SCITT D. A. Konviser Internet-Draft Gravit Open Network Foundation Intended status: Informational 21 July 2026 Expires: 22 January 2027 Verifiable Convergence Protocol (VCP) v0.1 draft-gravit-vcp-01 Abstract Verifiable Convergence Protocol (VCP) defines minimal data types and APIs for autonomous agents and human-machine systems to achieve epistemic convergence without centralized truth arbiters. VCP is transport-agnostic, blockchain-agnostic, and model-agnostic. This document defines a formal cost model where C_validation is the cost to verify a Claim's provenance and signatures, and C_manipulation is the cost to forge a quorum of attestations under GQRVP. The protocol enforces the invariant C_manipulation > C_validation for all accepted Claims. This revision addresses derivation of security parameters and empirical validation methodology. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 22 January 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights Konviser Expires 22 January 2027 [Page 1] Internet-Draft VCP July 2026 and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 2. Terminology and Definitions . . . . . . . . . . . . . . . . . 2 3. Cost Model - Formal Definition of C() . . . . . . . . . . . . 3 4. Conformance . . . . . . . . . . . . . . . . . . . . . . . . . 3 5. Core Types . . . . . . . . . . . . . . . . . . . . . . . . . 3 5.1. Claim . . . . . . . . . . . . . . . . . . . . . . . . . . 3 5.2. Attestation . . . . . . . . . . . . . . . . . . . . . . . 3 5.3. Action . . . . . . . . . . . . . . . . . . . . . . . . . 3 5.4. Trace . . . . . . . . . . . . . . . . . . . . . . . . . . 4 6. Core Endpoints . . . . . . . . . . . . . . . . . . . . . . . 4 7. GQRVP Security Parameters and Derivation . . . . . . . . . . 4 7.1. Derivation of Resilience Bound . . . . . . . . . . . . . 4 7.2. Threshold theta_critical . . . . . . . . . . . . . . . . 5 8. Empirical Validation - Reproducibility . . . . . . . . . . . 5 9. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 5 10. Security Considerations . . . . . . . . . . . . . . . . . . . 5 11. References . . . . . . . . . . . . . . . . . . . . . . . . . 5 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 6 1. Introduction As AI transitions to autonomous agents, lack of verifiable trust is a bottleneck. Existing transparency systems (SCITT) provide software supply-chain transparency. VCP extends this to epistemic transparency for AI actions. A system implementing VCP is an Epistemic Execution System (EES). No Action is accepted without verifiable Claim basis. 2. Terminology and Definitions GQRVP is defined in this document and across Gravit documentation as "Gossip with Quadratic Reputation and Verifiable Proofs". This definition is canonical and supersedes prior informal descriptions such as "Quantum-Ready" or "Quantum Resilient" used in early README drafts. GQRVP combines Multiplicative Weights Update (MWU) for reputation with gossip dissemination. Konviser Expires 22 January 2027 [Page 2] Internet-Draft VCP July 2026 3. Cost Model - Formal Definition of C() Let Claim c have k attestations from distinct DIDs. C_validation(c) = cost(COSE_Signature_Verify) * k + cost(fetch_trace) + cost(Merkle_Proof_Verify). Unit is abstract gas-equivalent operations. C_manipulation(c) = min cost for adversary to produce k' attestations sufficient to pass Action verification. Under GQRVP: C_manipulation(c) = k' * cost(DID_creation) + k' * cost(sign) * (1 / eta) ^ gamma, where eta is learning rate and gamma is quadratic exponent penalizing Sybil concentration. Invariant: A Claim is accepted only if C_manipulation(c) > C_validation(c) * security_margin, where security_margin = 2.0 by default. This formalizes the informal "manipulation costs more than validation". 4. Conformance A system is VCP-Compatible iff it implements: (1) 4 Core Endpoints, (2) confidence scoring via MWU plus Gossip as per GQRVP Section 5, (3) Actions reference Claim as basis, (4) Trace is immutable and content-addressed. 5. Core Types 5.1. Claim Atomic epistemic unit: claim_id (UUIDv7, content-addressed), content (CBOR/JSON), provenance (DID + Trace ref), confidence float 0.0-1.0, trace_id. 5.2. Attestation COSE or JOSE signature over Claim hash by DID. DID method MUST be did:web or did:jwk for -01. 