[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82089-en":3,"doc-seo-82089-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82089,1374391975076,"Riley","https://ap-avatar.wpscdn.com/avatar/14000253ca4ec9f6853?x-image-process=image/resize,m_fixed,w_180,h_180&k=1783305029341752051",8,"Research & Report","Proof-of-Continuity: A Temporal Model for Authority Propagation in Distributed Systems and AI Agents","Proof-of-Possession authorization models derive authority from artifacts like tokens, credentials, and capabilities, yet fail to ensure that discrete execution chains preserve the causal relationship from request origin to later authority use. This paper introduces Proof-of-Continuity for the Provenance Identity Continuity (PIC) model, requiring each execution step to remain causally linked and to propagate only a non-expansive subset of received authority. It adds Proof of Relationship as a single-hop causal primitive whose composition yields Proof-of-Continuity. The confused-deputy condition cannot arise as valid behavior under this model.","arXiv :2607 .08906v 1 [ cs .CR] 9 Jul 2026  \nProof-of-Continuity: A Temporal Model for Authority Propagation in Distributed Systems and AI Agents  \nNicola Gallo  \n8 July 2026  \nAbstract  \nProof-of-Possession authorization models derive authority from the possession of artifacts such as tokens, credentials, or capabilities. This paper argues that possession is insufficient for discrete execution chains, whether they span multiple services or occur as separated steps within the same machine, because it does not guarantee preservation of the causal relationship between the origin of a request and the authority exercised at later steps. We introduce Proof-of-Continuity, a minimal authority-propagation discipline for the Provenance Identity Continuity (PIC) model, in which each execution step must be causally linked to the previous step and may only propagate a non-expansive subset of the authority received from the origin. It introduces Proof of Relationship, a single-hop causal primitive whose transitive composition is Proof-ofContinuity; these complement Proof-of-Possession rather than replace it. Under this model, the confused deputy condition cannot be satisfied as valid model behavior: any privilege exercised at a later step must already be present in the origin authority context. This is directly relevant to distributed systems and AI agents, where executors invoke tools and downstream services while holding multiple authority sources, so that the same authority/causality mismatch recurs across service boundaries. Under Proof-of-Continuity these sources may be carried together but are never merged into a combined authority, since each step is authorized only against the authority context of the lineage that caused it.  \nThis paper concerns authorization propagation rather than authentication: identity and authentication mechanisms such as OIDC, verifiable credentials, wallets, and workload identity remain complementary mechanisms for establishing the origin, while Proof-of-Continuity addresses how authority propagates after that origin exists.  \n1 Model  \nWe formalize the PIC (Provenance Identity Continuity) Model as follows.  \nLet P be a finite set of principals, O a set of operations, and R a set of resources. Define a privilege as (o, r) ∈ O × R.  \nEach principal p has an associated privilege set:  \nPriv (p) ⊆ O × R.  \nA principal is used here as an abstract permissioned entity: it maybe a human identity established through an identity provider, wallet, OIDC/OIDC4VC-style flow [13, 14], or decentralized identifier [15]; a workload or machine identity such as those used in WIMSE/SPIFFE-style environments [11, 12]; a role; a service account; or another authenticated permissioned entity. What matters for this model is that a privilege set Priv (p) is associated with it and that it can express an intent within those privileges. When a permissioned entity p expresses such an intent, it selectsa subset of Priv (p); that subset becomes the origin authority context C0 ⊆ Priv (p) for a new execution lineage. The privileges in Priv (p) maybe expressed at the level of operations the principal is entitled to cause, not only those it performs directly; a downstream hop may realize such an authority through a locally different operation vocabulary via the policy translation T of Section 5 .  \nFor example, suppose Bob holds the privileges (read, Book) and (write, Book) . When Bob expresses an intent he selects a subset—say only (write, Book)—and that subset becomes the origin authority context C0 of a new lineage. Two executions may both involve Bob and the same selected privilege, yet need not be the same occurrence: each carries authority propagated along its own lineage. One may be a valid continuation of an intent Bob expressed within a lineage; another may be an unrelated execution exercising the same apparent privilege outside the lineage that granted it. The identity and privilege coordinates may be identical; the lineage coordin","cbCaigX93BMluPtj","https://ap.wps.com/l/cbCaigX93BMluPtj","pdf",279202,1,23,"English","en",105,"# Abstract\n# Model\n## PIC Model\n# Threat Model and Scope","[{\"question\":\"What problem does Proof-of-Continuity address in Proof-of-Possession authorization models?\",\"answer\":\"It addresses the lack of guarantees that discrete execution chains preserve the causal relationship between the request origin and the authority exercised later, especially across service boundaries or within separated steps on the same machine.\"},{\"question\":\"How does the PIC model enforce authority propagation under Proof-of-Continuity?\",\"answer\":\"Each execution transition must preserve causal continuity using Proof of Relationship and must restrict authority monotonically, requiring the next context to satisfy Ci+1 ⊆ Ci for every hop.\"},{\"question\":\"What does the PIC Safety result imply about privileges exercised at later execution steps?\",\"answer\":\"If the PIC Model holds, no execution step can exercise any privilege that was not present in the origin authority context, because the final context is always a subset of the origin context.\"}]",1784178155,58,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"proof-of-continuity-a-temporal-model-for-authority-propagation-in-distributed-systems-and-ai-agents","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/proof-of-continuity-a-temporal-model-for-authority-propagation-in-distributed-systems-and-ai-agents/82089/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What problem does Proof-of-Continuity address in Proof-of-Possession authorization models?","Question",{"text":74,"@type":75},"It addresses the lack of guarantees that discrete execution chains preserve the causal relationship between the request origin and the authority exercised later, especially across service boundaries or within separated steps on the same machine.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does the PIC model enforce authority propagation under Proof-of-Continuity?",{"text":79,"@type":75},"Each execution transition must preserve causal continuity using Proof of Relationship and must restrict authority monotonically, requiring the next context to satisfy Ci+1 ⊆ Ci for every hop.",{"name":81,"@type":72,"acceptedAnswer":82},"What does the PIC Safety result imply about privileges exercised at later execution steps?",{"text":83,"@type":75},"If the PIC Model holds, no execution step can exercise any privilege that was not present in the origin authority context, because the final context is always a subset of the origin context.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":105,"slug":137},19,"General","general"]