Mechanism
The three-tier architecture is a structural partition of the spatial-mesh device population governed at the credential layer rather than at the hardware layer. Each device carries an authority credential issued by the deploying credentialing authority. The authority credential encodes at minimum an issuing-authority identifier, a scope specification of the issuing authority's scope, a temporal-validity specification of the credential's validity period, a device-binding attestation binding the credential to the emitting device, and a cryptographic attestation produced under a digital-signature, threshold-signature, zero-knowledge, post-quantum, or equivalent attestation mechanism. The credentialing lifecycle disclosed in the provisional supports issuance, renewal, and revocation through the issuing authority, so a device's authority context can be re-credentialed or withdrawn without device retrieval, and an observation emitted outside a device's credentialed scope is evaluated against the receiving party's authority taxonomy rather than admitted unconditionally.
The structural rationale for tier separation is that each tier carries a different governance burden and a different physical-layer profile, and that conflating them forces every device to inherit the union of those burdens. By separating the population, the disclosure permits the lowest-capability devices to deploy first under the lightest governance, the mid-capability devices to layer in as conditions allow, and the highest-capability compute to follow when query and composition demand justifies it. Each tier is independently deployable so that revocation, rotation, and audit can be administered through the issuing authority without disturbing the others.
Tier 1, passive environmental markers, are devices installed on or embedded within navigable infrastructure that hold authority-credentialed stored data and emit or modulate a signal encoding that data in response to interrogation, deriving operating energy from an external source rather than from an internal battery. Physical embodiments include radio-frequency backscatter markers, passive optical retroreflective markers with data modulation, surface-acoustic-wave chipless identifiers, and Datamatrix-encoded retroreflective surfaces, installable as road studs, raised pavement markers, or equivalent pre-fabricated infrastructure elements. The stored data binds a marker identifier, a spatial reference, a segment or zone identifier, a delineation-role classification, local geometry, and an authority credential with temporal scope and a cryptographic attestation. The passive marker lacks an active radio configured to initiate communication and a processing capability sufficient to maintain a baseline environmental model, so it does not originate broadcasts, synthesize claims, or relay traffic.
Tier 2, active environmental sentinels, are devices installed at perception-critical locations that detect dynamic objects, conditions, or state deviations within a coverage volume and emit a governed observation encoding each deviation. A sentinel maintains a stored baseline environmental model of its coverage volume, computes deviations of current sensor readings from that baseline, and emits each deviation observation through the governed mesh with its authority credential. A perception-critical location is one at which an operating unit's own sensors are insufficient within its planning horizon, including blind corners, intersection approaches, merge zones, pedestrian crossings, and dock or berth approaches. Each deviation observation is receivable by operating units, by neighboring sentinels, and by cognitive infrastructure agents, and inter-sentinel communication supports hand-off of a detected deviation from one sentinel's coverage volume to the next while preserving the deviation's lineage.
Tier 3, cognitive infrastructure agents, are governed semantic agents deployed at coordination-critical locations that aggregate governed observations produced by passive markers and active sentinels within a coordination zone, maintain a local segment of the distributed spatial world model, and operate over cognitive domain fields including awareness, dispositional, confidence, integrity, capability, forecasting, and lineage fields. A coordination-critical location is one at which two or more operating units require coordination of their navigation or actuation decisions, such as major intersections, interchanges, berth-assignment points, or rail and waterway junctions. The agent communicates with operating-unit agents through the governed mesh, emitting coordination directives that each receiving unit evaluates through its own composite admissibility evaluator as a proposed mutation rather than as a command. Each aggregate observation preserves lineage back to its contributing observations, and a cognitive infrastructure agent is composable with other such agents through hierarchical aggregation up through unit, building, campus, zone, and regional levels.
Cross-tier traffic composes through the governance chain, evaluated by the receiving party. A device receiving an observation purporting to come from a passive marker or an active sentinel evaluates the authority credential, the device-binding attestation, and the cryptographic attestation, then evaluates the observation against its governance-configurable authority taxonomy, which maps the source's authority level to a behavioral response ranging from substrate-condition treatment through advisory treatment to untrusted-proposal treatment. A receiving operating unit evaluates the credential and lineage before injecting any observation as a mutation into its autonomous planning graph. An observation emitted without a valid governance credential is treated at the no-authority level rather than admitted. The evaluation is reciprocal, in that a higher-tier node consuming lower-tier observations evaluates the lower-tier credentials through the same authority-taxonomy mechanism that a lower-tier device uses when accepting governance or revocation messages.
