Mechanism
The bootstrap procedure begins at deployment time, before any external time observation has been admitted. Each participating agent maintains a local clock with governance-policy-characterized drift properties and exchanges governance-credentialed time-synchronization observations with its neighbors through one of the disclosed synchronization modalities. A cooperative time-estimation engine determines per-agent time-offsets by combining these synchronization observations with any admitted anchor contributions. When direct-anchor synchronization is insufficient, a transitive time-propagation extender produces agent time-offsets through neighbor references, so the consensus spans agents that have no direct line to any anchor.
The mechanism is anchor-less because, when no anchor observations are available, the time-estimation engine produces a relative-only temporal frame from the inter-agent synchronization observations alone. The frame is internally coherent: every contributing agent's offset is consistent with the observed exchanges, even though the frame is not yet bound to any external time. Internal coordination, formation flight, inter-unit handoff, sensor-fusion timing, scheduled radio slots, operates against this relative frame without waiting for absolute binding. A drift-compensation mechanism continuously compensates local-clock drift through fresh synchronization exchanges, and a clock-model learning mechanism refines each agent's drift characterization through governance-credentialed training.
Frame promotion handles the transition from a relative-only frame toward an absolute reference. A temporal anchor observation admission interface admits governance-credentialed temporal anchor contributions, such as a satellite-time observation, a received network time, or an atomic-reference observation, each evaluated through the composite admissibility evaluator. When an anchor contribution is admitted, the time-estimation engine incorporates it, and an evidential-fusion mechanism combines the mesh-derived time with the externally-sourced time. The relative-frame offsets among contributing agents remain mutually consistent through this transition; what changes is the binding of the shared frame to the external reference.
Each synchronization exchange, anchor admission, time-estimation event, and rejection event is recorded by a time-lineage recorder in the governance-chain lineage field. An adversarial-time rejection mechanism rejects spoofed, injected, or inadmissible time-synchronization observations. Where an admitted anchor is later found inadmissible, the rejection and the affected time-estimation events remain in lineage, so that any operation conducted under a since-rejected observation can be retrospectively re-evaluated against the recorded derivation chain.
Operating Parameters
Synchronization exchanges proceed through one of the disclosed synchronization modalities, configurable per declared mission profile. The mesh-derived time primitive admits a plurality of synchronization modalities, and the joint admission interface admits combined range-and-synchronization observations so that ranging exchanges produce jointly-optimized spatial and temporal estimates. Sharing exchanges across the time-consensus and position-consensus pipelines amortizes channel cost across both. The disclosure does not fix a beacon rate or a convergence interval; these are governance-policy and deployment parameters rather than disclosed constants.
A time-uncertainty propagator propagates synchronization uncertainty through the temporal graph, producing per-agent time-uncertainty estimates. Downstream operations consume these uncertainty estimates: coordination tasks requiring tighter time alignment consume the frame only when their declared temporal-precision bound is satisfied, and tasks tolerant of looser alignment proceed earlier. Convergence quality depends on graph connectivity and on the drift properties of the participating clocks, but the disclosure states these as governed properties rather than as fixed precision figures.
Governance credentials govern which observations enter the consensus. Each agent's synchronization observations carry the agent's authority credential, and the time-estimation engine combines them under governance policy. Temporal anchor contributions carry source credentials, and the temporal anchor observation admission interface admits or rejects each anchor contribution through the composite admissibility evaluator. The adversarial-time rejection mechanism rejects spoofed, injected, or inadmissible observations before they can influence the frame.
The mesh-derived time primitive admits a plurality of clock technologies, each agent maintaining a local clock with governance-policy-characterized drift properties that the time-estimation engine consumes as weighting inputs. Prior chip-scale atomic clocks, by contrast, provide high-precision time-of-day without distributed consensus; the present primitive combines precision clock sources with distributed mesh consensus. The clock-model learning mechanism refines each agent's drift characterization through governance-credentialed training, and each refinement enters lineage so that consensus quality and its governing parameters remain auditable.
