Where a Downstream Consumer Stands in a Settled Pair
Two parties settle. A third party reads the settlement record, verifies it, and produces a determination on the strength of it. The question this article addresses is what standing that third party holds in the records of the two who settled.
Section 6.2 of the filing binds a recognized matched pair (600) into a settlement record (604) comprising the two signed observations, a cryptographic binding over both, and an attestation of the window within which the pair was recognized, whereby the settlement record (604) supports non-repudiation and is verifiable by a downstream consumer from the record alone. Under Section 6.6, each party appends its own settlement-lineage entry (606) to its append-only lineage field (104), recording the two observations, the pairing determination, the cryptographic binding, each escrow event, each failure and rollback, and each downstream consumption of the settlement record (604).
A settled pair is not final against challenge. Section 6.16 states that such a pair is subject to challenge only through a credentialed dispute procedure, initiated by either settled party under its authority credential and evaluated for admissibility against declared time limits, an authority scope enclosing the action class, and standing. That procedure renders a resolution that may include a settlement reversal, a settlement amendment, a compensation directive, or a no-change outcome. The same section states how a reversal takes effect: the settled party appends a reversal record enumerating each reliance entered under the settlement identifier and emits a reversal notice to each relying party so enumerated.
The enumeration therefore operates over reliance that has been entered under that identifier. Paragraph [0408] of Section 10.5 discloses the act by which a third party enters it.
Building the Reliance Record and Registering It With Both Settled Parties
Two things must happen at the relying party before a reliance record exists. It independently verifies a settled matched pair (600) against the counterparty identity records (114) it holds for both settled parties, and it then produces a determination consuming that settlement.
Responsive to both, the relying party appends to its append-only lineage field (104) a reliance record carrying four elements: the settlement identifier; a consuming-determination reference identifying the exact determination with its action class and scope partition; the relying party's identity primitive; and its attested epoch. The record is bound to exactly one settlement and one determination.
The relying party then emits that record to both settled parties as a governed observation, complete upon emission and soliciting no acceptance. Under Section 6.1, a governed observation is a signed structure comprising at minimum an authority credential field, a continuity hash field, a spatial reference field, a temporal reference field, a time-to-live field, a payload field, and an observation lineage field, and its emission requires no acknowledgment, no handshake, no delivery confirmation, and no registration with a central authority.
Receipt is where the register forms. Each settled party, on verifying the reliance record and resolving the settlement identifier to a settlement-lineage entry of its own, enters it in a reliance register indexed by settlement identifier and appends a reliance acknowledgment. Both conditions are recited: the record is verified, and the identifier it carries resolves to a settlement the receiving party itself recorded.
Paragraph [0409] states what the register conditions. A settled party reversing or amending a settlement appends a reversal record carrying a reliance enumeration field and evaluates a reliance-completeness predicate by an evaluator in its own memory field (102). The predicate is satisfied only where, for every reliance record entered in that party's own reliance register under the settlement identifier, the enumeration carries a matching entry by relying-party identity and consuming-determination reference. Where satisfied, the reversal is given effect and a reversal notice is emitted to each enumerated relying party. Where not satisfied, the reversal record is appended as an attempted-reversal entry and the settlement is not reversed, continuing to obtain for a downstream consumer verifying it from the record alone.
The filing is explicit about the direction of that condition. It rests upon the reverting party's own enumeration alone: no other party is polled, votes, or responds, and the non-response of a relying party neither prevents nor conditions the reversal.
On the relying party's side, [0410] governs receipt of a reversal notice. Verified against the counterparty identity record (114) of the emitting settled party, the notice causes the relying party to append to its append-only lineage field (104) a reversal mark carrying the settlement identifier, the resolution class, the emitting identity and epoch, and a reference to its reliance record. The settlement the mark names is not deleted. Thereafter the relying party tests each settlement identifier presented as a determination input against its reversal marks, and one bearing a reversal-class mark is not admitted. What follows depends on the resolution class. Where the class is a reversal, the relying party re-resolves the referenced determination with the barred input unavailable, emitting an outcome of its recorded abstention class (126). Where the class is an amendment, it re-resolves against the amended terms and, if those terms supply every consumed input, produces a fresh determination and a fresh reliance record. The outcome propagates to consuming determinations under the conversion bar (502) and is adverse to no settled party.
Paragraph [0411] extends the structure one level. A party consuming not a settlement but another party's reliance-bearing determination appends a reliance record carrying, in place of the settlement identifier, an upstream-reliance reference naming that other party, the entry of its lineage at which its reliance record was appended, and the settlement identifier ultimately relied upon. Such a record is a transitive reliance record, and a sequence of them each referencing the next and terminating in one carrying a settlement identifier constitutes a reliance chain. The further party emits its transitive record as a governed observation to the referenced party alone, not to any settled party; that party verifies it, confirms the upstream reference resolves to its own reliance record, and enters it in its own reliance register. Each party holds a register of the parties immediately downstream of it and no enumeration of the whole chain. Under [0412], a party of the chain that admits a reversal notice and appends its mark and re-resolution evaluates the predicate over its own register indexed by the reliance record the notice named, and emits to each downstream party so enumerated a transitive reversal notice carrying its own reliance record identifier, the settlement ultimately reversed or amended, the resolution class, any amended terms, and a hop count.