Composite-observation construction at Tier 3 is bounded by an explicit lineage rule. A Tier 3 agent producing an aggregate claim, for example, "intersection 7B is presently in eastbound green with cross-traffic clear and pedestrian phase inactive", must carry the underlying Tier 1 marker attestations (the lane edges and crosswalk geometry), the underlying Tier 2 sentinel attestations (the signal phase, the pedestrian-button state), and any time-window or aggregation parameters used to fuse them into the composite. A consumer of the composite that wishes to verify the Tier 3 conclusion can trace each constituent claim back to its originating authority credential, and the Tier 3 conclusion is admissible only to the extent that its lineage is complete and the constituent observations are within their temporal validity. This lineage discipline is what prevents Tier 3 nodes from becoming opaque oracles whose outputs would otherwise have to be trusted on the basis of the Tier 3 signature alone.
Operating Parameters
Credential issuance follows a hierarchical authority taxonomy defined by a deploying authority for an operational domain. In a roadway domain, for example, the taxonomy includes a regulatory-infrastructure authority assigned to devices credentialed by national, state, or municipal transportation authorities, an emergency-preemptive authority for credentialed emergency services, an operational authority for local jurisdictions or facility operators, an advisory authority for registered contributors, and a no-authority level for devices without a valid governance credential. Each authority credential carries a temporal-validity specification of its validity period, and the credentialing lifecycle supports renewal and revocation through the issuing authority. The provisional does not fix specific validity durations; the temporal scope is governance-policy-defined per device and domain.
Tier 1 markers derive operating energy from an external source rather than an internal battery, so they respond to interrogation and consume no energy when idle. Tier 2 sentinels draw on an internal energy source that may comprise a battery, a capacitor, a photovoltaic cell, a kinetic, thermoelectric, or radio-frequency-harvesting element, a wired power interface such as Power over Ethernet or alternating-current mains, or any combination thereof, and emit deviation observations through the governed mesh as deviations from the stored baseline are detected. Tier 3 cognitive infrastructure agents are sited at coordination-critical locations and aggregate marker data, sentinel deviation observations, and operating-unit-reported observations into a local segment of the distributed spatial world model. The provisional does not specify read latencies, broadcast intervals, or query-response timing figures; these are left to the implementation and deployment domain.
Lower-tier inputs do not pollute a higher-tier aggregate without recourse. A cognitive infrastructure agent's confidence field encodes its assessed reliability of its awareness, modulated by sentinel health, coverage completeness, and detection consistency, so that an aggregate observation produced from degraded or inconsistent inputs carries a correspondingly lower confidence. When a credential is revoked, each consuming device down-weights or invalidates previously-admitted governed mesh messages emitted under that credential, in accordance with a governance-policy-defined retroactive-effect window. Every evaluation, state change, and actuation is recorded in the agent's lineage field, so the provenance of any aggregate is reconstructable.
The mesh adapts gracefully to partial tier coverage. A region with only Tier 1 deployment provides static-authority benefit: operating units consume signed lane edges, hazard zones, and jurisdictional boundaries directly from markers. Adding Tier 2 yields live state attestation overlaid on the static base. Adding Tier 3 yields composite observation, query support, and forwarded broadcasts. The capability scope visible to an operating unit is the union of the tiers present in the unit's current region, and the unit's confidence-governed actuation policy reads off that union to select an operating mode. Transitions between tier coverages, for example, a vehicle leaving a Tier-3-covered urban core for a Tier-1-only rural corridor, are observable as changes in the available attestation chains rather than as catastrophic loss of service, and the unit's policy is expected to anticipate and accommodate these transitions rather than rely on uniform coverage assumptions.
