<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version  (Ruby 3.3.6) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-palanisamy-scitt-aac-runtime-00" category="std" consensus="true" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="AAC model_attestation">The model_attestation Block for Agent Action Capsules: Model, Runtime, and Hardware Claims</title>
    <seriesInfo name="Internet-Draft" value="draft-palanisamy-scitt-aac-runtime-00"/>
    <author initials="G." surname="Palanisamy" fullname="Govindaraj Palanisamy">
      <organization>Independent</organization>
      <address>
        <email>npgovintarajan@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Mih" fullname="Steven Mih">
      <organization>Action State Group, Inc.</organization>
      <address>
        <email>steven@actionstate.ai</email>
      </address>
    </author>
    <date year="2026" month="October" day="02"/>
    <area>Security</area>
    <keyword>SCITT</keyword>
    <keyword>agent</keyword>
    <keyword>capsule</keyword>
    <keyword>model_attestation</keyword>
    <keyword>runtime</keyword>
    <keyword>provenance</keyword>
    <abstract>
      <?line 40?>

<t>This document defines the <tt>model_attestation</tt> block of the Agent Action
Capsule (AAC) profile — referenced twice by the base profile but never
defined there — and, within it, the <tt>compute_attestation</tt> container that
already carries runtime extensions in the field: the model-serving
runtime, the agent's own execution environment (architectural pattern,
orchestration framework, sandbox confinement, invoked tool version), and
host hardware, together with model and weights claims. Every claim carries an explicitly declared
source; a verifier grades claims by how they were observed and never
infers a stronger grade than the evidence supports. Hardware or platform
attestation, when present, is cited by content-addressed reference to a
foreign attestation record and verified with that record's own verifier.</t>
    </abstract>
  </front>
  <middle>
    <?line 56?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>An agent action recorded in an Agent Action Capsule (AAC) is executed by a
model running within a specific model-serving runtime, itself invoked by
an agent process in a specific execution environment, on host hardware.
Two capsules recording nominally identical actions can differ in what
actually happened depending on model checkpoint, quantization, sandbox
confinement, or the version of a tool package the agent invoked; without a
record of that environment, a forensic reviewer cannot tell a model-drift
event from a compromised tool from an unconfined sandbox. The base profile
<xref target="I-D.mih-scitt-agent-action-capsule"/> records the action, seals it under
canonicalization <xref target="RFC8785"/>, and <bcp14>MAY</bcp14> register its Capsule ID as
independently transparent to a SCITT <xref target="RFC9943"/> Transparency Service; the
agent-domain checks defined by the base profile are verified independently
of that registration, by a Class 1 or Class 2 verifier, from the record's
own bytes. Its epoch mechanism records baseline configuration shifts
across actions. Although the base profile references a <tt>model_attestation</tt>
block, it does not supply a formal definition.</t>
      <t>Two constraints matter. First, this extension is payload-extension-only:
<tt>model_attestation</tt> lives in the Capsule JSON like every other payload
member — the base profile's Section "Extensibility" states that all
Capsule extension points are in the Capsule JSON — and it does not touch
the Producer Envelope's protected header, which the base profile's
Section "Producer Envelope wire profile" holds closed to exactly three
entries (Section 3.1). Second, this extension <bcp14>MUST NOT</bcp14> change the base
profile's Class 1 or Class 2 verification model (Sections 6 and 8.2); a
verifier that does not implement it treats the block as informational
(<xref target="block"/>). This extension also imposes no mandatory transport
dependency; it is silent on how a Capsule is delivered.</t>
      <t><tt>model_attestation</tt> is a bare top-level payload member name, not a
namespaced one. This follows from a fact specific to this field: the base
profile already refers to <tt>model_attestation</tt> by that exact bare name,
twice, without defining it (in its epoch-boundary Capsule section and in
its Security Considerations), so the name is already reserved by the base
profile itself rather than being minted here. This document supplies the
definition for a name the base profile already uses, rather than
introducing a new namespaced member.</t>
      <t>This document defines the <tt>model_attestation</tt> block, generalizes it to
per-action use, and formalizes the model-serving runtime, agent execution
environment, and hardware facts producers observe — all within the
<tt>compute_attestation</tt> container (<xref target="compute"/>). The block is sealed
directly inside the Capsule payload and participates in derived
identifier generation (<tt>capsule_id</tt>).</t>
      <t>The core design principle is honesty of source. A model name reported by
the runtime is a claim; a weights digest computed over a loaded file is a
stronger claim; a measurement signed by a hardware root of trust is
stronger still. They represent distinct facts, and the record states
which one it holds. A verifier that cannot resolve a claim to its stated
source <bcp14>MUST</bcp14> report it as unresolved, <bcp14>MUST NOT</bcp14> report it as verified, and
<bcp14>MUST NOT</bcp14> upgrade an unknown grade to a known one.</t>
      <t>This block complements rather than replaces the base profile's epoch
machinery: it records per-action claims in force for an action while
remaining scoped to the active epoch and prevailing epoch-boundary
Capsule. <tt>model_id</tt> is <bcp14>RECOMMENDED</bcp14>, not <bcp14>REQUIRED</bcp14>, in
<xref target="model-attestation"/>: the epoch-boundary Capsule already records the
model transition, and an extension <bcp14>MUST NOT</bcp14> out-mandate its base.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

