Technical report / Version 1
A Challenge-Bound Memory-Consistency Predicate for Model-Key Release
OPAQUE Systems
Abstract
A key broker that gates model-key release on attestation checks code identity. It does not see how a designated memory region behaves while the release request is in flight. We describe a supplementary predicate implemented in Weight Custody Manifest. A runtime derives page-specific values and two traversal orders from a secret and the broker's challenge, writes every logical page, reads every page back, and signs a transcript of declared geometry, page counts, a readback commitment and a mismatch flag. The broker accepts the transcript only if it carries the current challenge, reports no mismatch and verifies under a pinned key, in addition to its existing release policy. At a pinned revision, 35 local tests across the memory sweep and broker modules passed on September 4, September 27 and October 1, 2026. A controlled aliased adapter yields an authentic negative transcript, which shows why signature verification and release approval have to be separate checks. We also analyze a retained 256 MiB protected-guest receipt without treating it as a fresh end-to-end key-release experiment. The predicate gives a bounded observation over a declared logical range. It does not prove full model-memory coverage, defeat a physical-owner attack or establish that memory stays unchanged after the check.
What this report contributes
A supplementary key-release predicate: a challenge-bound, signed write/read sweep of a declared memory range, accepted only when fresh, mismatch-free and signed by a pinned key.
Evidence and limits
- Software-only. At Weight Custody Manifest revision 2acedfa, 35 memory-sweep and broker tests passed on September 4, September 27 and October 1, 2026. No hardware quote chain or physical attack was exercised.
- The 256 MiB protected-guest figure comes from a receipt retained from August 27, 2026. That hardware run was not repeated and is not a fresh end-to-end key-release experiment.
- The predicate observes a declared logical range only. It does not prove full model-memory coverage, defeat a physical-owner attack, or show that memory stays unchanged after the check.
The source package preserves the recorded inputs and results. Tests and probes were rerun at the pinned revision on October 1, 2026 in a fresh environment. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Imran Siddique. A Challenge-Bound Memory-Consistency Predicate for Model-Key Release. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026challengeboundmemorysweep,
title = {A Challenge-Bound Memory-Consistency Predicate for Model-Key Release},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23091290},
url = {https://agentrust-io.com/research/challenge-bound-memory-sweep/v1/}
}
Version history
Version 1, October 1, 2026: First public edition. Revises a manuscript dated September 4, 2026; tests and probes were rerun on September 27 and October 1, 2026 and compared with main of September 30.
Revises a manuscript dated September 4, 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.