{
  "canonicalUrl": "https://xn--mwe.com/research/machine-intelligence-credential-architecture/",
  "correctionStatus": "CURRENT K05 RELEASE",
  "findings": [
    "The report treats 1\\. Research-Status Front Matter as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.",
    "The report treats 2\\. Executive Decision Brief as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.",
    "The report treats 3\\. Identity and Credential Definitions as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.",
    "The report treats 4\\. Identity-Class Taxonomy as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.",
    "The report treats Machine Identity vs. Workload Identity Matrix as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.",
    "The report treats 5\\. Standards Landscape as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.",
    "The source report identifies this proposition for governed review: Phase 1: Basal Workload Identity (Months 1-6): Deploy SPIFFE/SPIRE for all internal microservice identity management20. Systematically eliminate all hardcoded API keys and transition entirely to short-lived SVIDs.",
    "The source report identifies this proposition for governed review: Phase 2: RATS Integration (Months 7-12): Bind workload provisioning directly to hardware TEE execution. Implement RFC 9334 RATS Verifier nodes to evaluate hardware evidence before releasing decryption keys or identities26.",
    "The source report identifies this proposition for governed review: Phase 3: Cross-Domain & Agent Identity (Months 13-18): Deploy WIMSE infrastructure based on draft-ietf-wimse-arch-082. Transition external-facing persistent agents to utilizing DIDs and W3C VCs.",
    "The source report identifies this proposition for governed review: Phase 4: Governance and Delegation (Months 19-24): Implement Execution Context Tokens (draft-nennemann-wimse-ect-00) to generate full cryptographic audit trails23. Activate Eviulon governance policy engines to evaluate the verified identity DAGs.",
    "The source report identifies this proposition for governed review: Path: /docs/patefacere/architecture/credentials-machine-intelligence-2026.md.",
    "The source report identifies this proposition for governed review: Stable Report ID: REP-PATEFACERE-20260812-MI-CREDS-01."
  ],
  "headings": [
    "Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust",
    "1\\. Research-Status Front Matter",
    "2\\. Executive Decision Brief",
    "3\\. Identity and Credential Definitions",
    "4\\. Identity-Class Taxonomy",
    "Machine Identity vs. Workload Identity Matrix",
    "5\\. Standards Landscape",
    "6\\. Comparative Protocol Analysis",
    "Comparative Technology Matrix",
    "7\\. Trust-Anchor Models",
    "Trust-Anchor Decision Tree",
    "8\\. Key Lifecycle",
    "Key Lifecycle State Machine",
    "9\\. Revocation and Compromise Recovery",
    "Revocation-Currentness Model",
    "Compromise and Recovery Protocol",
    "10\\. Delegation and Capability Control",
    "Delegation-Chain Model",
    "11\\. Attestation and Runtime Binding",
    "12\\. Privacy and Selective Disclosure",
    "Public and Private Identifier Matrix",
    "13\\. Offline Verification",
    "14\\. Post-Quantum Continuity",
    "Post-Quantum Transition Roadmap",
    "15\\. Legal and Policy Limits",
    "Claims a Signature Does NOT Prove",
    "16\\. Threat Model",
    "Threats and Mitigations Matrix (40 Items)",
    "17\\. Recommended Patefacere Architecture",
    "18\\. Eviulon Verification and Governance Use",
    "19\\. Migration and Adoption Roadmap",
    "20\\. Validation Plan",
    "Acceptance Tests (60 Items)",
    "Interoperability Scenarios (25 Items)",
    "21\\. Open Questions",
    "23\\. Claim-to-Source Traceability",
    "24\\. .uai and /docs Integration",
    "Works cited"
  ],
  "id": "REP-K01-004",
  "lastReviewed": "2026-08-16",
  "machineRecordUrl": "https://xn--mwe.com/data/reports/machine-intelligence-credential-architecture.json",
  "originalFilename": "Machine Intelligence Credential Architecture(1).md",
  "qualification": "The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.",
  "rawSourcePublic": false,
  "releaseId": "K12-2026-08-16",
  "researchCutoff": "2026-08-16",
  "slug": "machine-intelligence-credential-architecture",
  "source": "machine-intelligence-credential-architecture-1.md",
  "sourceRevalidatedAt": "2026-08-15T23:00:00Z",
  "sourceSha256": "27b4c5078a681b37e0dcabf6e041e81bd3a7effd1c9d7179cf6a430495a7e70d",
  "sourceSizeBytes": 70865,
  "sourceStatus": "reference-source; review and correct before active use",
  "sourceTitle": "Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust",
  "status": "PROJECT TECHNICAL PROPOSAL",
  "summary": "A credential architecture separating subject identity, issuer authority, technical verification, claim status, revocation, currentness and purpose suitability.",
  "title": "Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust",
  "topic": "identity",
  "type": "ReportSynthesis"
}