<t>Capsule, Producer Envelope, epoch, epoch-boundary Capsule, epoch_id,
derived identifier, typed digest reference, and data-admission tiers are
used as defined in <xref target="I-D.mih-scitt-agent-action-capsule"/> and
<xref target="I-D.mih-sokolov-scitt-payload-binding"/>. Attester, Verifier, and
Evidence are used in the sense of <xref target="RFC9334"/> where foreign platform
attestation is discussed.</t>
      <dl>
        <dt>Source label:</dt>
        <dd>
          <t>A standardized vocabulary declaring how a claim's value was obtained:
self_reported (asserted by executing software), provider_reported
(returned by a remote model provider or serving API and preserved by the
producer without alteration), os_reported (reported by the host
operating system), computed (calculated by the producer from bytes it
held), or attested (cryptographically bound inside a verifiable foreign
attestation record). Additional labels <bcp14>MUST</bcp14> be namespaced.</t>
        </dd>
      </dl>
      <t>Every <tt>source</tt> map in this document (at the <tt>model_attestation</tt> level and
within each <tt>compute_attestation</tt> sub-object) follows the same default: if
the map is omitted, or a field has no entry in it, a verifier <bcp14>MUST</bcp14> treat
that field's source as <tt>self_reported</tt>. This rule is stated once here and
applies wherever a <tt>source</tt> field appears below; it is not restated per
sub-object.</t>
    </section>
    <section anchor="block">
      <name>The model_attestation Block</name>
      <t>A Capsule payload <bcp14>MAY</bcp14> carry a member named <tt>model_attestation</tt>. The block
participates in the derived identifier like every payload member: it is
canonicalized under JCS <xref target="RFC8785"/> and covered by <tt>capsule_id</tt>. A verifier
that does not implement this extension <bcp14>MUST</bcp14> ignore it for verification and
<bcp14>MUST NOT</bcp14> fail a Capsule solely because it is present.</t>
      <table>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Type</th>
            <th align="left">Req</th>
            <th align="left">Meaning</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">model_id</td>
            <td align="left">string</td>
            <td align="left">
              <bcp14>RECOMMENDED</bcp14></td>
            <td align="left">See <xref target="model-attestation"/>.</td>
          </tr>
          <tr>
            <td align="left">provider</td>
            <td align="left">string</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">See <xref target="model-attestation"/>.</td>
          </tr>
          <tr>
            <td align="left">model_revision</td>
            <td align="left">string</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">See <xref target="model-attestation"/>.</td>
          </tr>
          <tr>
            <td align="left">weights_digest</td>
            <td align="left">object</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">See <xref target="model-attestation"/>.</td>
          </tr>
          <tr>
            <td align="left">quantization</td>
            <td align="left">string</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">See <xref target="model-attestation"/>.</td>
          </tr>
          <tr>
            <td align="left">decoding</td>
            <td align="left">object</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">See <xref target="model-attestation"/>.</td>
          </tr>
          <tr>
            <td align="left">source</td>
            <td align="left">object</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">Field to source label mapping; see above for the omitted-entry default.</td>
          </tr>
          <tr>
            <td align="left">compute_attestation</td>
            <td align="left">object</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">Container for runtime/compute facts (<xref target="compute"/>).</td>
          </tr>
          <tr>
            <td align="left">epoch_consistency</td>
            <td align="left">string</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">consistent, inconsistent, or unknown (<xref target="epochs"/>).</td>
          </tr>
        </tbody>
      </table>
      <section anchor="model-attestation">
        <name>Model Members</name>
        <t>These members define the core model assertions referenced by the base
profile's epoch section. They <bcp14>MAY</bcp14> appear in any Capsule and <bcp14>SHOULD</bcp14> appear
in every epoch-boundary Capsule.</t>
        <table>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">Type</th>
              <th align="left">Req</th>
              <th align="left">Permitted Sources</th>
              <th align="left">Meaning</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">model_id</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>RECOMMENDED</bcp14></td>
              <td align="left">self_reported, os_reported, attested</td>
              <td align="left">Model name as reported by the runtime.</td>
            </tr>
            <tr>
              <td align="left">provider</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">self_reported, attested</td>
              <td align="left">Model provider or serving system.</td>
            </tr>
            <tr>
              <td align="left">model_revision</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">self_reported, attested</td>
              <td align="left">Provider- or repo-assigned revision.</td>
            </tr>
            <tr>
              <td align="left">weights_digest</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">computed, attested</td>
              <td align="left">
                <tt>{digest_alg, digest, scope}</tt> over loaded weights.</td>
            </tr>
            <tr>
              <td align="left">quantization</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">self_reported, computed, attested</td>
              <td align="left">Quantization label (e.g., Q4_K_M).</td>
            </tr>
            <tr>
              <td align="left">decoding</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">self_reported</td>
              <td align="left">Hyperparameters <tt>{temperature, top_p, seed}</tt>.</td>
            </tr>
          </tbody>
        </table>
        <t>For <tt>weights_digest</tt>, <tt>scope</tt> <bcp14>MUST</bcp14> be either <tt>file</tt> (digest over serialized
model bytes as loaded from storage) or <tt>tensors</tt> (digest over in-memory
tensor structures, admissible only under <tt>attested</tt>). A digest of a
reference string (e.g., a HuggingFace URI) <bcp14>MUST NOT</bcp14> be carried in
<tt>weights_digest</tt>; such identifiers belong in <tt>model_id</tt>.</t>
        <section anchor="verification-grade-semantics">
          <name>Verification Grade Semantics</name>
          <t>A verifier <bcp14>MAY</bcp14> derive grades according to the following matrix, never
exceeding what <tt>source</tt> and accompanying evidence substantiate:</t>
          <table>
            <thead>
              <tr>
                <th align="left">Record Fact</th>
                <th align="left">Verifier May Report</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">model_id only</td>
                <td align="left">model: self-reported name</td>
              </tr>
              <tr>
                <td align="left">weights_digest (scope: file, computed)</td>
                <td align="left">model: file-identified (recomputable)</td>
              </tr>
              <tr>
                <td align="left">weights_digest (attested via <xref target="attestation"/>)</td>
                <td align="left">model: attested at declared scope</td>
              </tr>
              <tr>
                <td align="left">quantization (self_reported)</td>
                <td align="left">quantization: claimed</td>
              </tr>
            </tbody>
          </table>
          <t>A verifier <bcp14>MUST NOT</bcp14> report "model attested" from <tt>model_id</tt> alone, and <bcp14>MUST
NOT</bcp14> report "quantization verified" from any field in this block, as none of
these fields establish which underlying arithmetic was executed. Detection of
substituted models or quantizations is out of scope for this record and
belongs to redundancy or referee mechanisms at the system level.</t>
        </section>
      </section>
    </section>
    <section anchor="compute">
      <name>The compute_attestation Container</name>
      <t><tt>compute_attestation</tt> groups environment observations into five
sub-objects: <tt>runtime</tt> (<xref target="runtime"/>, the model-serving runtime),
<tt>agent_runtime</tt> (<xref target="agent_runtime"/>, the agent's own execution
environment), <tt>invocation</tt> (<xref target="invocation"/>, what the model provider or
serving API reported about this call), <tt>hardware</tt> (<xref target="hardware"/>), and
<tt>attestation_refs</tt> (<xref target="attestation"/>), plus any namespaced member owned by another
specification (for example <tt>x-mesh-lifecycle-v1</tt>, <tt>host_binding</tt>).
<tt>runtime</tt> and <tt>agent_runtime</tt> are deliberately distinct: <tt>runtime</tt>
describes the process that served the model's inference (for example, a
local inference server or hosted serving stack); <tt>agent_runtime</tt>
describes the process that orchestrated the action — the agent loop, its
sandbox, and the tool it invoked — which may be a different process, on
different infrastructure, than the one that served the model. A verifier
<bcp14>MUST</bcp14> ignore members it does not recognize. A member <bcp14>MUST</bcp14> be absent rather
than <tt>null</tt> when its fact is unavailable.</t>
      <section anchor="runtime">
        <name>compute_attestation.runtime</name>
        <table>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">Type</th>
              <th align="left">Req</th>
              <th align="left">Meaning</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">name</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>RECOMMENDED</bcp14></td>
              <td align="left">Serving binary name and version.</td>
            </tr>
            <tr>
              <td align="left">runtime_digest</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Digest of the serving binary as measured.</td>
            </tr>
            <tr>
              <td align="left">measurement_class</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>RECOMMENDED</bcp14>*</td>
              <td align="left">Class of measurement (*when digest present).</td>
            </tr>
            <tr>
              <td align="left">platform_integrity</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">OS integrity bits (e.g., SIP, Secure Boot).</td>
            </tr>
            <tr>
              <td align="left">source</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Field to source label mapping; see above for the omitted-entry default.</td>
            </tr>
          </tbody>
        </table>
        <t>Standard <tt>measurement_class</tt> values include <tt>self_measured</tt>, <tt>os_measured</tt>,
<tt>tpm_measured</tt>, <tt>app_attested</tt>, <tt>mda_measured</tt>, and <tt>tee_measured</tt>. Field
status at the time of writing: <tt>self_measured</tt> and <tt>os_measured</tt> are
produced by shipping code; <tt>tee_measured</tt> has a record shape and verifier
with real Intel TDX vectors; <tt>tpm_measured</tt>, <tt>app_attested</tt>, and
<tt>mda_measured</tt> are named here so that the vocabulary is fixed before their
producers exist. Unknown classes <bcp14>MUST</bcp14> be treated as unrecognized, never
ordered above known classes; the classes are sibling roots of trust and the
ordering above is meaningful only within a single root.</t>
      </section>
      <section anchor="agent_runtime">
        <name>compute_attestation.agent_runtime</name>
        <t>Where <tt>runtime</tt> (<xref target="runtime"/>) describes the process that served the model,
<tt>agent_runtime</tt> describes the process that orchestrated the action: the
agent loop or orchestration framework, the environment and confinement it
ran in, and the version of any tool package it invoked to perform this
specific action. This is the environment-blindness gap: two Capsules
recording the same nominal action can behave differently depending on
sandbox confinement or a tool package's version, and without this record a
forensic reviewer cannot distinguish a compromised tool from an unconfined
sandbox from a model-drift event.</t>
        <table>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">Type</th>
              <th align="left">Req</th>
              <th align="left">Meaning</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">agent_type</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">The agent's architectural pattern (e.g., <tt>single_agent</tt>, <tt>multi_agent_orchestrator</tt>, <tt>react</tt>, <tt>plan_execute</tt>, <tt>supervisor_worker</tt>).</td>
            </tr>
            <tr>
              <td align="left">framework</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Agent orchestration framework or agent-loop implementation, name and version (e.g., <tt>langchain 0.3.1</tt>, <tt>custom-agent-loop 1.4.0</tt>).</td>
            </tr>
            <tr>
              <td align="left">runtime_env</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Execution environment the agent process ran in, name and version (e.g., <tt>python:3.11-slim</tt>, <tt>node:20-alpine</tt>).</td>
            </tr>
            <tr>
              <td align="left">sandbox_type</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Confinement mechanism isolating the agent process (e.g., <tt>gvisor</tt>, <tt>firecracker</tt>, <tt>wasm</tt>, <tt>unconfined</tt>).</td>
            </tr>
            <tr>
              <td align="left">tool_version</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Version or content digest of the tool package this action invoked, when the action involved a specific tool.</td>
            </tr>
            <tr>
              <td align="left">source</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Field to source label mapping; see above for the omitted-entry default.</td>
            </tr>
          </tbody>
        </table>
        <t><tt>agent_type</tt> names the architectural pattern the agent process implements
for this action, not the specific framework instance (that is
<tt>framework</tt>'s job) or a claim about correctness. The seeded values above
are illustrative, not exhaustive or registry-governed: <tt>single_agent</tt> (one
model, one decision loop), <tt>multi_agent_orchestrator</tt> (a coordinating
process dispatching to one or more sub-agents for this action),
<tt>react</tt> (interleaved reasoning-and-acting loop), <tt>plan_execute</tt> (a
separate planning phase precedes execution), and <tt>supervisor_worker</tt> (a
supervisor process dispatches to worker processes it does not itself
execute as). A value outside this list follows the same namespacing
discipline as <tt>constraint id</tt>/<tt>check_type</tt> in the base profile's Section
"Namespacing convention": bare names are reserved for the values seeded
here, and a party introducing a new value <bcp14>MUST</bcp14> namespace it with a URI or
reverse-DNS prefix. A verifier treats an unrecognized <tt>agent_type</tt> value
as informational, never as a validation failure — this field is
descriptive metadata, not a graded claim, and carries no source-grading
matrix of its own beyond the standard self-reported default.</t>
        <t><tt>sandbox_type: "unconfined"</tt> is itself an informative claim, not an absent
field: a producer that knows its agent process runs unconfined <bcp14>SHOULD</bcp14> say
so rather than omit the field, since the omission and the honest
disclosure of no confinement are otherwise indistinguishable to a
verifier. As with every field in this document, <tt>sandbox_type</tt> and
<tt>framework</tt> are self-reported unless graded otherwise by <tt>source</tt> or
corroborated by an <tt>attestation_refs</tt> entry (<xref target="attestation"/>); a verifier
<bcp14>MUST NOT</bcp14> infer actual confinement strength from the label alone;
<tt>gvisor</tt> and <tt>firecracker</tt> name mechanisms with different isolation
properties, and this document does not rank them.</t>
      </section>
      <section anchor="invocation">
        <name>compute_attestation.invocation</name>
        <t>Commercial and self-hosted model APIs commonly return invocation metadata
in addition to the text or tool output. This sub-object preserves such
provider or runtime facts without standardizing any provider-specific
response object. Every value here is a claim about what the serving side
reported for this call; none of it is a measurement of the serving
environment, which is what <xref target="runtime"/> and <xref target="hardware"/> carry.</t>
        <t>All fields below are <bcp14>OPTIONAL</bcp14>.</t>
        <table>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">Type</th>
              <th align="left">Permitted Sources</th>
              <th align="left">Meaning</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">requested_model_id</td>
              <td align="left">string</td>
              <td align="left">self_reported</td>
              <td align="left">Model identifier the caller asked for.</td>
            </tr>
            <tr>
              <td align="left">resolved_model_id</td>
              <td align="left">string</td>
              <td align="left">provider_reported, self_reported, attested</td>
              <td align="left">Model identifier reported as actually serving the call.</td>
            </tr>
            <tr>
              <td align="left">service_class</td>
              <td align="left">string</td>
              <td align="left">provider_reported, self_reported</td>
              <td align="left">Provider or runtime processing tier. Values are provider-defined unless registered by another profile.</td>
            </tr>
            <tr>
              <td align="left">backend_fingerprint</td>
              <td align="left">string</td>
              <td align="left">provider_reported</td>
              <td align="left">Opaque provider-issued deployment or configuration identifier. A change-detection value, not a hardware attestation.</td>
            </tr>
            <tr>
              <td align="left">reasoning</td>
              <td align="left">object</td>
              <td align="left">provider_reported, self_reported</td>
              <td align="left">Declared reasoning configuration (mode, effort, summary policy). Raw chain-of-thought <bcp14>MUST NOT</bcp14> appear here.</td>
            </tr>
            <tr>
              <td align="left">usage</td>
              <td align="left">object</td>
              <td align="left">provider_reported, self_reported</td>
              <td align="left">Non-content counters: input, output, cached, and reasoning tokens.</td>
            </tr>
            <tr>
              <td align="left">finish_status</td>
              <td align="left">string</td>
              <td align="left">provider_reported, self_reported</td>
              <td align="left">Termination status: <tt>completed</tt>, <tt>incomplete</tt>, <tt>failed</tt>, or a provider-namespaced finish reason.</td>
            </tr>
            <tr>
              <td align="left">response_ref</td>
              <td align="left">object</td>
              <td align="left">provider_reported</td>
              <td align="left">Digest-only or pairwise reference to a provider response identifier, for later correlation. Raw provider request and response identifiers <bcp14>SHOULD NOT</bcp14> be disclosed across parties by default.</td>
            </tr>
            <tr>
              <td align="left">reasoning_state_ref</td>
              <td align="left">object</td>
              <td align="left">provider_reported</td>
              <td align="left">Typed reference or digest of an opaque provider-issued reasoning-continuity artifact, when one is returned. Treated as opaque; this document neither defines nor requires disclosure of internal reasoning.</td>
            </tr>
            <tr>
              <td align="left">source</td>
              <td align="left">object</td>
              <td align="left">—</td>
              <td align="left">Field to source label mapping; see Conventions for the omitted-entry default.</td>
            </tr>
          </tbody>
        </table>
        <t><tt>reasoning</tt> <bcp14>MAY</bcp14> carry configuration metadata such as <tt>mode</tt>, <tt>effort</tt>,
<tt>summary</tt>, or a provider-namespaced equivalent. It <bcp14>MUST NOT</bcp14> carry hidden
chain-of-thought text, and a verifier <bcp14>MUST</bcp14> treat any text-valued member of
<tt>reasoning</tt> as a profile violation of the base profile's data-admission
tiers. A provider-issued opaque reasoning or thought signature <bcp14>MAY</bcp14> be
referenced through <tt>reasoning_state_ref</tt> when the producer needs to bind
the exact state token that was returned.</t>
        <t>The field names describe semantics, not a vendor API. An adapter <bcp14>MAY</bcp14>
preserve additional provider fields under a provider-controlled namespace,
subject to the base profile's data-admission rules. <tt>resolved_model_id</tt>
complements, and never replaces, <tt>model_id</tt> at the <tt>model_attestation</tt>
level: the former is what the provider said it served on this call, the
latter is the identity the producer records for the epoch.</t>
      </section>
      <section anchor="hardware">
        <name>compute_attestation.hardware</name>
        <table>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">Type</th>
              <th align="left">Req</th>
              <th align="left">Meaning</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">platform</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Platform enum (e.g., intel-tdx, amd-sev-snp, apple-silicon).</td>
            </tr>
            <tr>
              <td align="left">accelerator</td>
              <td align="left">string</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Accelerator or GPU name as reported.</td>
            </tr>
            <tr>
              <td align="left">memory_bytes</td>
              <td align="left">integer</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Unified or accelerator memory in bytes.</td>
            </tr>
            <tr>
              <td align="left">inventory</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Coarse CPU/firmware topology details.</td>
            </tr>
            <tr>
              <td align="left">source</td>
              <td align="left">object</td>
              <td align="left">
                <bcp14>OPTIONAL</bcp14></td>
              <td align="left">Field to source label mapping; see above for the omitted-entry default. Hardware is <tt>os_reported</tt> at best without a corroborating <tt>attestation_refs</tt> entry.</td>
            </tr>
          </tbody>
        </table>
        <t><strong>Never-enters.</strong> Device serial numbers, platform UUIDs, MAC addresses, and
other stable device identifiers <bcp14>MUST NOT</bcp14> appear in <tt>hardware</tt>, in clear or
as a digest: they are stable identifiers of small effective entropy and
re-identify a person's machine (base profile, "Data-Admission Tiers"). A
producer that must later show "this was my machine" <bcp14>MAY</bcp14> carry a salted
digest of such an identifier under an explicitly opt-in, namespaced field
whose salt the producer retains; this document does not define that field.</t>
      </section>
      <section anchor="attestation">
        <name>compute_attestation.attestation_refs</name>
        <t>This document defines no attestation format. Where hardware or platform
attestation exists, the Capsule cites it by a typed digest reference
<xref target="I-D.mih-sokolov-scitt-payload-binding"/> — <tt>{type, purpose, digest_alg,
digest}</tt> — where <tt>type</tt> resolves in the shared Artifact Type Registry to
the foreign record's declared digest context:</t>
        <sourcecode type="json"><![CDATA[
{
  "type": "example.tdx-quote-v1",
  "purpose": "hardware",
  "digest_alg": "SHA-256",
  "digest": "e3b0c442…b7852b855"
}
]]></sourcecode>
        <t>Verification of a cited attestation record is performed by the verifier
that record's issuer publishes, never by a re-implementation in this
profile's verifier. The result feeds this block as follows:</t>
        <ul spacing="normal">
          <li>
            <t>If the cited record verifies and binds <tt>weights_digest</tt>, <tt>runtime_digest</tt>,
or platform measurement values equal to those carried here, the verifier
<bcp14>MAY</bcp14> report those fields at source <tt>attested</tt>, at the grade the foreign
verifier reports. A foreign verifier's intermediate grades <bcp14>MUST</bcp14> be
carried through, not collapsed to a boolean.</t>
          </li>
          <li>
            <t>If the cited record does not verify, is absent, or binds different
values, no field in this block is upgraded, and the verifier <bcp14>SHOULD</bcp14>
report the citation as present-but-not-verified with the reason.</t>
          </li>
          <li>
            <t>A cited record <bcp14>MUST</bcp14> be carried byte-identically; it is never re-minted or
re-signed by the Capsule producer.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="cddl">
      <name>Formal CDDL Specification</name>
      <t>The following CDDL <xref target="RFC8610"/> grammar formally specifies the payload
schema:</t>
      <sourcecode type="cddl"><![CDATA[
model-attestation-block = {
  ? "model_id"            => tstr,
  ? "provider"            => tstr,
  ? "model_revision"      => tstr,
  ? "weights_digest"      => weights-digest-claim,
  ? "quantization"        => tstr,
  ? "decoding"            => decoding-params,
  ? "source"              => source-map,
  ? "compute_attestation" => compute-attestation-container,
  ? "epoch_consistency"   => "consistent" / "inconsistent"
                             / "unknown",
  * tstr                  => any
}

