Technology

Protocol Architecture: XAP and VEMP

Two patent application families defining two protocol categories. The Execution Authority Protocol (XAP / AMIAP) family governs runtime authorization of autonomous machines; the Verifiable Enterprise Messaging Protocol (VEMP) family governs pre-decryption admission of encrypted communications. Each family includes a parent application and a continuation that closes the design-around perimeter.

Diagram of the security stack showing four layers: Identity and Integrity, Authorization, XAP (highlighted as a new category for execution authority), and Operation. XAP evaluates each operation at execution time and produces a cryptographic record an independent party can verify. The diagram is annotated with the five category principles: execution-time evaluation, integrity at time of use, decision bound to evidence, proof of authorization, and proportional response.
Figure 01 Where XAP sits in the security stack. The execution authority layer operates above session-time authorization and below the operation itself, evaluating constraints per operation and producing a record an independent party can verify.
AM
XAP PARENT · YH-AMIAP-001
Autonomous Machine Identity & Authority Protocol · Filed March 2026
The Gap XAP Addresses
Identity providers authenticate machine entities. Access control systems decide whether an entity may access a resource at session establishment. Policy engines distribute rule sets. Audit and SIEM systems record events. Hardware attestation (TPM, TEE) validates platform integrity at enrollment. Each of these is solved, and each is necessary. None of them evaluate whether a specific operation should execute at the moment it is requested, against the current state of the machine, and produce a cryptographic record that an independent party can reproduce. A credential valid at issuance may be invalid at execution due to posture change, zone drift, or environmental compromise; the existing stack has no enforcement point that notices.

XAP defines a new protocol category that occupies the layer between access being granted and the operation actually executing. An autonomous machine is governed against runtime conditions at the time each operation is requested, with machine integrity validated at time of use rather than at enrollment. Each decision is bound to a cryptographic record that an independent third party can verify without access to the enforcement system. The category is complementary to authentication, access authorization, and channel security.

What the Parent Establishes
The Parent application establishes the XAP category and its defining properties: per-operation evaluation at the moment of execution, integrity evidence at time of use, cryptographic binding of decisions to runtime evidence, and an independent verification path that does not require access to the enforcement system. The category is designed to be algorithm-agnostic, preserving its verification properties across classical, hybrid, and post-quantum deployments. Specific claim language is held in the filed application and made available to qualified evaluators under NDA.
CN
CONTINUATION · YH-AMIAP-CON-1 · IMPLICIT DERIVABILITY
AMIAP Continuation — Implicit Derivability · Filed April 2026
The Distributed Enforcement Reality
Production enforcement is never monolithic. Different components — gateways, sidecars, host-level agents, signing services, audit logs — perform different parts of governance, often procured from different vendors, operated by different teams, in different administrative domains. Distributed tracing systems (OpenTelemetry, Jaeger) correlate spans across service boundaries but do not produce outputs designed for independent verification of authorization decisions. SIEM aggregates log records without ensuring the aggregated outputs meet a verification standard. A protocol category whose scope does not account for distributed enforcement would fail to match the systems it is designed to govern.

The continuation specifies how XAP category membership applies when governance is performed by cooperating distributed components rather than a single point. It establishes a verification standard that holds regardless of how many components participate, how their outputs are denominated, or whether they are operated by different entities in different administrative domains. The detailed structural requirements that make this rigorous are set out in the filed claims and made available to qualified evaluators under NDA.

Distributed Enforcement Topologies Covered
The category covers the enforcement topologies real production deployments use, including gateway-and-host architectures, CI/CD pipeline governance, multi-domain federation across administrative boundaries, serverless and event-driven execution, and resource-constrained environments. Architectural details and verification procedures are set out in the filed application and made available to qualified evaluators under NDA.
XAP FAMILY · PARENT + IMPLICIT DERIVABILITY CONTINUATION
The Execution Authority Protocol (XAP) Category

The Parent defines the category. The continuation extends it to the distributed enforcement topologies real production deployments use. Prosecution of each application is insulated from the other through a prosecution history firewall.

Communication Governance Family — VEMP
VE
VEMP PARENT · YH-VEMP-001
Verifiable Enterprise Messaging Protocol · Filed March 2026

VEMP defines a new protocol category that occupies the layer between message delivery and content access. A communication object is delivered into a first communication plane carrying a structured message authority artifact; admission into a controlled second communication plane requires evaluation of artifact-bound preconditions before any decryption occurs. State machine advancement, cryptographic profile compliance, lineage-bound constraint propagation, and post-release revocation are all enforced at the protocol level. The category is distinct from S/MIME and OpenPGP, TLS, secure email gateways, information rights management, secure portal architectures, and zero-trust network access — each governs a distinct function at a distinct point in the communication lifecycle.

Pre-decryption admission
Evaluation before any key release
Authorization preconditions evaluated before decryption keys are released to any recipient process.
State machine governance
Multi-state communication lifecycle
Formal communication state machine with artifact-bound state-transition validation logic enforced at each transition.
Lineage propagation
Constraints follow derived communications
Replies, forwards, and AI-agent-derived communications are cryptographically bound to the constraints of the parent communication object.
Post-release revocation
Bounded enforcement latency
Decryption-key invalidation within a protected-boundary key management service, architecturally independent of recipient endpoint behavior.
AB
CONTINUATION · YH-VEMP-CON-1 · ADMISSION BEFORE DECRYPTION
VEMP Continuation — Admission Before Decryption · Filed April 2026

The continuation specifies how VEMP category membership applies across alternative key-management and governance-record architectures. Three architectural patterns are addressed: (i) protected execution boundaries implemented through cloud-hosted key management services or trusted execution environments rather than hardware security modules; (ii) communication governance state machines implemented with reduced state counts or through policy evaluation mechanisms equivalent to a formally named multi-state machine; and (iii) governance records implemented as a plurality of cooperating signed data structures rather than a single binary artifact. The continuation preserves the core governance relationships across diverse implementation architectures.

VEMP FAMILY · PARENT + ADMISSION BEFORE DECRYPTION CONTINUATION
The Pre-Decryption Admission Control Category

The VEMP Parent defines the category. The Admission Before Decryption continuation extends it across alternative key-protection and governance-record architectures. Prosecution of each application is insulated from the other through a prosecution history firewall.