Fixed Structure and Declared Quantities
Several elements are fixed by the recitations themselves. A reliance record is bound to exactly one settlement and one determination. The reliance register is indexed by settlement identifier. The consuming-determination reference identifies the exact determination with its action class and scope partition. The reliance-completeness predicate matches on two elements, relying-party identity and consuming-determination reference, and is satisfied only where every entered record has a matching entry.
Other quantities are declared rather than fixed. Propagation within a party's own lineage is bounded by a re-resolution cascade bound declared in its signed policy object (112), the traversal terminating in a recorded abstention state rather than unbounded recursion; the filing recites the bound and its effect without reciting a magnitude. Admissibility of the dispute record that can produce a reversal is evaluated against declared time limits, an authority scope enclosing the action class, and standing. Section 6 states that where the parties resolve different policy objects, each applies its own. The reliance record, emitted as a governed observation, carries a time-to-live field encoding a validity duration, the field being recited rather than any duration.
Two constraints hold across those quantities: an outcome emitted on re-resolution propagates under the conversion bar (502) and is adverse to no settled party, and under Section 6.16 no step of the credentialed dispute procedure increments any refusal meter of either party.
Composition With the Settlement Substrate and the Reversal Path
Paragraph [0408] sits in Section 10.5, which covers tool provenance, reliance, and contested pairing. The provenance material in that section responds to an upstream change by marking rather than deleting. On a verified provenance withdrawal under [0398], the consuming agent deletes nothing and the artifact, chain, dispatch entries, and prior determinations all persist; a withdrawn-provenance mark under [0400] leaves the determination not modified, reversed, deleted, or reclassified. A reversal mark likewise leaves the settlement it names undeleted.
Downward, the mechanism takes the matched pair (600), the settlement record (604), and the settlement-lineage entry (606) as its subject, the governed observation of Section 6.1 as its transport, and the counterparty identity record (114) as its verification basis. The append-only lineage field (104), which admits no deletion and no modification of an appended entry, is where a reliance record, a reversal mark, and an attempted-reversal entry all land. Section 6.6 already recites a settlement-lineage entry (606) recording each downstream consumption of the settlement record (604), and a reliance record carries such a consumption to the parties that settled.
Laterally, a re-resolution that loses a required input emits an outcome of the relying party's recorded abstention class (126), one member of the closed set consisting of the accepted determination (122), the rejected determination (124), the not-determinable determination (126), and the not-applicable determination (128), and the conversion bar (502) of Section 5 governs what a consuming determination may do with it. Section 6.16 supplies the route by which a settled pair is challenged, and so supplies the reversal or amendment the register conditions.
Adjacent Art and the Structural Line
Established categories address neighboring problems, and the distinction is structural rather than one of degree.
Certificate revocation infrastructure publishes the revoked state of a credential through revocation lists and status responders, leaving consultation to the relying party, which polls a publisher. The publisher's ability to revoke is conditioned on nothing the relying party did, and no revocation binds to a specific downstream decision. Under [0408] and [0409], registration travels upstream, binds to one consuming determination by action class and scope partition, and the reverting party's own enumeration conditions whether a reversal is given effect.
Consensus ledgers, clearing houses, and central counterparties reach finality through a consensus round over a shared global record, or maintain an authoritative registry of positions against which unwinds are effected. A single global record is central to those designs. Section 6.3 recites contrary conditions for the settlement this mechanism operates upon: no third-party intermediary participates, no quorum, distributed ledger commit, or consensus round is a condition of settlement, and no pre-negotiated session state exists between the parties. Each party holds its own settlement lineage and its own reliance register, the predicate is evaluated in the reverting party's own memory field (102), and no party of a reliance chain holds an enumeration of the whole chain.
Two-phase commit and consent protocols have a coordinator poll participants, with a participant's response or silence gating the commit. The recitation of [0409] runs the other way: no other party is polled, votes, or responds, and the condition is completeness of an enumeration the reverting party performs over its own register.
Publish-subscribe notification, webhooks, and provenance graphs deliver events to registered listeners or record derivation relationships after the fact, describing what happened without placing a condition on an upstream party's own subsequent act. In the filed mechanism, the registration is a signed governed observation, verified against a counterparty identity record (114) and resolved against the receiving party's own settlement-lineage entry before entry, and the enumeration matches on a determination reference.
None of the foregoing is characterized here as practicing the disclosed mechanism, and nothing in this article asserts or implies that any product, protocol, standard, or party infringes any claim.
Disclosure Scope
The mechanism described here, the reliance record registered with the settled parties, is disclosed in U.S. Provisional Application No. 64/117,812 at Section 10.5, paragraph [0408]. Paragraphs [0409] through [0412] of the same application disclose the reliance-completeness predicate conditioning a reversal, the relying party's reversal mark and re-resolution, the transitive reliance record and the reliance chain, and one-hop propagation along that chain. The settlement substrate is disclosed at Sections 6.1, 6.2, 6.3, and 6.6, and the credentialed dispute procedure that can render a reversal or an amendment at Section 6.16. Reference numerals used here are those of that application. This article is published as a technical disclosure to establish public, timestamped prior art in the described mechanism.