source-label = "self_reported" / "provider_reported" / "os_reported"
             / "computed" / "attested" / tstr

source-map = {
  * tstr => source-label
}

weights-digest-claim = {
  "digest_alg" => tstr,
  "digest"     => tstr,
  "scope"      => "file" / "tensors" / tstr
}

decoding-params = {
  ? "temperature" => float / int,
  ? "top_p"       => float / int,
  ? "seed"        => int,
  * tstr          => any
}

compute-attestation-container = {
  ? "runtime"          => runtime-claims,
  ? "agent_runtime"    => agent-runtime-claims,
  ? "invocation"       => invocation-claims,
  ? "hardware"         => hardware-claims,
  ? "attestation_refs" => [* foreign-attestation-ref],
  * tstr               => any
}

runtime-claims = {
  ? "name"               => tstr,
  ? "runtime_digest"     => tstr,
  ? "measurement_class"  => measurement-class-label,
  ? "platform_integrity" => { * tstr => any },
  ? "source"             => source-map
}

agent-runtime-claims = {
  ? "agent_type"   => tstr,
  ? "framework"    => tstr,
  ? "runtime_env"  => tstr,
  ? "sandbox_type" => tstr,
  ? "tool_version" => tstr,
  ? "source"       => source-map
}

invocation-claims = {
  ? "requested_model_id"  => tstr,
  ? "resolved_model_id"   => tstr,
  ? "service_class"       => tstr,
  ? "backend_fingerprint" => tstr,
  ? "reasoning"           => { * tstr => tstr / int / float / bool },
  ? "usage"               => { * tstr => uint },
  ? "finish_status"       => tstr,
  ? "response_ref"        => { * tstr => any },
  ? "reasoning_state_ref" => { * tstr => any },
  ? "source"              => source-map
}

measurement-class-label = "self_measured" / "os_measured"
                        / "tpm_measured" / "app_attested"
                        / "mda_measured" / "tee_measured"
                        / tstr

hardware-claims = {
  ? "platform"     => tstr,
  ? "accelerator"  => tstr,
  ? "memory_bytes" => uint,
  ? "inventory"    => { * tstr => any },
  ? "source"       => source-map
}

