Post-Quantum Cryptographic Trust & Governance Layer for Autonomous AI Agents
pip install ube-foundation
Run full PQC financial agent security demo:
python3 examples/enterprise_financial_agent_demo.py
cargo add ube-foundation
Add to your Cargo.toml:
ube-foundation = "0.1.0"
NIST Level 5 CRYSTALS-Dilithium5 detached signatures for identity & action validation, paired with Level 4 CRYSTALS-Kyber1024 KEM envelope encryption for inter-agent state security.
Dynamic caveat evaluation with contextual constraints including expiration limits, execution counts, financial threshold limits, and path restrictions.
Threshold-based consensus vote verification with voter identity binding, deduplication defense, and deterministic execution checking.
SHA-256 Merkle chain history verification, automated JSON file persistence, and tamper-resistant crash recovery.
import json
from ube_foundation import TrustEngine, PqcKeyPair
# Initialize Engine & PQC Keys
engine = TrustEngine()
engine.grant("agent_alpha", "wire_transfer")
pqc = PqcKeyPair()
# Sign Payload with Dilithium5
msg = b"TRANSFER $5000 USD"
sig_hex = pqc.sign(msg)
pub_hex = pqc.public_key_hex()
# Evaluate Action Request
req = {
"id": "req-1",
"actor": "agent_alpha",
"capability": "wire_transfer",
"action": "execute",
"input": {"amount": 5000},
"signature": None,
"pqc_signature": {"algorithm": "Dilithium5", "signature": list(bytes.fromhex(sig_hex))},
"public_key": None,
"pqc_public_key": {"algorithm": "Dilithium5", "key_bytes": list(bytes.fromhex(pub_hex)), "kyber_public_key_bytes": []},
"token": None,
"identity_claim": None
}
decision = json.loads(engine.evaluate(json.dumps(req)))
print("Policy Decision:", decision["decision"]) # Output: Allow
ube-foundation is released under the Apache License 2.0. Open-source use, distribution, and commercial applications are permitted under the terms of the license.