1. Cheap Identities, Costly Complaints

An autonomous agent in an open network has to accept complaints about its own conduct. That is the price of accountability to counterparties it did not choose and cannot vet. It takes in signed artifacts asserting that it behaved badly, checks each against what it recorded doing, and lets the outcome bear on whether it keeps acting.

The trouble is how cheap the input is. Standing up a fresh identity in such a network typically amounts to little more than generating a keypair. An adversary who wants an agent taken out of service does not need one true complaint. It needs volume.

Consider the arithmetic these structures run. Metering is merit-independent and accumulates on both refusal paths: an artifact the agent's record contradicts produces the rejected determination, an artifact it cannot resolve against its append-only lineage field produces the not-determinable determination, and both accumulate increments. Reach the declared rate threshold inside the declared window and the authorization gate goes to the withheld state. A counter, though, cannot tell forty complaints from forty parties apart from forty complaints from one party wearing forty faces. Section 2.1 of the filed chapter states the exposure without softening it: volume alone drives the gate to the withheld state, and the volume available to an adverse party is limited only by the cost of presenting further identities.

2. Why the Usual Defenses Stall

The standard reflex, as such schemes are generally described, is to make identity expensive: bind each account to a phone number, a payment instrument, a government credential, or a stake that can be forfeited. It works, and it costs the openness that made the network worth building. Onboarding becomes a gate, the gate needs an operator, and that operator becomes the party everyone has to trust. Computational puzzles only relocate the problem, since a price high enough to deter a determined adversary also falls on the first-time counterparty with least reason to pay it.

Shared reputation and scoring services collapse the question into somebody else's database. Every participating agent then depends on that service being available, honest, correct, and reachable when the decision has to be made, and its scores are portable by design, which is what makes them worth buying and worth attacking. A score earned elsewhere is no evidence of anything the evaluating agent observed.

Clustering approaches that infer collusion from behavioral similarity yield a probabilistic judgment about a party's character. An agent holding such a judgment is adjudicating, and an autonomous agent without an arbiter is in no position to do that.

One assumption sits under all three: that Sybil resistance means establishing who a party really is, at network scope, as a fact everyone agrees on. Questions of that kind need an authority to settle them.

3. The Disclosed Mechanism

Chapter 2 of the filing does not try to determine who anyone is. It changes what gets charged. The refusal counter is incremented per origin-equivalence class rather than per conduct evaluation artifact, such a class being a set of asserting parties between which the semantic agent's own records evidence a derivable relation of a relation type declared in the signed policy object. The counter is charged per source, not per assertion.

Derivation is an ordered procedure run on receipt of an artifact. The agent retrieves the counterparty identity record of the asserting party, or instantiates one, then reads from the signed policy object an enumeration of declared relation types, each naming a class of lineage entry and a matching condition over such entries. Every declared type is evaluated between the present party and each party already assigned to a class, in the current window or a preceding one.

Three types are enumerated. A shared dispatch lineage is evidenced where the lineage field holds one entry recording a dispatch to the present party and a second recording a dispatch to the compared party, both recording a common parent dispatch entry as their immediate antecedent. A co-signature is evidenced where a single lineage entry bears a signature verifiable against an identity primitive of each of the two parties. A common introduction path is evidenced where the counterparty identity records of both parties each record an introducing party and the two recorded introducing parties are identical. Each type is independently sufficient. Where a relation is evidenced the present party joins the compared party's class; where more than one class is implicated the classes merge; where nothing is evidenced a new class forms. The assignment and the entries relied upon are appended to the lineage field, and the resulting class identifier is written into each member's counterparty identity record, where it records an assignment and not a determination about conduct.

The evaluation runs entirely on the agent's own lineage entries and the counterparty identity records it holds, with no centralized registry, no directory query, no consensus procedure, and no coordination with a further execution node. The class is also local: a second agent holding different records derives a partition that need not agree, nothing reconciles the two, and neither agent admits an identifier derived by the other.

Assignment persists rather than expiring, so a party assigned in one window is a compared party in each succeeding window without re-derivation. The per-class increment register alone is window-scoped and reset.

Section 2.5 closes the remaining hole: identities the agent has never encountered would otherwise each form a distinct class contributing at full weight. A class is designated an untested class where every constituent edge resolves not-typeable under the severance-survival test. Where such a class's recorded introduction paths also converge upon a common ancestor entry within a declared depth, a cost multiplier greater than zero and less than unity applies to its contribution, which then accumulates in a weighted contribution register holding a rational quantity. The rate of the window is the integer count held by the rate accumulator plus that register rounded down.

4. Applying It in an Open Network

Under per-artifact charging, an adversary's cost per increment is one fresh identity, the rate threshold is a fixed integer, and it needs that many identities and no true grievance at all.

Under per-source charging the cost changes shape. Where the agent's lineage records dispatches to the fabricated identities under a common parent dispatch entry, they share a dispatch lineage and land in one class; an entry carrying signatures from two of them evidences co-signature; a common introducer evidences the common introduction path. That class contributes one increment in the window, because the register is consulted before the rate accumulator is touched and the procedure terminates without incrementing where the class has already contributed.