foreign-attestation-ref = {
  "type"       => tstr,
  "purpose"    => tstr,
  "digest_alg" => tstr,
  "digest"     => tstr
}
]]></sourcecode>
    </section>
    <section anchor="epochs">
      <name>Relationship to Epochs</name>
      <t>The base profile's epoch-boundary Capsule records a macroscopic
configuration shift across a registry or agent lifecycle. This block
records the configuration in force for one action. The two <bcp14>MUST NOT</bcp14>
contradict: a Capsule whose <tt>model_attestation</tt> names a model different
from the one the prevailing epoch-boundary Capsule opened is either a
producer defect or an unrecorded epoch change, and a verifier <bcp14>SHOULD</bcp14>
report <tt>epoch_consistency: inconsistent</tt> regardless of what the producer
stated. A producer that populates <tt>epoch_id</tt> <bcp14>SHOULD</bcp14> carry this block in
the epoch-boundary Capsule with <tt>source</tt> labels, so the transition is
commit-addressed as the base profile intends.</t>
    </section>
    <section anchor="verification">
      <name>Verification</name>
      <t>This extension adds no additional verification semantics beyond the base
profile's Class 1 and Class 2 verifier checks (Sections 6 and 8.2 of
<xref target="I-D.mih-scitt-agent-action-capsule"/>) on the sealed AAC record. When this
extension is implemented, a verifier <bcp14>MAY</bcp14> apply the checks below.</t>
      <ol spacing="normal" type="1"><li>
          <t>Validate field shapes against <xref target="cddl"/> and the <tt>source</tt> map; a field
without a source entry is <tt>self_reported</tt> per <xref target="block"/>.</t>
        </li>
        <li>
          <t>For each entry in <tt>attestation_refs</tt>, resolve <tt>type</tt> per
<xref target="I-D.mih-sokolov-scitt-payload-binding"/>; if resolvable and the record
is available, invoke the issuer's verifier and record its result and
grade.</t>
        </li>
        <li>
          <t>Derive per-field grades per <xref target="model-attestation"/>, never exceeding the
stated source and the foreign verifier's result.</t>
        </li>
        <li>
          <t>Report <tt>epoch_consistency</tt> from the ledger context when available.</t>
        </li>
        <li>
          <t>Report unknown <tt>measurement_class</tt> or source labels as unrecognized,
never as equal to or higher than a known class or label.</t>
        </li>
        <li>
          <t>Treat <tt>agent_runtime</tt> fields (<xref target="agent_runtime"/>) as self-reported by
default and never infer confinement strength from <tt>sandbox_type</tt>'s
value; this document ranks no sandbox mechanism against another.</t>
        </li>
        <li>
          <t>Treat <tt>invocation</tt> fields (<xref target="invocation"/>) labelled <tt>provider_reported</tt>
as the provider's claim preserved by the producer: a verifier <bcp14>MUST NOT</bcp14>
report a <tt>provider_reported</tt> value as <tt>computed</tt> or <tt>attested</tt>, and
<bcp14>MUST NOT</bcp14> report <tt>resolved_model_id</tt> as establishing model identity on
its own.</t>
        </li>
      </ol>
    </section>
    <section anchor="epistemic">
      <name>Relationship to evidence stores and epistemic typing</name>
      <t>A local evidence store <bcp14>MAY</bcp14> preserve these fields as evidence about the
execution environment. The source labels in this document describe how a
specific field value was obtained and are intentionally narrower than a
general evidence taxonomy. An implementation that maps them onto a wider
taxonomy <bcp14>SHOULD</bcp14> do so without silently upgrading them, for example:</t>
      <ul spacing="normal">
        <li>
          <t><tt>self_reported</tt>: a producer claim;</t>
        </li>
        <li>
          <t><tt>provider_reported</tt>: a claim returned by a remote provider or API and
preserved by the producer;</t>
        </li>
        <li>
          <t><tt>os_reported</tt>: an observation attributed to an operating-system source;</t>
        </li>
        <li>
          <t><tt>computed</tt>: a deterministic derivation over identified bytes; and</t>
        </li>
        <li>
          <t><tt>attested</tt>: a claim supported by a separately verified attestation
record.</t>
        </li>
      </ul>
      <t>Tool-call content, tool-call result content, prompt and context material,
intentionally emitted rationale artifacts, human reports, semantic
judgments, outcome adjudications, and regulatory obligation results are
outside this block even when they concern the same action. They belong to
separate records or extensions and may be linked by typed references.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All claims in this block outside of an independently validated
<tt>attestation_refs</tt> record are assertions made by the Capsule producer. The
function of this profile is not to make those claims true but to make them
specific, signed, and non-repudiable under the AAC verifier acceptance
path. A producer that later serves a different model than it claimed has
signed the discrepancy. Claims about which arithmetic ran (quantization,
precision) cannot be verified from any record the producer alone signs;
systems that need that assurance obtain it by redundancy or hardware
attestation, outside this document. The same honesty-of-source discipline
applies to <tt>agent_runtime</tt> (<xref target="agent_runtime"/>): <tt>sandbox_type:
"unconfined"</tt> is exactly as signed and non-repudiable as any other value,
which is what lets a forensic reviewer later distinguish an unconfined
sandbox that was disclosed from one that was silently omitted.</t>
      <t>A verifier <bcp14>MUST NOT</bcp14> round up: an unknown <tt>measurement_class</tt>, an
unresolvable <tt>attestation_refs.type</tt>, or a <tt>source</tt> label it does not know
is reported as unrecognized, never treated as the highest grade the
verifier knows. This rule exists because the failure it prevents — a
forged grade string accepted by an old verifier — is otherwise cheap.</t>
    </section>
    <section anchor="privacy-considerations">
      <name>Privacy Considerations</name>
      <t>Every field in this block is subject to the base profile's data-admission
tiers (clear-safe, digest-only, never-enters) and its default-deny
posture: producers and adapters <bcp14>MUST</bcp14> classify each candidate field before
admission, and <bcp14>MUST NOT</bcp14> admit a field merely because this document does
not mention it.</t>
      <t><tt>model_id</tt>, <tt>provider</tt>, and <tt>decoding.seed</tt> are deployment or run
parameters and clear-safe: they describe the model and its configuration,
not a person. <tt>weights_digest</tt> and <tt>runtime_digest</tt> are digests of
software artifacts and carry no end-user privacy exposure on their own; a
producer <bcp14>MUST</bcp14> still ensure the artifact digested does not itself embed
tenant- or user-identifying material — a model fine-tuned on a single
tenant's private corpus is itself a sensitive artifact, and digesting it
does not launder that sensitivity, so <tt>model_id</tt> and <tt>weights_digest</tt> for
such a model are tier-appropriate to the tenant's own data, not
automatically clear-safe.</t>
      <t><tt>agent_runtime.agent_type</tt>, <tt>.framework</tt>, <tt>.runtime_env</tt>, and
<tt>.sandbox_type</tt> are ordinarily deployment constants and clear-safe.
<tt>agent_runtime.tool_version</tt>
is clear-safe only when the tool package identifier or digest does not
itself encode end-user or tenant-identifying information (for example, a
tenant-named internal tool, or a per-tenant container image tag); a
producer whose tool naming does so <bcp14>MUST</bcp14> treat the field as digest-only or
omit it. A producer for whom <tt>agent_type</tt>, <tt>framework</tt>, <tt>runtime_env</tt>, or
<tt>sandbox_type</tt> varies per end-user request or per tenant (for example,
per-tenant sandbox images keyed to a customer) <bcp14>MUST</bcp14> re-evaluate that
field's tier rather than relying on the clear-safe default stated here,
since a per-tenant value is then itself a tenant-correlation handle.</t>
      <t><tt>hardware.inventory</tt> is intentionally constrained to prevent device
fingerprinting: device serial numbers, MAC addresses, platform UUIDs, and
other persistent hardware identifiers <bcp14>MUST NOT</bcp14> appear in
<tt>compute_attestation</tt>, in clear or as a digest, per <xref target="hardware"/>.</t>
      <t>No field defined in this block is an end-user or session identifier at
any tier; none should be added without also updating this section.</t>
    </section>
    <section anchor="impl">
      <name>Implementation Status</name>
      <t>This section records the status of known implementations of this block at
the time of posting, per <xref target="RFC7942"/>. It is to be removed before
publication as an RFC.</t>
      <t>Mesh-LLM capsule plugin (Apache-2.0, Rust and Python): a producer at the
inference boundary of a peer-to-peer model-serving network. It writes
<tt>compute_attestation.runtime</tt> with a SHA-256 digest of the serving binary
and a <tt>measurement_class</tt> of <tt>os_measured</tt> where the host operating system
can report it and <tt>self_measured</tt> otherwise, and records serving provenance
(serving node, requesting party, token usage, generation parameters) under
a namespaced member of <tt>compute_attestation</tt>. Quantization and hardware
facts the host does not expose are recorded as absent, never fabricated.
A name hash is recorded under a field name that says it is a name hash,
after an earlier field name that overclaimed a weights binding was renamed.
Its reference library reads <tt>model_attestation</tt> in its verifier, ledger,
disclosure, and viewer paths.</t>
      <t>capsule-emit (Apache-2.0, Python): the reference emitter and verifier
treats <tt>model_attestation.compute_attestation</tt> as the extension container
for runtime and compute facts, and other extensions (for example the
OpenTelemetry correlation block of draft-palanisamy-scitt-aac-otel) are
placed there today.</t>
    </section>
    <section anchor="registration">
      <name>Conformance Vectors</name>
      <t>This is a tier-2 (per-profile) extension in the sense of
<xref target="I-D.mih-agent-accountability-conformance"/>: it defines its own
semantics and must-fail cases on top of the tier-1 binding conformance
that <xref target="I-D.mih-sokolov-scitt-payload-binding"/> (CPB) defines for every AAC
payload member. This document is not itself a binding-layer artifact and
does not register a <tt>type</tt> in the CPB Artifact Type Registry; that
registry governs the <tt>type</tt> field of a typed digest reference — used here
only by <tt>attestation_refs</tt> entries (<xref target="attestation"/>) — a different and
narrower thing than a named payload extension like <tt>model_attestation</tt>
itself.</t>
      <t>As of this writing, the registry structure for tier-2 (per-profile)
conformance artifacts is explicitly not yet specified —
<xref target="I-D.mih-agent-accountability-conformance"/> states plainly that this is
"TBD in a future revision." This document therefore cannot cite a settled
registration procedure for itself, and does not assert one. What it does
provide now, so that registration is a formality once the tier-2 registry
exists rather than a rewrite, is the two-sided conformance-vector set that
document's discipline (Section 5) requires of any record profile:
positive vectors with pinned values, and must-fail vectors that a
conformant implementation <bcp14>MUST</bcp14> refuse rather than merely mismatch.</t>
      <t>Positive vector (<bcp14>MUST</bcp14> be accepted, and graded per <xref target="model-attestation"/>
and <xref target="attestation"/> without exceeding the stated <tt>source</tt>):</t>
      <sourcecode type="json"><![CDATA[
{
  "model_attestation": {
    "model_id":
      "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M",
    "weights_digest": { "digest_alg": "SHA-256",
                        "digest": "1993f98e…", "scope": "file" },
    "source": { "model_id": "self_reported",
                "weights_digest": "computed" },
    "compute_attestation": {
      "runtime": { "name": "mesh-llm-host-runtime 0.76.0",
        "measurement_class": "os_measured" },
      "agent_runtime": { "agent_type": "react",
                         "sandbox_type": "gvisor",
                         "tool_version": "sha256:9b7412f8…" },
      "attestation_refs": []
    }
  }
}
]]></sourcecode>
      <t><bcp14>MUST</bcp14>-FAIL vectors (a conformant verifier <bcp14>MUST NOT</bcp14> grade the field above
what these rules permit):</t>
      <artwork><![CDATA[
// (a) weights_digest present with no "source" entry: MUST default
// to self_reported, MUST NOT be treated as "computed" or "attested".
{ "model_attestation": {
    "weights_digest": { "digest_alg": "SHA-256",
                        "digest": "1993f98e…", "scope": "file" } } }

// (b) unrecognized measurement_class: MUST be reported as
// unrecognized, MUST NOT be treated as equal to or higher than any
// known class.
{ "model_attestation": { "compute_attestation": { "runtime": {
    "name": "custom-runtime 1.0",
    "measurement_class": "quantum_measured" } } } }

// (c) attestation_refs entry whose cited record does not verify: no
// field in the block may be upgraded to "attested" on account of the
// citation.
{ "model_attestation": {
    "weights_digest": { "digest_alg": "SHA-256",
                        "digest": "1993f98e…", "scope": "file" },
    "source": { "weights_digest": "attested" },
    "compute_attestation": { "attestation_refs": [
      { "type": "example.invalid-attestation-v1",
        "purpose": "hardware",
        "digest_alg": "SHA-256", "digest": "0000…" } ] } } }

