Mechanism

Marker-track segments are the unit of credentialed routing in the architecture disclosed in Provisional Application 64/049,409. Each segment is a span of authority-credentialed track: a sequence of governance-credentialed markers encoding the segment's topology, including curvature, grade, speed envelope, lane assignment, and permitted vehicle classes. Each marker carries an authority credential of the authorizing freight-track, transit, or transport authority, a cryptographic integrity attestation, a temporal-validity specification including issuance timestamp and governance-policy-defined expiration, and a revision-version indicator supporting governance-chain-preserving updates.

Because authorization attaches to the segment rather than to the unit, a transport authority reviews and approves the track segment itself. The disclosure describes simplified regulatory compliance through per-segment regulatory approval rather than per-unit sensor-stack approval: prior autonomous-vehicle services operate without regulator-reviewed per-segment approval, whereas this primitive produces segment-by-segment governance-credentialed authorization admitting regulatory review prior to deployment.

A unit preparing to operate constructs an authorized-route manifest before departure. The route-manifest constructor retrieves applicable track topology from the shared environmental world view, and a per-segment authority evaluator verifies each segment's authority credential against the unit's operator class and authority credentials. A composite admissibility evaluator is applied to candidate route manifests. A segment whose authority credential does not validate for the unit's operator class is not composed into that unit's manifest.

The route manifest carries lineage linking the manifest to each contributing topology segment, each credentialing authority, and the governance-policy version applied to manifest construction. Route-manifest consumption at downstream operation is governance-chain-preserving, with each consumption event recorded in lineage supporting post-hoc audit of route authorization decisions.

Operating Parameters

Track-segment authorization, revision, and retraction proceed through a topology-update and governance-approval mechanism. A topology-update-request interface receives governance-credentialed update requests from authorized authorities. A topology-update admissibility evaluator applies governance-policy-defined update admissibility rules. A stakeholder-notification mechanism notifies affected operator-class fleets of pending updates. An update-deployment interface commits approved updates to the marker infrastructure with cryptographic revision-version attestation. A topology-update-lineage recorder records each update request, admissibility determination, stakeholder notification, deployment, and downstream consequence.

Regulatory constraints are also expressed in the marker-encoded topology directly. Regulatory-zone entry and exit markers encode speed reductions, access restrictions, or coordination requirements for zones such as school zones, construction zones, weigh-station approaches, port-entry points, and border crossings. A unit operating on a segment operates within the segment's governed speed envelope, lane assignment, and regulatory overlay.

Segment authorization is temporally bounded. Markers carry a temporal-validity specification with issuance timestamp and governance-policy-defined expiration, and a revision-version indicator. A marker-revision evaluator verifies that a marker's revision version is the most recent admitted version, and a credentialing authority may emit a revocation governed observation identifying a specific credential or credential class as no longer authoritative, after which consuming units down-weight or invalidate previously-admitted observations.

Each marker read, navigation determination, admissibility evaluation, topology update, and fail-safe transition is recorded by the marker-track lineage recorder in the governance-chain lineage field. The authorization decisions for a route are auditable through that lineage independently of the unit's own operational logs.

Alternative Embodiments

Marker carriage admits embodiments. The primitive admits a plurality of marker types, including passive energy-harvesting markers (radio-frequency backscatter tags, surface-acoustic-wave chipless tags, optical retroreflectors with modulated data, magnetic-signature tags, photonic tags), semi-passive markers with small-battery-backed response, active markers with continuous broadcast, hybrid markers with configurable active and passive modes, multi-modal markers providing redundant authentication across multiple physical channels, embedded-infrastructure markers integrated into road studs, lane reflectors, or gantries, mobile-deployed markers supporting temporary placement, and ephemeral markers with a governance-policy-defined time-to-live supporting limited-duration track authorization.

Cross-authority composition admits embodiments. A route may span multiple governance authorities. Composition patterns include sequential-authority composition with transitions at credentialed authority-boundary markers, joint-authority composition with governance-policy-defined contribution rights, delegated-authority composition where one authority delegates route-credentialing to another for specified segments, federated-authority composition where authority-mapping rules translate credentials across authority taxonomies, and escalated-authority composition where a higher authority overrides sub-authority credentials for specified route types such as emergency response or regulatory inspection.