Order matters, and the filing fixes it. Normalization runs on receipt, before the register is consulted, so an identity presented mid-window joins the class of its related parties before any increment attributable to its artifact is applied. A further identity therefore cannot yield a further increment where the relation is evidenced from records already held. A merge arriving late neither inflates nor deflates the rate: the merged class counts as having contributed where any constituent class did, and a contribution already applied is not withdrawn.

Section 2.6 works a trace through it. A policy object declares a rate threshold of five, a cost multiplier of one fifth, and an introduction-path depth of two. Forty artifacts arrive from forty newly encountered parties sharing no declared relation type and carrying no recorded severance event, so forty untested classes form. Thirty-five have recorded introduction paths converging upon a common ancestor entry at depth two, so the multiplier applies and the weighted contribution register reaches seven; the remaining five do not converge and contribute at full weight, the rate accumulator reaching five. The rate is twelve and the threshold is satisfied. Had all forty instead recorded a common introducing party, one class would have formed, contributed one increment, and the gate would have remained in the granting state.

For an operator the consequence is narrow but real: complaints can be accepted from parties never met, with no onboarding gate and no vetting authority, while a single origin's contribution to the withholding of an action stays bounded however many identities it presents.

What the procedure declines to do matters as much. Normalization suppresses no determination and withholds no adjudication. An artifact from a party in a class already recorded still produces a determination and is still appended to the lineage field, only the contribution to the refusal counter being aggregated. That is the line between this and a spam filter that quietly discards complaints. The multiplier holds the same line for the newly encountered party, which the filing describes as retaining capacity to correct the agent: it excludes no class and suppresses no determination.

5. Deployment Considerations

The signed policy object parameterizes the mechanism, and those parameters are where deployment judgment lives. The enumeration of declared relation types is load-bearing: the specification requires at least one, and an empty enumeration assigns every party to a distinct class, restoring the condition of Section 2.1. What is declared fixes what evidence of common origin the agent can see at all.

Introduction-path depth trades reach against the risk of grouping parties a shallower test would keep apart. The declared depth counts traversals beyond the immediate introducing party and is at least one, since a depth of zero would detect convergence only through an identical immediate introducing party. The cost multiplier sets how far a converging untested class is discounted, and the continuation interval sets the period within which a subsequent event of a severance class must re-establish an edge for the severance to count as survived. Designation is recomputed on three triggers and no other: receipt of an artifact from a member, append of a severance event against a constituent edge or of an entry carrying such an edge to a survived value, and merge.

The test is also deliberately permissive about missing evidence. An edge that fails to resolve for want of a recorded severance event, for want of a recorded outcome of one, or because the declared continuation interval has not elapsed is itself an edge resolving not-typeable, and its class stays eligible. Designation rests upon that resolution alone and upon no narrower condition.

One arithmetic detail deserves attention. The weighted contribution register holds a rational quantity and is neither rounded nor truncated upon accumulation; rounding down happens only at comparison against the threshold, and no rounded value is written back, so a residue below one survives across contributions inside a window and is discarded on reset. Many small reduced contributions therefore aggregate rather than vanishing to truncation one at a time.

Then the limits, taken as the filing states them.

  • Merit is not determined. No step evaluates whether a refusal was well founded, and no party adjudicates. Aggregation governs metering alone.
  • A genuinely unrelated adversary is not detected. Identities evidencing none of the declared relation types in the agent's records form distinct classes and contribute separately. The multiplier reduces that contribution without eliminating it, and only where introduction paths converge. The bound reaches as far as the evidence can group.
  • No portable standing is produced. The partition is local and never reconciled, so nothing here is inherited by another agent as a ready-made defense. That is a commitment, not a gap.
  • Recomputation does not rewrite the window. A recomputation that changes a designation is appended and governs contributions applied after the append. A contribution already applied within the current window stands.

6. Disclosure Scope

The mechanism described here is disclosed in U.S. Provisional Application No. 64/117,812, Chapter 2, "Origin-Equivalence Normalization," principally at Sections 2.1 through 2.6, together with the definitions of "origin-equivalence class," "untested class," "reason-type," and "severance event," and the metering structure of Chapter 3 on which it runs.

Disclosed: incrementing a refusal counter per origin-equivalence class rather than per conduct evaluation artifact; derivation of such a class by an ordered procedure over declared relation types read from a signed policy object, including shared dispatch lineage, co-signature, and common introduction path; persistence of the assignment beyond the window with the per-class increment register alone reset; class merge with reconciliation of that register such that a merged class contributes, within one window, the minimum of one increment and the number of constituent classes that contributed; designation of an untested class by the severance-survival test; the introduction-path convergence test at a declared depth; and a cost multiplier greater than zero and less than unity accumulated in a weighted contribution register rounded down only at comparison time.

Disclaimed: any requirement for a centralized registry, directory, consensus procedure, or coordination with a further execution node; any reconciliation of class partitions between agents; any transmission or admission of a class identifier derived by another agent; any portable standing conferred on an asserting party; and any adjudication of the merits of an assertion.

The application is pending. Nothing here asserts that any particular system practices the disclosed subject matter, and nothing here states that any party requires a license. This publication places the disclosure on the public record with a date.