// (d) agent_runtime.tool_version present with no "source" entry:
// MUST default to self_reported, MUST NOT be treated as "computed".
{ "model_attestation": { "compute_attestation": { "agent_runtime": {
    "tool_version": "sha256:9b7412f8…" } } } }
]]></artwork>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions. <tt>model_attestation</tt> is a bare payload
member name seeded by the base profile itself (<xref target="block"/>), not a
namespaced extension, so the base profile's namespacing convention does
not apply to the member name. Source labels and measurement classes are
closed vocabularies of this document (Conventions and <xref target="runtime"/>); a
future revision may request IANA registries for either if independent
extensions appear. Registration of this document as a conforming tier-2
profile awaits the registry work noted in <xref target="registration"/>.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC8610">
          <front>
            <title>Concise Data Definition Language (CDDL): A Notational Convention to Express Concise Binary Object Representation (CBOR) and JSON Data Structures</title>
            <author fullname="H. Birkholz" initials="H." surname="Birkholz"/>
            <author fullname="C. Vigano" initials="C." surname="Vigano"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <date month="June" year="2019"/>
            <abstract>
              <t>This document proposes a notational convention to express Concise Binary Object Representation (CBOR) data structures (RFC 7049). Its main goal is to provide an easy and unambiguous way to express structures for protocol messages and data formats that use CBOR or JSON.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8610"/>
          <seriesInfo name="DOI" value="10.17487/RFC8610"/>
        </reference>
        <reference anchor="RFC8785">
          <front>
            <title>JSON Canonicalization Scheme (JCS)</title>
            <author fullname="A. Rundgren" initials="A." surname="Rundgren"/>
            <author fullname="B. Jordan" initials="B." surname="Jordan"/>
            <author fullname="S. Erdtman" initials="S." surname="Erdtman"/>
            <date month="June" year="2020"/>
            <abstract>
              <t>Cryptographic operations like hashing and signing need the data to be expressed in an invariant format so that the operations are reliably repeatable. One way to address this is to create a canonical representation of the data. Canonicalization also permits data to be exchanged in its original form on the "wire" while cryptographic operations performed on the canonicalized counterpart of the data in the producer and consumer endpoints generate consistent results.</t>
              <t>This document describes the JSON Canonicalization Scheme (JCS). This specification defines how to create a canonical representation of JSON data by building on the strict serialization methods for JSON primitives defined by ECMAScript, constraining JSON data to the Internet JSON (I-JSON) subset, and by using deterministic property sorting.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8785"/>
          <seriesInfo name="DOI" value="10.17487/RFC8785"/>
        </reference>
        <reference anchor="I-D.mih-scitt-agent-action-capsule">
          <front>
            <title>An Agent Action Capsule Profile for SCITT</title>
            <author fullname="Steven Mih" initials="S." surname="Mih">
              <organization>Action State Group, Inc.</organization>
            </author>
            <date day="26" month="September" year="2026"/>
            <abstract>
              <t>   This document defines a SCITT statement profile for recording what an
   AI agent did: the Agent Action Capsule.  A Capsule is a digest-
   committed record of one agent action carrying its verdict-level
   disposition (executed, blocked, denied, errored, timed out), the
   deterministic constraints that were evaluated, the effect that was
   committed together with a confirmed-effect binding that distinguishes
   a dispatched attempt from an observed result, and an honest human-in-
   the-loop flag.  Capsules are identified independently of signing and
   MAY be authenticated by one or more COSE_Sign1 Producer Envelopes.
   Its Capsule ID can separately be made transparent by registration in
   a SCITT Transparency Service.  A Capsule is recorded on every
   verdict, including refusals: a blocked or denied Capsule is the
   auditor-grade evidence that a gate worked.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-mih-scitt-agent-action-capsule-05"/>
        </reference>
        <reference anchor="I-D.mih-sokolov-scitt-payload-binding">
          <front>
            <title>Canonicalization Declaration for SCITT Signed Statements</title>
            <author fullname="Steven Mih" initials="S." surname="Mih">
              <organization>Action State Group, Inc.</organization>
            </author>
            <author fullname="Anton Sokolov" initials="A." surname="Sokolov">
              <organization>Tyche Institute</organization>
            </author>
            <date day="12" month="September" year="2026"/>
            <abstract>
              <t>   Independently written systems that anchor records to a SCITT
   Transparency Service repeatedly need the same construction: a
   canonical form of structured content, a content-addressed identifier
   derived from that form, binding to a SCITT Signed Statement and
   Receipt, and references that cite external artifacts by digest.  This
   document, referred to as CPB, specifies that construction as
   declarations rather than as a payload format.  A payload profile
   declares its canonicalization algorithm and exclusion set and thereby
   obtains a reproducible derived identifier.  A CPB Signed Statement
   carries either the complete statement content as specified by RFC
   9943 or a digest of content held elsewhere using the COSE Hash
   Envelope of RFC 9995.  CPB also defines an abstract typed digest
   reference information model and one optional protected-header
   encoding, cpb-refs; a payload profile may instead define its own
   reference serialization.  An IANA registry assigns the
   canonicalization algorithm identifiers that these declarations name.
   CPB does not define payload content formats, establish or require a
   universal artifact-type registry, or require either typed-reference
   carrier.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-mih-sokolov-scitt-payload-binding-05"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC7942">
          <front>
            <title>Improving Awareness of Running Code: The Implementation Status Section</title>
            <author fullname="Y. Sheffer" initials="Y." surname="Sheffer"/>
            <author fullname="A. Farrel" initials="A." surname="Farrel"/>
            <date month="July" year="2016"/>
          </front>
          <seriesInfo name="BCP" value="205"/>
          <seriesInfo name="RFC" value="7942"/>
          <seriesInfo name="DOI" value="10.17487/RFC7942"/>
        </reference>
        <reference anchor="RFC9334">
          <front>
            <title>Remote ATtestation procedureS (RATS) Architecture</title>
            <author fullname="H. Birkholz" initials="H." surname="Birkholz"/>
            <author fullname="D. Thaler" initials="D." surname="Thaler"/>
            <author fullname="M. Richardson" initials="M." surname="Richardson"/>
            <author fullname="N. Smith" initials="N." surname="Smith"/>
            <author fullname="W. Pan" initials="W." surname="Pan"/>
            <date month="January" year="2023"/>
            <abstract>
              <t>In network protocol exchanges, it is often useful for one end of a communication to know whether the other end is in an intended operating state. This document provides an architectural overview of the entities involved that make such tests possible through the process of generating, conveying, and evaluating evidentiary Claims. It provides a model that is neutral toward processor architectures, the content of Claims, and protocols.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9334"/>
          <seriesInfo name="DOI" value="10.17487/RFC9334"/>
        </reference>
        <reference anchor="RFC9943">
          <front>
            <title>An Architecture for Trustworthy and Transparent Digital Supply Chains</title>
            <author fullname="H. Birkholz" initials="H." surname="Birkholz"/>
            <author fullname="A. Delignat-Lavaud" initials="A." surname="Delignat-Lavaud"/>
            <author fullname="C. Fournet" initials="C." surname="Fournet"/>
            <author fullname="Y. Deshpande" initials="Y." surname="Deshpande"/>
            <author fullname="S. Lasker" initials="S." surname="Lasker"/>
            <date month="June" year="2026"/>
            <abstract>
              <t>Traceability in supply chains is a growing security concern. While Verifiable Data Structures (VDSs) have addressed specific issues, such as equivocation over digital certificates, they lack a universal architecture for all supply chains. This document defines such an architecture for single-issuer signed statement transparency. It ensures extensibility and interoperability between different transparency services as well as compliance with various auditing procedures and regulatory requirements.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9943"/>
          <seriesInfo name="DOI" value="10.17487/RFC9943"/>
        </reference>
        <reference anchor="I-D.mih-agent-accountability-conformance" target="https://datatracker.ietf.org/doc/draft-mih-agent-accountability-conformance/">
          <front>
            <title>Agent Accountability: A Conformance and Verification Method</title>
            <author initials="S." surname="Mih" fullname="Steven Mih">
              <organization>Action State Group, Inc.</organization>
            </author>
            <date year="2026" month="July" day="31"/>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-mih-agent-accountability-conformance-00"/>
        </reference>
      </references>
    </references>
    <?line 744?>

