Network Working Group D. A. Konviser Internet-Draft Gravit Open Network Foundation Intended status: Informational 24 July 2026 Expires: 25 January 2027 Gravit Epistemic Verification Protocol (GEVP) v0.1 draft-gravit-gevp-04 Abstract Gravit Epistemic Verification Protocol (GEVP) defines minimal data types and APIs for autonomous agents and human-machine systems to achieve epistemic convergence without centralized truth arbiters. GEVP is transport-agnostic, blockchain-agnostic, and model-agnostic. This document defines a parameterized cost model where C_validation is the cost to verify a Claim's provenance and signatures, and C_manipulation is the estimated cost to forge a quorum of attestations under GQRVP. The protocol enforces the engineering invariant C_manipulation > C_validation for all accepted Claims. This document was previously published as draft-gravit-vcp-00 and -01 under the acronym VCP (Verifiable Convergence Protocol). To avoid collision with VeritasChain Protocol (VCP) defined in draft-kamimura- scitt-vcp [KAMIMURA-VCP], which is a SCITT profile for financial trading audit trails first published December 2025, the acronym is changed to GEVP from -02 onward. The two protocols are unrelated and address different domains. The former VCP acronym is deprecated and MUST NOT be used for this protocol. This revision (-04) archives reproducible trace to Zenodo DOI for long-term permanence (addresses GitHub rebase risk), adds Section 3.2 Authentication Profile (SHOULD did:web, MAY did:key, PoW/stake deferred), adds Section 1.2 explicit comparison table with [KAMIMURA- VCP], adds Liaison Statement with SCITT WG, adds Implementation Status with two independent implementations, retains Informational status per RFC track strategy, and retains all normative content from -03 Posted 23 Jul 2026. This revision (-03) removed workgroup tag, normalized Godel ASCII. This revision (-02) pinned commits, added confusion matrix, clarified heuristics, defined SCITT mappings, added Appendix B. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Konviser Expires 25 January 2027 [Page 1] Internet-Draft GEVP July 2026 Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 25 January 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 3 2. Related Work and Disambiguation . . . . . . . . . . . . . . . 3 3. Comparison with VeritasChain VCP [KAMIMURA-VCP] . . . . . . . 4 4. Terminology and Definitions . . . . . . . . . . . . . . . . . 4 5. Cost Model - Parameterized Estimate of C() . . . . . . . . . 5 6. Authentication Profile and DID Method . . . . . . . . . . . . 5 7. Conformance . . . . . . . . . . . . . . . . . . . . . . . . . 6 8. Implementation Status . . . . . . . . . . . . . . . . . . . . 6 9. Core Types . . . . . . . . . . . . . . . . . . . . . . . . . 7 9.1. Claim . . . . . . . . . . . . . . . . . . . . . . . . . . 7 9.2. Attestation . . . . . . . . . . . . . . . . . . . . . . . 7 9.3. Action . . . . . . . . . . . . . . . . . . . . . . . . . 7 9.4. Trace . . . . . . . . . . . . . . . . . . . . . . . . . . 7 10. Core Endpoints . . . . . . . . . . . . . . . . . . . . . . . 8 11. GQRVP Security Parameters and Heuristic Bound . . . . . . . . 8 11.1. Heuristic Resilience Bound - Proof Sketch, Not Formal Derivation . . . . . . . . . . . . . . . . . . . . . . . 8 11.2. Threshold theta_critical . . . . . . . . . . . . . . . . 9 12. Empirical Validation - Reproducibility with Pinned Commits . 9 13. SCITT Architecture Mapping - Exact Definitions . . . . . . . 10 Konviser Expires 25 January 2027 [Page 2] Internet-Draft GEVP July 2026 13.1. SCITT Primitives (Recap) . . . . . . . . . . . . . . . . 10 13.2. GEVP to SCITT Mapping - Normative . . . . . . . . . . . 10 13.3. Separation of SCITT Guarantees from Epistemic Guarantees . . . . . . . . . . . . . . . . . . . . . . . 11 13.4. Comparison to VeritasChain VCP [KAMIMURA-VCP] . . . . . 12 14. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 12 15. Security Considerations . . . . . . . . . . . . . . . . . . . 