System and method for generating a crypto-graphically verifiable governance execution certificate as a structural output of a non-bypassable AI architecture

GB2704202APending Publication Date: 2026-08-26AIGUARD SYSTEMS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
GB2026007087
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-03-29
Publication Date
2026-08-26

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A cryptograhpically verifiable Governance Execution Certificate (GEC) is generated as a structural output of a non-bypassable AI output execution-control architecture. The GEC contains a hash 106 of
Need to check novelty before this filing date? Find Prior Art

Claims

Claim 11. A computer-implemented system for generating a cryptographically verifiable Governance Execution Certificate as a structural output of a non-bypassable Al output execution-control architecture, the system comprising: a certificate generation component configured to generate a signed Governance Execution Certificate (GEC) only upon receipt, via an authenticated internal interface that rejects requests from any component outside an authorised set of internal components of the execution-control architecture, of a completed execution permission having an execution state of ALLOW or MODIFY, wherein the completed execution permission is generated by a control component of the execution-control architecture that evaluates a candidate Al output against runtime governance parameters including at least a confidence parameter, a consequence parameter, and a user state parameter, and wherein the response generation component of the execution-control architecture is structurally prevented from invoking the certificate generation component directly; wherein the certificate generation component, upon receipt of a completed execution permission having an execution state of ALLOW or MODIFY, constructs a GEC object comprising at least a reference identifier corresponding to the completed execution permission, a cryptographic hash of the output as prepared for delivery, the governance parameters applied, and an execution decision field, applies a deterministic canonical serialisation process to the GEC object fields excluding the signature field to produce a canonical byte sequence, and obtains a cryptographic signature over that canonical byte sequence from a hardware-protected key management facility in which a private signing key is stored without being exposed in plaintext outside the hardware boundary; a certificate retention component configured to retain signed GEC objects in retrievable form and to return a retention confirmation upon successful retention, the retention component exposing a retrieval interface by which an external party can obtain a retained signed GEC by certificate identifier; and a delivery control component configured to: (i) permit delivery of the output as prepared for delivery only where the completed execution permission has an execution state of ALLOW or MODIFY and a retention confirmation has been received from the certificate retention component within a defined timeout period; (ii) include a certificate reference identifier in a delivery payload accompanying the delivered output; and (iii) where a retention confirmation is not received within the defined timeout period, independentlydetermine that the delivery precondition has not been met and block delivery without requiring an explicit failure notification from the certificate generation component, and record a failure event in an immutable audit log comprising at least the execution permission identifier, a timestamp, a failure reason, and a candidate output reference; wherein successful generation and retention of the signed GEC within the defined timeout period are mandatory preconditions to delivery, such that no output is delivered unless a retrievable signed GEC is available through the retrieval interface.Claim 22. A computer-implemented system for generating a machine-verifiable Al output governance record as a structural output of a non-bypassable Al output execution-control architecture, the system comprising: a certificate generation component configured to receive, via an authenticated internal interface inaccessible to components outside an authorised set of internal components of the execution-control architecture, a completed execution permission having an execution state of ALLOW or MODIFY generated by a control component that has evaluated a candidate Al output against runtime governance parameters, together with a set of governance parameters including at least a confidence parameter, a consequence parameter, a user state parameter, and an accessibility compliance indicator, and a cryptographic hash of the output as prepared for delivery; wherein the certificate generation component constructs a Governance Execution Certificate (GEC) object comprising mandatory fields including: a unique certificate identifier; a reference identifier to the completed execution permission; the cryptographic hash of the output as prepared for delivery; the confidence parameter value and confidence band classification; the consequence parameter classification; a hash of the user state parameter bundle; the execution decision; an accessibility policy reference and a boolean accessibility compliance indicator; a policy version identifier; a timestamp; an issuer identifier; and a cryptographic signature computed over a deterministic canonical serialisation of all other fields using a signing key held in a hardware-protected key management facility; wherein the deterministic canonical serialisation process produces a canonical byte sequence that is reproducible by an independent verifier from the same field values, such that any two conforming implementations produce byte-for-byte identical output; a certificate retention component configured to retain signed GEC objects in retrievable form and to return a retention confirmation upon successful retention within a defined timeout period, such that delivery of the output as prepared for delivery is conditioned on receipt of that retention confirmation; and a verification-key publicationinterface configured to publish the issuer’s public verification key at a well-known network-accessible endpoint, thereby enabling independent third-party verification of signed GEC objects without access to internal components of the system.Claim 33. A computer-implemented method for generating a cryptographically verifiable Governance Execution Certificate as a structural output of a non-bypassable Al output