<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 4.0.6) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC5280 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.5280.xml">
<!ENTITY RFC3161 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.3161.xml">
]>


<rfc ipr="trust200902" docName="draft-somaratne-scitt-stc-stp-00" category="info" submissionType="IETF">
  <front>
    <title abbrev="STC and STP for SCITT">Sovereign Tensor Container (STC) and Provenance (STP) Specifications</title>

    <author initials="C." surname="Somaratne" fullname="Chamara Somaratne">
      <organization>Sovereign Stack Global</organization>
      <address>
        <email>chamara@anthosa.com</email>
      </address>
    </author>

    <date year="2026" month="August" day="28"/>

    <area>Security</area>
    <workgroup>SCITT Working Group</workgroup>
    <keyword>Internet-Draft</keyword>

    <abstract>


<?line 32?>

<t>This document defines the Sovereign Tensor Container (STC-1.0) and Sovereign Tensor Provenance (STP-1.0) specifications. STC-1.0 establishes a strict 64-byte physical memory alignment standard for binary machine learning tensor payloads to enable zero-copy Direct Memory Access (DMA). STP-1.0 defines an embedded cryptographic provenance framework utilizing C2PA profiles, X.509 signature chains, and SCITT-compatible attestations to secure supply-chain integrity for distributed AI models.</t>



    </abstract>



  </front>

  <middle>


<?line 36?>

<section anchor="introduction"><name>Introduction</name>

<t>The proliferation of large neural networks has exposed severe fragmentation in model distribution and supply-chain security. Existing container formats rely on out-of-band metadata files and arbitrary-length headers, which force unaligned memory access during host-to-device transfers and break cryptographic provenance chains upon redistribution.</t>

<t>This document proposes an architectural framework to secure the AI supply chain by embedding Supply Chain Integrity, Transparency, and Trust (SCITT) principles directly into the tensor payload container. The foundational architecture is published under Zenodo <xref target="STC-ZENODO"/>.</t>

</section>
<section anchor="stc-10-memory-alignment-architecture"><name>STC-1.0: Memory Alignment Architecture</name>

<t>To achieve true zero-copy Unified DMA, STC-1.0 dictates a hermetic binary container utilizing strict 64-byte physical cache-line alignment.</t>

<t>All metadata preceding the tensor payload MUST be dynamically padded. Runtimes MUST apply the following mathematical constraint to calculate the padding length (in bytes) before the payload initiates:</t>

<t><spanx style="verb">padding = (64 - (length (mod 64))) (mod 64)</spanx></t>

<t>This alignment ensures execution runtimes can <spanx style="verb">mmap</spanx> the artifact and dispatch it directly to the GPU without CPU byte-shifting.</t>

</section>
<section anchor="stp-10-cryptographic-provenance-trust-block"><name>STP-1.0: Cryptographic Provenance (TRUST Block)</name>

<t>The STP-1.0 specification defines a mandatory <spanx style="verb">TRUST</spanx> block within the STC header structure. This block acts as a cryptographic execution gate for inference engines.</t>

<section anchor="c2pa-and-x509-integration"><name>C2PA and X.509 Integration</name>

<t>The <spanx style="verb">TRUST</spanx> block MUST contain:</t>

<t><list style="numbers" type="1">
  <t>An AI-specific C2PA manifest <xref target="C2PA"/> detailing training data lineage and synthetic token ratios.</t>
  <t>An X.509 certificate chain <xref target="RFC5280"/> binding the artifact to a verified developer identity.</t>
  <t>An absolute SHA-256 payload hash of the aligned tensor bytes.</t>
</list></t>

</section>
<section anchor="scitt-attestation"><name>SCITT Attestation</name>

<t>By embedding these cryptographic claims natively, the STC artifact functions as a self-contained Statement for a SCITT Transparency Service. Inference runtimes SHOULD verify the X.509 signatures and payload hash against a trusted SCITT ledger before allocating VRAM.</t>

</section>
</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<t>Traditional ML checksums are easily spoofed during man-in-the-middle redistribution, leading to weight poisoning. STP-1.0 mitigates this by mandating cryptographic signature verification at the engine level. A compromised private key could allow an attacker to sign a poisoned model; therefore, short-lived certificates and Time-Stamp Protocol (TSP) <xref target="RFC3161"/> integration are strongly recommended.</t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<t>This document requests the registration of a new media type, <spanx style="verb">application/vnd.stc</spanx>, to identify Sovereign Tensor Container artifacts.</t>

</section>


  </middle>

  <back>


<references title='References' anchor="sec-combined-references">

    <references title='Normative References' anchor="sec-normative-references">

&RFC5280;
&RFC3161;
<reference anchor="C2PA" target="https://c2pa.org/specifications/specifications/1.3/specs/C2PA_Specification.html">
  <front>
    <title>C2PA Technical Specification</title>
    <author >
      <organization></organization>
    </author>
    <date year="n.d."/>
  </front>
</reference>


    </references>

    <references title='Informative References' anchor="sec-informative-references">

<reference anchor="STC-ZENODO" target="https://doi.org/10.5281/zenodo.22120344">
  <front>
    <title>Sovereign Tensor Architecture: A Unified Open Standard</title>
    <author >
      <organization></organization>
    </author>
    <date year="n.d."/>
  </front>
</reference>


