Mechanism
Each proposed settlement begins with a pair of observations, a first observation and a second observation, one from each party. Each observation is a signed record carrying the observing party's authority credential, the time of observation, the spatial coordinate of observation, and the cryptographic signature of the observing party. The architecture binds the two signed observations together: a pair-binding composer produces a cryptographic binding over the first and second signed observations, and a spatial-temporal attestation composer binds that cryptographic pair with the spatial-proximity and temporal-proximity attestations derived from mesh-derived coordinates and mesh-derived time.
The proximity window has two governance-policy-defined components: a spatial proximity window defining the spatial region within which the parties must be located at the time of their respective observations, and a temporal proximity window defining the time interval within which the second observation must arrive relative to the first observation. Spatial-window verification uses mesh-derived coordinates with governance-chain-preserving position lineage; temporal-window verification uses mesh-derived time with governance-chain-preserving temporal lineage. Both windows are governance-policy-defined, so the bounds are set by the governance policy in force for the transaction type rather than fixed in the architecture.
Evaluation is governance-policy-defined. Given a pair of signed observations and the applicable spatial and temporal proximity windows, the architecture verifies that both parties were located within the spatial window and that the second observation arrived within the temporal window. A pair that satisfies both windows settles; a pair that violates either window produces a governance-chain-preserving rejection with lineage recording that includes the violation type, the first and second observations, the measured and required windows, and the governance-policy-defined rejection consequences. Both the settled pair and the rejection enter the operational lineage as signed records.
Operating Parameters
Spatial proximity windows admit a plurality of governance-policy-defined forms, including without limitation radio-range windows defined by mesh-protocol reachability at the pairing location, polygonal spatial windows defined by governance-policy-defined boundaries, radius-from-point windows centered on a fixed location, topology-bound windows defined by membership in a governance-policy-defined topology node, sensor-coverage windows defined by overlap of both parties' sensor coverage, vehicle-proximity windows defined by inter-vehicle range for moving transactions, credentialed-venue windows defined by the spatial extent of a governance-credentialed venue, and composite spatial windows combining two or more forms.
Temporal proximity windows likewise admit a plurality of governance-policy-defined forms, including without limitation absolute-duration windows specified as a time interval from the first observation, relative-event windows defined by governance-policy-defined events, multi-event windows requiring multiple governance-policy-defined events, authority-clock windows defined by governance-credentialed authority timing, operational-context windows varying by transaction type and conditions, adaptive windows adjusted based on transaction class and historical timing, and composite temporal windows combining two or more forms. Both window verifications draw on mesh-derived coordinates and mesh-derived time so that the windowing decision is grounded in the same observational substrate as every other architectural decision.
Window parameters are governance-policy-defined and can evolve through governance-policy update rather than software modification. The architecture supports successor versions emitted with a governance-policy-defined version-lineage chain, a deprecation phase in which a governance authority signals that consuming agents should transition to successor versions within a governance-policy-defined transition window, and a retirement phase in which a deprecated parameterization is no longer admitted after the transition window elapses. Each transition is recorded by a lifecycle-lineage recorder.
Alternative Embodiments
Window embodiments vary by the spatial and temporal forms a governance policy selects. A radius-from-point embodiment centers the spatial window on a fixed location, suited to a settlement gated to a specific marker. A polygonal embodiment defines the spatial window by governance-policy-defined boundaries. A topology-bound embodiment defines the spatial window by membership in a governance-policy-defined topology node. A composite embodiment combines two or more spatial forms, and pairs the spatial window with whichever temporal form, absolute-duration, relative-event, authority-clock, or adaptive, the transaction type calls for.
Settlement-binding embodiments vary as well. A baseline embodiment binds the pair with a per-party signature interface and a pair-binding composer producing a cryptographic binding over the two signed observations. A high-assurance embodiment additionally invokes a multi-attester consensus composer that produces optional multi-attester signatures for high-assurance transactions, and a content-addressed-storage linker anchors the settlement to a content-addressed storage reference where applicable.
Composition
Proximity windowing composes with the architecture's mesh-derived coordinate and mesh-derived time primitives through joint spacetime reference production. Spatial-window verification draws on mesh-derived coordinates and temporal-window verification on mesh-derived time, so the windowing decision is grounded in the same observational substrate as every other architectural decision, and improvements in the underlying mesh-derived references propagate to window verification.
Windowing also composes with the cryptographic settlement binding that follows a satisfied window. The spatial-temporal attestation composer binds the cryptographic pair with the spatial-proximity and temporal-proximity attestations, and a non-repudiation verifier supports downstream verification that the settlement was authentically produced. The settlement record carries the window verification within its governance-chain lineage, so downstream audit can verify both that the windows were satisfied and that they were the windows in force for the transaction.
