CAIN-42 Evolution 28 — Portable Execution Identity

TESTED library · not hosted · not third-party reviewed · ephemeral keys.

Any agent can connect and receive a signed, portable execution identity. Identity travels; authority does not: every receiving domain recomputes authority, every model/runtime change invalidates it until re-evaluated, and every allowed action goes through the E8 Action Commit boundary and leaves a signed receipt.

Invariants 90/90; adversarial scenarios 442/442 contained; mutation 9/10 killed (survivor explained: replay_cache_off); conformance 17/17; tests 11 passed / 0 failed; clean-room verifier INTACT (243/243).

End-to-end proof

StepResult
EXTERNAL_AGENTOK
CAIN_CONNECTOK
PORTABLE_EXECUTION_IDENTITYOK
BOUNDED_AUTHORITYOK
DELEGATED_SUBAGENTOK
MODEL_RUNTIME_CHANGEOK
REAUTHORIZATIONOK
GOVERNED_ACTIONOK
E8OK
MCP_A2A_APIOK
EXECUTIONOK
SUBAGENT_BOUNDEDOK
GOVERNANCE_RECEIPTOK
INDEPENDENT_VERIFICATIONOK
REVOCATIONOK
FAILED_REPLAYOK

Adversarial categories

CategoryContained
identity75/75
delegation53/53
replay_fork55/55
cross_domain50/50
model_runtime_substitution50/50
credential50/50
memory_identity_confusion51/51
protocol_boundary58/58