Mechanism

Each mesh agent performs ranging against participating neighbor agents through a governance-credentialed inter-agent ranging mechanism, producing range observations between agents. Each range observation is authenticated through the governance-chain continuity identity and is subject to admissibility evaluation by the composite admissibility evaluator. An observation that is spoofed, injected, or otherwise inadmissible is rejected by the adversarial-range rejection mechanism rather than admitted into the localization.

A cooperative localization engine determines agent positions through multilateration from the admitted range observations and from admitted anchor positions. Where direct-anchor ranging is insufficient, a transitive localization extender produces agent positions through neighbor references. A precision-and-uncertainty propagator carries ranging precision and ranging-covariance through the localization chain, producing per-position uncertainty estimates. Where multilateration admits more than one solution, an ambiguity-resolution mechanism selects among the candidates. Each range observation, localization event, frame definition, uncertainty update, ambiguity resolution, and rejection event is recorded by a coordinate-lineage recorder in the governance chain lineage field, so a downstream consumer can reconstruct any position's derivation chain.

Anchor positions are admitted through an anchor observation admission interface that accepts governance-credentialed anchor position contributions. A coordinate-frame specifier defines the frame type, origin, orientation, scale, and temporal association of the coordinate system. As anchor positions propagate, the cooperatively produced frame is bound to absolute reference. In the absence of any anchor observations, an anchor-less bootstrap mechanism produces a relative-only coordinate frame.

Operating Parameters

Ranging cadence, propagation horizon, and admissibility thresholds are governance-policy parameters rather than fixed constants. Range observations propagate through the governed mesh under the multi-hop relay discipline, which carries a hop-count field incremented at each rebroadcast and a maximum-hop-count parameter specified by governance policy and enforced by each relaying agent, so that an observation whose hop-count exceeds the policy maximum is not rebroadcast. This bounds propagation and prevents stale observations from looping through the mesh. The disclosure does not fix particular cadences, horizons, or tolerance figures; those are deployment choices made within the disclosed framework.

The achievable precision of mesh-derived coordinates is bounded by ranging-modality accuracy and by reference-node density within ranging distance of consuming agents. Where precision falls below a governance-policy-defined threshold, a reference-node densification mechanism produces on-demand precision improvement by deploying additional reference nodes that integrate into the existing coordinate system through cooperative localization. A densification-need detector identifies the regions where precision is insufficient, a candidate-deployment evaluator selects deployment locations and modalities, and a deployment-admissibility evaluator screens candidates before a deployment executor places the nodes.

The adversarial-range rejection mechanism rejects spoofed, injected, or otherwise inadmissible range observations, and rejection events are recorded in the coordinate lineage alongside the admitted observations. Admissibility is evaluated through the composite admissibility evaluator, which corroborates a range across multiple sources before the observation contributes to a position. This is the structural hook by which spoofed or malfunctioning agents are surfaced.

The localization operates over the bounded local neighborhood reachable within the policy-bound propagation horizon rather than over the entire agent population, which is what allows the architecture to scale to large deployments. The disclosure does not state a particular per-agent memory or compute footprint.

Alternative Embodiments

The inter-agent ranging mechanism admits a range observation through at least one of a plurality of ranging modalities, and prior modality-specific positioning systems are limited to a single modality where the present primitive integrates many modalities into a single coordinate graph. The disclosure treats the particular ranging technology as a deployment choice and does not claim any one of them; radio-frequency, optical-wireless, and acoustic exchange are among the governed modalities described elsewhere in the architecture.

The cooperative localization engine determines positions through multilateration, and the precision-and-uncertainty propagator carries ranging-covariance through the localization chain. The disclosure does not claim a particular solver algorithm; the particular numerical method is a deployment choice made within the disclosed framework.

In an anchor-rich deployment, many agents carry independently established positions and cooperation principally improves precision and resilience where external positioning is denied. In an anchor-sparse deployment, anchors are scarce or intermittent and cooperation principally maintains internal frame consistency until anchor positions can be re-admitted. In a zero-anchor deployment, the anchor-less bootstrap mechanism produces a relative-only coordinate frame, and absolute reference is acquired later as anchor positions become admissible.

An evidential-fusion mechanism combines mesh-derived positions with externally-sourced positions, including satellite navigation, inertial dead-reckoning, and visual-inertial odometry, through the composite admissibility evaluator. A coordinate-frame federation mechanism aligns two or more independently maintained mesh-derived coordinate systems, producing a governance-chain-preserving alignment across them. Coordinate emissions are authority-filtered and privacy-tier-filtered through the observation routing and identity primitives, so that consumers receive coordinate bearings differentiated by their credentials.

Composition With Other Subsystems

Cooperative localization composes with the credentialing substrate: every range observation, every position, and every anchor admission is governance-credentialed and admissibility-checked, so the coordinate frame inherits the substrate's tamper-evidence and audit properties. It composes with the lineage substrate through the coordinate-lineage recorder, which records each range observation, localization event, frame definition, uncertainty update, ambiguity resolution, rejection event, and federation event in the governance chain lineage field, so a downstream consumer can trace any reported position to its constituent observations.

It composes with the governed mesh protocol through range-observation emission and ingestion, with the dispositional field through disposition-weighted range admission, with the cross-domain coherence evaluator through multi-source range corroboration, with the capability envelope through coordinate-precision-bounded operation, and with the observation routing primitive through authority-filtered coordinate emission. It composes with the environmental disruption sensing primitive through ranging-disruption detection and with the cascade propagation primitive through positioning-failure cascade analysis.