Alternative Embodiments
The mechanism applies to any mesh of agents capable of governance-credentialed time-synchronization exchange. Embodiments include unmanned-aerial-vehicle swarms operating where satellite time is unavailable, subterranean sensor meshes lacking sky view, indoor robotics fleets where multipath corrupts external time signals, naval surface formations operating under emissions-controlled conditions, and rapidly-deployed disaster-response meshes whose deployment outpaces external-infrastructure availability.
The synchronization modality is not constrained to a single medium. The primitive admits a plurality of synchronization modalities, and hybrid embodiments admit observations from multiple modalities simultaneously, each contributing agent's synchronization observation carrying its authority credential. The joint admission interface further admits combined range-and-synchronization observations, so a single exchange can contribute to both the temporal and the spatial estimate.
Anchor admission is governed rather than fixed. Deployments that can reach a satellite-time source, a network time, or an atomic reference admit those anchor contributions through the temporal anchor observation admission interface; deployments with no reachable anchor operate against the relative-only frame produced by the transitive time-propagation extender. Whichever anchors are available, the composite admissibility evaluator decides admission under the governance policy declared for the deployment.
A partitioned-operation embodiment admits temporary network partitions: each partition continues to operate against its own coherent temporal frame, and on rejoin a governance-policy-defined merging procedure reconciles the frames rather than synchronizing them automatically. The time-frame federation mechanism aligns independently-maintained temporal frames, and the merge event enters lineage so that operations conducted under either pre-merge frame remain auditable. Agents joining a running deployment contribute synchronization observations against the existing agent set, and the time-lineage recorder records each such event in the governance chain.
Composition
Anchor-less bootstrap composes with the per-agent clock-model learning mechanism: each agent maintains a local clock with governance-policy-characterized drift properties, and the clock-model learning mechanism refines those characterizations through governance-credentialed training. The time-estimation engine consumes each agent's drift characterization as a weighting input, so that an agent whose drift model carries wider uncertainty contributes with correspondingly weighted influence. The composition is structural; the engine reads each agent's drift characterization as an input rather than treating it as an external configuration.
The bootstrap also composes with the mesh-derived coordinate primitive through the joint admission interface, which admits combined range-and-synchronization observations so that ranging exchanges produce jointly-optimized spatial and temporal estimates over a single observation set rather than two independent sets. A joint uncertainty propagator produces per-agent spacetime uncertainty, and a four-dimensional observation emitter produces observations carrying spatial coordinates and time with joint uncertainty.
A further composition arises with the governance chain itself. Each agent's synchronization observation carries its authority credential, and each admitted temporal anchor contribution carries the source authority that produced it. The time-estimation engine is therefore not only a numerical procedure but a governance-aware one: admissibility determinations, weight assignments, and anchor admissions are all recorded against the governance chain so that the resulting temporal frame supports deterministic reconstruction of each timestamp's derivation chain, from the deployment-time relative-only bootstrap through every subsequent admitted anchor. Downstream consumers of the frame, coordination tasks, mission-planning subsystems, and post-mission analysis, read both the resolved time and the credentialed lineage by which it was resolved.
Composition with the cascade-propagation primitive admits the time-uncertainty propagator's per-agent uncertainty estimates as inputs to cascaded coordination: a rise in propagated time-uncertainty, indicating that synchronization has degraded, propagates as a governance-credentialed event to coordination tasks that may then widen tolerance windows or defer time-critical maneuvers under cascade-temporal-consistency enforcement. Composition with the health-monitoring primitive permits attestation of time-consensus quality through the governance-credentialed timestamp attestation interface, by which a formation may attest a bounded time-uncertainty to a superior authority. Composition with the revocation mechanism ensures that an agent whose credential is revoked mid-deployment is removed from the consensus rather than continuing to influence the frame; the revocation enters lineage and the affected contributions are retired. Composition with the time-frame federation mechanism admits cross-boundary coordination: two independently-maintained temporal frames are aligned under governance-chain-preserving federation with cross-authority translation, admitting coordination across formation boundaries without merging the underlying frames.
