How Identity Works on the Platform
For those who want to understand the architecture: oneWallet.online sits at the intersection of two distinct but connected identity models, governed by the Registrar & Notary.
Humans & Organisations
Humans and organisations have legal personhood – the recognised capacity to enter legal agreements, bear rights, and face obligations. They are registered as first-class parties by the Registrar & Notary (a Meta-QTSP or Federation of cross-jurisdictional QTSPs) through high-assurance document verification and eIDAS 2.0 PID issuance.
Their oneWallet is the command centre for this legal identity – managing their agreement portfolio, consent records, and the AI agents and devices they own and authorise.
AI Agents & Devices
AI Agents and autonomous devices have no legal personhood. They operate as delegated proxies on behalf of legal parties in Agreement DAGs – machine-executable digital twins of legal agreements – with authority delegated through OBO (On-Behalf-Of) Tokens. Each token defines the proxy's Role, Authorisation, Policy, and Rules.
Liability rests entirely with the legal principal (the human or organisation) who issued the OBO Token. An agent can never exceed the authority of the principal who created it. DRAGON enforces this at the hardware level – no configuration required.
| Feature | Legal Party (Human / Org) | Agent Proxy (AI / Device) |
|---|---|---|
| Liability | Borne directly by the party | Always rests with the legal principal |
Registrar: Architecting Next-Generation Agentic Supply Chain Assurance (SSCA) and Cyber Supply Chain Risk Management (C-SCRM)
Critical Insight: In the Agentic Age, traditional software security frameworks collapse because autonomous AI agents formulate and execute commands at machine speed at the intent layer, rendering standard perimeter firewalls and post-hoc logging obsolete. The Registrar addresses this foundational flaw by moving from probabilistic "Assumed Trust" to deterministic "Substantiated Integrity". By expanding standard Software (SBOM) and Hardware (HBOM) metrics to incorporate Model (MBOM) and Data (DBOM) architectures, the system locks law into silicon, ensuring that unauthorized or non-compliant actions are physically uncomputable and topologically unreachable.
1. The Imperative of Comprehensive SSCA & C-SCRM
The global digital economy operates on a dangerous paradox. High-velocity autonomous machine execution at the edge demands instant, unconstrained agency, yet modern compliance paradigms rely on "Assumed Trust" – manual audits, reactive patch cycles, and static documentation filed away in compliance portals. This legacy approach results in staggering inefficiencies, draining up to 35% of IT budgets on redundant ETL reconciliation and forcing engineering teams to waste significant resources on manual audit archaeology.
In the shifting landscape of Software Supply Chain Assurance (SSCA) and Cyber Supply Chain Risk Management (C-SCRM), the introduction of Horizon 2 Agentic AI causes this legacy framework to break down. When an autonomous agent hallucinates, suffers prompt injection, or drifts from its regulatory mandate, the failure occurs at the intent layer. To traditional security systems, the resulting traffic looks authenticated, valid, and encrypted.
To protect enterprise balance sheets from unbounded algorithmic liability, security architecture must shift from "Trust, then Verify" to "Verify, then Execute". This requires verifying not just the identity of an actor, but the genetic integrity of the entire digital artifact through a unified, recursive manifest managed by a definitive state engine: the Registrar.
End-to-End Supply Chain Assurance & Risk Management Map
SSCA & C-SCRM Architecture Specification
Hardware & Firmware Attestation
Firmware attestation quotes from edge hardware, 3D IC chiplets, and POI appliances (HBOM) are verified via silicon root-of-trust and Measured Boot before execution leasing.
Models & Software Lineage
Software dependencies (SBOM) and dynamic neural weight adapters (MBOM) are bound to explicit Control Flow Graphs and cryptographically signed Policy Hashes.
KeyMESH & Data Products
Law-Bound Data Products (DBOM) and Multi-Tenant Cryptographic Key Management (KeyMESH) enforce automated Remote Key Loading and continuous key rotation across edge clouds.
2. Productizing Data and Models: The Emergence of MBOM and DBOM
To meet this challenge, the platform elevates standard supply chain models into a multi-dimensional, four-pillar framework – fusing HBOM, SBOM, MBOM, and DBOM into a unified Product Bill of Materials (PBOM).