12 16. References . . . . . . . . . . . . . . . . . . . . . . . . . 12 Appendix A. Formal Completeness Boundary of theta_critical (Informational) . . . . . . . . . . . . . . . . . . . . . 14 Appendix B. Liaison Statement with SCITT WG . . . . . . . . . . 14 Appendix C. Changelog -04 vs -03 (24 Jul 2026) . . . . . . . . . 15 Appendix D. Changelog -03 vs -02 . . . . . . . . . . . . . . . . 15 Appendix E. Changelog -02 vs -01 . . . . . . . . . . . . . . . . 15 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 16 1. Introduction As AI transitions to autonomous agents, lack of verifiable trust is a bottleneck. Existing transparency systems (SCITT) provide software supply-chain transparency. GEVP extends this to epistemic transparency for AI actions. A system implementing GEVP is an Epistemic Execution System (EES). No Action is accepted without verifiable Claim basis. This document is an Individual Internet-Draft, not endorsed by the IETF, with no formal standing. Intended WG: SCITT. This document is not a SCITT profile for financial trading audit trails; for that, see [KAMIMURA-VCP]. 2. Related Work and Disambiguation The acronym VCP is already in active use in the SCITT working group by [KAMIMURA-VCP], first published December 2025, titled "A SCITT Profile for Verifiable Audit Trails in Algorithmic Trading: The VeritasChain Protocol (VCP)". That document defines a SCITT profile for tamper-evident audit trails of AI-driven algorithmic trading decisions, with conformance tiers Silver/Gold/Platinum, per-Actor hash chaining, and crypto-shredding for GDPR. Konviser Expires 25 January 2027 [Page 3] Internet-Draft GEVP July 2026 This document (GEVP) defines an unrelated system for epistemic convergence of autonomous agents. To avoid ambiguity in citations, implementation claims, mailing-list discussions, and future RFC references, the acronym VCP is deprecated for this protocol from -02 onward and replaced by GEVP. Implementations MUST use GEVP and MUST NOT use VCP to refer to Gravit Epistemic Verification Protocol. This document references [KAMIMURA-VCP] for disambiguation and for SCITT terminology alignment. 3. Comparison with VeritasChain VCP [KAMIMURA-VCP] To avoid confusion, this section provides normative comparison: VCP [KAMIMURA-VCP] is a SCITT profile for financial trading audit trails: defines VCP Event as Signed Statement with per-Actor hash chaining, conformance tiers Silver/Gold/Platinum, modules VCP-TRADE and VCP-RISK, and crypto-shredding for GDPR. Focus is completeness and tamper-evidence of trading events. GEVP defines epistemic convergence for autonomous agents: Claim/Attestation/Action/Trace, GQRVP with MWU and quadratic reputation, cost model C_manipulation > C_validation * 2.0, theta_critical RECOMMENDED 0.73 with empirical TPR 93.4% (1401/1500) FPR 0.4% (6/1500). GEVP does NOT use per-Actor hash chaining, does NOT define trading modules, does NOT use crypto-shredding. Domains are complementary, no feature overlap. Implementations of GEVP MUST NOT claim VCP conformance and vice versa unless implementing both profiles separately. 4. Terminology and Definitions GQRVP is defined in this document and across Gravit documentation as "Gossip with Quadratic Reputation and Verifiable Proofs". This definition is canonical and supersedes all prior informal descriptions such as "Quantum-Ready" or "Quantum Resilient" or "Gravit Quantum-Ready Verification Protocol" used in early README drafts or in draft-gravit-vcp-00. GQRVP combines Multiplicative Weights Update (MWU) for reputation with gossip dissemination. Epistemic Execution System (EES): A system where state transitions are gated by verifiable claims. Triad: Open Network (Gateway, Coordinator) - interaction, Continuum (SCE) - state evolution, Quantum (Omega Trace Store) - trace integrity. Claim, Attestation, Action, Trace: See Section 5. These terms are defined for GEVP and are distinct from VCP Event, VCP Issuer, VCP Receipt as defined in [KAMIMURA-VCP]. Konviser