model provider or serving API
   reported about this call), hardware (Section 4.4), and
   attestation_refs (Section 4.5), plus any namespaced member owned by
   another specification (for example x-mesh-lifecycle-v1,
   host_binding). runtime and agent_runtime are deliberately distinct:
   runtime describes the process that served the model's inference (for
   example, a local inference server or hosted serving stack);
   agent_runtime describes the process that orchestrated the action —
   the agent loop, its sandbox, and the tool it invoked — which may be a
   different process, on different infrastructure, than the one that
   served the model.  A verifier MUST ignore members it does not
   recognize.  A member MUST be absent rather than null when its fact is
   unavailable.

Palanisamy & Mih          Expires 5 April 2027                  [Page 7]
Internet-Draft            AAC model_attestation             October 2026

4.1.  compute_attestation.runtime

     +====================+========+==============+=================+
     | Field              | Type   | Req          | Meaning         |
     +====================+========+==============+=================+
     | name               | string | RECOMMENDED  | Serving binary  |
     |                    |        |              | name and        |
     |                    |        |              | version.        |
     +--------------------+--------+--------------+-----------------+
     | runtime_digest     | string | OPTIONAL     | Digest of the   |
     |                    |        |              | serving binary  |
     |                    |        |              | as measured.    |
     +--------------------+--------+--------------+-----------------+
     | measurement_class  | string | RECOMMENDED* | Class of        |
     |                    |        |              | measurement     |
     |                    |        |              | (*when digest   |
     |                    |        |              | present).       |
     +--------------------+--------+--------------+-----------------+
     | platform_integrity | object | OPTIONAL     | OS integrity    |
     |                    |        |              | bits (e.g.,     |
     |                    |        |              | SIP, Secure     |
     |                    |        |              | Boot).          |
     +--------------------+--------+--------------+-----------------+
     | source             | object | OPTIONAL     | Field to source |
     |                    |        |              | label mapping;  |
     |                    |        |              | see above for   |
     |                    |        |              | the omitted-    |
     |                    |        |              | entry default.  |
     +--------------------+--------+--------------+-----------------+

                                 Table 4

   Standard measurement_class values include self_measured, os_measured,
   tpm_measured, app_attested, mda_measured, and tee_measured.  Field
   status at the time of writing: self_measured and os_measured are
   produced by shipping code; tee_measured has a record shape and
   verifier with real Intel TDX vectors; tpm_measured, app_attested, and
   mda_measured are named here so that the vocabulary is fixed before
   their producers exist.  Unknown classes MUST be treated as
   unrecognized, never ordered above known classes; the classes are
   sibling roots of trust and the ordering above is meaningful only
   within a single root.

Palanisamy & Mih          Expires 5 April 2027                  [Page 8]
Internet-Draft            AAC model_attestation             October 2026

4.2.  compute_attestation.agent_runtime

   Where runtime (Section 4.1) describes the process that served the
   model, agent_runtime describes the process that orchestrated the
   action: the agent loop or orchestration framework, the environment
   and confinement it ran in, and the version of any tool package it
   invoked to perform this specific action.  This is the environment-
   blindness gap: two Capsules recording the same nominal action can
   behave differently depending on sandbox confinement or a tool
   package's version, and without this record a forensic reviewer cannot
   distinguish a compromised tool from an unconfined sandbox from a
   model-drift event.

Palanisamy & Mih          Expires 5 April 2027                  [Page 9]
Internet-Draft            AAC model_attestation             October 2026

   +==============+========+==========+===============================+
   | Field        | Type   | Req      | Meaning                       |
   +==============+========+==========+===============================+
   | agent_type   | string | OPTIONAL | The agent's architectural     |
   |              |        |          | pattern (e.g., single_agent,  |
   |              |        |          | multi_agent_orchestrator,     |
   |              |        |          | react, plan_execute,          |
   |              |        |          | supervisor_worker).           |
   +--------------+--------+----------+-------------------------------+
   | framework    | string | OPTIONAL | Agent orchestration framework |
   |              |        |          | or agent-loop implementation, |
   |              |        |          | name and version (e.g.,       |
   |              |        |          | langchain 0.3.1, custom-      |
   |              |        |          | agent-loop 1.4.0).            |
   +--------------+--------+----------+-------------------------------+
   | runtime_env  | string | OPTIONAL | Execution environment the     |
   |              |        |          | agent process ran in, name    |
   |              |        |          | and version (e.g.,            |
   |              |        |          | python:3.11-slim,             |
   |              |        |          | node:20-alpine).              |
   +--------------+--------+----------+-------------------------------+
   | sandbox_type | string | OPTIONAL | Confinement mechanism         |
   |              |        |          | isolating the agent process   |
   |              |        |          | (e.g., gvisor, firecracker,   |
   |              |        |          | wasm, unconfined).            |
   +--------------+--------+----------+-------------------------------+
   | tool_version | string | OPTIONAL | Version or content digest of  |
   |              |        |          | the tool package this action  |
   |              |        |          | invoked, when the action      |
   |              |        |          | involved a specific tool.     |
   +--------------+--------+----------+-------------------------------+
   | source       | object | OPTIONAL | Field to source label         |
   |              |        |          | mapping; see above for the    |
   |              |        |          | omitted-entry default.        |
   +--------------+--------+----------+-------------------------------+