execution-control architecture, the method comprising: receiving, by a certificate generation component via an authenticated internal interface that rejects requests from any component outside an authorised set of internal components of the execution-control architecture, a completed execution permission having an execution state of ALLOW or MODIFY generated by a control component that has evaluated a candidate Al output against runtime governance parameters including at least a confidence parameter, a consequence parameter, and a user state parameter, together with those governance parameters and a cryptographic hash of the output as prepared for delivery; constructing a Governance Execution Certificate (GEC) object comprising fields recording the governance parameters, a reference identifier corresponding to the completed execution permission, the execution decision, and the cryptographic hash of the output as prepared for delivery; applying a deterministic canonical serialisation process to the GEC object fields excluding the signature field to produce a canonical byte sequence reproducible by an independent verifier; obtaining a cryptographic signature over the canonical byte sequence from a hardware-protected key management facility; retaining the signed GEC object in retrievable form and receiving a retention confirmation; including a certificate reference identifier in a delivery payload accompanying the delivered output only after receipt of the retention confirmation; permitting delivery only where the completed execution permission has an execution state of ALLOW or MODIFY and the retention confirmation has been received within a defined timeout period; and where signature generation, retention, or communication with the certificate retention component fails within the defined timeout period, independently determining that the delivery precondition has not been met, blocking delivery without requiring an explicit failure notification, and recording a failure event comprising at least the execution permission identifier, timestamp, failure reason, and candidate output reference; wherein no GEC is generated where the completed execution permission has an execution state of DEFER or SUPPRESS.Claim 44. A computer-implemented system for controlling downstream processing of an Al-generated output received from an external source, the system comprising: an ingestion component configured to receive the Al-generated output together with a delivery payload containing a certificate reference identifier associated with the Al-generated output; a retrieval component configured to obtain, from a retrieval interface of an issuing system, a signed Governance Execution Certificate (GEC) identified by the certificate reference identifier; a verification component configured to retrieve a public verification key from a well-known network-accessible endpoint of the issuing system, apply a deterministic canonical serialisation process to the GEC fields excluding the signature field to produce a canonical byte sequence, verify a cryptographic signature over the canonical byte sequence using the retrieved public verification key, and compute a cryptographic hash of the received Al-generated output for comparison with an output hash field recorded in the GEC, wherein where the output hash depends on a canonical encoding or multipart ordering rule, the verification component retrieves or receives a hash profile reference identifying the encoding and hash-computation rules used at issuance and applies the same rules when recomputing the output hash; and a processing control component configured to permit automated downstream processing of the Al-generated output only when the cryptographic signature is valid, the computed cryptographic hash matches the output hash field recorded in the GEC, and an execution decision field recorded in the GEC indicates ALLOW or MODIFY; wherein the processing control component is further configured to reject, quarantine, or route to human review the Al-generated output where the certificate reference identifier is absent from the delivery payload, the signed GEC is unavailable from the retrieval interface, the cryptographic signature is invalid, the computed cryptographic hash does not match the output hash field recorded in the GEC, or the execution decision field does not indicate ALLOW or MODIFY.DEPENDENT CLAIMSClaim 55. The system of claim 1, wherein the response generation component is structurally prevented from initiating delivery without a completed execution permission having an execution state of ALLOW or MODIFY, and wherein the certificate generation component's authenticated internal interface does not include the response generation component's service identity in its caller allowlist.Claim 66. The system of claim 1, wherein the hardware-protected key management facility is a hardware security module conforming to FIPS 140 Level 3 or equivalent, and wherein the facility enforces a key usage policy permitting signing operations only when invoked by a certificate generation component via an authenticated caller identity.Claim 77. The system of claim 1, wherein the cryptographic signature is computed using the Ed25519 algorithm as specified in RFC 8032 or ECDSA with the P-256 curve and SHA-256 as specified in FIPS 186-4, and wherein the signature is encoded as a Base64url string as defined in RFC 4648.Claim 88. The system of claim 1, wherein the deterministic canonical serialisation process applied to the GEC object fields is the JSON Canonicalization Scheme as defined in RFC 8785, which sorts object keys in Unicode code point order, applies UTF-8 encoding throughout, and produces no whitespace outside string values, such that any two conforming implementations processing the same field values produce byte-for-byte identical canonical output.Claim 99. The system of claim 1, wherein the cryptographic hash of the delivered output is computed using SHA-256 as specified in FIPS 180-4 or SHA-3-256 as specified in FIPS 202, and is recorded in the output hash field as a hexadecimal string prefixed with the algorithm identifier.Claim 1010. The system of claim 1, further comprising a verification-key publication interface configured to publish the issuer's public verification key at a well-known network-accessible endpoint in a machine-readable format including JSON Web Key Set (JWKS) format as defined in RFC 7517, thereby enabling third-party verifiers to retrieve the public verification key without requiring access to internal components of the system.Claim 1111. The system