Revocation is administered through the issuing authority. To revoke a credential, a credentialing authority emits a revocation governed observation identifying a specific device, a specific credential, or a specific credential class as no longer authoritative. Upon consuming the revocation, each consuming device down-weights or invalidates previously-admitted governed mesh messages emitted under the revoked credential, in accordance with a governance-policy-defined retroactive-effect window specifying the duration of past emissions subject to the revocation, and a device whose credential has been revoked is ineligible to emit governed mesh messages under the revoked authority context. The same lifecycle governs the issuance, renewal, and revocation of credentials across all three tiers.
Alternative Embodiments
Tier-1 embodiments include radio-frequency backscatter markers operating in ultra-high-frequency, high-frequency, low-frequency, microwave, millimeter-wave, or higher bands; passive optical retroreflective markers with spatial, temporal, or spectral data modulation, including Datamatrix-encoded retroreflective surfaces; surface-acoustic-wave chipless identifiers; magnetic-induction or near-field magnetic-coupling markers; passive photonic, acoustic, chemical or spectroscopic, and magnetic-signature markers; and combinations of the foregoing. The unifying property is that the device holds authority-credentialed stored data and emits or modulates that data in response to interrogation without an internal battery and without originating new claims.
Tier-2 embodiments include sentinels installed at blind corners, intersection approaches, merge zones, pedestrian crossings, construction-zone boundaries, grade crossings, platform edges, dock and berth approaches, and other perception-critical locations, sensing through radio-frequency disruption, optical, thermal, acoustic, ultrasonic, radar, lidar, chemical, magnetic, vibration, or other modalities, in any combination. The provisional leaves the signaling medium open, contemplating radio-frequency, optical, acoustic, magnetic, quantum-communication, wired, or any combination of signaling media. The unifying property is baseline-deviation computation and the governance-credentialed emission of the resulting deviation observations within a credentialed scope.
Tier-3 embodiments include cognitive infrastructure agents deployed at major intersections, highway interchanges, port berth-assignment points, warehouse-zone boundaries, airfield taxiway junctions, rail junctions, waterway locks, and building-floor or platform entry points. Cognitive infrastructure agents are composable through hierarchical aggregation, in which unit-level agents produce summary observations consumed by building-level agents, building-level agents by campus-level agents, campus-level agents by zone-level agents, and zone-level agents by a regional-level agent, with each summary observation preserving lineage back to its contributing observations. The provisional places no limit on the number of aggregation tiers or the topology of aggregation, contemplating tree, lattice, peer-to-peer, and hybrid arrangements.
A device's credentialed authority is not fixed for life. The credentialing lifecycle disclosed in the provisional supports credential transfer upon transfer of ownership or control, credential suspension pending investigation without immediate revocation, credential downgrade reducing a device from a first authority level to a lower one, and credential escalation temporarily elevating a device to a higher authority level. Each such lifecycle transition is recorded in the device's lineage field and in the credentialing authority's lineage field, producing a governance-chain-preserving record of the device's credentialing history. A roadside cabinet that hosts compute can thus be escalated or downgraded between authority levels through its issuing authority rather than re-deployed.
Cross-authority embodiments are handled through the disclosed cross-authority boundary translation, in which a governance-credentialed boundary agent maps an observation from a first authority taxonomy of a first operational domain to an equivalent observation in a second authority taxonomy of a second operational domain, per the taxonomy-translation mechanism of the provisional. Combined with credential downgrade, this lets an observation credentialed under one authority be consumed, at an equivalent or reduced authority level, within a second authority's region. The mechanism matters for corridor operators whose roadways traverse multiple municipal, regional, and federal jurisdictions, and whose fleets must consume credentialed observations consistently as the unit moves across boundaries.
Composition with Adjacent Primitives
The three-tier architecture composes with the receiving operating unit's confidence-governance policy. The unit's policy maps the available tier coverage to an admissible action envelope: actions requiring composite observation may be admissible only when Tier 3 coverage is present; actions requiring live attestation may downgrade when only Tier 1 is present; actions safe under static authority alone remain admissible across all tier coverages. The mapping is declarative in the unit's policy and evaluated at decision time against the currently observed tier set.
