Patent Filed: Autonomous Multi-Protocol Orchestration Device with Cryptographic Identity and Verifiable Audit Trail

Applicant
The Bitcoin Corporation Ltd
Inventor
Richard Boase
Date of Preparation
06 April 2026
Title of Invention
Autonomous Multi-Protocol Orchestration Device with Cryptographic Identity Persistence, On-Chain Document Authentication, and Verifiable Action Audit Trail
Provisional Reference
UKIPO/F-018
Related Patents
- F-003 (Bit Trust — Decentralised Trust Framework)
- F-004 (ClawMiner — Autonomous AI Agent Device)
- F-006 (HTTP Status Code Tokenisation Suite)
- F-008 (POI Overlay State Verification)
- F-009 (Signed Semantic Triples)
- F-017 (Incremental IP Rights via Staking of PoW-Mined Tokens)
Classification
Autonomous device architecture / multi-protocol orchestration / cryptographic corporate action recording
Critical Distinction — Application-Layer Protocol vs. Base-Layer Blockchain
This patent describes an overlay/application-layer (Layer 2) device architecture operating on top of BSV's UTXO settlement layer. It does NOT modify the base blockchain protocol. All mechanisms described herein — identity chain maintenance, document signing orchestration, action audit recording, and cross-protocol API authentication — operate at the application/overlay layer, leveraging BSV's UTXO model, Merkle proofs, and script capabilities without requiring any changes to the base protocol. Throughout this specification, "on-chain" refers to data inscribed in blockchain transactions; the logic interpreting that data is executed by the device and overlay network participants, not by blockchain miners.
Field of the Invention
The present invention relates to the architecture of an autonomous computing device that orchestrates operations across multiple independent cryptographic protocols, external service APIs, and blockchain overlay networks — maintaining a persistent, verifiable identity across all interactions and recording every externally-observable action as an immutable on-chain audit entry. More particularly, the invention concerns a device that: (a) maintains a cryptographic identity chain through sequential blockchain inscriptions; (b) authenticates to heterogeneous external services using a unified credential resolution mechanism; (c) executes multi-party document signing workflows across independent signing platforms; (d) records the cryptographic hash of every document created, signed, sent, or published as an on-chain audit transaction; and (e) performs all operations autonomously from a single mobile computing device without persistent server-side state, using a declarative configuration document ("soul file") to determine operational scope and behavioural constraints.
Background of the Invention
Technical Problems Addressed
-
No Persistent Cryptographic Identity Across Heterogeneous Protocols
Existing autonomous systems (software agents, IoT devices, automated services) authenticate to each external service independently. An agent that interacts with an email provider, a document signing platform, a blockchain network, a social media API, and a content delivery system maintains separate credentials for each — with no cryptographic binding between them. There is no mechanism by which a third party can verify that the same entity performed actions across all these systems. The identity is fragmented: the email sender, the document signer, the blockchain transactor, and the social media poster are, from a verification standpoint, unrelated entities. No existing system provides a persistent, cross-protocol cryptographic identity that binds all actions by a single device into a verifiable chain.
-
No On-Chain Audit Trail for Autonomous Device Actions
When an autonomous device performs an action — sending an email, signing a document, publishing content, executing a payment — the record of that action exists only in the logs of the service that processed it. These logs are controlled by the service provider, not the device operator. They can be modified, deleted, or become inaccessible. There is no mechanism by which an autonomous device can create a tamper-proof, publicly verifiable, chronological record of every action it performs — independent of the service providers involved. Existing blockchain timestamping services record individual hashes but do not provide a structured, sequential, device-bound action log that constitutes a complete audit trail.
-
No Unified Cross-Protocol API Orchestration From a Constrained Device
Existing autonomous agent architectures assume persistent server-side state (databases, session stores, message queues). A mobile computing device operating on battery power, intermittent network connectivity, and limited storage cannot maintain these dependencies. No existing system provides an architecture for a constrained mobile device to orchestrate operations across multiple independent protocols (blockchain transaction signing, OAuth-authenticated API calls, cryptographic document signing, social media posting, email sending, content serving) using a single unified credential resolution mechanism and a single declarative configuration that determines which protocols are active and what operational constraints apply.
