Pith. sign in
Pith Number

pith:PHSJFORL

pith:2026:PHSJFORLQ5UFTBB6I37KCJPREF
not attested not anchored not stored refs pending

SUDP: Secret-Use Delegation Protocol for Agentic Systems

Hejia Geng, William Knottenbelt, Xiaohang Yu, Xinmeng Zeng

SUDP lets untrusted agents trigger secret-backed operations with single-use grants that never expose reusable authority.

arxiv:2604.24920 v3 · 2026-04-27 · cs.CR · cs.AI

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{PHSJFORLQ5UFTBB6I37KCJPREF}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

Under explicit assumptions, we show that SUDP satisfies the ASU requirements: authorization is verifiable, operation-bound, and single-use. SUDP also provides storage confidentiality and wrapping-epoch key isolation under stated sealing and erasure assumptions; plaintext-level forward secrecy of the underlying secret additionally requires the environment to rotate and revoke it.

C2weakest assumption

The protocol satisfies its security properties under explicit assumptions including stated sealing and erasure assumptions for confidentiality and key isolation, plus environment-driven rotation and revocation of the secret for forward secrecy.

C3one line summary

SUDP is a protocol allowing untrusted agents to cause bounded, secret-backed operations through fresh user grants redeemed by a custodian, preventing reusable secret exposure.

Receipt and verification
First computed 2026-05-25T02:02:15.776853Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

79e492ba2b876859843e46fea125f1214d5e08875a1db8e4a3c298042f92c0d5

Aliases

arxiv: 2604.24920 · arxiv_version: 2604.24920v3 · doi: 10.48550/arxiv.2604.24920 · pith_short_12: PHSJFORLQ5UF · pith_short_16: PHSJFORLQ5UFTBB6 · pith_short_8: PHSJFORL
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/PHSJFORLQ5UFTBB6I37KCJPREF \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 79e492ba2b876859843e46fea125f1214d5e08875a1db8e4a3c298042f92c0d5
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "8df73df0c54299c27a9192e1b1b99df99320f1c300ad79a8c80692e00bafb096",
    "cross_cats_sorted": [
      "cs.AI"
    ],
    "license": "http://arxiv.org/licenses/nonexclusive-distrib/1.0/",
    "primary_cat": "cs.CR",
    "submitted_at": "2026-04-27T19:02:08Z",
    "title_canon_sha256": "9a3eb97b34bfd1c61d7738c16f2784310c56e2a73e2505f74c04e91080c41e11"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2604.24920",
    "kind": "arxiv",
    "version": 3
  }
}