+---------------------------------------+
| PBOM (Product Bill of Materials) |
+---------------------------------------+
|
+--------------------+-------+-------+--------------------+
| | | |
+--------------+ +--------------+ +--------------+ +--------------+
| HBOM | | SBOM | | MBOM | | DBOM |
| (Hardware) | | (Software) | | (Model) | | (Data) |
+--------------+ +--------------+ +--------------+ +--------------+
| Silicon Root | | Code Lineage | | Neural Weights| | Provenance |
| Attestation | | Dependencies | | lineage/Adapters | Jurisdictional|
| TEE Valid | | CFG Mapping | | Parameter Hash | Tag / Consent|
+--------------+ +--------------+ +--------------+ +--------------+
The Model Bill of Materials (MBOM)
The MBOM tracks and verifies the lineage, architecture, parameters, and tuning adapters (e.g., LoRA, PEFT) of AI and Machine Learning models. It mathematically tracks neural weights, preventing the "Clean Mind, Dirty Intent" vulnerability where an uncompromised model structure is subtly poisoned or manipulated into generating toxic outputs. The Registrar cryptographically binds these weights to a specific Policy Hash (PH) at execution time.
The Data Bill of Materials (DBOM)
The DBOM elevates passive datasets into managed, productized, and self-describing Law-Bound Data Products (LBDPs). Stored within the Registrar, a DBOM captures complete data lineage and provenance, cryptographic schema definition, and transformation logic, EU LAU-1 or NUTS jurisdictional tags, and dynamic user consent status. This structure ensures data injected is legally admissible for that exact operational context.
3. The Recursive xBOM Topology
The cornerstone of next-generation agentic assurance is the structural flexibility of the Extended Bill of Materials (xBOM) graph. Rather than acting as flat, isolated lists, xBOMs utilise a nested, recursive topology where one Bill of Materials can contain, reference, or wrap another.
- The Feature SBOM as a Governance Primitive: Within the Cloud Development Environment (CDE), features are authored from scratch alongside an implicit Control Flow Graph (CFG). This tracks software dependencies, legal classifiers, and financial/experience metrics, serving as a composable unit that can be aggregated into broader system-level xBOMs.
- Topological Wrapping: An MBOM (Model) depends on a DBOM (Data) for its training provenance, while itself being encapsulated within an SBOM (Software) microservice, which executes inside a hardware-isolated environment attested by an HBOM (Hardware).
- Continuous Authority to Operate (cATO): The Registrar fuses this multi-dimensional graph into a single, dynamic cryptographic signature known as the Policy Hash (PH). The platform enforces a strict "No xBOM, No Deploy" mandate. If a single microservice updates without authorisation, a hardware stepping drifts, or data consent expires, the Policy Hash instantly invalidates. The node revokes cATO at wire-speed, preventing silent drift across execution layers.
4. Driving ServiceOps, AI, and Data Governance in the Agentic Age
This recursive xBOM topology enables a highly resilient, automated operational paradigm for enterprise ServiceOps, AI, and Data governance.
Category Theory & Jurisdictions
By leveraging category theory, every Packaged Business Capability (PBC) is modelled as an exclusive authority boundary mapped directly onto the platform’s multi-layered legal constitution – the Axiom MESH. Each PBC maps one-to-one to a canonical BIAN service domain and serves as the single-writer owner of that domain's data state. AI agents are admitted temporarily, rendering shadow IT or privilege escalation structurally impossible.
Separation of Powers
To prevent generative models from corrupting executable business logic, the Constitutional Operating System (COS) enforces a strict structural separation of powers:
- The Legislature (TopHAT): Establishes the core non-negotiable legal prose and symbolic axioms.
- The Judiciary (DRAGON Engine): Adjudicates every proposed machine intent using Triadic Adjudication in constant time ($O(1)$).
- The Executive (System of Orchestration): Translates approved intents into actual workflows via Actuator DAGs.
Zero-Privilege Interns
AI agents are treated as "Zero-Privilege Interns." They are intelligence-rich but authority-poor; they can construct a complex "DAG-of-Thought" but possess zero direct execution privileges. To interact with a data product or move capital, the agent must be granted a short-lived, single-purpose On-Behalf-Of (OBO) Token that cryptographically projects the authority of a verified human Principal.
| Governance Layer | Legacy AI & Data Management (Probabilistic) | Registrar-Anchored Framework (Deterministic) |
|---|---|---|
| Verification Gate | Post-hoc manual sampling and log analysis | Pre-execution Runtime Attestation ($O(1)$ constant time) |
| AI Control Mode | Unbounded model behaviour, reactive guardrails | Neuro-Symbolic Caging via explicit Agreement DAGs |
| Data Privacy (GDPR) | Manual, lengthy data integration and pruning pipelines | Under 2-minute automated erasure via Law-Bound Data Products |
| Risk Containment | Lateral exploitation and unbounded organisational liability | "TEE Hardware-Isolated Enclaves" hardware isolation and structural VETOs |
The Ultimate Assurance: Lawful Act Hyperedges (LAHE)
Every successfully adjudicated transaction or data access is recorded as a Lawful Act Hyperedge (LAHE) on a graph-native, Bi-Temporal Ledger. By tracking both Valid Time (the real-world activation of a policy) and Transaction Time (the nanosecond of recording), the platform unlocks Perfect Historical Replay. This creates an unalterable, court-defensible "receipt of reasoning" that explicitly distinguishes between an operational execution breach and a law design failure, converting compliance from a resource-draining regulatory liability into a high-yield capital asset.