<section anchor="fix-to-the-base-profile">
      <name>Fix to the base profile</name>
      <t>Revisions -04 and -05 of draft-mih-scitt-agent-action-capsule reference
<tt>model_attestation</tt> in their epoch-boundary section and their security
considerations without defining it, while producers and a registry entry
already use the block. This document supplies the definition (<xref target="block"/>,
<xref target="model-attestation"/>). The authors recommend that -06 of the base profile
(a) cite this document for the definition or fold <xref target="block"/> in, and (b)
name the two extension containers explicitly: namespaced top-level members
for correlation/provenance extensions, and
<tt>model_attestation.compute_attestation</tt> for runtime and compute
extensions. Until (b) lands, implementations place namespaced extensions
under <tt>model_attestation.compute_attestation</tt> as well (see <xref target="impl"/>).</t>
    </section>
    <section anchor="example">
      <name>Complete Example</name>
      <t>The following is an example of a complete <tt>model_attestation</tt> object:</t>
      <sourcecode type="json"><![CDATA[
{
  "model_attestation": {
    "model_id":
      "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M",
    "provider": "mesh-llm",
    "weights_digest": {
      "digest_alg": "SHA-256",
      "digest": "1993f98e…04724b12",
      "scope": "file"
    },
    "quantization": "Q4_K_M",
    "decoding": {
      "temperature": 0.0,
      "seed": 42
    },
    "source": {
      "model_id": "self_reported",
      "weights_digest": "computed",
      "quantization": "self_reported"
    },
    "compute_attestation": {
      "runtime": {
        "name": "mesh-llm-host-runtime 0.76.0",
        "runtime_digest": "c204ac76…4f23b723",
        "measurement_class": "os_measured",
        "platform_integrity": {
          "sip_enabled": true
        },
        "source": {
          "sip_enabled": "os_reported"
        }
      },
      "agent_runtime": {
        "agent_type": "react",
        "framework": "custom-agent-loop 1.4.0",
        "runtime_env": "python:3.11-slim",
        "sandbox_type": "gvisor",
        "tool_version": "sha256:9b7412f8…12345678",
        "source": {
          "agent_type": "self_reported",
          "framework": "self_reported",
          "runtime_env": "self_reported",
          "sandbox_type": "os_reported",
          "tool_version": "computed"
        }
      },
      "invocation": {
        "requested_model_id": "hermes-2-pro-7b",
        "resolved_model_id":
          "bartowski/Hermes-2-Pro-Mistral-7B-GGUF:Q4_K_M",
        "usage": { "input_tokens": 412, "output_tokens": 88 },
        "finish_status": "completed",
        "source": {
          "requested_model_id": "self_reported",
          "resolved_model_id": "provider_reported",
          "usage": "provider_reported",
          "finish_status": "provider_reported"
        }
      },
      "hardware": {
        "platform": "apple-silicon",
        "accelerator": "Apple M4 Max",
        "memory_bytes": 28991029248,
        "source": {
          "platform": "os_reported",
          "accelerator": "os_reported",
          "memory_bytes": "os_reported"
        }
      },
      "attestation_refs": []
    },
    "epoch_consistency": "consistent"
  }
}
]]></sourcecode>
    </section>
    <section anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>The authors thank the maintainers of the Mesh-LLM capsule plugin, whose
shipping <tt>runtime</tt> measurements fixed the first two measurement classes,
and the reviewers of the RATS architecture whose grading discipline
<xref target="attestation"/> follows.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA81923bbVpbg+/mKM/RDxCyClmTFF7qrqhXbSdQTOy7LTk+v
WlkiSIAiyiCAAkDJbEW16iPmA+apP2Q+pb5k9u3cAFCWM7VqxjNdEUngXPbZ
99uJoki1WZunMz16v071pkzS/CJu27Rp4zYrC/1tXi4/6lVZ69PLtGj16ZK+
fhFXzTZPm5l+ja9M9Ltt0WabdKLjItE/xHVyHdepfpHH2aYZqXixqNMrmOT0
9EV/kpFKymURb2AVSR2v2qiK87jImnizi5pl1rZRHC+jmmeIDg/VMm7Ty7Le
zXTTJiqr6plu623THh8ePjs8VjBzPNPn6XJbZ+1OfUx312WdzPSfzl+cvX8P
S8SdTPSS9zDpL2iia7Odqi6v0iIulukvCn4tkos4LwtY6S5tVJXBoG25nOim
rNs6XTXw126Df/yi4m27LuuZ0pHOCgDU91P91u5Laa15x9+XV1mRxHX8587P
ZX0Jn/6TFgSQOyuStErhf4p2hD+nmzjL4fuiusQRWhwhLv71Er+eLsvNyE58
PtWvs7Wb8bxNYUvmu3AaOd5zgEOqv6/LbTXRZ8Vy6s3Y0Ov/GtOTCLB0Gmeq
KOsNjHGVwob1u+9ePH18dGj+fPL0G/zzLHo53WRrc6R4CBGPEslRBE+VH8u8
vJKnq3iXl3ESLQBWWXE5U1mx6sz45NnJsfz57NGjE/Pns5NH/rBm2mUJJxwv
shwwJFqWPBqcMj6rtaEJg/P+0wAk/cK9QAj/c1pnq2zJJPM6hYNPRjxQXF+m
7Uyv27ZqZg8fJjEArI6XH9N6mqXtagrgfwjY/5AR/z4rfEgDW+yif72Tpn9D
x03/YNK7j1rDOuHV48Pjx9Hhk+jREX3ZwC7TBiFv5j0r2rQu0jZ6ics35Huf
XSAZqyiKdLxoECCtUu/XWaMBFtsNAj1JV1mRNroFtjTvUehcL4gxlSt6wOdN
SniTPgBmM0YCXmXw6e9/+58aCDOtU5g90e11Bme32NHri7hJ7YOLbasLAFmt
eAkJPlLzAHDWE32dteus0BmwEFocEFu1bdNwebDVNoa3a3gmblWcA09KdsBz
aoSh4S86/dSmRYOEBCdIw62yNAde1RpuHAHUgb4vlWVJ+BOB96tGl9cFjAGc
js4yLa6yuiwIfgdxvVxnbbpst3Wc6wpXVxcTVcLXKYKc3ljVgCPAHT8C44LN
LcpPuHLc9oZ4ZFZclR8RBGWZa4AJLnVMTF6ty6bVa+H0sKoSEB0AReDhpRNp
XKfZ5bpt9JJEwVS/glF2/MlCI8ZNVHkGpJ7v4OTh1zpNVFNu62X6XMc4M9AX
DH5Zx0lqBsPjW5fXCJAdzANnVC4QWrBenJkPEdAVlg1jwJ7L4tKMgcfCAE+v
sgRxQjfbqgI2Dmu08gvEXpXHLSKtCuTD9RpIqqrThqEEKwJQJ7ggPHhC/SSB
nxv40mIdwEjHCgYDkBTal7J1ugQJRauWrSYMR0Qe+VVO24BiqhQT0CZLkjxV
6gFSY10mW6YCdVowlmjmsTIKDAyIBlsfEudCMrAdxineUaz4NAEBC0BEg/8A
0SpdItsLEdXJzqxt0nxlcWixU7FZExDbEqCjw3EGMXmi4XOAbFP1/ro04ruR
jeHMRbnJijgHHMIjbYEh57J7OCCYO8lWcBQ46TURJdAGPb2OKxCtsEQWsTgU
zMm7BmpZfqzKDBfyl20Mo/6n4IAQjAoIpqwJqYRUkD/FTDwVMH3Yu6NeA5fn
BNASuE6sBA+Iq8HBB1CIUQtDZrGEHV9lKSA8bqooW92mOWxUjiEB/GgV8vwW
yLvcwA/IoeCvrDGUzN8XelvI4hOzm6l+32GI6ubm85L79laOgRk2/wggSuMc
DrmFiRKgRVhuWeCpCAz1zY3oB7e3rDm+Pv0PGOgyAyWjRvyxmHn2UscNELNV
guDYgIkVTQUIATtF0tKk3/GgKPdhUe/tI8sdaISAoMhQYImKd5GUoNQUfMiN
Ngx/SCwgO7C0GaxDmePihdeCHkg5qAADlh8hWvCfx5aAJ3wKOJEhcIUEvtgB
X5jqM9h8WpVL4KXpco164caCGBeWw0qZV19uhZk3azj5BtC6LmEmQfypPs0R
vS7X/T1ZzoT8cUDIKhKySMggl+EhxDXkkvmOsXED9EUwy/Bx4EhEl6gV1gBV
2MCGpM5Uf5fVDYlLYi0i8pDPGL3OfhmVRb6bqSGJn4OuZ8WkwYt/O//pDfzy