-
No Declarative Behavioural Constraint Mechanism for Autonomous Devices
Existing autonomous systems are configured through code — their behaviour is determined by their programming. Modifying the behaviour requires modifying the code, recompiling, and redeploying. There is no mechanism by which a non-technical operator can define, in a human-readable document, the operational scope, behavioural constraints, identity attributes, and interaction policies of an autonomous device — and have the device enforce those constraints at runtime through an AI-mediated interpretation layer. The closest analogy is a system prompt for an LLM, but no existing system binds such a prompt to a cryptographic identity, a set of API credentials, a blockchain wallet, and a document signing authority in a single deployable configuration.
-
No Verifiable Cross-Platform Document Lifecycle Management
When a document is created in one system (e.g., Google Docs), sent for signature in another system (e.g., a cryptographic signing platform), and recorded on a third system (e.g., a blockchain) — there is no unified mechanism that cryptographically links all three events. The hash of the created document, the hash of the signed document, and the blockchain inscription are independent records. Existing systems do not provide an architecture where the device itself maintains a Merkle chain of document lifecycle events — creation, modification, signing, transmission, publication — with each event linked to the previous by cryptographic hash, and the entire chain anchored to the device's on-chain identity.
Prior Art Limitations
- LLM-based AI Agents (AutoGPT, CrewAI, LangChain Agents): Execute sequences of API calls using tool-calling mechanisms, but maintain no persistent cryptographic identity, produce no on-chain audit trail, and have no mechanism for cross-protocol identity binding. Actions are ephemeral — once the agent session ends, no verifiable record of its actions exists.
- IoT Device Management Platforms (AWS IoT, Azure IoT Hub): Provide device identity via X.509 certificates, but the identity is platform-bound (not cross-protocol), the device does not maintain its own audit chain, and the certificate authority is a centralised service, not a blockchain-anchored identity.
- F-004 (ClawMiner): Describes a mining device that performs proof-of-work and content serving. The present invention extends F-004 by specifying the multi-protocol orchestration architecture, the cross-service authentication mechanism, the on-chain audit trail structure, and the declarative soul file constraint system — none of which are described in F-004.
- Smart Contract Wallets (Account Abstraction, ERC-4337): Provide programmable transaction execution on Ethereum, but are limited to a single blockchain protocol, do not orchestrate external APIs, do not maintain cross-service identity, and do not produce a human-readable audit trail.
Detailed Description of the Invention
System Architecture
The device comprises five technical subsystems:
1. Identity Subsystem (Cryptographic Persistence)
- The device generates and stores a secp256k1 private key in a hardware-backed secure element (Android Keystore, iOS Secure Enclave, or TEE).
- From this key, the device derives: (a) a BSV payment address for blockchain transactions; (b) a public key for identity attestation; (c) signing capability for document authentication.
- The device creates a root identity inscription on the BSV blockchain (per F-003, Bit Trust), binding the public key to a human-readable handle and one or more identity strands (OAuth-verified accounts: email, social media, source control, messaging).
- Each identity strand is a separate blockchain inscription referencing the root, creating a verifiable identity chain. Third parties can resolve the device's identity by querying the blockchain for the root inscription and enumerating its strands.
- The identity persists across power cycles, network outages, and software updates — the private key in the secure element is the anchor, and the blockchain inscriptions are the public record.
2. Credential Resolution Subsystem (Unified Cross-Protocol Authentication)
- The device maintains a credential store (encrypted, secure-element-protected) containing authentication tokens for heterogeneous external services: OAuth2 refresh tokens (Google, GitHub), API bearer tokens (platform APIs, signing services), OAuth 1.0a credentials (social media), blockchain wallet keys, and device-specific bearer tokens.