The Dawn of Agentic ServiceOps
Modern digital enterprises suffer from an operational and regulatory governance deficit. By moving from probabilistic "Assumed Trust" to deterministic "Substantiated Integrity," the onePOI.online Constitutional Operating System (COS) translates multi-tenant natural language intents and relational agreements into deterministic, silicon-enforced execution states.
1 Core Architectural Integration: Registrar & KnowledgeHUB
The relationship between the Registrar and the KnowledgeHUB serves as the ultimate core foundation for the platform's System of Record (SoR) and its property of Substantiated Integrity.
┌─────────────────────────────────────────────────────────┐
│ REGISTRAR │
│ (Verification, Admission Control, & Lineage) │
└────────────────────────────┬────────────────────────────┘
│
Enforces xBOM Invariant
│
▼
┌─────────────────────────────────────────────────────────┐
│ KNOWLEDGEHUB │
│ (Bi-Temporal Hypergraph Core: Valid vs. System Time) │
└────────────────────────────┬────────────────────────────┘
│
Generates Topology of xBOMs
│
▼
[HBOM: Silicon] ↔ [SBOM: Code] ↔ [MBOM: Models] ↔ [DBOM: Data]
1.1 Gatekeeper of Origin
The Registrar acts as the definitive trusted enrollment, admission control, and verification authority. It unifies ITAM, CMDB, and ModelOps into an axiom-governed single source of truth. No workload, human principal, device, or AI agent can exist unless explicitly registered, cryptographically signed, and continuously tracked.
1.2 Multi-Dimensional xBOMs
Every asset is decomposed into a composite Extended Bill of Materials (xBOM) topology: HBOM (physical silicon root-of-trust), SBOM (code dependencies & CVE state), MBOM (model neural weights & tuning adapters), and DBOM (Law-Bound Data Product manifests & consent parameters).
1.3 Bi-Temporal Core
KnowledgeHUB materializes xBOM assets as a federated Data Mesh aligned with BIAN v13 and FIBO ontologies, implementing Bi-Temporal Fidelity across Valid Time ($V_t$: physical policy activation) and Transaction Time ($T_t$: nanosecond ledger recording).
2 Control Flow Knowledge Graphs (CFKG) & The Inspector
The dynamic interplay between static system topology and runtime intent is mapped by the Inspector via wire-speed Control Flow Knowledge Graphs (CFKGs).
[ Human / Agentic Proposed Intent Vector ]
│
▼
┌─────────────────────────────────────────────────────────┐
│ INSPECTOR ENGINE FLIGHT │
│ (Syntactic Edge Scrub & Runtime Schema Matching) │
└────────────────────────────┬────────────────────────────┘
│
Maps Runtime Payload into CFKG
│
▼
┌─────────────────────────────────────────────────────────┐
│ CONTROL FLOW KNOWLEDGE GRAPH (CFKG) │
│ (Intersects Active xBOM Topologies with ADAG Rules) │
└────────────────────────────┬────────────────────────────┘
│
Pre-Pruning / SMT Solver Evaluation
│
▼
[ Sparse Legal-State Reachability Graph Matrix (LSRG) ]
2.1 Syntactic Scrubber
Intercepts infrastructure payloads and execution calls at wire-speed, verifying code modifications, regex formats, and data serialization payloads against DBOM/SBOM schemas before host kernel resources are exposed.
2.2 CFKG Construction
Merges xBOM states with Agreement DAGs under Deontic Logic operators: Permissions ($\mathbf{P}$), Obligations ($\mathbf{O}$), and Prohibitions ($\mathbf{F}$).
2.3 SMT Solver & DRAGON ASIC
Evaluates logical paths using SMT solver loops. Applying canonical dominance ($\mathbf{F} \succ \mathbf{O} \succ \mathbf{P}$), it compiles valid pathways into a Legal-State Reachability Graph (LSRG) loaded onto DRAGON ASIC static RAM for $O(1)$ hardware execution under 100 microseconds.
