LICET: A Cryptographic Protocol for Multi-Modal Physiological Human-Intent Verification in Autonomous AI Agent Authorization
Abstract
As autonomous AI agents gain the capacity to execute consequential actions in high-stakes domains -- medical prescribing, financial transactions, critical infrastructure control -- existing authorization mechanisms fail to answer a fundamental question: was the authorizing human genuinely conscious, uncoerced, and cognitively capable at the exact moment of authorization? Passwords, static biometrics, and digital signatures verify identity, not intent state. We present LICET (Latin: it is permitted), a middleware protocol that cryptographically binds AI agent authorization events to the real-time physiological state of the authorizing human via a three-layer architecture: (1) an identity anchor using ECG waveform morphology -- an anatomically determined signal resistant to pharmacological manipulation; (2) a liveness layer using continuous electrodermal activity (EDA) and overnight HRV pattern matching; and (3) a voluntary state layer using personalized Mahalanobis distance fusion across five physiological channels with pharmacological attack pattern detection. LICET additionally provides: per-event session-key derivation via HKDF; a Schnorr zero-knowledge proof over BN128, enabling third-party audit without exposing biometric data; a SHA-256 hash-chained ledger providing tamper-evident authorization records; and a four-level biometric trust hierarchy (L0-L3) aligned with IETF RATS architecture (RFC 9334). The protocol is designed as a coercion cost elevation mechanism: no single pharmacological intervention at survivable doses defeats the multi-signal fusion system. A reference implementation is publicly deployed at https://licet.dev.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.