                                 Table 5

   agent_type names the architectural pattern the agent process
   implements for this action, not the specific framework instance (that
   is framework's job) or a claim about correctness.  The seeded values
   above are illustrative, not exhaustive or registry-governed:
   single_agent (one model, one decision loop), multi_agent_orchestrator
   (a coordinating process dispatching to one or more sub-agents for
   this action), react (interleaved reasoning-and-acting loop),
   plan_execute (a separate planning phase precedes execution), and
   supervisor_worker (a supervisor process dispatches to worker
   processes it does not itself execute as).  A value outside this list

Palanisamy & Mih          Expires 5 April 2027                 [Page 10]
Internet-Draft            AAC model_attestation             October 2026

   follows the same namespacing discipline as constraint id/check_type
   in the base profile's Section "Namespacing convention": bare names
   are reserved for the values seeded here, and a party introducing a
   new value MUST namespace it with a URI or reverse-DNS prefix.  A
   verifier treats an unrecognized agent_type value as informational,
   never as a validation failure — this field is descriptive metadata,
   not a graded claim, and carries no source-grading matrix of its own
   beyond the standard self-reported default.

   sandbox_type: "unconfined" is itself an informative claim, not an
   absent field: a producer that knows its agent process runs unconfined
   SHOULD say so rather than omit the field, since the omission and the
   honest disclosure of no confinement are otherwise indistinguishable
   to a verifier.  As with every field in this document, sandbox_type
   and framework are self-reported unless graded otherwise by source or
   corroborated by an attestation_refs entry (Section 4.5); a verifier
   MUST NOT infer actual confinement strength from the label alone;
   gvisor and firecracker name mechanisms with different isolation
   properties, and this document does not rank them.

4.3.  compute_attestation.invocation

   Commercial and self-hosted model APIs commonly return invocation
   metadata in addition to the text or tool output.  This sub-object
   preserves such provider or runtime facts without standardizing any
   provider-specific response object.  Every value here is a claim about
   what the serving side reported for this call; none of it is a
   measurement of the serving environment, which is what Section 4.1 and
   Section 4.4 carry.

   All fields below are OPTIONAL.

   +===================+======+==================+=====================+
   |Field              |Type  |Permitted Sources |Meaning              |
   +===================+======+==================+=====================+
   |requested_model_id |string|self_reported     |Model identifier the |
   |                   |      |                  |caller asked for.    |
   +-------------------+------+------------------+---------------------+
   |resolved_model_id  |string|provider_reported,|Model identifier     |
   |                   |      |self_reported,    |reported as actually |
   |                   |      |attested          |serving the call.    |
   +-------------------+------+------------------+---------------------+
   |service_class      |string|provider_reported,|Provider or runtime  |
   |                   |      |self_reported     |processing tier.     |
   |                   |      |                  |Values are provider- |
   |                   |      |                  |defined unless       |
   |                   |      |                  |registered by        |
   |                   |      |                  |another profile.     |

Palanisamy & Mih          Expires 5 April 2027                 [Page 11]
Internet-Draft            AAC model_attestation             October 2026