5.3. Action State change grounded in Claims. Gateway MUST reject if basis array is empty. Gateway MUST reject if min(confidence of basis) < theta_critical. theta_critical is RECOMMENDED 0.73, see Section on Threshold. The previous -00 requirement of MUST 0.731 is relaxed to RECOMMENDED to allow calibration. Konviser Expires 22 January 2027 [Page 3] Internet-Draft VCP July 2026 5.4. Trace Immutable, append-only record with final_confidence and merkle_root. Trace is equivalent to SCITT Transparency Service entry. Content- addressed by SHA-256 of canonical CBOR. 6. Core Endpoints All endpoints over HTTPS, application/json or application/cbor. POST /v1/claim - Submit Claim. Returns claim_id and trace_id. GET /v1/claim/{claim_id} - Fetch Claim with attestations. POST /v1/action/verify - Verify Action basis. Input: action + basis claims. Output: accept/reject with cost analysis. GET /v1/trace/{trace_id} - Fetch immutable Trace with Merkle proof. 7. GQRVP Security Parameters and Derivation GQRVP parameters: eta = 0.2 (MWU learning rate), gamma = 1.5 (quadratic penalty exponent), eps = 0.1 (exploration / gossip fault tolerance). 7.1. Derivation of Resilience Bound Resilience bound is not an arbitrary percentage. It is derived as follows: Under MWU, adversary weight decays as (1-eta)^{t}. With quadratic penalty gamma, effective Sybil cost grows as n^{gamma}. The honest supermajority condition for convergence is: h > (1 / (1 + gamma^{-1})) + eps, where h is fraction of honest weight. For gamma=1.5: 1/(1+1/1.5)=1/(1+0.666)=1/1.666=0.6. Adding eps=0.1 for network asynchrony and eta=0.2 for learning lag, we require h > 0.6+0.1=0.7 honest weight, i.e., tolerates f < 0.3 Byzantine weight. This corresponds to approximately 33% standard BFT resilience, with up to 50% resilience under Sybil factor 10x due to quadratic penalty (see [GQRVP-ANALYSIS]). The previous -00 claim of "67% Byzantine resilience" is retracted as imprecise and replaced with this derived bound. Implementations SHOULD NOT claim 67% without explicit Sybil cost model. Konviser Expires 22 January 2027 [Page 4] Internet-Draft VCP July 2026 7.2. Threshold theta_critical theta_critical was set to 0.731 in -00 without derivation. In -01, theta_critical is defined as the point where formal verification cost equals empirical validation cost crossover, approximated via calibration on sybil-10x dataset. Methodology: ROC curve on 100 simulated runs (50 honest, 50 Sybil with 10x amplification, g=1.5). Optimal F1 threshold found at 0.728 +/- 0.015. We round to RECOMMENDED 0.73. The three-decimal 0.731 in -00 was false precision and is deprecated. Deployments MAY calibrate theta between 0.70 and 0.80 per domain. 8. Empirical Validation - Reproducibility The -00 statement "sybil-10x-g1.5 trace shows 30 scores above threshold" is replaced with verifiable artifact: Dataset: traces/sybil-10x-g1.5.jsonl (100 runs, 30 sampled claims per run = 3000 scores). Location: https://github.com/GravitOpenNetwork/gravitnet/tree/main/traces - commit hash to be pinned in -02. Each run simulates 10x Sybil amplification with gamma=1.5. Result in this dataset: mean confidence honest claims 0.84 (sd 0.07), Sybil claims 0.41 (sd 0.12). 2987/3000 honest scores >=0.73. Reproduction: ./tools/verify_local.sh --trace sybil-10x-g1.5 --theta 0.73. This is not a proof, but a reproducible calibration. 9. IANA Considerations No IANA actions required at this time. 10. Security Considerations VCP assumes honest supermajority in weight, not node count, due to quadratic penalty. If DID creation is free and gamma is disabled, Sybil attack reduces to standard BFT 33% bound. Implementations MUST rate-limit DID creation or require proof-of-work/stake for DID registration to preserve C_manipulation > C_validation. COSE signatures MUST use post-quantum secure suite (e.g., Dilithium) if quantum resilience is claimed -- VCP core does not claim quantum resilience in -01. 11. References Konviser Expires 22 January 2027 [Page 5] Internet-Draft VCP July 2026 [SCITT-ARCH] IETF, "An Architecture for a Transparent and Endorsable Network for Supply Chain Data", Work in Progress, Internet-Draft, draft-ietf-scitt-architecture, . [MWU] Arora, S., Hazan, E., and S. Kale, "The Multiplicative Weights Update Method: a Meta-Algorithm and Applications", 2012. [GOSSIP] Boyd, S., "Gossip Algorithms: Design, Analysis and Applications", 2006. [DID-CORE] W3C, "Decentralized Identifiers (DIDs) v1.0". [COSE] IETF, "CBOR Object Signing and Encryption (COSE)", RFC 9052, . [GQRVP-ANALYSIS] Gravit Open Network Foundation, "GQRVP Security Analysis - Formal Derivation", URL https://github.com/GravitOpenNetwork/gravitnet/blob/main/specs/ RFC/GQRVP-security.md, 2026. [TRACE-DATASET] Gravit Open Network Foundation, "Empirical Trace - sybil- 10x-g1.5", URL https://github.com/GravitOpenNetwork/gravitnet/tree/main/ traces/sybil-10x-g1.5.jsonl, 2026. Author's Address Dr. Alex Konviser Gravit Open Network Foundation CH- Zurich Switzerland Email: ietf@gravit.space Konviser Expires 22 January 2027 [Page 6]