Expires 25 January 2027 [Page 4] Internet-Draft GEVP July 2026 5. Cost Model - Parameterized Estimate of C() Let Claim c have k attestations from distinct DIDs. This section defines a parameterized cost estimate, not a formal theorem derived from MWU regret bounds. Full game-theoretic derivation is deferred to [GQRVP-ANALYSIS] as work in progress. C_validation(c) = cost(COSE_Signature_Verify) * k + cost(fetch_trace) + cost(Merkle_Proof_Verify). Unit is abstract gas-equivalent operations. This is operational and transparent. C_manipulation(c) = min estimated cost for adversary to produce k' attestations sufficient to pass Action verification. As parameterized estimate under GQRVP: C_manipulation(c) = k' * cost(DID_creation) + k' * cost(sign) * (1 / eta) ^ gamma, where eta is MWU learning rate (used here as penalty parameter modeling rounds adversary must sustain, not directly as attack cost) and gamma is quadratic exponent penalizing Sybil concentration. The use of eta in this form is heuristic: lower eta slows honest weight decay, increasing rounds adversary must sustain. This is NOT derived from Arora et al. [MWU] Theorem 2.1; it is a modeling choice for cost comparison. Invariant: A Claim is accepted only if C_manipulation(c) > C_validation(c) * security_margin, where security_margin = 2.0 by default. The default value of 2.0 is chosen empirically as the minimum multiplicative buffer that accounts for (a) variance in cost(DID_creation) across supported DID methods (did:web, did:jwk) and (b) the stochastic nature of MWU-based confidence scoring under realistic network asynchrony. This value MAY be overridden by a deployment-specific profile when measured adversarial cost distributions are available. The constant is an engineering safety factor, not a cryptographically derived bound. As a starting point for deployment profiles, RECOMMENDED parameters: did:web at most 10 new DID registrations per hour per controlling domain, did:jwk require proof-of-work with difficulty approximately 2^20 hash operations, any DID method exponential back-off after repeated failed attestations. Exact values left to deployment profile and Transparency Service Registration Policy. This formalizes the informal "manipulation costs more than validation" as an engineering invariant, not a cryptographic proof. 6. Authentication Profile and DID Method This document is an Informational proposal. Full DID method agility is deferred to deployment profile, but this section defines minimal profile for interoperability: Konviser Expires 25 January 2027 [Page 5] Internet-Draft GEVP July 2026 Implementations SHOULD support did:web per [DID-CORE] and [RFC3986] for issuer and attester identifiers, as did:web provides DNS-based discoverability compatible with SCITT Transparency Service identities. Implementations MAY support did:key for ephemeral attestors. Proof-of-Work or Proof-of-Stake admission control for DID creation is deferred to deployment profile, but implementations MUST rate-limit DID creation or require PoW/stake to preserve invariant C_manipulation > C_validation. did:web introduces DNS/HTTPS central trust anchor; this limitation is acknowledged and MUST be documented in deployment. COSE signatures SHOULD use post-quantum suite if quantum resilience is claimed; GEVP core does not claim quantum resilience in v0.1. 7. Conformance A system is GEVP-Compatible iff it implements: (1) 4 Core Endpoints defined in Section 6, (2) confidence scoring via MWU plus Gossip as per GQRVP Section 7, (3) Actions reference Claim as basis with rejection if empty, (4) Trace is immutable and content-addressed. 8. Implementation Status This section records implementation status for IESG evaluation per RFC 7942. Two independent implementations exist in gravitnet repository: 1. Reference implementation (Python): Gateway, Coordinator, SCE Continuum, Omega Trace Store, tools/verify_local.sh --trace sybil- 10x-g1.5 --theta 0.73 reproduces confusion matrix TP 1401 FP 6 TN 1494 FN 99 Precision 0.996 Recall 0.934 F1 0.964 ROC AUC ~0.98 on pinned dataset blob/7755f53. 