   +-------------------+------+------------------+---------------------+
   |backend_fingerprint|string|provider_reported |Opaque provider-     |
   |                   |      |                  |issued deployment or |
   |                   |      |                  |configuration        |
   |                   |      |                  |identifier.  A       |
   |                   |      |                  |change-detection     |
   |                   |      |                  |value, not a         |
   |                   |      |                  |hardware             |
   |                   |      |                  |attestation.         |
   +-------------------+------+------------------+---------------------+
   |reasoning          |object|provider_reported,|Declared reasoning   |
   |                   |      |self_reported     |configuration (mode, |
   |                   |      |                  |effort, summary      |
   |                   |      |                  |policy).  Raw chain- |
   |                   |      |                  |of-thought MUST NOT  |
   |                   |      |                  |appear here.         |
   +-------------------+------+------------------+---------------------+
   |usage              |object|provider_reported,|Non-content          |
   |                   |      |self_reported     |counters: input,     |
   |                   |      |                  |output, cached, and  |
   |                   |      |                  |reasoning tokens.    |
   +-------------------+------+------------------+---------------------+
   |finish_status      |string|provider_reported,|Termination status:  |
   |                   |      |self_reported     |completed,           |
   |                   |      |                  |incomplete, failed,  |
   |                   |      |                  |or a provider-       |
   |                   |      |                  |namespaced finish    |
   |                   |      |                  |reason.              |
   +-------------------+------+------------------+---------------------+
   |response_ref       |object|provider_reported |Digest-only or       |
   |                   |      |                  |pairwise reference   |
   |                   |      |                  |to a provider        |
   |                   |      |                  |response identifier, |
   |                   |      |                  |for later            |
   |                   |      |                  |correlation.  Raw    |
   |                   |      |                  |provider request and |
   |                   |      |                  |response identifiers |
   |                   |      |                  |SHOULD NOT be        |
   |                   |      |                  |disclosed across     |
   |                   |      |                  |parties by default.  |
   +-------------------+------+------------------+---------------------+
   |reasoning_state_ref|object|provider_reported |Typed reference or   |
   |                   |      |                  |digest of an opaque  |
   |                   |      |                  |provider-issued      |
   |                   |      |                  |reasoning-continuity |
   |                   |      |                  |artifact, when one   |
   |                   |      |                  |is returned.         |
   |                   |      |                  |Treated as opaque;   |

Palanisamy & Mih          Expires 5 April 2027                 [Page 12]
Internet-Draft            AAC model_attestation             October 2026

   |                   |      |                  |this document        |
   |                   |      |                  |neither defines nor  |
   |                   |      |                  |requires disclosure  |
   |                   |      |                  |of internal          |
   |                   |      |                  |reasoning.           |
   +-------------------+------+------------------+---------------------+
   |source             |object|—                 |Field to source      |
   |                   |      |                  |label mapping; see   |
   |                   |      |                  |Conventions for the  |
   |                   |      |                  |omitted-entry        |
   |                   |      |                  |default.             |
   +-------------------+------+------------------+---------------------+

                                  Table 6

   reasoning MAY carry configuration metadata such as mode, effort,
   summary, or a provider-namespaced equivalent.  It MUST NOT carry
   hidden chain-of-thought text, and a verifier MUST treat any text-
   valued member of reasoning as a profile violation of the base
   profile's data-admission tiers.  A provider-issued opaque reasoning
   or thought signature MAY be referenced through reasoning_state_ref
   when the producer needs to bind the exact state token that was
   returned.

   The field names describe semantics, not a vendor API.  An adapter MAY
   preserve additional provider fields under a provider-controlled
   namespace, subject to the base profile's data-admission rules.
   resolved_model_id complements, and never replaces, model_id at the
   model_attestation level: the former is what the provider said it
   served on this call, the latter is the identity the producer records
   for the epoch.

4.4.  compute_attestation.hardware

   +==============+=========+==========+==============================+
   | Field        | Type    | Req      | Meaning                      |
   +==============+=========+==========+==============================+
   | platform     | string  | OPTIONAL | Platform enum (e.g., intel-  |
   |              |         |          | tdx, amd-sev-snp, apple-     |
   |              |         |          | silicon).                    |
   +--------------+---------+----------+------------------------------+
   | accelerator  | string  | OPTIONAL | Accelerator or GPU name as   |
   |              |         |          | reported.                    |
   +--------------+---------+----------+------------------------------+
   | memory_bytes | integer | OPTIONAL | Unified or accelerator       |
   |              |         |          | memory in bytes.             |
   +--------------+---------+----------+------------------------------+
   | inventory    | object  | OPTIONAL | Coarse CPU/firmware topology |

Palanisamy & Mih          Expires 5 April 2027                 [Page 13]
Internet-Draft            AAC model_attestation             October 2026

   |              |         |          | details.                     |
   +--------------+---------+----------+------------------------------+
   | source       | object  | OPTIONAL | Field to source label        |
   |              |         |          | mapping; see above for the   |
   |              |         |          | omitted-entry default.       |
   |              |         |          | Hardware is os_reported at   |
   |              |         |          | best without a corroborating |
   |              |         |          | attestation_refs entry.      |
   +--------------+---------+----------+------------------------------+

                                 Table 7

   *Never-enters.* Device serial numbers, platform UUIDs, MAC addresses,
   and other stable device identifiers MUST NOT appear in hardware, in
   clear or as a digest: they are stable identifiers of small effective
   entropy and re-identify a person's machine (base profile, "Data-
   Admission Tiers").  A producer that must later show "this was my
   machine" MAY carry a salted digest of such an identifier under an
   explicitly opt-in, namespaced field whose salt the producer retains;
   this document does not define that field.