Authority recognition across jurisdictions admits embodiments. Cross-mode authority-taxonomy translation enables handoffs between governance authorities without requiring authorities to adopt one another's taxonomies. Cross-authority composition is subject to governance-policy-defined cross-authority compatibility, so a segment credentialed under one authority is composed into a route operated under another only where the policy admits the translation.

Update handling admits embodiments. An ephemeral or limited-duration segment authorization expires under its temporal-validity specification. A revision supersedes a prior version through the revision-version indicator. A retraction removes a segment's authorization through the topology-update mechanism, with affected operator-class fleets notified through the stakeholder-notification mechanism before deployment.

Composition With Marker-Track Architecture

Regulatory segment approval composes with the marker-track credentialed-marker architecture disclosed in Provisional 64/049,409. The same governance-credentialed markers that carry topology and speed-envelope data carry the authority credential the regulatory review attaches to. The same marker-read admissibility evaluation that authenticates operational marker reads authenticates the authority credential and revision version. The regulatory layer is not a separate channel; it is a structural property of the credentialed-marker substrate.

Approval composes with marker-track lineage. The marker-track lineage recorder records each admissibility evaluation, topology update, and route-manifest construction and consumption event. A regulatory reviewer auditing which segments were authorized for which operator classes, and which units operated on those segments under which manifests, receives a governance-chain-preserving record showing those determinations.

Approval composes with the marker-sequence-primary navigation model. During operation the unit's primary navigation reference is the governance-credentialed sequence of marker reads. At each marker read the unit validates the marker's authority credential through the governance chain and updates its route-progress state against the pre-departure authorized-route manifest, so per-segment authorization is re-verified at the point of traversal rather than only at manifest construction.

Approval composes with marker-read admissibility and adversarial-marker rejection. The marker-read admissibility evaluator rejects spoofed, injected, substituted, or otherwise inadmissible marker reads, so an unauthorized or tampered marker cannot present itself as an approved segment. Rejections trigger governance-chain-preserving graduated response and cascade propagation to adjacent units and infrastructure agents.

Distinction From Prior Art

Prior autonomous-vehicle services operate without regulator-reviewed per-segment approval. They are certified, if at all, at the level of the unit's sensor stack, which a regulator must evaluate per unit and per software revision. The marker-track primitive instead produces segment-by-segment governance-credentialed authorization admitting regulatory review prior to deployment, moving the unit of approval to the track segment.

Prior autonomous-vehicle architectures operate through sensor-primary navigation producing path-by-inference routes without governance-credentialed attestation of authorized route. The marker-track primitive operates through governance-credentialed marker sequences as the primary routing reference, producing provable route authorization through authority-credentialed attestation that admits regulatory and liability review.

Prior architectures do not support cross-authority route composition spanning multiple jurisdictional authorities. The marker-track primitive composes segments credentialed by different authorities into a single authorized-route manifest, with authority-mapping rules translating credentials across authority taxonomies, so a route crossing jurisdictions is authorized segment by segment by the authority governing each segment.

Disclosure Scope

This disclosure covers the structural pattern of attaching authority-credentialed attestation of authorized use to marker-track track segments, authorizing each segment through a governance-chain-preserving topology-update and governance-approval mechanism, composing a unit's route manifest only from segments whose authority credential validates against the unit's operator class, and admitting regulatory review of segments prior to deployment. Marker-type plurality, regulatory-zone entry and exit markers, temporal-validity and revision-version handling, segment retraction and revocation, and cross-authority and federated-authority composition are within the disclosure's contemplation.

Application contexts within scope include freight, passenger, transit, ride-sharing, delivery, and emergency-response deployments operated by personally-owned and fleet-operated units, in which per-deployment governance-policy parameterization varies the operator class, vehicle form factor, and applicable authority taxonomy without architectural modification. Regulatory-zone markers encode speed reductions, access restrictions, and coordination requirements for school zones, construction zones, weigh-station approaches, port-entry points, and border crossings, evaluated alongside the segment's authority credential at construction and at traversal.

The disclosure further contemplates that the marker payload, the authority-credential and revision-version configuration, the topology-update admissibility rules, and the route-manifest lineage record format are deployment-tunable, while the structural invariant, per-segment authority-credentialed authorization composed into a route manifest under the unit's operator class, with regulatory review prior to deployment and governance-chain-preserving lineage, is the disclosed contribution. This disclosure is described in U.S. Provisional Application No. 64/049,409. Per-segment approval is what shifts the regulatory unit from the per-unit sensor stack to the track segment, and that shift is the central structural contribution.