Efk4CpaSZJAMqzbpZgEfUXR3Nw/sFCwEgtvoFc/OWspIk1Lb8JkCf7AKhVs5
8YOGcGJoPaIqBHBry+1yrfDRt8SkYVmviqs0LytcCiwKRTWg1hr0BESO63W2
7B8Z4IhddW8cYCS1fXIEPDNPUFSWTPawfEAJJJt1naYKUJdk74EZ79H0aDxF
mJSo5HSO6vWH8/f6zU/vNaKicDFcl3LQ3IvqohYzOzXTNfoxgejp9HgMEl5Z
CU9Qt1DLNlVOnBVhCRZW3DKDYe0vRnQQO6AExq8Obm7ol9vbMTKyYAvAiUoc
D8CBYwNugtnVghUpfAREvzJUvdw9xwnh/QY2B7OTCLpGgpZzRlU1RYwERQUQ
fwhfM6SqBeJIW1ZRDviZG8TUgpiooU9oo7HCv4FVoXIKBqYsf1XmeXndGEa+
ghN04hLOlI7JUxn9M9FG6SQyb/DxQUV6J8IG0YPXS8tSpCJPrHRiQgfRCIA5
IP1XGFS0AB0fLNidBU4jKEU0UCh80ljjaDo1IJ2ZZTVjNJ1p5TgngcwuWlQ5
jxnbnYlmAYOsGWWAbaa4NpD/TES1gaA1KIhxZWxRKMe1yLcR8/R9pi+L2QLO
TPzpQBKxroWTwtvptfbOj093+ptMmokGwQTgARmZkuhsS1WltchbXAlLSma/
9FDPVnAqGGsaVq9SoUYBwxidilCL+BDxlMao0szLQL0QrQ+B9zmLB6hQnhA6
NPSK9AQaAaj2CXAqYkYZYUPAQg2N4PJAdIMal1XEkGF6QByguUSxfscmAYGL
gHMwF3XkIkvmY4I/ykjYHRgNqHNXdVbAaEy/ayCzBjASxDdbGiAqhUsRNtQp
8gRWXElKi81GdE0WCJomxr5JsksYTcvGgYaBNcDPuBP4xFgLLyprhtgRNmnc
bGvmcrhK0brd0dQlMAhUMtDHBaO4MZo2y3OCMBKM2COwFPi+AGKmM+VzdmqG
iDfFAgZggEhGsgL3H/Jh0S9h3DIHXJBtIydBmqaBjJnGIoJhhiMCb94W8iLI
EytAgieMQsUWpX1mW7GNRhrqxwK1IjHaUMvjL5BHCoExciHkWVY0AWOACfN4
KWTS0QCIf6lNDJYyINFuhssySpZHdGJuZsQsYKvEMgpjWAEgQUuu0T1G/LFZ
gixOmDuzKgygY1WOUBq09xg0DXgyZJ9Gz5ga5gBIjDjz7tWLn16/fvXm5auX
LCvevfrjh7N3+AmY680Nk75Hi7e3LAz2cGfHYa3CLhYeCcKM1VdcKtnlPRUA
hEHEwpMYMcF0ivYnsHa0Oki64+svLZNtmBQ/op1Oc45wtNGE/4uj4t9mX/j3
+Q+nP/5o/1DyxPkPP3348aX7y71pQYQfcZXBV2oEhsWINzX66e37s5/enP44
Yt3N59AsrEGWaJQjNRwVkjIYHsA/lnW2YOv52xdv//f/OjoBQ+O/gaVxfHT0
DCwN/vD06MkJfED3AM+G6qx8RDeFQkszJhMUmSqwq6wFxWSCxNCsEa9JdCn1
9Z8QMr/M9L8sltXRye/lC9xw8KWBWfAlwaz/Te9lBuLAVwPTWGgG33cgHa73
9D+Czwbu3pf/8gcyY6Kjp3/4vVKGACZ9FXnCyDzZg9PyPVDMRImI0E5EAOh3
SJHCoq3VwyeELtkoTsA6JjRvM3IX1anaNnT21irM0F69lymMzMx79C5P9u0t
cF0iXVznz9Y2xCFeGc8UoiWtRowN4PLAxkAisKn76JHgXE2sibxLQ24rUlqz
ZrlFtxTg2Dkz7jxepPlMoV+bIhwgdkCtSPRVuYwX2xzBzC45ZFmsBRNDBP55
FedbMDtiVBdI+CfoGUbd7MJKzwOwBVKRo0YTQS5ZrlqUbmOOsaBKaN+BMQ6A
9La1lYXAXcFAEulsnkdTw2g8p2/PDHcN9EYYyug0zs+St6IxwORl4y3VE/kE
aHQ7wQiAgPg8rnoHB7WB16ycP1jG+RKg5L1lJyStnex5YJQwzhr09DH5iPhU
6PV6V7UliLdqjZ4R4BaE3EYxMr7PeJHbw4WR+s5DULROkyRjQ4jPtGGevUg9
3RSOnT2wcxbbc7CDqj4jPADhv09NZUsGEVR0whTk5x43eLNdROXiz6Drja0t
QxiMChYQVrzNW5C6K1KwaCWAShugE9QJSDEn4wZ0IbLZ0GhFnZGc755bmPZJ
5qEivYVeAvwU1QRengdIORfjoBZTjjUZYNbwMJER7i4We4EIi7U5CzReFTNz
kIDAo66NxSgKE48IiKMcDEhK3hVnvXnA5qtSpz11GF1j6DDfkcpozcdk6Iw8
pVt1VWiEdJ9H+j6U0Eid8b585x28SQ49/W8vzn0fHlHgsiSjGInBV8d95VLt
M/KHvA6A8KjBwyJQ7QpcCoHSuAKlyjPQQfFMkZjSZQysU85GNGQ4h1/1d3SE
v+r3IBvgP+/Sv8D/vk5j0uF+hQdm6F0f/g/8alQ0+A7UcXrHl4Tw6TxN9aB2
NqUBLBfzBjAi8vNv8/ToCCZI/aYxxHS5ELn4q2Ys/aIxfJf4b1sFyJYy4Zd+
w/xC4cPv8hGDQtd4kg7ZTAXzPQfZAYS+AHQlzEK6ENYTMZ8R/sQTDbC3PbO+
sIYwDitW40N5X+zsjomME7AGg95T9H6jv3oYnPYJCs/5n2A2Yy7B+DReI8Or
Bw84UwMwHIm6AVbThylp6UAsG3mGNR+CDFnREtUjeU5avhdQHXDTGAPL+IPE
UEVG5qnBhWeZAPsQBZQfUChdiCcN6337CfltWvNZatZymvsT95fQeCBVAmVi
4mT8rwJ68irEje5qGYIi92ILnQl7cwzpRqy0fAHf2D/JWxk+wvHxiQiwgX0W
Zswv4C1GiQqmmN/wOxdxfjkRnX3CRvXtnN0q4lSROe7NiDrbGpz9j/4wzC8O
0unldKL/eHLx3y9ej+/FtEIN+Ff9A6BmDYIYEKBFwprfwIGQUrnl2Hl1UWG0
LE1u50Su3wF45yEM5xNQPxAKc6vWpRm5OeZIbHN9ILAmEGGuBotqse1ZDQXs
Mx4p1E2btqzBhhnjac5R6pZ10xkoKyJgB2W9U/w7QnaLSQXoERWzCXVTMnRZ
K5gbeM5RKTVmF4ZClYuFywEJcGP9w/byEr74DpRU/eHd2dj5G2CjnChAzuQu
VICNb4HFOE2G1TH0UxeeIwVVL+CBQaLO9+RTOk83eOTLBpUup1ECk2ItyeQc
YC4Lh5nFs8P6LHmdY9jMp4lkHKSflnCQFClHNcfqjORRWSLWAc8j94/LPFig
5dVmmHWDLO0de+q+iwmxfraLinfwE/nPejzMZ1d0FvJ5RsgYWWQkJjRAoQeE
WzPyVDraGLth8IfIgpmMJX4KTZPx4JCWrq6yGIR4IL69ke1jqBRK8gcTfJ+y
DwLSwkH8n2dsmSLNhafZ8T6ORJLJxCOmBs/tRkl+EpKGd5X/brAe48EcmZj6
TmwDY1KJU5/slwKNdjR1GsnzAQHZIPyyZi0BP6KgnNADDO52DQwjW5KFbVIy
pvpl2kqABUYj3MlaskVp/Q0Ss7/GhoyqLVEgQ5XVnazx8k4UEw1FiQD8KGZR
BSEujySbujB0o8U4ZLnC9qA1bYb0JKcR3Twwao/aE0a4xEy0Jkhl4lCE2UsB
K1wBXXp2VTPTcxGic1R95G9MKtgbGxlP1JzcNxf+m8E35v3BZCs/lAI2/Ryz
OZayBxjIfcRRiBHYpfhCWvkODEukoJVuxRpCnwCOb6IBNLr5AGTErqK5B8ML
zD/l3QQEN9FVvm0IRXuxKtyb+FoKCqErE2UUskOUST/FaKnp+ScQCc06yrNV
utwtgS1cHaF0Qm/Jhfi1MPzizgTpqAvtmMIyebZAMYimmglbeIdp/a6NcaxQ
1hCZj+LmsVD9ioLBIl389QKEFBBhnHu/08ukJOGikd0YXamNlx/Hz7urvWsh
LqNOliNxAZN1wDG4vCwrSolSkmnj4jKUkpPZhCB6kbnBJkYLFqQjZy55mVOY
FaXct7CzOraSeeKy20rS3wfAFdjjvqFtlH8/eQH5xGUB2gSFyBhjjBISLyjo
xCEXRRPPi22ezzlJDiMEFLbOMCAUY+gDBQbJ4yFmMTVhtpsHhgz/AdY6S739
ljofPuAuGhesp3MuntNoZTVOox1SMV9aXYf9tMG4wMQl1peIMu4ifxdLypkY
XuLXaFXS7zCwHy48+JpgLEsS74aoqMYDfIGhjEuKvQ8rqz+da/fIAs9LlLLz
s7cTDtyn+tuyNAP/k0xudS7OaJDLXTjN2fOMFL/Mt6DEsXvPQBeZEZhi7qOa
t9Um+BkWdGHVVPi8SWL/d2JYbZq676a8NSwCaLdWBBKmwqFcA/AwL727EB7I
XwuFFsRDTAy3WWcEHCCGJH3emZUcn7GN3K7jymImUy5lidYpMDfMxc71+5f/
A35cgl7f4Fh375okR7BzbdI/OIeCkzNkr148gJJOPuH6U/RJ489ZrVzyQPoJ
ePlUfxBvBJ1Z6tzR5Knl4ArGiIW3JEaBxjTVmqUgIEowxHN2Rsh4uFi0Pkis
A4I2LkouvJXHIm2KBsuIBJFprLa5BOdsOit8m3O0fT93CsQC8KhQYVDq3wls
w9rIWH+BOOurJ18ugmYu05HkD8q7vfnfFDH2tC725drUVoxg1MDbs8IJLj/L
FbSKIM/Vk2fADcDWRV5EKo1VLWSV4ovPmu4SIjzZpMBdXsYVbOa6tIVHymX9
2niCpP8a+bukrKB1DMduBSWll7scXzWQ9M5hB38vXzVmp7x1E0cKVGi1NzuX
9ZrLLSr598rFtauSrC8vr1dTXu8/wn/NyNXyy0Oi7L2n+Q7WEhgxMWfCuaCH
iZcCB8/444VDt7LG34Dyl/QQiKfiQmwacm1sK5SWTVlfID6m9VzEjUXRPevk
RPY9aE2HSUFawn8baZAc3a6kt1uCxV2CuQN84XD6aEra7RLYSrmJvNGOpifT
Q7NMox4A/u5Z6KvBOg2nIRqKNlS2d3HVDvCvmMG6jqImzza4ugJwZHZ8GMU5
yJLULEoQ6a5jfuFhvss0hnPIOeLZX59ZxiWdFk6+wmwurmrCj2Ct0pocRpv1
IMJfmO0Mr+dnw1NqU0rhOZCstuyy6TOT6WzYjRRneIo4/pBTVYifO1nm/1x1
Zu4obs4GGK9xkLT6ULeo2yhrvps0e8ovRi5odufwP8MSPbKISFAA953bH+dA
2X8uF2PmeJzaxZYnsDTMz0PWy6FEdE2iH4e1LtqyouznHExKororSWRNP61j
+AodZ+Q8oJT4XXSJzkTMD+iwC30AFgq7KCdkrCSwBUIAJLHxXdxEHyA3JSFA
qKoMqIDhAhwxp4t8deR2qYGL1uRpYwpudAeK6A9g5oTZrXAIeRpfkVs7bkrk
qRHQEqV6wKhmbQETg/WANY9e3jZF7ZurZao1p5yloO6ljfMfjEXJ7PM9Gsd+
q7u7SslHw8+aH9PQXOP0WCULAzWL/LCcrAHHKxmXsPUcDqcflzfeAYQp5otk
FWXpYBTdJffrLJk/nFPhhOC0xJaHk+zV6I0bFSlbMsVGM5dyzAqdTeAwJCVI
xyioUL+S7DTKDsV0gG4qLu+UtE3r6UAAkbIco3sZPS8U1G/S6OWbczwfUGjD
BEjONifJ7HRUHZAxTaS6aeiix2pS3eGRLBGpBLbvVioJXeI20iSrdhVRzSZt
Y8xJkrxwdj8nTJ68cVM2Vxi2FOEzeFrsiEZOiWYcVZOku1K0NZPc03EIGx4F
HMoXFzM9cvx7RImIknVN4slW35qF0WIL8QYoSUmPXS4MsR/U5WmcrsjbFo1f
jCRBwCbeKbBA/GxO5K+uTnKCSvsyNZyXM7iMdsr5vYTBeYnmDcKlKANdj4r8