4.5.  compute_attestation.attestation_refs

   This document defines no attestation format.  Where hardware or
   platform attestation exists, the Capsule cites it by a typed digest
   reference [I-D.mih-sokolov-scitt-payload-binding] — {type, purpose,
   digest_alg, digest} — where type resolves in the shared Artifact Type
   Registry to the foreign record's declared digest context:

   {
     "type": "example.tdx-quote-v1",
     "purpose": "hardware",
     "digest_alg": "SHA-256",
     "digest": "e3b0c442…b7852b855"
   }

   Verification of a cited attestation record is performed by the
   verifier that record's issuer publishes, never by a re-implementation
   in this profile's verifier.  The result feeds this block as follows:

   *  If the cited record verifies and binds weights_digest,
      runtime_digest, or platform measurement values equal to those
      carried here, the verifier MAY report those fields at source
      attested, at the grade the foreign verifier reports.  A foreign
      verifier's intermediate grades MUST be carried through, not
      collapsed to a boolean.

Palanisamy & Mih          Expires 5 April 2027                 [Page 14]
Internet-Draft            AAC model_attestation             October 2026

   *  If the cited record does not verify, is absent, or binds different
      values, no field in this block is upgraded, and the verifier
      SHOULD report the citation as present-but-not-verified with the
      reason.

   *  A cited record MUST be carried byte-identically; it is never re-
      minted or re-signed by the Capsule producer.

5.  Formal CDDL Specification

   The following CDDL [RFC8610] grammar formally specifies the payload
   schema:

   model-attestation-block = {
     ? "model_id"            => tstr,
     ? "provider"            => tstr,
     ? "model_revision"      => tstr,
     ? "weights_digest"      => weights-digest-claim,
     ? "quantization"        => tstr,
     ? "decoding"            => decoding-params,
     ? "source"              => source-map,
     ? "compute_attestation" => compute-attestation-container,
     ? "epoch_consistency"   => "consistent" / "inconsistent"
                                / "unknown",
     * tstr                  => any
   }

   source-label = "self_reported" / "provider_reported" / "os_reported"
                / "computed" / "attested" / tstr

   source-map = {
     * tstr => source-label
   }

   weights-digest-claim = {
     "digest_alg" => tstr,
     "digest"     => tstr,
     "scope"      => "file" / "tensors" / tstr
   }

   decoding-params = {
     ? "temperature" => float / int,
     ? "top_p"       => float / int,
     ? "seed"        => int,
     * tstr          => any
   }

   compute-attestation-container = {

Palanisamy & Mih          Expires 5 April 2027                 [Page 15]
Internet-Draft            AAC model_attestation             October 2026

     ? "runtime"          => runtime-claims,
     ? "agent_runtime"    => agent-runtime-claims,
     ? "invocation"       => invocation-claims,
     ? "hardware"         => hardware-claims,
     ? "attestation_refs" => [* foreign-attestation-ref],
     * tstr               => any
   }

   runtime-claims = {
     ? "name"               => tstr,
     ? "runtime_digest"     => tstr,
     ? "measurement_class"  => measurement-class-label,
     ? "platform_integrity" => { * tstr => any },
     ? "source"             => source-map
   }

   agent-runtime-claims = {
     ? "agent_type"   => tstr,
     ? "framework"    => tstr,
     ? "runtime_env"  => tstr,
     ? "sandbox_type" => tstr,
     ? "tool_version" => tstr,
     ? "source"       => source-map
   }

   invocation-claims = {
     ? "requested_model_id"  => tstr,
     ? "resolved_model_id"   => tstr,
     ? "service_class"       => tstr,
     ? "backend_fingerprint" => tstr,
     ? "reasoning"           => { * tstr => tstr / int / float / bool },
     ? "usage"               => { * tstr => uint },
     ? "finish_status"       => tstr,
     ? "response_ref"        => { * tstr => any },
     ? "reasoning_state_ref" => { * tstr => any },
     ? "source"              => source-map
   }

   measurement-class-label = "self_measured" / "os_measured"
                           / "tpm_measured" / "app_attested"
                           / "mda_measured" / "tee_measured"
                           / tstr

   hardware-claims = {
     ? "platform"     => tstr,
     ? "accelerator"  => tstr,
     ? "memory_bytes" => uint,
     ? "inventory"    => { * tstr => any },

Palanisamy & Mih          Expires 5 April 2027                 [Page 16]
Internet-Draft            AAC model_attestation             October 2026

     ? "source"       => source-map
   }

   foreign-attestation-ref = {
     "type"       => tstr,
     "purpose"    => tstr,
     "digest_alg" => tstr,
     "digest"     => tstr
   }

6.  Relationship to Epochs

   The base profile's epoch-boundary Capsule records a macroscopic
   configuration shift across a registry or agent lifecycle.  This block
   records the configuration in force for one action.  The two MUST NOT
   contradict: a Capsule whose model_attestation names a model different
   from the one the prevailing epoch-boundary Capsule opened is either a
   producer defect or an unrecorded epoch change, and a verifier SHOULD
   report epoch_consistency: inconsistent regardless of what the
   producer stated.  A producer that populates epoch_id SHOULD carry
   this block in the epoch-boundary Capsule with source labels, so the
   transition is commit-addressed as the base profile intends.