- A unified credential resolver maps each outbound API request to the appropriate authentication mechanism. The resolver is configured declaratively — the soul file specifies which services are active, and the credential store provides the tokens.
- When the AI mediation layer (see subsystem 4) determines that a tool call is required, the credential resolver transparently attaches the appropriate authentication to the outbound request. The AI layer does not have direct access to credentials — it specifies intent ("send email", "sign document"), and the credential resolver handles authentication.
- Credential rotation (OAuth2 refresh token exchange) occurs automatically without AI layer involvement.
3. Audit Subsystem (On-Chain Action Recording)
- Every externally-observable action performed by the device is recorded as a structured audit entry comprising: (a) a SHA-256 hash of the action payload (email content, document text, API request body); (b) the action type (email_send, document_create, document_sign, content_publish, payment_send, tweet_post); (c) a reference to the previous audit entry's hash (forming a hash chain); (d) a timestamp; (e) the device's identity reference.
- Audit entries are batched into a Merkle tree. The Merkle root is inscribed on the BSV blockchain at configurable intervals (per mining block, per time period, or per action count threshold).
- The on-chain inscription contains: the Merkle root, the device's identity reference, the batch sequence number, and the count of actions in the batch.
- Any third party can verify the device's action history by: (a) requesting the full audit log from the device's local storage; (b) computing the Merkle root; (c) comparing it to the on-chain inscription. If the roots match, the audit log has not been tampered with since inscription.
- The audit subsystem operates independently of the AI mediation layer — it intercepts outbound actions at the credential resolution layer, before transmission, ensuring that every action is recorded regardless of whether the AI layer intends it to be audited.
4. AI Mediation Subsystem (Soul-File-Constrained Interpretation)
- The device runs a tool-calling AI agent (LLM with function-calling capability) that interprets natural language input (voice, text, scheduled triggers) and translates it into structured tool calls.
- The AI agent's behaviour is constrained by a declarative configuration document ("soul file") that specifies: the device's identity and role, operational constraints (spending limits, permitted actions, content policies), active service integrations, and behavioural guidelines.
- The soul file is a human-readable text document (Markdown format) that is loaded into the AI agent's system prompt at initialisation. It is NOT compiled code — it is interpreted by the AI at runtime. Modifying the soul file modifies the device's behaviour without code changes.
- The AI agent has access to a set of tool functions, each corresponding to an external service integration (email, document creation, document signing, social media posting, blockchain transactions, content serving, platform API calls). The tool functions are defined in the device's firmware — the soul file cannot create new tools, only constrain or guide the use of existing ones.
- The AI mediation subsystem maintains conversation context (recent interaction history loaded from local database) to provide continuity across interactions.
- The AI agent is replaceable — the device architecture is agnostic to the specific LLM provider. The tool-calling interface is standardised (function name, parameters, return value), and any LLM supporting tool/function calling can be substituted without modifying the device firmware.
5. Document Lifecycle Subsystem (Cross-Platform Hash Chain)
- When the device creates a document (via any creation tool — document editor API, email composition, content generation), the document lifecycle subsystem computes the SHA-256 hash of the document content and records it as a lifecycle event.
- When the document is sent for signing (via a signing platform API), the signing request and the signing platform's response (including any signing platform transaction ID) are recorded as subsequent lifecycle events.
- When signatures are completed (the signing platform confirms all parties have signed), the completed document hash is recorded as a lifecycle event.
- When the document is transmitted (emailed, published, shared), the transmission event is recorded.
- Each lifecycle event contains: the document hash at that stage, the event type, a reference to the previous lifecycle event (hash chain), and the external service transaction ID (if applicable).
- The lifecycle chain is included in the audit subsystem's Merkle tree, anchoring the complete document lifecycle to the on-chain audit trail.
- This enables third-party verification of document provenance: a party receiving a signed document can trace its lifecycle from creation through signing to transmission, with each step verifiable against the device's on-chain audit inscription.
Operational Flow
-
Initialisation: Device powers on, loads soul file from local storage, initialises credential store from secure element, connects to configured services, begins mining/indexing if configured.