3 Bitemporal Hypergraph & B-HGNN Neural Learning
Transactions persist as Lawful Act Hyperedges (LAHEs) in a global hypergraph ledger (Bitemporal Ledger). **Bitemporal Hypergraph Neural Networks (B-HGNNs)** run continuous Graph Data Science over the living ledger, evaluating causal graph learning and generating real-time predictive assurance vectors to detect systemic anomalies before execution.
4 Multi-Cloud Service Mesh & eBPF Kernels
Utilises a sidecarless **Constitutional Service Mesh (CSM)** driven by **Cilium** and **eBPF**. Network sockets pass via non-blocking ring buffers directly into Wasm sandboxes. Decouples security via SPIFFE/SPIRE workload identities and Lawful Warrants, while supporting **Constitutional Island Mode** for offline edge survival.
5 Next-Gen ServiceOps: Phygital Arbitrage & Zombie Agent Extermination
Phygital Service Arbitrage
Competitive tenant cohorts securely share multi-edge physical infrastructure. Micro-royalties and assurance fees are captured natively at execution via Lawful Act Hyperedges, dividing rewards between host, anchor, and legal engineers.
Neuro-Symbolic Shadow DAGs
System of Intelligence executes probabilistic planning via Supervisory Shadow DAGs, simulating proposed strategy changes against historical bitemporal hypergraph paths prior to real-world deployment.
Exterminating Zombie Agents
Short-lived OBO Tokens project human authority. When regulatory policies update, TopHAT pushes prohibition updates ($\mathbf{F}$). Because $\mathbf{F} \succ \mathbf{P}$, orphan "Zombie Agents" are instantly and structurally nullified at the eBPF kernel layer without code retraining.
| Operational Objective / Metric | Legacy ServiceOps Frameworks | onePOI.online COS Integrated Architecture |
|---|---|---|
| Asset Identity & Lineage | Disconnected CMDB assets, fragmented code registries, unmonitored container blobs. | Unified xBOM Framework (HBOM, SBOM, MBOM, DBOM) continuously verified by the Registrar. |
| Audit & Forensic Verification | Time-consuming linear loops ($O(N)$) parsing mutable text log files to piece together past breaches. | Constant-Time ($O(1)$) automated legal queries utilising non-repudiable Evidence Envelopes. |
| Network Interception Model | Resource-heavy sidecar proxies running in user-space, injecting severe processing latency. | Sidecarless kernel-level interception via eBPF handing traffic context over to Wasm sandboxes. |
| Autonomous AI Governance | Unchecked API access tokens allowing probabilistic engines to execute unsafe ledger steps. | Strict Separation of Law and Logic enforced via deterministic DRAGON ASICs and short-lived OBO Tokens. |
Before any entity can participate in the ecosystem – whether a user wallet, any agent, or any device – it must be registered with a full provenance record.
Hardware Bill of Materials
Complete provenance of every physical component – silicon to POI appliance. TEE attestation certificates, firmware version hashes, eBPF kernel-level identity. Every device in your network is cryptographically traceable to its manufacturing origin.
Software Bill of Materials
Full dependency graph, CVE mapping, licence chain, and formal verification proof certificates. No software component deploys without a registered SBOM entry verified by the Constitutional Foundry.
Data Bill of Materials
Origin, classification, consent basis, transformation history, retention policy, and sovereignty jurisdiction of every Data Product. GDPR and FiDA data residency compliance is architectural – not policy-dependent.
Model Bill of Materials
Full AI model lineage – architecture, training datasets (via DBOM references), bias evaluation, version history, and decision attribution. Every AI inference in oneWallet is traceable to a registered model version.
All records anchored to the System of Record
All xBOM records are stored immutably in the System of Record's bitemporal ledger. Every update creates a new LAHE record. Together with the active Policy Hash and execution hardware signatures, these constitute a Minimum Viable Evidence Bundle (MVEB) – providing a deterministic audit trail that allows regulators to verify and replay the exact runtime state of any capability deployed.
Every Capability Has a Birth Certificate
xBOM Relationship Map – HBOM · SBOM · DBOM · MBOM
What: Concentric rings: outer ring is a deployed capability (e.g. a fraud-scoring service). Inner rings unpack it into its constituent BOMs: MBOM (model weights + training data lineage) → DBOM (data inputs + provenance) → SBOM (software dependencies + CVE state) → HBOM (silicon attestation, Measured Boot). Each BOM stamped with its signing authority. One LAHE in the centre showing 'this act was performed by a capability with this full provenance chain'.
Why: xBOMs are alphabet soup unless the reader can see how they nest. The diagram converts the page's authority claim ('every capability has a birth certificate') into a verifiable structure.