7.  Verification

   This extension adds no additional verification semantics beyond the
   base profile's Class 1 and Class 2 verifier checks (Sections 6 and
   8.2 of [I-D.mih-scitt-agent-action-capsule]) on the sealed AAC
   record.  When this extension is implemented, a verifier MAY apply the
   checks below.

   1.  Validate field shapes against Section 5 and the source map; a
       field without a source entry is self_reported per Section 3.

   2.  For each entry in attestation_refs, resolve type per
       [I-D.mih-sokolov-scitt-payload-binding]; if resolvable and the
       record is available, invoke the issuer's verifier and record its
       result and grade.

   3.  Derive per-field grades per Section 3.1, never exceeding the
       stated source and the foreign verifier's result.

   4.  Report epoch_consistency from the ledger context when available.

   5.  Report unknown measurement_class or source labels as
       unrecognized, never as equal to or higher than a known class or
       label.

Palanisamy & Mih          Expires 5 April 2027                 [Page 17]
Internet-Draft            AAC model_attestation             October 2026

   6.  Treat agent_runtime fields (Section 4.2) as self-reported by
       default and never infer confinement strength from sandbox_type's
       value; this document ranks no sandbox mechanism against another.

   7.  Treat invocation fields (Section 4.3) labelled provider_reported
       as the provider's claim preserved by the producer: a verifier
       MUST NOT report a provider_reported value as computed or
       attested, and MUST NOT report resolved_model_id as establishing
       model identity on its own.

8.  Relationship to evidence stores and epistemic typing

   A local evidence store MAY preserve these fields as evidence about
   the execution environment.  The source labels in this document
   describe how a specific field value was obtained and are
   intentionally narrower than a general evidence taxonomy.  An
   implementation that maps them onto a wider taxonomy SHOULD do so
   without silently upgrading them, for example:

   *  self_reported: a producer claim;

   *  provider_reported: a claim returned by a remote provider or API
      and preserved by the producer;

   *  os_reported: an observation attributed to an operating-system
      source;

   *  computed: a deterministic derivation over identified bytes; and

   *  attested: a claim supported by a separately verified attestation
      record.

   Tool-call content, tool-call result content, prompt and context
   material, intentionally emitted rationale artifacts, human reports,
   semantic judgments, outcome adjudications, and regulatory obligation
   results are outside this block even when they concern the same
   action.  They belong to separate records or extensions and may be
   linked by typed references.

9.  Security Considerations

   All claims in this block outside of an independently validated
   attestation_refs record are assertions made by the Capsule producer.
   The function of this profile is not to make those claims true but to
   make them specific, signed, and non-repudiable under the AAC verifier
   acceptance path.  A producer that later serves a different model than
   it claimed has signed the discrepancy.  Claims about which arithmetic
   ran (quantization, precision) cannot be verified from any record the

Palanisamy & Mih          Expires 5 April 2027                 [Page 18]
Internet-Draft            AAC model_attestation             October 2026

   producer alone signs; systems that need that assurance obtain it by
   redundancy or hardware attestation, outside this document.  The same
   honesty-of-source discipline applies to agent_runtime (Section 4.2):
   sandbox_type: "unconfined" is exactly as signed and non-repudiable as
   any other value, which is what lets a forensic reviewer later
   distinguish an unconfined sandbox that was disclosed from one that
   was silently omitted.

   A verifier MUST NOT round up: an unknown measurement_class, an
   unresolvable attestation_refs.type, or a source label it does not
   know is reported as unrecognized, never treated as the highest grade
   the verifier knows.  This rule exists because the failure it prevents
   — a forged grade string accepted by an old verifier — is otherwise
   cheap.