2. Edge implementation (Rust/WASM): Independent COSE_Sign1 verification and Merkle proof verification, compatible with SCITT SCRAPI. Both implementations interoperate on Claim payload and Receipt verification. Reproducibility: Dataset archived at Zenodo DOI placeholder 10.5281/ zenodo.GEVP04 (to be finalized upon Zenodo upload) and GitHub blob/7755f53/traces/sybil-10x-g1.5.jsonl (1.21MB). Trace README at blob/9f3e5d1. Permanent archive mitigates GitHub rebase risk noted in -03 review. Konviser Expires 25 January 2027 [Page 6] Internet-Draft GEVP July 2026 9. Core Types 9.1. Claim Atomic epistemic unit: claim_id (UUIDv7, content-addressed), content (CBOR/JSON), provenance (DID + Trace ref), confidence float 0.0-1.0, trace_id. A Claim is NOT a VCP Event as defined in [KAMIMURA-VCP]. In SCITT mapping (Section 9), a Claim is the application payload of a SCITT Signed Statement. { "claim_id": "sha256:canonical-cbor-hash", "content": "string or CBOR", "provenance": [{"type": "url|attestation", "src": "string", "signed_by": "did:web:..."}], "confidence": 0.0-1.0, "trace_id": "trace-sha256-..." } 9.2. Attestation COSE or JOSE signature over Claim hash by DID. DID method MUST be did:web or did:jwk for -02. Note: A GEVP Attestation is NOT a SCITT Receipt. A SCITT Receipt is issued by a Transparency Service and proves registration or inclusion of a Signed Statement in its Verifiable Data Structure. An Attestation is issued by the Claim author (Issuer) and proves authorship. See Section 9 for exact mapping. 9.3. Action State change grounded in Claims. Gateway MUST reject if basis array is empty. Gateway MUST reject if min(confidence of basis) < theta_critical. theta_critical is RECOMMENDED 0.73, see Section 7.2. The previous -00 requirement of MUST 0.731 is retracted as false precision. 9.4. Trace Immutable, append-only record with final_confidence and merkle_root. A GEVP Trace is NOT equivalent to a SCITT Transparency Service entry. A Trace is application-level record of epistemic verification rounds. In SCITT mapping (Section 9), a Trace is included as part of the Signed Statement payload or as separate attachment referenced by the Statement, and its inclusion is proven by a SCITT Receipt issued by the Transparency Service. Konviser Expires 25 January 2027 [Page 7] Internet-Draft GEVP July 2026 10. Core Endpoints All endpoints over HTTPS, application/json or application/cbor. Authorization beyond Attestation signature (API auth, rate-limiting, error versioning) is out of scope for -02 and deferred to deployment profile. POST /v1/claim - Submit Claim. Returns claim_id and trace_id. In SCITT terms: application submits payload to be wrapped as Signed Statement. GET /v1/claim/{claim_id} - Fetch Claim with attestations and optional SCITT Receipt if registered. POST /v1/action/verify - Verify Action basis. Input: action + basis claims. Output: accept/reject with cost analysis. This endpoint enforces Registration Policy-like checks (basis non-empty, confidence threshold) before submitting to Transparency Service. GET /v1/trace/{trace_id} - Fetch immutable Trace with Merkle proof. If SCITT-registered, returns also Receipt chain. 11. GQRVP Security Parameters and Heuristic Bound GQRVP parameters: eta = 0.2 (MWU learning rate), gamma = 1.5 (quadratic penalty exponent), eps = 0.1 (exploration / gossip fault tolerance). 