Origin-Equivalence Normalization

Metering that can't be gamed by splitting one accuser into many.

Primary technical disclosure

Secondary technical

Content-Blind Encounter Commitment and the Paired Encounter Receipt How a content-blind encounter commitment and paired encounter receipt let a semantic agent import verifiable evidence for origin-equivalence class derivation without importing any portable evaluation of conduct.Cross-Receipt Equivocation Detection: Catching an Agent That Tells Two Stories Cross-receipt equivocation detection lets a verifying semantic agent identify two encounter attestations that record one encounter yet name different determination classes, withdrawing both from origin-equivalence class derivation without any registry, directory, or coordination with a further execution node.The Untested-Origin Saturation Bound: Pricing a Flood of Freshly Minted Identities How the untested-origin saturation bound multiplies a scope partition's cross-partition propagation-suspension bound by one less the proportion of conduct evaluation artifacts arriving from untested origin-equivalence classes, making saturation by freshly minted identities cheaper to contain than saturation by counterparties with recorded histories.Counterparty-Side Fork Detection: Recognizing a Split Identity From Outside How a receiving agent detects a forked or cloned counterparty identity from the outside using the inherited governance record, epoch identifiers, the successor-continuity test, and an appended lineage-discontinuity record, without a registry, a quorum, or a revocation authority.The Attestation Origin-Equivalence Gate: An Anti-Collusion Bound How an attestation origin-equivalence gate bounds concerted non-execution attestations per locally derived origin-equivalence class, without scoring any party, incrementing any counter, or consulting a registry.The Bridging Party and the Deferred Merge: Charging One Windowed Increment Against Every Origin-Equivalence Class a Single Asserting Party Bridges How a semantic agent defers the merge of two origin-equivalence classes, records the asserting party relating them as a bridging party, and charges one windowed increment against each bridged class in the per-class increment register of its refusal counter.The Common-Execution-Node Relation Type: Charging Co-Hosted Asserting Parties as One Origin How a declared relation type evidenced by a common execution node recorded as having hosted two asserting parties assigns them to one locally derived origin-equivalence class, so their assertions are charged as a single source.Receiver-Side First-Encounter Budget Decrement: Pricing a Stranger's Arrival Per Presented-Material Origin Class The receiver-side first-encounter budget decrement charges a semantic agent's own authorization budget when it instantiates an ephemeral-tier record for a party it has never met, metered per presented-material origin-equivalence class computed from presented identity material alone.Mutual First Encounter Without Cross-Budget Coordination: Two Strangers, Two Matched Pairs, Two Separate Budget Decrements Mutual first encounter admission between two semantic agents that hold no counterparty identity record of one another, structured as two independent matched pairs with two separate first-encounter budget decrements and no cross-budget coordination, offset, or credit.

Applications · general

Applications · specific

W3C Decentralized Identifiers and Verifiable Credentials: Verifying an Identifier Versus Metering Its Origin How W3C Decentralized Identifiers and Verifiable Credentials verify an identifier while origin-equivalence normalization meters the origin behind it, charging an autonomous agent's refusal counter per source of assertion rather than per assertion, with no registry consulted.Okta Auth for GenAI: Agent Identity and Origin Equivalence How Okta Auth for GenAI approaches agent identity for AI applications, and how origin-equivalence normalization derives local, non-portable source classes from an agent's own lineage records so refusal metering resists identity splitting.WorkOS: Agent Identity Infrastructure and Source Metering How WorkOS-style agent identity infrastructure and the origin-equivalence normalization mechanism of the Adaptive Query portfolio address different halves of agent trust: identity issuance and authentication versus locally derived source metering of refusals.Entra Agent ID: Directory Identity and Derived Origin Classes How Microsoft Entra Agent ID and directory-issued agent identity compare with locally derived origin-equivalence classes, a filed architecture that meters agent refusals per source of assertion instead of per assertion to blunt identity-splitting in open agent networks.SPIFFE and SPIRE: Workload Identity and Origin Equivalence How SPIFFE and SPIRE workload identity, trust domains, and SVID attestation compare with locally derived origin-equivalence classes that meter agent refusals per source of assertion rather than per assertion.Cloudflare Bot Management: Blocking Agents and Metering Sources How Cloudflare Bot Management approaches automated traffic at the network edge, and how origin-equivalence normalization meters agent refusals per derived source class rather than per assertion, using locally derived, non-portable identity relations.HUMAN Security: Bot Networks and Metering by Source How bot mitigation platforms such as HUMAN Security and the Adaptive Query origin-equivalence architecture approach identity splitting from different layers, covering Sybil resistance, refusal charging per source, agent lineage records, and locally derived equivalence classes.

Terminology