This specification defines privacy-preserving interaction mechanisms for AI agents identified with did:atp. It has three parts: pairwise identifiers that prevent cross-relying-party correlation, selective disclosure of credential attributes via Merkle membership, and zero-knowledge range proofs that prove a numeric attribute lies in a range without revealing it.
These mechanisms let an agent prove what a relying party needs — that an attribute is a member of an issuer-attested credential, or that a value is within bounds — while disclosing nothing further.
This document is an early draft work product of the Agent Trust Protocol (ATP) Community Group. It is not a W3C Standard nor on the W3C Recommendation track. It is published to seek review and contribution from Community Group members.
The three mechanisms are at different maturities and are labelled accordingly below. Selective disclosure (Merkle membership) is implemented with deterministic known-answer vectors. Pairwise identifiers are implemented as an HKDF derivation. Zero-knowledge range proofs are implemented over Ristretto255 Pedersen commitments but are marked experimental; their construction and security review are an explicit ask to CG members.
As well as sections marked as non-normative, all authoring guidelines, diagrams, examples, and notes in this specification are non-normative. Everything else is normative.
The key words MUST, MUST NOT, SHOULD, and MAY are to be interpreted as described in BCP 14 [[RFC2119]] [[RFC8174]] when, and only when, they appear in all capitals.
A pairwise identifier is a per-peer, unlinkable identifier an agent presents to a specific relying party so that two relying parties cannot correlate the agent across contexts. A conforming implementation MUST derive the pairwise pseudonym deterministically from the agent's long-term secret and a peer-specific salt using HKDF [[RFC5869]], and the derivation MUST be one-way: the pseudonym MUST NOT reveal the agent's canonical identifier.
The pairwise pseudonym is carried as a dedicated segment of the
did:atp identifier; its syntax and binding rules are defined
in the did:atp Pairwise Identifiers
section. This specification defines the privacy contract; did:atp defines
the on-the-wire form.
Pairwise identifiers limit but do not eliminate correlation (timing, traffic analysis, and colluding peers remain out of scope). CG input is sought on rotation cadence and on stating these limits normatively.
Selective disclosure lets an agent reveal a subset of a credential's attributes while committing to the whole credential. A conforming implementation MUST commit to the full credential as a domain-separated SHA-256 Merkle root, computed over the credential's attributes in key order, and MUST produce, for each revealed attribute, an authentication path to that root.
The Merkle construction is domain-separated to prevent second-preimage and type-confusion attacks:
0x00;0x01;ATP-merkle-empty placeholder.Verification MUST establish that each disclosed attribute is a member of the committed root and, when an issuer-attested root is supplied, that the committed root matches it. The issuer's signature over the root is verified out-of-band by the credential service and is out of scope here.
credential = {
id: "urn:cred:atp:conformance:1",
name: "Ada Lovelace",
role: "engineer",
clearance: "secret",
org: "did:atp:agents.example.com"
}
merkleRoot = e22c3d1565d0a4fdf85286018145138a60146bba89d59e6e44cdbe7f568e5213
// disclose ["name","org"] → revealedIndices [1,4], one path per revealed attr
A range proof lets an agent prove a numeric attribute lies in [0, 2n) without revealing it. The reference construction is a bit-decomposition with a Chaum–Pedersen OR proof per bit over Ristretto255 [[!RFC9496]] Pedersen commitments; no new cryptographic primitive is introduced.
This construction is experimental. It MUST NOT be relied upon for production confidentiality until it has received independent cryptographic review. CG members with applied-cryptography expertise are explicitly invited to review the bit-decomposition + OR construction, the Fiat–Shamir transcript, and the choice of generators.
Selective-disclosure vectors are deterministic known-answer tests (the Merkle root above is fixed by the credential and computed independently of the implementation). They are maintained alongside the ATP Conformance & Interoperability suite. CG members may contribute additional vectors as table rows.
Domain separation in the Merkle construction is mandatory: omitting the leaf/node tags enables second-preimage attacks that forge membership. Selective disclosure hides unrevealed values but not the set of attribute names in the credential schema; implementations SHOULD consider schema-level metadata leakage. The experimental range proof's guarantees are unverified pending review (see above).