Search papers, labs, and topics across Lattice.
This paper introduces an authority-decomposition framework that identifies the specific coalitions of trust domains necessary to execute protected actions in high-risk automated systems. By modeling various components and their causal relationships, the framework reveals that achieving a designated protected state transition often requires more trust domains than previously assumed, as demonstrated through analytical cases in a protocol model. The findings highlight the complexities of control distribution in automated systems and the inadequacy of traditional authority labels in ensuring secure execution.
Trust domains required for protected execution can exceed expectations, revealing that five domains may be necessary for certain high-risk automated systems. WHY_IT MATTERS: This insight challenges existing assumptions about authority in automated systems and could significantly influence the design of security protocols in high-stakes environments.
High-risk automated systems distribute control across services, credentials, protected components, and lifecycle mechanisms. Labels such as authorized, approved, privileged, or protected therefore do not answer a basic causal question: which actors can actually make a consequential action occur? This paper provides an action-relative method for deriving which trust-domain coalitions are sufficient to cause protected execution, defined as the occurrence of a designated protected state transition. The framework models components, powers, resources, boundaries, and alternative realization structures; includes update, recovery, override, disablement, and alternative invocation; and separates causal control over execution from control over the authoritative account of an operation. It derives inclusion-minimal sufficient coalitions and tests whether claimed execution boundaries remain independent of designated upstream domains. Cross-domain analytical cases illustrate the method. In a split-control, release-intended, open-state, source-bounded Havenlon protocol model, the ordinary witness requires five trust domains, while certificate replacement yields a three-domain inclusion-minimal known requirement set among source-enumerated protocol witnesses; the Linux domain remains insufficient for the complete transition. Deployed global non-bypassability and boundary-bound veto coverage remain unresolved. The framework is a conceptual and analytical tool. It does not certify implementations, establish deployment security, guarantee complete discovery of hidden powers, or define evidence-verification semantics.