11.1. Heuristic Resilience Bound - Proof Sketch, Not Formal Derivation This section was titled "Derivation" in -01. Per feedback, it is renamed to heuristic bound with proof sketch. It is NOT a formal theorem derived from MWU regret bounds. It is a parameterized condition for honest weight dominance used for engineering calibration. Heuristic: Under MWU, adversary weight decays as (1-eta)^t. With quadratic penalty gamma, effective Sybil cost grows as n^gamma. As modeling assumption, honest supermajority condition for convergence is modeled as: h > (1 / (1 + gamma^{-1})) + eps, where h is fraction of honest weight. For gamma=1.5: 1/(1+1/1.5)=1/(1+0.666)=0.6. Adding eps=0.1 for network asynchrony and eta=0.2 for learning lag, we model requirement h > 0.7 honest weight, i.e., tolerates f < 0.3 Byzantine weight. This corresponds to approximately 33% standard BFT resilience in worst case without quadratic benefit. Konviser Expires 25 January 2027 [Page 8] Internet-Draft GEVP July 2026 Previous -00 claim of "67% Byzantine resilience" is retracted as imprecise and MUST NOT be used. Implementations SHOULD NOT claim 67% without explicit Sybil cost model. Claim "up to 50% resilience under Sybil factor 10x" in -01 is rephrased as observed in simulation under 10x Sybil amplification with gamma=1.5 (see empirical section), not as general theorem. See [GQRVP-ANALYSIS] for full analysis and open questions. Link to Arora et al. [MWU] is for background on MWU, not as source of this formula. 11.2. Threshold theta_critical theta_critical was set to 0.731 in -00 without derivation. In -01, theta_critical is defined as point where formal verification cost equals empirical validation cost crossover, approximated via calibration on sybil-10x dataset. Methodology: ROC curve on 100 simulated runs (50 honest, 50 Sybil with 10x amplification, g=1.5, artificial 50/50 class balance -- not reflective of real-world attack distribution, documented as limitation). Optimal F1 threshold found at 0.728 +/- 0.015. We round to RECOMMENDED 0.73. The three-decimal 0.731 in -00 was false precision and is deprecated. Deployments MAY calibrate theta between 0.70 and 0.80 per domain. See Appendix B for Godel completeness boundary interpretation. 12. Empirical Validation - Reproducibility with Pinned Commits The -00 statement "sybil-10x-g1.5 trace shows 30 scores above threshold" is replaced with verifiable artifact with pinned commits (addresses -01 TODO). Dataset: traces/sybil-10x-g1.5.jsonl (100 runs, 30 sampled claims per run = 3000 records = 1500 honest + 1500 sybil). Location: https://github.com/GravitOpenNetwork/gravitnet/tree/main/traces Pinned commits for -02: data file https://github.com/GravitOpenNetwork/gravitnet/blob/7755f53/traces/ sybil-10x-g1.5.jsonl (commit 7755f53, 1.21 MB, 3000 lines) and README https://github.com/GravitOpenNetwork/gravitnet/blob/9f3e5d1/traces/ README.md (commit 9f3e5d1). These blobs are immutable. Future revisions will pin new datasets with new hashes. Full confusion matrix at theta=0.73 for pinned seed (one reproducible instance, not general guarantee): Honest: mean 0.839 sd 0.07, passes theta 1401/1500 (93.4% TPR). Sybil: mean 0.412 sd 0.12, passes theta 6/1500 (0.4% FPR). Combined: 1407 passes out of 3000. True Positives 1401, False Positives 6, Konviser Expires 25 January 2027 [Page 9] Internet-Draft GEVP July 2026 True Negatives 1494, False Negatives 99. Precision 0.996, Recall 0.934, F1 0.964. ROC AUC ~0.98 (empirical). Note: 2987/3000 honest >=0.73 mentioned in -01 text was from different seed; corrected to 1401/1500 for pinned file to ensure reproducibility. Variation across seeds is expected. This reconciles published dataset statistics with draft values. Limitation: 50/50 class balance is artificial and does not reflect real attack prior. Dataset is simulation, not production traffic. This is not a proof, but a reproducible calibration for threshold selection. Reproduction: ./tools/verify_local.sh --trace sybil-10x-g1.5 --theta 0.73 -- also python snippet in traces/README.md for independent verification of C() invariant (0 violations expected for honest passes). 13. SCITT Architecture Mapping - Exact Definitions This section defines the exact mapping of GEVP concepts to SCITT architecture [SCITT-ARCH] and SCRAPI [SCRAPI], addressing disambiguation from [KAMIMURA-VCP]. 13.1. SCITT Primitives (Recap) Per [SCITT-ARCH]: Issuer creates Signed Statement, submits to Transparency Service via SCRAPI, Service validates against Registration Policy, appends to Verifiable Data Structure (append- only log), and returns Receipt (COSE Receipt, Merkle inclusion proof). Receipt proves registration. Transparent Statement is Signed Statement plus Receipt. 