The architecture composes with cross-jurisdiction handoff. As a unit traverses jurisdictional boundaries, the authority credentials it consumes change: different issuing authorities, different authority taxonomies, possibly different tier coverage densities. The unit's policy tracks the current authority context and applies the correct trust anchors and authority-taxonomy expectations for each region. The transition is structurally clean because each authority credential carries its own issuing-authority identifier and scope.
The architecture composes with audit and post-incident review. Every authority-credentialed observation consumed into a unit's decision is recorded with its authority level, its lineage chain, and the unit's policy state at the time of consumption. Reconstruction of a decision is possible from the recorded chain alone; the auditor does not need to recover the operating environment to verify which observations were admissible. The audit composition is particularly important for incident reconstruction in regulated domains, autonomous vehicle collisions, port-yard equipment incidents, harbor-approach safety events, where the question is not only what the unit did but what attestations it had available at the moment of decision and whether its policy correctly mapped those attestations onto the action ultimately taken.
The architecture composes with the spatial-mesh's broader confidence-governance model. Each credentialed observation carries an evidential weight assigned by the consuming unit's authority taxonomy and is evaluated by the composite admissibility evaluator, which weighs the authority level of the source, the corroboration provided by neighboring observations, and the observation's temporal validity. The receiving unit's composite admissibility evaluator admits, gates, defers, or rejects each proposed actuation against these inputs, so an action the available confidence does not support is gated or deferred by the evaluator rather than by ad hoc reasoning. This composition makes the tier architecture a first-class input to autonomous decision-making rather than an opaque infrastructure layer that the unit must reason about separately.
Prior-Art Differentiation
Existing vehicle-to-everything (V2X) communication proposals, including Dedicated Short-Range Communications (DSRC) at 5.9 GHz and Cellular Vehicle-to-Everything (C-V2X), require active radios with dedicated power, cellular subscriptions, and complex protocol stacks, and their security systems authenticate messages through public-key infrastructure but treat all authenticated messages homogeneously, without an authority-taxonomy semantics that differentiates behavioral response according to the message source's governance authority. The three-tier separation here is a governance and capability classification under that authority taxonomy rather than a hardware or radio classification.
Prior proposals to embed radio-frequency identification tags in road surfaces treat the tags as standalone data points and do not integrate them into an architecture that includes active environmental sensing, multi-tier progressive enhancement, or governed coordination. The three-tier architecture under Provisional 64/049,409 makes each tier independently deployable: each tier provides governance-credentialed observation coverage of a navigable region without requiring deployment of the subsequent tier. A region with only Tier 1 markers delivers signed static geometry to operating units; adding Tier 2 sentinels overlays live deviation observations; adding Tier 3 agents adds aggregation, coordination, and forecasting. The provisional discloses sub-configurations in which any proper subset of the tiers, or any two-tier combination, or all three tiers, is present, each independently deployable.
Prior passive-marker and tag-and-reader schemes provide an un-credentialed identifier or a relay-point code for look-up against a remote database, and constitute only a single-tier architecture. The disclosure here instead unifies marker-borne static authority, sentinel-borne live deviation observation, and agent-borne composite observation as independently deployable, progressively composable tiers, with every observation authority-credentialed, lineage-linked, and composite-admissibility-evaluable through the common governance chain.
Disclosure Scope
The disclosure under U.S. Provisional Application No. 64/049,409 covers the three-tier environmental device architecture and its independently deployable tiers, the passive environmental marker, active environmental sentinel, and cognitive infrastructure agent primitives, the inter-tier composition through the governance chain, the authority-credentialed device communication model and its governance-configurable authority taxonomy, the credentialing lifecycle of issuance, renewal, revocation, transfer, suspension, downgrade, and escalation, the aggregation of governed observations by cognitive infrastructure agents with lineage to contributing observations, the hierarchical aggregation of such agents, the partial-coverage sub-configurations and the confidence-governor behavior under transitions between deployment regions, and the cross-authority boundary translation across jurisdictions.
Implementations across radio, optical, contact, and printed physical layers are within scope, as are aggregation patterns ranging from single-node Tier 3 agents to redundant clusters and federated multi-authority meshes. The licensing posture treats the tier separation and its cryptographic governance as the licensable primitive; specific physical-layer or radio-stack choices are left to implementers and are not the subject of restriction.