of claim 1, further comprising a verification interface comprising at least one externally accessible API configured to receive a certificate object and generate a verification response comprising a signature validity indicator, an integrity indicator, a verification timestamp, and, where the delivered output is provided by the verifying party, an output hash match indicator.Claim 1212. The system of claim 2, wherein the GEC object comprises an accessibility policy reference field identifying the accessibility policy profile applied to the candidate output and a boolean accessibility compliance indicator, wherein the accessibility compliance indicator is produced by an accessibility evaluation engine that applies one or more evaluation rules derived from the policy profile to the candidate output and returns a boolean compliance result prior to execution-permission evaluation.Claim 1313. The system of claim 12, wherein the evaluation rules applied by the accessibility evaluation engine include one or more of: a reading level assessment against a defined Flesch-Kincaid grade level threshold; a language clarity check against plain language guidelines; a structural element check for required accessibility attributes; a sensory characteristic independence check; and a safe content check against vulnerability-aware content safety rules specified in the policy profile.Claim 1414. The system of claim 2, wherein the GEC object further comprises a transformation applied boolean field and a transformation reference field comprising a reference to a transformation record enabling retrieval of the unmodified candidate output where a transformation was applied prior to delivery, and wherein an unmodified representation of the candidate output is preserved in independent storage with an association maintained to the signed GEC.Claim 1515. The system of claim 1, wherein the retrieval interface exposes at least: a first endpoint retrieving a signed GEC by its unique certificate identifier; a second endpoint retrieving asigned GEC by its execution permission reference identifier; and a third endpoint accepting a certificate object and returning a verification response.Claim 1616. The system of claim 1, wherein the certificate generation component is deployed in a network segment that is inaccessible from the public internet and from the response generation component's network segment, with network policy enforcing that inbound connections are accepted only from network segments associated with members of the authorised set of internal components.Claim 1717. The method of claim 3, further comprising publishing the issuer's public verification key in JSON Web Key Set format at a well-known network-accessible endpoint, thereby enabling an external verifier to retrieve the public verification key and independently verify the signed GEC.Claim 1818. The method of claim 3, further comprising making available, together with the delivered output or via the retrieval interface, the signed GEC and, where the output hash depends on a canonical encoding or multipart ordering rule, a hash profile reference identifying the encoding and hash-computation rules used to compute the output hash, thereby enabling an external verifier to recompute the output hash from the delivered output and compare the recomputed output hash with the output hash field of the GEC.Claim 1919. The system of claim 1, wherein the certificate reference identifier included in the delivery payload comprises the unique certificate identifier of the signed GEC and a verification URL identifying the retrieval interface, and wherein the delivery control component is configured to populate said delivery payload only after receiving from the certificate retention component a retention confirmation identifying the unique certificate identifier of the retained signed GEC.Claim 2020. The system of claim 11, wherein the verification interface comprises a POST endpoint publicly accessible without authentication and configured to operate only on externally supplied certificate data, returning a verification response without exposing any information from the certificate retention component beyond the verification result.Claim 2121. The system of claim 1, wherein, where retention of the signed GEC is not confirmed within the defined timeout period, the delivery control component treats the completed execution permission as consumed but unconfirmed, retains the candidate output and associated execution permission for a configurable retry or manual-review period, and raises an operator alert indicating that a governed output could not be delivered because a retrievable signed GEC was not available.Claim 2222. The system of claim 1, wherein for non-text candidate outputs the output hash is computed as follows: for JSON-structured outputs, by applying a deterministic canonical serialisation process to the output object and computing SHA-256 over the resulting canonical byte sequence; for binary outputs, by computing SHA-256 over the raw bytes of the output as transmitted; and for multipart outputs, by computing SHA-256 over the concatenation of the component hashes in an order specified by the active policy profile; wherein the canonical encoding applied at issuance and at verification is consistent across independent implementations.Claim 2323. The system of claim 10, wherein the verification-key publication interface publishes public keys corresponding to all active and recently retired signing keys during a defined transition period, each public key being identified by a respective key identifier.Claim 2424. The system of any of claims 1,2 or 4, wherein the delivery payload comprises the signed GEC itself in addition to the certificate reference identifier, and wherein a recipient or downstream system is configured to verify the signed GEC received in the delivery payload without prior retrieval from the retrieval interface, while the issuing system independently retains the signed GEC in retrievable form for audit and re-verification.Claim 2525. The system of claim 4, wherein where the GEC comprises an expiry field and the current time exceeds the value of the expiry field, the processing control component treats the GEC as invalid for verification purposes and routes the Al-generated output to human10 review, notwithstanding that the cryptographic signature remains valid.T +44(0)30 0300 2000

Citation Information

Patent Citations

  • ViewUS2025/0371127A1onEspacenetopensinnewtab

  • ViewUS12592823B1onEspacenetopensinnewtab

  • ViewUS12602481B1onEspacenetopensinnewtab