Prior Art
The disclosed primitive evaluates a bound pair of signed observations, one from each party, against a governance-policy-defined spatial proximity window and temporal proximity window, and it preserves both the settled pair and any rejection within a governance-chain-preserving lineage. The spatial and temporal windows are governance-policy-defined and verified against mesh-derived coordinates and mesh-derived time, rather than against a single party's self-asserted position.
The primitive settles a matched pair without a third-party intermediary. Where conventional payment processors settle through a third-party intermediary holding counterparty risk, the present primitive produces a persistent settlement record admissible by downstream consumers without third-party mediation, and the windowing requirement ensures that every settlement carries a credentialed proximity attestation rather than an unverified proximity assertion.
Operational Scenarios
Operational scenarios illustrate the primitive's application. In a roadway tolling scenario, the first observation is the tolling marker's broadcast carrying location, authority, and rate, and the second observation is the vehicle's counter-observation carrying vehicle identifier, classification, and timestamp; the governance policy requires spatial-coincidence at the tolling marker plus temporal-coincidence within the vehicle's pass-through window. In an energy-transfer scenario such as vehicle-to-grid, vehicle-to-building, or peer-to-peer transfer, the first observation is the energy-receiver's demand directive and the second observation is the energy-source's delivered-energy observation, paired under a spatial window appropriate to the connection and a temporal window appropriate to the transfer interval. In a capacity-reservation scenario, the first observation is the place-governing agent's reservation grant and the second observation is the reserving unit's acceptance.
Across these scenarios the common pattern is that the value being exchanged is bound to a spatial and temporal coincidence: the toll is owed because the vehicle passed a specific tolling marker, the energy transfer is settled because the source delivered to a receiver within the connection's window. A settlement that accepts an unverified proximity assertion invites a settlement in which the proximity never occurred. The disclosed primitive verifies every settlement against the governance-policy-defined spatial and temporal windows and records every window violation as a governance-chain-preserving rejection, so that the operational lineage cannot be silently cleansed of failed attempts.
Implementation Notes
Window verification against mesh-derived references is the primitive's principal engineering concern. Spatial-window verification relies on mesh-derived coordinates with governance-chain-preserving position lineage, and temporal-window verification on mesh-derived time with governance-chain-preserving temporal lineage. Because both windows and the references they are checked against are governance-policy-defined and lineage-carrying, a settlement's window decision can be re-derived and audited from the recorded observations rather than trusted on assertion.
Window publication and governance updates require their own discipline. The spatial and temporal windows in force for a transaction type are governance-policy-defined, and parameter changes propagate through governance-policy update with a governance-policy-defined version-lineage chain rather than through software modification. A content-addressed-storage linker anchors a settlement to a content-addressed storage reference where applicable, so the parameterization under which a pair settled is recoverable from the lineage.
The rejection record warrants particular attention. A naive implementation that simply discards out-of-window pairs produces a lineage in which only successful settlements appear, which biases downstream analytics and creates an opening for selective non-recording. The disclosed primitive produces a governance-chain-preserving rejection with lineage recording for every window violation, capturing the violation type, the first and second observations, the measured and required windows, and the governance-policy-defined rejection consequences, retained with the same discipline as settled records.
Adversarial Considerations
The signed-observation discipline and the mesh-derived window verification address several adversarial scenarios. An observation that arrives after the second observation should have arrived falls outside the temporal proximity window and produces a governance-chain-preserving rejection rather than a settlement. A replay, in which an adversary resubmits a prior observation, is addressed by the architecture's continuity-based device identity: a dynamic-device-hash field supports continuity-based identity validation rather than a static identifier vulnerable to replay, and discontinuities in the dynamic-device-hash sequence reveal replay regardless of whether a device possesses a valid static credential. A fabricated position or time observation is addressed by the spoofing-detection mechanism, which evaluates signal-integrity attestation together with temporal-coherence and spatial-coherence tests to distinguish genuine measurements from adversarially fabricated ones, and by spatial-window and temporal-window verification against mesh-derived coordinates and mesh-derived time rather than against either party's self-asserted values.
Disclosure Scope
This article describes subject matter disclosed in U.S. Provisional Application No. 64/049,409. The disclosure covers matched-pair settlement gated by a spatial proximity window and a temporal proximity window, the governance-policy-defined forms those windows admit, the verification of those windows against mesh-derived coordinates and mesh-derived time with governance-chain-preserving lineage, the governance-policy-defined version-lineage chain for window parameters, the cryptographic settlement binding over the paired signed observations, and the governance-chain-preserving rejection recorded for window violations. The disclosure further covers application of the primitive to roadway tolling, energy-transfer, and capacity-reservation scenarios. Specific window forms, coordinate frames, and governance policies are implementation choices within the disclosed framework.