10.  Privacy Considerations

   Every field in this block is subject to the base profile's data-
   admission tiers (clear-safe, digest-only, never-enters) and its
   default-deny posture: producers and adapters MUST classify each
   candidate field before admission, and MUST NOT admit a field merely
   because this document does not mention it.

   model_id, provider, and decoding.seed are deployment or run
   parameters and clear-safe: they describe the model and its
   configuration, not a person. weights_digest and runtime_digest are
   digests of software artifacts and carry no end-user privacy exposure
   on their own; a producer MUST still ensure the artifact digested does
   not itself embed tenant- or user-identifying material — a model fine-
   tuned on a single tenant's private corpus is itself a sensitive
   artifact, and digesting it does not launder that sensitivity, so
   model_id and weights_digest for such a model are tier-appropriate to
   the tenant's own data, not automatically clear-safe.

   agent_runtime.agent_type, .framework, .runtime_env, and .sandbox_type
   are ordinarily deployment constants and clear-safe.
   agent_runtime.tool_version is clear-safe only when the tool package
   identifier or digest does not itself encode end-user or tenant-
   identifying information (for example, a tenant-named internal tool,
   or a per-tenant container image tag); a producer whose tool naming
   does so MUST treat the field as digest-only or omit it.  A producer
   for whom agent_type, framework, runtime_env, or sandbox_type varies
   per end-user request or per tenant (for example, per-tenant sandbox
   images keyed to a customer) MUST re-evaluate that field's tier rather
   than relying on the clear-safe default stated here, since a per-
   tenant value is then itself a tenant-correlation handle.

Palanisamy & Mih          Expires 5 April 2027                 [Page 19]
Internet-Draft            AAC model_attestation             October 2026

   hardware.inventory is intentionally constrained to prevent device
   fingerprinting: device serial numbers, MAC addresses, platform UUIDs,
   and other persistent hardware identifiers MUST NOT appear in
   compute_attestation, in clear or as a digest, per Section 4.4.

   No field defined in this block is an end-user or session identifier
   at any tier; none should be added without also updating this section.

11.  Implementation Status

   This section records the status of known implementations of this
   block at the time of posting, per [RFC7942].  It is to be removed
   before publication as an RFC.

   Mesh-LLM capsule plugin (Apache-2.0, Rust and Python): a producer at
   the inference boundary of a peer-to-peer model-serving network.  It
   writes compute_attestation.runtime with a SHA-256 digest of the
   serving binary and a measurement_class of os_measured where the host
   operating system can report it and self_measured otherwise, and
   records serving provenance (serving node, requesting party, token
   usage, generation parameters) under a namespaced member of
   compute_attestation.  Quantization and hardware facts the host does
   not expose are recorded as absent, never fabricated.  A name hash is
   recorded under a field name that says it is a name hash, after an
   earlier field name that overclaimed a weights binding was renamed.
   Its reference library reads model_attestation in its verifier,
   ledger, disclosure, and viewer paths.

   capsule-emit (Apache-2.0, Python): the reference emitter and verifier
   treats model_attestation.compute_attestation as the extension
   container for runtime and compute facts, and other extensions (for
   example the OpenTelemetry correlation block of draft-palanisamy-
   scitt-aac-otel) are placed there today.

12.  Conformance Vectors

   This is a tier-2 (per-profile) extension in the sense of
   [I-D.mih-agent-accountability-conformance]: it defines its own
   semantics and must-fail cases on top of the tier-1 binding
   conformance that [I-D.mih-sokolov-scitt-payload-binding] (CPB)
   defines for every AAC payload member.  This document is not itself a
   binding-layer artifact and does not register a type in the CPB
   Artifact Type Registry; that registry governs the type field of a
   typed digest reference — used here only by attestation_refs entries
   (Section 4.5) — a different and narrower thing than a named payload
   extension like model_attestation itself.

Palanisamy & Mih          Expires 5 April 2027                 [Page 20]
Internet-Draft            AAC model_attestation             October 2026

   As of this writing, the registry structure for tier-2 (per-profile)
   conformance artifacts is explicitly not yet specified —
   [I-D.mih-agent-accountability-conformance] states plainly that this
   is "TBD in a future revision."  This document therefore cannot cite a
   settled registration procedure for itself, and does not assert one.
   What it does provide now, so that registration is a formality once
   the tier-2 registry exists rather than a rewrite, is the two-sided
   conformance-vector set that document's discipline (Section 5)
   requires of any record profile: positive vectors with pinned values,
   and must-fail vectors that a conformant implementation MUST refuse
   rather than merely mismatch.