13.2. GEVP to SCITT Mapping - Normative Claim: The application payload of a SCITT Signed Statement. When a GEVP Claim is registered, it is encoded as CBOR/JSON and placed in the payload of a COSE_Sign1 Signed Statement. The Issuer of the Signed Statement is the GEVP Issuer (did:web / did:jwk for -02). Custom protected headers MAY include: confidence (float), trace_id, gqrvp_params (eta, gamma, eps). Attestation: NOT a SCITT Receipt. An Attestation is a separate COSE/ JOSE signature over Claim hash by DID, proving authorship. Multiple Attestations can be aggregated before creating the Signed Statement. The Signed Statement signature by Issuer MAY coincide with one Attestation if Issuer is also author, but conceptually distinct. Konviser Expires 25 January 2027 [Page 10] Internet-Draft GEVP July 2026 Action verification: Pre-registration check performed by GEVP Gateway before submission to Transparency Service. Gateway MUST reject Action if basis array empty or min(confidence) < theta_critical. This check is analogous to Registration Policy enforcement in SCITT, but applied at application layer. Transparency Service MAY also enforce its own Registration Policy (e.g., rate-limiting, DID allowlist). Trace: NOT a Transparency Service entry. A GEVP Trace is application-level immutable record of epistemic verification rounds (gqrvp_rounds, final_confidence, merkle_root of claim set). When registered with SCITT, the Trace is either embedded in Signed Statement payload alongside Claim or stored separately and referenced by trace_id. Inclusion of Trace is proven by SCITT Receipt, not by Trace itself. Transparency Service: In GEVP deployment, a SCITT-compliant Transparency Service configured with GEVP Registration Policy. It operates Verifiable Data Structure. Who acts as operator is deployment-specific and out of scope for -02. Receipt: COSE Receipt issued by Transparency Service proving inclusion of Signed Statement (containing Claim) in its log. GEVP clients MUST verify Receipt via COSE_Verify and Merkle proof. A GEVP client that holds Claim + Attestations + Receipt has registration evidence. Transparent Statement: Signed Statement (with Claim payload) + Receipt. This is what GEVP stores in Omega Trace Store as equivalent to Trace entry with external verifiability. 13.3. Separation of SCITT Guarantees from Epistemic Guarantees SCITT provides: authenticity (who issued Signed Statement), transparency (inclusion proven by Receipt), registration evidence (when and by which Service), accountability (log is append-only, non- repudiation). SCITT does NOT establish factual accuracy or epistemic truth of Statement payload. GEVP provides on top: epistemic convergence via GQRVP (MWU + quadratic penalty + gossip) and threshold theta_critical. The epistemic mechanism is clearly separated: SCITT guarantees that a Claim was registered and not tampered with; GEVP estimates whether a Claim should be trusted epistemically based on confidence aggregation under Sybil constraints. An attacker can register a false Claim with valid SCITT Receipt; GEVP's role is to assign low confidence to it if honest weight dominates. Konviser Expires 25 January 2027 [Page 11] Internet-Draft GEVP July 2026 13.4. Comparison to VeritasChain VCP [KAMIMURA-VCP] [KAMIMURA-VCP] defines VCP Event as payload of Signed Statement for trading audit trails, with per-Actor hash chaining, three conformance tiers, and crypto-shredding. GEVP does NOT use per-Actor hash chaining, does NOT define trading-specific modules (VCP-TRADE, VCP- RISK), and does NOT use crypto-shredding. GEVP focuses on confidence aggregation for epistemic claims, not completeness guarantees for trading events. The two profiles are complementary and address different domains. 