    </references>

</references>



  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA4VXYW/bNhD9rl9xyL7EQKQ4bht0HgbMc7quQLMGtbsN+7LQ
Em0RoUiNpJKpRf/73pGyFafr9qGFI5G847v33p3yPM+CClrO6WRl76WTamdo
LY23jpbWBKGMdHS6Wi8nJExFNw6rjDCl5Ic3E1q1slRbVYqgrPEnmdhsnLzn
49bLuAOraIvTVss36/VJVtnSiAbxKie2Ife2EU4EI3NfqoC/Q4l/bT6dZpUI
WDabzi7z6ct89jJDDLmzrp+TMlub+W7TKO8Rdt23WPnm1fqnLFOtm1NwnQ+z
6fTb6SwTToo5rWTZORX67MG6u52zXTtPGdFveKDMjl7zw+xO9lhR4TQTpDMy
5FecZ5aJLtTWzTOiHOH9nJYFrfbJ4ylRutayFvzwyTvrdoh3AHgVRHlHr7Xd
CB3fy0YoPacybf5BGATzoihtk2XGugbo3ksO/v6n5YvZy+nw89nF5QX/XM5u
FvN40L6Y/AR1LGuD0ujjKp2klcLtZMDSOoTWz8/Py1krCiR67o9K+vTPi+JZ
fOTPOcafRycXdWj0ScbleZQzmJD/8eqXd1fvjnP8gnALV9YqyDJ0Du8X9MHg
ZFnRu1ZGzEwlXPWV7CurYvIX0wIAXZx/lMZWtpjNLmbTZ8+fn2Q5qM7/kdj4
4ESJmq5r5QmE7BppAlVyC7J7CrWk/9FCflFMkx6+WPhEIGnlMYQFDUeQ9EFs
tPI1wgpCWqoMdPk83/RBUlv3PhavkQ1YT0IjTMzUD1BEXW2UEXjbCGBnJGkp
nGE+h5RPK3ptRYVrWUJeGy3po3Q2L23b05VyQJuuU4BFWUrv6fTqejHhHGPy
B1iEAUs3sqpQkNL1bbA7J9paldSOV946iIAlRl1QWn3kRCIVsWartPRn9Hvx
YvotedxFcJ2Z89DTWUKTFYnUmhZIcaoiBMYowsY38CxjSb5rW93ncSvUCFtg
bUc4KsUwbrqANBdvqLGV1L5IlW9UVWmZZd+wup2tupIPZh5ITlCrrXQxFtkt
aWYYGdk5lABGwLfyVAtP8u/WehzvJdee77zjsqSdSCjGHBPhp3y5o6T94EcF
vfobCxmn8kCxpB5PTuqeOJsu5Habb/iURgYBZxQU4YwHC7dRYLTrcy3NLtRU
S1FJB0wfUJ6aj0NpOhMJJKsDn1K5K+SB6PCbkAebV/JeYTXOMx5wpAiwdHH3
9aqnElLXIlcnH1+8eCoy7GLwIp3EKHdAPFJnrDNLEUVMyKUwtOkHHnLWq/Rm
Gd+82RPhjNacfgvrN2WfqLXmlgBJMsMmSEOZUrWMYBU1gEPAIxsjHitnrEtB
TJSt7SA+vhySfnQFSbhn2yU5V4AbJaA/ogvRp0+jB37+XDADBwuYH8R3UPdj
FwR8lljZoBp3tcfi3bsj5Hp2cJQKDoI2yXZSSweyoFKDQ4z8GrX5NcspEVPm
mg3lYDtIe6H1SMAWuMlYhX8B7frDak0bSVWPtshHAuBWsHkU9L4zQTXIMS4S
sYIhIqu1feADwf5acgOJuUD7oCPKw8zAk7LTuGLcwkfyhoH4p5EfuP4EsUH7
/aKUkzIqKAZnnmW3+53f0+nlc/T00/0RUC/wmEwmh5+3A4lHA8ZdURx2AvA0
Ctzt71SC2LdNI9rbGFu4oLZoNpGDUAaMDYpUYaTdQLrXNx/oQaHtd4GW+M3X
yH2ttuwNA2NuEmOWRzp83HDW7xnRH7Ut7ybJ1vYuftSBRk8H0kxmJuBt3HxL
G94dUwGYsRdikEuOwnTpIi9ZCkAkrcX1cBSfduwQIzo7rhe7MyYDyaKUgHDH
KfDNvkktghFKzSEJWYzmfJxbpM3AZpTyoqCFgU3k+zum43Az+Dk0/+kT//35
M26NHToSlunEPyKRmeYCXh9NusfoFVUT7B2mjpgFspzFICm9UnJRGcvB+hBi
mMsQBWo7iOJQfRRZELpFUiw8VmrbAlBVgU7cBrJnMQBmE6vRu2j18yKfvbg8
cBd9p+auFE8dfHyQXCR8wjFNtIuxaWbZj4/tEru9fFKlUgvVeEyvPK5puOW+
5ofkt50pUweORfZSb/O9mVQ8lwUZVcEFFkMOjw0Yw7fjplKgsPvyH/Sy+vnd
h7dXCZtkA08GhNSBjnAQO+430FQa9OUwOMAFqh1AHaQPz7HMd9z71/eL66Sh
oe3yPOcBfiKZB8ucqNRg6tdvUVZZ3vkOuOAKJIVXUKpvrd1y+VLHBMFyZXKk
nKfB4knvO+NZLMFu6QEzYo32Z5W3zLxxvmoQdhctO0RJ9YMm40hwVKlxZkpM
GsQsQoQtCQoxUUVwiXiKchZfSMgY7e6e2YqvGzzvdBXBeYhNOPC3CFDjrstz
rBiS5EGBB5nv+HQXIT0jj2+ggL5wz0PgKINUozUKmoMOTcumFGxpNSxphY/E
qA/+WIE+1CjuCC4As2YHeOGHtgGRuEfEGW3xy+LLOh1NE07+1YHqaWZ3csfo
HwY4gantAe2qUuAJvhDP6JZ7zQDb+b2pCnxt3p7xzZMOQcD/GPz3eoDW/gHV
KQUgNw8AAA==

-->

</rfc>

