Protocol Architecture: XAP and VEMP
Two patent application families defining two protocol categories. The Execution Authority Protocol (XAP / AMIAP) family governs runtime authorization of autonomous machines; the Verifiable Enterprise Messaging Protocol (VEMP) family governs pre-decryption admission of encrypted communications. Each family includes a parent application and a continuation that closes the design-around perimeter.
XAP defines a new protocol category that occupies the layer between access being granted and the operation actually executing. An autonomous machine is governed against runtime conditions at the time each operation is requested, with machine integrity validated at time of use rather than at enrollment. Each decision is bound to a cryptographic record that an independent third party can verify without access to the enforcement system. The category is complementary to authentication, access authorization, and channel security.
The continuation specifies how XAP category membership applies when governance is performed by cooperating distributed components rather than a single point. It establishes a verification standard that holds regardless of how many components participate, how their outputs are denominated, or whether they are operated by different entities in different administrative domains. The detailed structural requirements that make this rigorous are set out in the filed claims and made available to qualified evaluators under NDA.
The Parent defines the category. The continuation extends it to the distributed enforcement topologies real production deployments use. Prosecution of each application is insulated from the other through a prosecution history firewall.
VEMP defines a new protocol category that occupies the layer between message delivery and content access. A communication object is delivered into a first communication plane carrying a structured message authority artifact; admission into a controlled second communication plane requires evaluation of artifact-bound preconditions before any decryption occurs. State machine advancement, cryptographic profile compliance, lineage-bound constraint propagation, and post-release revocation are all enforced at the protocol level. The category is distinct from S/MIME and OpenPGP, TLS, secure email gateways, information rights management, secure portal architectures, and zero-trust network access — each governs a distinct function at a distinct point in the communication lifecycle.
The continuation specifies how VEMP category membership applies across alternative key-management and governance-record architectures. Three architectural patterns are addressed: (i) protected execution boundaries implemented through cloud-hosted key management services or trusted execution environments rather than hardware security modules; (ii) communication governance state machines implemented with reduced state counts or through policy evaluation mechanisms equivalent to a formally named multi-state machine; and (iii) governance records implemented as a plurality of cooperating signed data structures rather than a single binary artifact. The continuation preserves the core governance relationships across diverse implementation architectures.
The VEMP Parent defines the category. The Admission Before Decryption continuation extends it across alternative key-protection and governance-record architectures. Prosecution of each application is insulated from the other through a prosecution history firewall.