14. IANA Considerations No IANA actions required at this time. 15. Security Considerations GEVP assumes honest supermajority in weight, not node count, due to quadratic penalty. If DID creation is free and gamma is disabled, Sybil attack reduces to standard BFT 33% bound. Implementations MUST rate-limit DID creation or require proof-of-work/stake for DID registration to preserve C_manipulation > C_validation. DID rate- limiting parameters: as a starting point, RECOMMENDED at most 10 new DID registrations per hour per controlling domain for did:web, PoW difficulty approximately 2^20 hash operations for did:jwk, and exponential back-off after repeated failed attestations. Exact values left to deployment profile and Transparency Service Registration Policy. COSE signatures MUST use post-quantum secure suite (e.g., Dilithium) if quantum resilience is claimed -- GEVP core does not claim quantum resilience in -02. did:web introduces DNS/HTTPS central trust anchor -- documented as limitation vs "without centralized truth arbiters". SCITT Receipt verification MUST include Merkle inclusion proof validation and Service identity check per [SCITT-ARCH]. 16. References [SCITT-ARCH] IETF, "An Architecture for a Transparent and Endorsable Network for Supply Chain Data", Work in Progress, Internet-Draft, draft-ietf-scitt-architecture, . Konviser Expires 25 January 2027 [Page 12] Internet-Draft GEVP July 2026 [SCRAPI] IETF, "SCITT Reference API (SCRAPI) - OpenAPI for SCITT", Work in Progress, Internet-Draft, draft-ietf-scitt-scrapi, . [KAMIMURA-VCP] Kamimura, T., "A SCITT Profile for Verifiable Audit Trails in Algorithmic Trading: The VeritasChain Protocol (VCP)", Work in Progress, Internet-Draft, draft-kamimura-scitt- vcp, URL https://www.ietf.org/archive/id/draft-kamimura- scitt-vcp-00.html, . [MWU] Arora, S., Hazan, E., and S. Kale, "The Multiplicative Weights Update Method: a Meta-Algorithm and Applications", 2012. [GOSSIP] Boyd, S., "Gossip Algorithms: Design, Analysis and Applications", 2006. [DID-CORE] W3C, "Decentralized Identifiers (DIDs) v1.0". [COSE] IETF, "CBOR Object Signing and Encryption (COSE)", RFC 9052, . [GQRVP-ANALYSIS] Gravit Open Network Foundation, "GQRVP Security Analysis - Formal Derivation (Work in Progress)", URL https://github.com/GravitOpenNetwork/gravitnet/blob/main/specs/ RFC/GQRVP-security.md, 2026. [TRACE-DATASET] Gravit Open Network Foundation, "Empirical Trace - sybil- 10x-g1.5 Pinned", URL https://github.com/GravitOpenNetwork/gravitnet/blob/7755f53/ traces/sybil-10x-g1.5.jsonl, 2026. [TRACE-README] Gravit Open Network Foundation, "Traces README Pinned", URL https://github.com/GravitOpenNetwork/gravitnet/blob/9f3e5d1/ traces/README.md, 2026. [DID-RUBRIC] W3C, "DID Specification Rubrics". [RFC3986] IETF, "Uniform Resource Identifier (URI): Generic Syntax", RFC 3986, . Konviser Expires 25 January 2027 [Page 13] Internet-Draft GEVP July 2026 [ZENODO-GEVP04] Gravit Open Network Foundation, "GEVP Empirical Trace sybil-10x-g1.5 - Zenodo Archive (to be finalized)", DOI 10.5281/zenodo.GEVP04, URL https://doi.org/10.5281/zenodo.GEVP04, . [GODEL] Godel, K., "On Formally Undecidable Propositions of Principia Mathematica and Related Systems", 1931. Appendix A. Formal Completeness Boundary of theta_critical (Informational) This appendix is purely interpretive and is not required for interoperability or conformance. It may be removed in future revisions. GEVP operates at the boundary of formal provability. No formal system can prove all true statements of interest per Godel's Second Incompleteness Theorem [GODEL]. Theta_critical is defined as practical boundary between formal sufficiency and semantic escalation. In draft-gravit-vcp-00, theta_critical was stated as 0.731 MUST with 30 scores above threshold (0 below, 30 above) as knee point. This was false precision. In -01/-02 (now GEVP), theta is RECOMMENDED 0.73, calibrated via ROC (0.728 0.015) on sybil-10x dataset (100 runs, 30 claims each). In pinned dataset 7755f53: honest mean 0.839 passes 1401/1500 @0.73, sybil mean 0.412 passes 6/1500. When confidence >= theta, system MAY treat result as formally sufficient. When below, SHOULD escalate to Continuum-style semantic verification. Interpretation: High-confidence regime (above theta) dominates for honest claims (93.4% TPR in this seed), but protocol reserves formal- to-epistemic transition point. This reflects Godel-grounded design: remainder must be handled by epistemic verification, not formal proof. This appendix is philosophical interpretation, not formal reduction from Godel. Appendix B. Liaison Statement with SCITT WG Status: GEVP is an Individual Internet-Draft proposing a complementary epistemic layer on top of SCITT architecture. GEVP reuses SCITT Signed Statement, Transparency Service, Receipt, Registration Policy, and SCRAPI per [SCITT-ARCH] and [SCRAPI]. GEVP does NOT require SCITT WG charter change. Konviser Expires 25 January 2027 [Page 14] Internet-Draft GEVP July 2026 Feedback solicited: correctness of SCITT mapping (Claim as payload, Attestation != Receipt, Trace != TS entry), Registration Policy enforcement (pre-registration check at Gateway analogous to SCITT Registration Policy), and suitability for Informational RFC. Contact: ietf@gravit.space. If SCITT WG deems epistemic convergence out of scope, authors propose to continue in IRTF DINRG as alternative venue, maintaining SCITT compatibility. Relationship to [KAMIMURA-VCP]: VeritasChain VCP is sovereign domain for financial audit trails. GEVP references [KAMIMURA-VCP] for disambiguation and terminology alignment. No competition. Appendix C. Changelog -04 vs -03 (24 Jul 2026) -04: Zenodo DOI for reproducible trace (10.5281/zenodo.GEVP04 placeholder, mitigates GitHub rebase risk per -03 review), Section 3.2 Authentication Profile (SHOULD did:web, MAY did:key, rate-limit or PoW/stake), Section 1.2 Comparison table VCP vs GEVP, Implementation Status with two independent implementations (Python ref and Rust/WASM edge), Liaison Statement with SCITT WG, retains Informational track per strategy, 0 non-ASCII, VALID xml2rfc v3. Appendix D. Changelog -03 vs -02 -03: Editorial for SCITT submission: removed workgroup tag (Individual I-D, IESG state I-D Exists, Stream None), normalized Godel to ASCII (0 non-ASCII, 0 idnits warnings), date 23 Jul 2026, no normative changes from -02 Posted 19:27. Appendix E. Changelog -02 vs -01 - Renamed from VCP to GEVP to avoid collision with [KAMIMURA-VCP] (VeritasChain Protocol, Dec 2025). Acronym VCP deprecated. Added Related Work disambiguation Section 1.1, added [KAMIMURA-VCP] reference, added comparison Section 8.4. - Pinned commits 7755f53 (data) and 9f3e5d1 (README) for reproducibility, addresses -01 TODO - Added full confusion matrix: TPR 93.4% (1401/1500), FPR 0.4% (6/1500), Precision 0.996, Recall 0.934, F1 0.964, ROC AUC ~0.98 at theta=0.73 -- reconciles dataset statistics - Renamed Derivation to Heuristic Bound with proof sketch, clarified C_manipulation as parameterized estimate not derived from MWU Konviser Expires 25 January 2027 [Page 15] Internet-Draft GEVP July 2026 - Defined exact SCITT mappings per [KAMIMURA-VCP] feedback: Attestation != Receipt (Attestation is author signature, Receipt is Service-issued inclusion proof), Trace != Transparency Service entry (Trace is app record, inclusion proven by Receipt), Claim is payload of Signed Statement. Added Section 8 with normative mapping and separation of SCITT authenticity vs epistemic truth guarantees. - Specified trust and admission model: did:web centralization limitation, MUST rate-limit DID creation or require PoW/stake, deferred to deployment profile - Clarified did:web centralization limitation, API auth out of scope - Added Appendix B: Godel completeness boundary - Retracted 67% claim reaffirmed, 50% claim rephrased as observed in simulation - Fixed inconsistency 2987/3000 vs 1401/1500 by pinning to actual file Author's Address Dr. Alex Konviser Gravit Open Network Foundation CH- Zurich Switzerland Email: ietf@gravit.space Konviser Expires 25 January 2027 [Page 16]