   Positive vector (MUST be accepted, and graded per Section 3.1 and
   Section 4.5 without exceeding the stated source):

   {
     "model_attestation": {
       "model_id":
         "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M",
       "weights_digest": { "digest_alg": "SHA-256",
                           "digest": "1993f98e…", "scope": "file" },
       "source": { "model_id": "self_reported",
                   "weights_digest": "computed" },
       "compute_attestation": {
         "runtime": { "name": "mesh-llm-host-runtime 0.76.0",
           "measurement_class": "os_measured" },
         "agent_runtime": { "agent_type": "react",
                            "sandbox_type": "gvisor",
                            "tool_version": "sha256:9b7412f8…" },
         "attestation_refs": []
       }
     }
   }

   MUST-FAIL vectors (a conformant verifier MUST NOT grade the field
   above what these rules permit):

Palanisamy & Mih          Expires 5 April 2027                 [Page 21]
Internet-Draft            AAC model_attestation             October 2026

   // (a) weights_digest present with no "source" entry: MUST default
   // to self_reported, MUST NOT be treated as "computed" or "attested".
   { "model_attestation": {
       "weights_digest": { "digest_alg": "SHA-256",
                           "digest": "1993f98e…", "scope": "file" } } }

   // (b) unrecognized measurement_class: MUST be reported as
   // unrecognized, MUST NOT be treated as equal to or higher than any
   // known class.
   { "model_attestation": { "compute_attestation": { "runtime": {
       "name": "custom-runtime 1.0",
       "measurement_class": "quantum_measured" } } } }

   // (c) attestation_refs entry whose cited record does not verify: no
   // field in the block may be upgraded to "attested" on account of the
   // citation.
   { "model_attestation": {
       "weights_digest": { "digest_alg": "SHA-256",
                           "digest": "1993f98e…", "scope": "file" },
       "source": { "weights_digest": "attested" },
       "compute_attestation": { "attestation_refs": [
         { "type": "example.invalid-attestation-v1",
           "purpose": "hardware",
           "digest_alg": "SHA-256", "digest": "0000…" } ] } } }

   // (d) agent_runtime.tool_version present with no "source" entry:
   // MUST default to self_reported, MUST NOT be treated as "computed".
   { "model_attestation": { "compute_attestation": { "agent_runtime": {
       "tool_version": "sha256:9b7412f8…" } } } }

13.  IANA Considerations

   This document has no IANA actions. model_attestation is a bare
   payload member name seeded by the base profile itself (Section 3),
   not a namespaced extension, so the base profile's namespacing
   convention does not apply to the member name.  Source labels and
   measurement classes are closed vocabularies of this document
   (Conventions and Section 4.1); a future revision may request IANA
   registries for either if independent extensions appear.  Registration
   of this document as a conforming tier-2 profile awaits the registry
   work noted in Section 12.

14.  References

14.1.  Normative References

Palanisamy & Mih          Expires 5 April 2027                 [Page 22]
Internet-Draft            AAC model_attestation             October 2026

   [I-D.mih-scitt-agent-action-capsule]
              Mih, S., "An Agent Action Capsule Profile for SCITT", Work
              in Progress, Internet-Draft, draft-mih-scitt-agent-action-
              capsule-05, 26 September 2026,
              <https://datatracker.ietf.org/doc/html/draft-mih-scitt-
              agent-action-capsule-05>.

   [I-D.mih-sokolov-scitt-payload-binding]
              Mih, S. and A. Sokolov, "Canonicalization Declaration for
              SCITT Signed Statements", Work in Progress, Internet-
              Draft, draft-mih-sokolov-scitt-payload-binding-05, 12
              September 2026, <https://datatracker.ietf.org/doc/html/
              draft-mih-sokolov-scitt-payload-binding-05>.

   [RFC2119]  Bradner, S., "Key words for use in RFCs to Indicate
              Requirement Levels", BCP 14, RFC 2119,
              DOI 10.17487/RFC2119, March 1997,
              <https://www.rfc-editor.org/rfc/rfc2119>.

   [RFC8174]  Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC
              2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174,
              May 2017, <https://www.rfc-editor.org/rfc/rfc8174>.

   [RFC8610]  Birkholz, H., Vigano, C., and C. Bormann, "Concise Data
              Definition Language (CDDL): A Notational Convention to
              Express Concise Binary Object Representation (CBOR) and
              JSON Data Structures", RFC 8610, DOI 10.17487/RFC8610,
              June 2019, <https://www.rfc-editor.org/rfc/rfc8610>.

   [RFC8785]  Rundgren, A., Jordan, B., and S. Erdtman, "JSON
              Canonicalization Scheme (JCS)", RFC 8785,
              DOI 10.17487/RFC8785, June 2020,
              <https://www.rfc-editor.org/rfc/rfc8785>.

14.2.  Informative References

   [I-D.mih-agent-accountability-conformance]
              Mih, S., "Agent Accountability: A Conformance and
              Verification Method", Work in Progress, Internet-Draft,
              draft-mih-agent-accountability-conformance-00, 31 July
              2026, <https://datatracker.ietf.org/doc/draft-mih-agent-
              accountability-conformance/>.