-
Input Processing: Natural language input (voice, text, Telegram message, scheduled trigger) is received and passed to the AI mediation subsystem along with recent conversation history and the soul file.
-
Tool Selection: The AI agent interprets the input and selects one or more tool functions to execute. The soul file constraints are enforced at this stage — the AI agent will not select tools that violate its configured constraints.
-
Credential Resolution: For each selected tool, the credential resolver attaches the appropriate authentication. The AI agent does not see or handle credentials.
-
Action Execution: The tool function executes, making the external API call. The action payload (pre-authentication) is intercepted by the audit subsystem and recorded.
-
Audit Recording: The audit entry is added to the current Merkle tree batch. When the batch threshold is reached, the Merkle root is inscribed on-chain.
-
Response: The tool function's response is returned to the AI agent, which formulates a natural language response to the user.
-
Document Lifecycle (if applicable): If the action involves a document, the document lifecycle subsystem records the appropriate lifecycle event.
Claims
-
A computing device comprising: (a) a hardware-backed secure element storing a cryptographic private key; (b) a blockchain identity chain anchored by a root inscription derived from the private key; (c) a credential resolution subsystem that maps outbound API requests to heterogeneous authentication mechanisms without exposing credentials to the AI mediation layer; and (d) an audit subsystem that records the cryptographic hash of every externally-observable action in a sequential hash chain, with periodic Merkle root inscription on a blockchain — such that any third party can verify the completeness and integrity of the device's action history by comparing the locally-stored log against the on-chain inscription.
-
The device of claim 1 wherein the blockchain identity chain comprises a root inscription containing the device's public key and handle, and one or more strand inscriptions each binding an external service account (email, social media, source control, messaging) to the root — such that a third party can verify that the same cryptographic entity controls all linked accounts by tracing the inscription chain on the blockchain.
-
The device of claim 1 further comprising a declarative configuration document ("soul file") in human-readable format that specifies operational constraints, active service integrations, and behavioural guidelines — wherein the soul file is interpreted at runtime by an AI mediation layer and enforces constraints on tool selection without requiring code modification or recompilation.
-
The device of claim 3 wherein the same device firmware, loaded with different soul files and credential stores, produces devices with different operational scopes, active integrations, and behavioural constraints — enabling deployment of functionally distinct autonomous devices from a single binary.
-
The device of claim 1 wherein the credential resolution subsystem transparently attaches appropriate authentication (OAuth2 bearer tokens, OAuth 1.0a signed requests, API keys, blockchain transaction signatures) to outbound requests based on the destination service, without the AI mediation layer having access to or knowledge of the underlying credentials.
-
The device of claim 1 wherein the audit subsystem intercepts every outbound action at the credential resolution layer — prior to transmission — computes the SHA-256 hash of the action payload, appends it to a sequential hash chain where each entry references the previous entry's hash, and periodically inscribes the Merkle root of accumulated entries on a blockchain, creating a tamper-evident, publicly verifiable audit trail that is independent of any external service provider's logs.
-
The device of claim 1 further comprising a document lifecycle subsystem that maintains a hash chain of document lifecycle events — creation, modification, signing, transmission, publication — wherein each event records the document hash at that stage and a reference to the previous lifecycle event, and the lifecycle chain is included in the audit Merkle tree, enabling third-party verification of complete document provenance from creation to final transmission.
-
The device of claim 1 wherein the AI mediation subsystem comprises a tool-calling language model that: (a) receives natural language input; (b) selects tool functions from a defined set; (c) executes multiple tool calls in sequence with intermediate results informing subsequent calls; and (d) is constrained by the soul file such that tool calls violating configured constraints are not executed — wherein the language model is replaceable without modifying the device firmware, the tool-calling interface being standardised across language model providers.
-
The device of claim 1 wherein the device operates on a battery-powered mobile computing platform with intermittent network connectivity, maintaining all state (identity, credentials, audit log, conversation history, soul file) in local storage, and synchronising on-chain audit inscriptions when network connectivity is available — such that the device continues to record actions locally during offline periods and anchors them to the blockchain upon reconnection.