Prior-Art Boundary
The disclosed primitive is structurally distinguished from prior time-distribution architectures in several respects, each drawn from the disclosure. Prior satellite-derived time services operate through broadcast signals from centrally-operated constellations whose acquisition is required for timing and whose denial precludes timing, whereas the present primitive produces time bearings from cooperating mesh agents without dependence on satellite availability. Prior network-time-protocol systems are client-server hierarchical and depend on centralized stratum-1 time servers, whereas the present primitive operates through cooperative consensus without a master clock. Prior precision-time-protocol systems require a hierarchical master-slave configuration with dedicated grandmaster clocks, whereas the present primitive is master-less and self-organizes through mesh agents.
Prior blockchain timestamp protocols timestamp at block-commit granularity, producing coarse timestamps, whereas the present primitive produces continuous governance-credentialed timestamps at observation granularity. Prior trusted-timestamp-authority systems centralize timestamp issuance at a single authority, whereas the present primitive produces multi-authority timestamps admissible through composite admissibility. Prior chip-scale atomic clocks provide high-precision time-of-day without distributed consensus, whereas the present primitive combines precision clock sources with distributed mesh consensus.
The disclosed architecture treats master-less operation as the nominal condition and produces an anchor-less temporal bootstrap to a usable relative-only frame when no anchor observations are available. Prior systems do not support a governance-chain-preserving temporal lineage for timestamp derivation, whereas the present primitive supports deterministic reconstruction of each timestamp's derivation chain, so that admissibility and binding decisions remain auditable for the lifetime of the deployment. Prior systems do not support time-frame federation across independently-maintained systems with cross-authority translation, whereas the present primitive produces governance-chain-preserving federation. A corrupted external source is handled through the adversarial-time rejection mechanism and recorded in lineage, so that any clock derived under a since-rejected observation can be retrospectively re-evaluated against the recorded history.
Disclosure Scope
This article describes the anchor-less temporal bootstrap mechanism disclosed in U.S. Provisional Application No. 64/049,409. Forward-deployed defense formations gain a relative time frame at the moment of deployment without waiting for sky view or for radio-link establishment to a rear authority. Disaster-response meshes gain the same property in environments where external infrastructure has been damaged or has not yet been established. Subterranean and indoor robotics gain a structurally-coherent time approach in which internal coordination uses the relative-only frame and external coordination waits only for admitted anchor contributions to accumulate. Maritime formations operating under emissions-controlled conditions gain an internal-time mechanism that does not depend on any specific external timing infrastructure.
The scope of the disclosure encompasses the anchor-less temporal bootstrap mechanism that produces a relative-only temporal frame when no anchor observations are available, the cooperative time-estimation engine, the transitive time-propagation extender that produces agent time-offsets through neighbor references, the temporal anchor observation admission interface governed by the composite admissibility evaluator, the time-uncertainty propagator that downstream operations consume, and the composition with adjacent mesh primitives including per-agent drift modeling and joint range-and-synchronization consensus. The disclosure further encompasses the credentialed agent-identity records that weight per-agent contributions and the time-lineage recorder that records synchronization exchanges, anchor admissions, time-estimation events, and rejection events for downstream verification.
Embodied properties of the disclosed architecture include master-less nominal operation, the production of a relative-only frame from zero-anchor conditions, the symmetric treatment of every agent as both a contributor and a consumer of the consensus, and the verifiability of the temporal frame's derivation history against the governance chain. These properties are presented as part of the architectural disclosure rather than as performance claims of any particular implementation.
The disclosure further encompasses the drift-compensation mechanism that continuously compensates local-clock drift through fresh synchronization exchanges; the clock-model learning mechanism that refines per-agent drift characterizations through governance-credentialed training; the adversarial-time rejection mechanism that rejects spoofed, injected, or inadmissible observations; the evidential-fusion mechanism that combines mesh-derived time with externally-sourced time through the composite admissibility evaluator; the governance-credentialed timestamp attestation interface and its multi-attester consensus composer; the time-frame federation mechanism that aligns independently-maintained temporal frames with cross-authority translation; the partitioned-operation embodiment that admits temporary network partitions under governance-policy-defined merging; and the joint spatial-temporal graph that composes the time primitive with the mesh-derived coordinate primitive. Specific implementations of estimation algorithms, synchronization waveforms, clock hardware, credential signing schemes, and lineage storage formats are admitted as substitutable components within the disclosed structure rather than as essential features, so long as the substituted component honors the governance policy and produces lineage entries compatible with the governance chain.