   [RFC7942]  Sheffer, Y. and A. Farrel, "Improving Awareness of Running
              Code: The Implementation Status Section", BCP 205,
              RFC 7942, DOI 10.17487/RFC7942, July 2016,
              <https://www.rfc-editor.org/rfc/rfc7942>.

Palanisamy & Mih          Expires 5 April 2027                 [Page 23]
Internet-Draft            AAC model_attestation             October 2026

   [RFC9334]  Birkholz, H., Thaler, D., Richardson, M., Smith, N., and
              W. Pan, "Remote ATtestation procedureS (RATS)
              Architecture", RFC 9334, DOI 10.17487/RFC9334, January
              2023, <https://www.rfc-editor.org/rfc/rfc9334>.

   [RFC9943]  Birkholz, H., Delignat-Lavaud, A., Fournet, C., Deshpande,
              Y., and S. Lasker, "An Architecture for Trustworthy and
              Transparent Digital Supply Chains", RFC 9943,
              DOI 10.17487/RFC9943, June 2026,
              <https://www.rfc-editor.org/rfc/rfc9943>.

Appendix A.  Fix to the base profile

   Revisions -04 and -05 of draft-mih-scitt-agent-action-capsule
   reference model_attestation in their epoch-boundary section and their
   security considerations without defining it, while producers and a
   registry entry already use the block.  This document supplies the
   definition (Section 3, Section 3.1).  The authors recommend that -06
   of the base profile (a) cite this document for the definition or fold
   Section 3 in, and (b) name the two extension containers explicitly:
   namespaced top-level members for correlation/provenance extensions,
   and model_attestation.compute_attestation for runtime and compute
   extensions.  Until (b) lands, implementations place namespaced
   extensions under model_attestation.compute_attestation as well (see
   Section 11).

Appendix B.  Complete Example

   The following is an example of a complete model_attestation object:

   {
     "model_attestation": {
       "model_id":
         "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M",
       "provider": "mesh-llm",
       "weights_digest": {
         "digest_alg": "SHA-256",
         "digest": "1993f98e…04724b12",
         "scope": "file"
       },
       "quantization": "Q4_K_M",
       "decoding": {
         "temperature": 0.0,
         "seed": 42
       },
       "source": {
         "model_id": "self_reported",
         "weights_digest": "computed",

Palanisamy & Mih          Expires 5 April 2027                 [Page 24]
Internet-Draft            AAC model_attestation             October 2026

         "quantization": "self_reported"
       },
       "compute_attestation": {
         "runtime": {
           "name": "mesh-llm-host-runtime 0.76.0",
           "runtime_digest": "c204ac76…4f23b723",
           "measurement_class": "os_measured",
           "platform_integrity": {
             "sip_enabled": true
           },
           "source": {
             "sip_enabled": "os_reported"
           }
         },
         "agent_runtime": {
           "agent_type": "react",
           "framework": "custom-agent-loop 1.4.0",
           "runtime_env": "python:3.11-slim",
           "sandbox_type": "gvisor",
           "tool_version": "sha256:9b7412f8…12345678",
           "source": {
             "agent_type": "self_reported",
             "framework": "self_reported",
             "runtime_env": "self_reported",
             "sandbox_type": "os_reported",
             "tool_version": "computed"
           }
         },
         "invocation": {
           "requested_model_id": "hermes-2-pro-7b",
           "resolved_model_id":
             "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M",
           "usage": { "input_tokens": 412, "output_tokens": 88 },
           "finish_status": "completed",
           "source": {
             "requested_model_id": "self_reported",
             "resolved_model_id": "provider_reported",
             "usage": "provider_reported",
             "finish_status": "provider_reported"
           }
         },
         "hardware": {
           "platform": "apple-silicon",
           "accelerator": "Apple M4 Max",
           "memory_bytes": 28991029248,
           "source": {
             "platform": "os_reported",
             "accelerator": "os_reported",

Palanisamy & Mih          Expires 5 April 2027                 [Page 25]
Internet-Draft            AAC model_attestation             October 2026

             "memory_bytes": "os_reported"
           }
         },
         "attestation_refs": []
       },
       "epoch_consistency": "consistent"
     }
   }

Appendix C.  Acknowledgments

   The authors thank the maintainers of the Mesh-LLM capsule plugin,
   whose shipping runtime measurements fixed the first two measurement
   classes, and the reviewers of the RATS architecture whose grading
   discipline Section 4.5 follows.

Authors' Addresses

   Govindaraj Palanisamy
   Independent
   Email: npgovintarajan@gmail.com

   Steven Mih
   Action State Group, Inc.
   Email: steven@actionstate.ai

Palanisamy & Mih          Expires 5 April 2027                 [Page 26]