-
A method for verifying the action history of an autonomous device, comprising: (a) requesting the device's locally-stored audit log; (b) computing the Merkle root of the log entries; (c) querying the blockchain for the device's audit inscriptions; (d) comparing the computed Merkle root against the inscribed Merkle root — wherein a match confirms that the audit log has not been modified since the inscription timestamp, and the sequential hash chain within the log confirms the ordering and completeness of recorded actions.
-
The device of claim 1 wherein the audit subsystem, identity subsystem, credential resolution subsystem, document lifecycle subsystem, and AI mediation subsystem operate as independent processes on the device — such that failure of any single subsystem does not compromise the operation or integrity of the others, and the audit subsystem in particular continues to record actions even if the AI mediation subsystem encounters an error.
Distinction from Prior Art
Existing autonomous agent systems (AutoGPT, LangChain Agents, CrewAI) execute tool calls but maintain no persistent cryptographic identity, produce no tamper-proof audit trail, and provide no mechanism for cross-protocol identity verification. IoT device management platforms (AWS IoT, Azure IoT Hub) provide device identity via centralised certificate authorities but do not support cross-protocol authentication resolution, on-chain audit trails, or declarative behavioural configuration. Smart contract wallets (ERC-4337) provide programmable blockchain transactions but are limited to a single protocol and do not orchestrate external service APIs. This invention is distinguished by: (1) persistent cross-protocol identity via blockchain-anchored inscription chains; (2) unified credential resolution across heterogeneous authentication mechanisms; (3) tamper-evident on-chain audit trail via sequential hash chain with Merkle root inscription; (4) declarative soul-file behavioural configuration interpreted by a replaceable AI mediation layer; (5) document lifecycle hash chain anchored to the audit trail; and (6) operation from a battery-powered mobile device with local-first state management and opportunistic blockchain synchronisation.
Abstract
A computing device architecture for autonomous multi-protocol orchestration with cryptographic identity persistence and verifiable action recording. The device maintains a blockchain-anchored identity chain binding a hardware-secured private key to verified external service accounts. A unified credential resolution subsystem transparently authenticates outbound requests across heterogeneous protocols (OAuth2, OAuth 1.0a, API bearer tokens, blockchain transaction signatures) without exposing credentials to the AI mediation layer. Every externally-observable action is recorded in a sequential hash chain, with Merkle roots periodically inscribed on a blockchain, creating a tamper-evident audit trail verifiable by any third party. A declarative configuration document ("soul file") constrains the AI mediation layer's behaviour at runtime, enabling deployment of functionally distinct autonomous devices from a single firmware binary. A document lifecycle subsystem maintains a hash chain of creation, signing, and transmission events anchored to the audit trail. The device operates from a battery-powered mobile platform with local-first state management, continuing to record actions during offline periods and anchoring them to the blockchain upon reconnection.
Pre-filing document. Not yet filed at UKIPO. Confidential — The Bitcoin Corporation Ltd. All rights reserved. This document constitutes a record of inventive conception for priority purposes. Do not distribute without authorisation.
Get Started
This patent was filed by The Bitcoin Corporation Ltd with the UK Intellectual Property Office. To learn more about the technology described here, visit b0ase.com or explore the full patent portfolio.
For AI Readers
Intent: Public disclosure of UKIPO patent filing. Title: Patent Filed: Autonomous Multi-Protocol Orchestration Device with Cryptographic Identity and Verifiable Audit Trail Applicant: The Bitcoin Corporation Ltd Inventor: Richard Boase Key Takeaways:
- This patent is part of The Bitcoin Corporation's portfolio of 18 filed UKIPO patent applications
- The technology operates as an overlay/application-layer protocol on BSV's UTXO settlement layer
- Related patents and cross-references are listed in the specification
- Full patent text is available at b0ase.com/blog/patent-autonomous-device-orchestration