It composes with the mesh-derived time primitive through a jointly consistent spatial-temporal reference, producing a unified governance-credentialed spacetime reference. Each range observation carries a temporal association through the coordinate-frame specifier, so static and mobile agents participate in the same coordinate system.

Distinction From Prior Art

Prior satellite-navigation systems operate on broadcast signals from centrally operated constellations whose acquisition is required for positioning and whose denial precludes positioning, whereas the present primitive produces coordinate bearings from cooperating mesh agents without dependence on a central positioning authority. Prior differential-positioning and assisted-positioning systems operate on reference-station networks maintained by positioning-service operators, whereas the present primitive self-organizes through mesh agents without dependence on a positioning-service operator. Prior positioning systems using static identifiers, including satellite pseudo-random-noise codes, beacon broadcast addresses, and fixed-identifier access points, are vulnerable to identifier spoofing, whereas the present primitive authenticates each range observation through the governance-chain continuity identity with admissibility evaluation.

Prior modality-specific positioning systems are limited to a single ranging modality, whereas the present primitive admits many ranging modalities integrated into a single coordinate graph. Prior systems produce a single canonical position without consumer-specific differentiation, whereas the present primitive produces authority-filtered and privacy-tier-filtered coordinate emissions. Prior systems do not support governance-chain-preserving lineage for coordinate determinations, do not support coordinate-frame federation across independently maintained systems, and do not produce anchor-less bootstrap to a usable relative-coordinate frame, whereas the present primitive produces all three.

Failure Modes And Adversarial Considerations

The principal adversarial concern is range spoofing: an attacker emits range observations that misreport distance, attempting to drag the cooperative solution toward a position favorable to the attacker. The adversarial-range rejection mechanism rejects spoofed, injected, or otherwise inadmissible range observations. Authentication through the governance-chain continuity identity forecloses injection by a wholly unauthorized adversary, and admissibility evaluation through the composite admissibility evaluator corroborates a range against multiple sources before it contributes to a position. Each rejection event is recorded in the coordinate lineage.

A second concern is anchor compromise. An anchor whose position is wrong, whether mis-surveyed or derived from a spoofed external source, can distort the absolute frame. Anchor positions are admitted only through the anchor observation admission interface as governance-credentialed contributions and are corroborated through the composite admissibility evaluator, so an anchor whose contribution conflicts with the other admitted evidence is surfaced rather than silently accepted. The evidential-fusion mechanism combines mesh-derived positions with externally-sourced positions through the same admissibility evaluation rather than trusting any single external source outright.

A third concern is the Sybil case, in which an adversary instantiates many credentialed-looking agents to outweigh the legitimate population. The cooperative architecture relies on the architecture's identity-spoofing and Sybil-attack resistance, which is provided through the governance-chain continuity identity rather than through the cooperative localization itself. The disclosure does not claim that cooperative localization is by itself a Sybil defense.

A fourth concern is connectivity collapse. If the mesh fragments into components that share no anchor and no inter-component ranges, a self-healing topology maintainer updates the coordinate graph under agent failure, removal, or addition, and each component continues to operate in its own frame. When connectivity returns, the coordinate-frame federation mechanism aligns the independently maintained coordinate systems, treating the rejoining inter-component ranges as admitted observations, provided those ranges are governance-credentialed and admissible.

Implementation Notes

Reference-node densification supports several deployment forms without limitation: pre-placed permanent reference nodes, deployable semi-permanent reference nodes, airdroppable expendable reference nodes, vehicle-deployable reference nodes, drone-positionable reference nodes, hand-placeable reference nodes, mobile reference nodes on authority-credentialed platforms, and ingested or worn reference nodes in human-factor applications. Densification is governance-policy-configurable per deployment, with deployment intervals bounded by the specific densification form.

Where reference-node precision falls below a governance-policy-defined threshold within ranging distance of consuming agents, the densification-need detector identifies the region, the candidate-deployment evaluator selects deployment locations and modalities, the deployment-admissibility evaluator screens the candidates, and a post-densification integration engine integrates the deployed nodes through cooperative localization. A densification-lineage recorder records each detection, deployment, and resulting precision improvement.

Adversarial cases, including range spoofing and anchor compromise, are handled through the adversarial-range rejection mechanism and through admissibility corroboration, and each rejection event is recorded in the coordinate lineage so that retrospective analysis can reach the rejected observations.

Bootstrapping a fresh deployment proceeds through the anchor-less bootstrap mechanism, which produces a relative-only coordinate frame from zero-anchor conditions, after which anchor positions are admitted as they become available and the relative frame is bound to absolute reference as those positions propagate. The bootstrap sequence is recorded in the coordinate lineage so that retrospective analysis of any reported position can reach back into the founding range observations and anchor admissions.

Disclosure Scope

This article describes the cooperative localization and mesh-derived coordinate aspect of U.S. Provisional Application No. 64/049,409. The disclosure covers the governance-credentialed inter-agent ranging mechanism, the anchor observation admission interface, the cooperative localization engine and its determination of positions through multilateration, the transitive localization extender, the coordinate-frame specifier, the precision-and-uncertainty propagator, the ambiguity-resolution mechanism, the adversarial-range rejection mechanism, the anchor-less bootstrap mechanism, the coordinate-frame federation mechanism, the self-healing topology maintainer, the evidential-fusion mechanism, the coordinate-lineage recorder, and the reference-node densification mechanism, together with the composition with the credentialing, lineage, mesh-protocol, and mesh-derived-time subsystems. It does not claim particular ranging technologies, particular solver algorithms, or particular operating tolerances; those are deployment choices made within the disclosed framework.