All Posts

└─ tech·research·talks·notes
⌘K

2026 11 posts

Designing PIC-X: Centralized Token Exchange End to End
Designing PIC-X. Centralized Token Exchange End to End. PIC Profile 0.2 defines centralized PIC-X-mediated authority continuity. This walkthrough follows one…
Designing PIC-X: PIC Token JWT and COSE Artifacts
Designing PIC-X. PIC Token JWT and COSE Artifacts. PIC Profile 0.2 defines centralized PIC-X-mediated authority continuity. The active profile is…
Designing PIC-X: Exposing Configuration through .well-known/pic-x-configuration
Designing PIC-X. Exposing Configuration through .well-known/pic-x-configuration. PIC-X exposes discovery at two levels: a server control-plane document and a…
Designing PIC-X: Deriving an Initial PIC Context of Authority
Designing PIC-X. Deriving an Initial PIC Context of Authority. PIC-X receives an OAuth access token at the selected realm token endpoint, validates it, and…
Designing PIC-X: From Specification to Architecture to Code
Designing PIC-X. From Specification to Architecture to Code. PIC-X stands for Provenance Identity Continuity Exchange. Verifiable Authority Continuity across…
From Hardy’s Compiler to Hardy’s AI Agent: When the Threat Model Changes, the Confused Deputy Returns
From Hardy’s Compiler to Hardy’s AI Agent. The question. This article examines one narrowly defined security property: whether authority propagated across time…
Trusting AI Agents, Who Is Acting?
Who Is Acting? AI agent security is usually approached as an identity problem: the question becomes “what is the agent’s identity, and what is it…
TDI2026 - PIC
On April 20–21, 2026, the 4th International Workshop on Trends in Digital Identity (TDI 2026) takes place in Verona. The workshop program also includes the talk…
LFDT - From Identity-First to Authority Continuity
On March 3, 2026, LF Decentralized Trust hosted the session “From Identity-First to Authority Continuity”, presented by Nicola Gallo.
ZTAuth* and PIC: From Research to Ground Truth
Over the past couple of years I have written several articles touching on ZTAuth* and PIC. Reading them today, some point in different directions, different…

2025 4 posts

A Trust Model for Ambient Mesh, microsegmentation, and async flows
Ambient Mesh is redefining the Cloud Native service mesh for Zero Trust, whilst ZTAuth* completes it with Trust Chains built on Trust Elevation, Trust Levels…
Programmable Fiduciary Money and Order Instruments
Single-merchant payments are easy; real commerce is not. The moment users ask an AI agent to buy multiple items from different merchants at the best available…
Decentralized Models for Programmable Fiduciary Money
AI agents bring new security challenges, but also an opportunity to rethink traditional models. By looking at payments from a decentralized perspective, we can…
Working on Permguard
Kicking things off with something I’ve been building: `Permguard`, an open source project under the Apache 2.0 license.