The Registrar is engaged as part of the onboarding sprint – scoping your SBOM requirements, mapping your xBOM architecture, and establishing the cATO pipeline that keeps your deployments continuously authorised.
Registrar Provenance & Bitemporal Integrity
Explores SBOM/HBOM/MBOM integrity checks, cryptographic heartbeats, and bitemporal historical audit trails.
The Ultimate Inventory for Complete System Trust
The Registrar acts as the system's official record keeper. It tracks the exact origin, version, and identity of every piece of hardware, software, and AI model in the network. By verifying that every part has a valid digital certificate before it runs, the Registrar keeps hackers from introducing unauthorised code or using compromised equipment. Note: the system guarantees execution of the programmed rules as written, but does not judge whether the rules themselves are good – that remains a human responsibility.
xBOM Supply Chain Provenance & Continuous Authority to Operate
The Registrar maintains complete supply chain assurance by enforcing an extended Bill of Materials (xBOM) registry tracking Software (SBOM), Hardware (HBOM), Model (MBOM), and Data (DBOM) dependencies. To satisfy DORA's cyber-resilience guidelines, the Registrar compiles legislative intents and policies into a flattened Legal-State Reachability Graph (LSRG). The root of this graph is minted as a Policy Hash and cached directly on the DRAGON DCPU's hardware registers, enabling silicon-level enforcement where non-compliant states are physically uncomputable. Any firmware or configuration drift immediately invalidates the node's credentials.
Compliance Frameworks
Native compliance logic alignment mapping to PSD3, eIDAS 2.0, and DORA resilience guidelines.
Commercial Pooled ROI
Shared physical infrastructure distribution model reducing CapEx overhead by up to 80%.
Architectural Integration (Symphony of Systems)
The xBOM Registrar serves as the definitive, bitemporal authority of the System of Record (SoR) layer. It integrates directly with the System of Agreement (SoA) and System of Orchestration (SoO) by compiling legislative policy into a flattened Legal-State Reachability Graph (LSRG). This graph is hashed into a single Policy Hash, which is cached directly on the DRAGON DCPU's hardware registers. SVID identity leases generated from hardware quotes are verified against this Policy Hash in real-time, ensuring that any unauthorised code execution or hardware drift triggers an immediate, hardware-enforced Structural VETO.
xBOM Registries & Cryptographic Heartbeats
Unified xBOM Verification
Every node continuously validates its Software Bill (SBOM), Hardware Bill (HBOM), Model Bill (MBOM), and Data Bill (DBOM) dependencies. A break in any link of this chain (e.g., swapping a RAM module or altering driver firmware without an authorised change order) triggers an immediate Structural VETO.
Measured Boot & Root of Trust
Boot sequence begins with the Core Root of Trust for Measurement (CRTM) etched in silicon ROM, extending hashes of BIOS, bootloader, kernel, and firmware into TPM Platform Configuration Registers (PCRs) via $PCR_{new} = \text{Hash}(PCR_{old} \mathbin{\Vert} \text{Hash}(new\_code))$, generating a signed Attestation Quote.
Continuous Attestation (cATO)
cATO heartbeats are submitted at randomized 30 – 120s intervals. Using privileged eBPF memory probes, they measure runtime memory pages, kernel page tables, and Control Flow Graphs (CFG). Any TOCTOU exploitation immediately invalidates the node's SPIFFE/SPIRE SVID cryptographic identity lease.
The Zero-Day Revocation Graph
Upon discovering a vulnerability (e.g., zero-day library exploit), the Registrar queries its highly connected xBOM graph to identify all running instances containing the library. It pushes a targeted revocation payload globally, blackholing and isolating affected nodes in under 100ms.
Bitemporal Monotonicity & SMT Solver Proofs
The system proves that historical records are immutable and cannot be rewritten by verifying bitemporal monotonic invariants.
Bitemporal Monotonicity Theorem
Asserting that Valid-Time ($T_{valid}$) must always be less than or equal to Transaction-Time ($T_{transaction}$) to prevent future-dated or historical tampering.
SMT Solver (Z3) Constraints
The Registrar database driver enforces bitemporal writing safety at the transaction boundary:
(declare-const t_valid Int)
(declare-const t_transaction Int)
(declare-const write_legal Bool)
; Bitemporal Monotonicity Invariant: Valid-Time must never exceed Transaction-Time
(assert (= write_legal (<= t_valid t_transaction)))
; Test if a future-dated write (where valid-time exceeds transaction-time) is permitted
(assert (and write_legal (> t_valid t_transaction)))
(check-sat)
; Expected result: unsat