cPTrDJMECk9Xo4wbqtizJXf6tGEc4phk6Og1uTOoy3hwnLOV5ZguWy3BEWyL
nJRcPmm3noWXpgMIi1y5XJS1yTVCT0vf78eSp+f988soXdIEecQ0F8IFgAEq
T4tL2KotUmLRR47x58oIf+ZhvvxntcVzFhPAPE8VaxbAEeDwKwwkpzZFOUiW
t76nuPiIC9jsN8qcsxUsMs/zqtSLcrNJ62UWczEqgV08fuyKPX171uCYG7IF
OelMe+MZasRIdCz5VSYA1KafyFogjQT4KqxLbBnnmrYJaQ3FqZQfnzVWJKcE
GKvC5eARQwO7yrwTGfkOrKupSsoB5LwiqaplvkcWqEtSF5FuXdDW0wlDKouC
Vhqiv/m5iVVI2kyYox46t8KSAnZbZg1P59m+BH7fcc25THCmp3lugiGUR0X0
YVSwIUvn/yK0j3p6+pct+T8uhqL73cAtB9W9NClyPwCIiL1/ZMCJASC57oPj
9lIcJ5+N5HuTurhAo23RqjlHsyLRZrnGse9O/NwKvOC+j5vCoWkiYoE/iwrI
lWaMlyZDVviYKeAMAgpGJeBlLpBZFMkFvHeJedaoUNy1WNTKqxhOzk0K3H7L
Jbt5uTOGe1gQ6UCIkp1L12CxJnpG5GLErK228BmLHKxogL6NcA9wvjShTDdA
uLwDxJSJTleAQ5jisN1s0LlWlXm23IHK9i6+1mSERuUq4hrO1oUyJYWGS51w
ndsGLaIvW+MbzFsWM4taNYBGNAP+B6xsIiwNG6WAmsc1Gt5eWjC2Ckm+wDz/
Zn0hvtEvw7r3SM6FVLDSADNOJs1T8c1ilhN/JGMTtCj6nqwWiw5eSItXI0u1
xEkME2XknSCyPnwqRKUGAHHG0jis43dBPMuM/Yxz5KeYFFyzLZULPuGRei8S
KxK49gZptEvGR6+pKDLIBrjClzI7U2qDEKSq2TOiA7nXnt9TgrzbIazeS9sA
tWuY+JxxhEiUFVsMIeCqUKSJIU4VRo02+dwgIZ33l4d93hH9heS1mHq5omRY
gZbR6FCdI0sNfX52JfuMelS672XP+1Us97Dq7cRzL0M3pHOjQ3CmCppRSPiI
y0z6GJ8Q4r8LrRECwLLQ/6fPPEbAU66zBDBH9fgFKinGXhrIl2bHLTwTETd0
8eBVsDUyZUxV5FUmKpxRBTomX1hRoaiiAhlwF3sEqRxLIWjzsjGpjLKjCKqL
VPm9W9Y11bPPBxB97rw/1vQowHIkoxlj05RpzrWu9BLzMTZPrmMPT7lkiXV8
tk6NAx7QRFKGjPAAhEmwRdbbM9gnKopx1XISkTL6n9UeYy/+L3oPp015p47U
VINZLvk6hAATTHggZBb1806oU2o7QH3eU0vmyquUm7hOKbZQbhIkwuytA1CU
9zGTVKh6g7lijVMz7R6bOKNKeLHqy8LpmRR0UDn5vIz/n/lf26mkMLVqhiAp
HXS/QWCF+c0Dq3H+A3zmJqS6x3X51vycFtuNcZMih8qjNsF4/yaJmvQqaopq
guI7T6MmA1lfFuIejZfLNE/Ju7XP2e09Af//+7cfelmlJrSMOXsXnPX3Kwd4
KanUG+xDwZlcyHG8cflVtGulFQWOlxFTxO/3JT3HNaDji7cfHoI1uLmWsvcy
Ly+RYbYgtJt/or/VdvABrJp7WbmE0AuUa7YYSDuzGsG9z6Imbv/112+QVHA2
5Glffw1KHqrbkm6p4dwxd2LiMOXDh7OX8Pn16QttOgIx0SnWiin9C72eNIwv
/LuKHqYz2iQgxCsw7/D7slbEnVleEz3u2MfAQ/tjYgbYBgsPQfCkUpiKnKba
0ZJqm+CHRSZgnAN3/Qq7eFB9rD7wOc5Ej14ixzm1HOc9TjFCV6ONBDNb3WBA
lpUhrHHUI2IAyGw3OzP4KKhvabBEC6vEjQrCktPX6A3TDFpHlVUbmdCJVQYx
an8NRn9Kw3b5CiamNV0NxDofbAa8KSq6IzLcwRsMDndy64eaARRlUMzFfrWp
5jjy+jONqDjQ3kyC+nlsRUX+YKqcGy59vH95IilO8xscBtB6W2P/DJOWTSna
ckq3c8lbovg3e75E9tiyo2ZN9tCpKIjMht9JiAAbHYgsoQpG2/XKpoTaEvsC
FZaZUn/961/1nwFH1Y3SgFUw2mimR5L2NQWeG/1lW7aYnjaa4BOyfHzIQJZ/
cNvB385/OI2Ov3ns/0TjPlocLk9Ojv/+t/9aPHn6zfHi6TffjNQtrkKpILGY
uj5xR7CBLl9ZY8LhrgQgrIyyWydFCY5+SymiyDlYVEtNZBTGM40r0qu/cK7L
99QAABAEEJn1IVc6H9tGIwDUSJ+xVscbkEXLQFzYjcjRDOWnhzlScwSgh7mB
F0m8+qDUAt8kjQYp1CR6s5c/gIyW5lCUhMtPi/qE2RMsLuZ+cguTuun25ldP
Wj2YRyPl1KCd+Y3SCYFlwSFhWrbJApcUFhjELFW0UVYFlwBGIENOeoj1oiyB
RxfTPUC1bIYm3VEjOXagkxnAYLauU1w4AQ2nGsoyphQ7bp2QBEkavFm2JmEU
C0NajpTS2eK4aLFtI1hU1O1EZzR13M1puBGT2GNggopDZHuw5babjlE0I+nT
Uta0nMi1vQgagQiXptzi77jd1IuXL3/U50Fu6s2DZZLkt6Kv26R8epKLEx8f
HQIjA8CgjSWdU9CDxsOYhBrpGdUs16DeC3fBkVWvUCpicP9OI9/5g2STg7o8
0t6/3/1et8DXJvyIUYfveCQszRkNPRJSnHtEvo/4+4hDMvyKnwk+Gp7YFLN0
12a+j6hypZGnmdSCZ+lpCUWBriYPDgjJET4o3wcAtc1j5N1eMdyIJxm5ereR
fqhHfgHcSOm7/j3EgBYlkxFj/5og0H8MJgGTGNi69DWJWAX9HWzcd1zR7D1P
Cn3rqZudJT20QOEnXf3BQ1qNnRMroRm7ZJkOvrQcXN7QmctLvjzzz3rk443/
PZUFOHQacQMxWKHUBNkFwrwdrHBU4JU00awrIKcWXsTWifIE1jmNHKD7T2CQ
18dS+aV7WO6Q7kQmtzYRTKNgCNNRmtu7yAqCpLuRmYySfgafd7Gikb9s82X4
sNU6/GWYLzvr6KiTBNI/fW3kVLBh+P2XvTjtYBWu3wEHteVR/y2PQ4RyvYc/
yLy6KbojesL7OqKvGX8NU+ylKNMubzysR/fU7R2cJ2A8uMmho3JbdcH7UW8L
NkQ72g+AtLgadX/zo72jzm9+wlP3t3A7vY30cMjD5l4Mq7eontunv98gVDQa
PPeBME13F9YHNwpPxT9E+i+ROfyvIXrUjezRUuxiAAf9Ubb4vnkhiDgML973
+Y/2jOmj14A38YvRsX+MeyjAChSTem1Eh/28V5ohW/byulmSeIndd77pZ3sL
h0/vNSfLpw6vcihpSHmIN3jOpR6e+n6qkTllx1rZ52QI8n4n0TuCPSzTCEvD
DToLt9Zi9/svEK7GOnwAVi67zDHbH22DV1SdD7qrlOmz9jrUnqzfwMs4Q2N0
ntQlCu9sqQZ6wZpAUWzz8Gw+rLbFW5KywM1C/Ca+nViq3/wMYzoueTulzGzj
r1LkvI6TDCu5XD8O9sAM9ZOR1C9JyHDmjs08KaUHwd7OaXaSkts4YxMRDiHF
zhWVpOjy0ty6jVO6qB02tyjg4HAvUCI2k1hM855aOgtaMKDH4xIohKLgWBXi
OcNpEYrbwkgwxHORVWVFPYQaMwf63iX8x04x38wr1B3t3chas2lD3AjIdtl0
Hd6opUu52WR+q/K43yWPrGCwQ8kI870c4tDyGqwmCbuzXKAj6NZioyZ+Utqe
JrJ4DN2GyaZL80ALWQxX3a8315gDEKk0otR4IQmjAvncxIES9Ci2ThayqsMS
8ZiaIRO18OIohQVgdUSZEhk1yWNTnYp3MPENHY6YG0NW66210/2GTM9N4yNk
yM5TLV4O6YLUa2qEbiVtO+BO1fEUrWZuz2Q7J/X92xPb31HcdhV5W/S9XYRg
3a9kDPI4h/0mcSj0a5jKP3OpAEd7yMHlOaokGM6OMuzkyC4r9E7DOOTbmKpH
WANNtfnYpJHBK/4ZBsFAuxjjOnPV+dwdzPR+Mq2iZO0D7iBeylSdTE0Rfp8f
zL18uTShNp/sreSwpFf++I0dxfRsGSpzw34LXiSk6ZVM0bUuJtvUOtOwrhWs
Q5M0GftFVJoyExZYsv1YgvG92lxxrPULosfUqDBIXlzQbTUSefHCiZxauD+n
MMyS/KrBUci/1XXGYwIgJ7tKWYwrUzDEJDlGU/XE7sivx3bb8cuyxwwG5ALz
niU/x+XEttSKfvxKLp7oNZmzzHzWC7KjQNTW5RYPzSRpe5xezd4BOvh5p1IP
hun2MRiI7hIemKYC1JzCyybDbrcFESSnB0+HVBPXlgJ0L/H4phUi+AYLJ3ZU
rIiKi3xF3cq4wDp8lTikjX8HbQ9wkba7oRS7p2rw/gcpQAiooNevzobmqT+h
qzBj3tBvU8hyvhbpxtIqx8rfui6vLdkoacXs1trGn8qi3OwozN/xvnOsCwQN
ZasCoMkFfI2Hrcx7RqYnGOF0KZ/UZBz7p1SSyU1DcBaRhDPIM99h+EGCNfcT
xof6KDazyaCDbRX9pFRppEh9E/dgOU3iB1VnlCLkujRg1ANOg3pSIBAK10Ex
kqYRcrcLjmSRHleJ2XmYD4Z52EvuwCIxFeIprv0IWQzPaamRRypup3Kdi9mq
qcwAKFvHticgyA9NagDoNWCZRkvqz8qpcRNK8eWvRCDZX7CYr7LVksTqNxjq
zOJ8okLsSiVttZY6gdSmSoGCtt5uuFkxBiQmVllSf94ml5KqAagCsMJMEvhS
tKrGpOVdov6I8fkSKP/SBJxwrdzNNKj7YD2S7oUy6TKUtLQ0tUdUBxL7Xbuk
qU5buhoXYywQktp7jHA50rcAVPWPgj5hfhlrk3t6wnNKsOu57K3YbKKUKgT/
NhAptEgHm2GYKk3M73TtyzYYGtoXdMBtq9W2MJ1WeB1WKza3OsAgpMtQ9IrX
3NZbvkbK/ZpuLE+aSJNvSb0hW7SC8yTViYPauB5UTJ1SBBZ0RXVcqorbdd9+
kOg6J5r77SKksTOys6y13XHWcaMk5oJzYU4dLAI7vkzlzj6bNY753F4nGixO
PAjuwcEMJy7ZGpuK14V3VYptiyNHEITfqZqA4NE8V8wZpKIZc7b4LzgvsEEp
KZGYt0S2wyY1xi8R3tIU4LyRFSJPEMGlAzymy4l8ceVOtv0nXpvw2UYx41mo
z8xUr3rGXL+BChSDfuD8Y+7PwrkhnJ+swpz6PEWCHrgLiFEgKDYeLCq2mW4u
n5TOyHYKuY4bJ5Ekv2a6p50StardVjO/VfuAHou4rkw7eNpoj0anpAZK+mNo
vga1bTiHyrwmesNNBPweA1QMhOowaIo2HOxuHKGiJL8hLCdV2NahZA5I6VZG
BR1XVEBINyOgc+kyFfPDpGwxudoinTJ3DRvoLezHZIt8wHCMK+KHb1HYLfvs
8NVAtZG7UOELkgI5FVMfUOJQ1MQrm8lB2c4COsluGssVNo3R7SNgtDtVlQ1G
eGbeVRGkS3HKowTI6dQxi4hsT+AKiW8Jc9MIZZfl+mxxvlOCNV6m8+8G+JjX
x7Wfp6MQKzYsZmG57jKWjJLHjW5jmnqY8NUUQ02mC5FfQgA0rbxWfSTYLbwk
vcqqm7ZdgwVW4DWbKM4P5VSqaS9lgpfUyZrgNdHfDXX4kk7ZTluwVYA7boqc
RAAarLBg/Ek/VZIgTcI8o+5Oz31fGMGaLo+At+lRLkWWvByePE26FaUac4MT
bAQI/J9aQOK8NmdMWuFxKhxRh8AGGVDUbgtO/zSdNmQcuv0ItTxqMlptG7/U
kFqdZ5So5tLKqWs7LZGvo1F2mXlsBCh11OBXQcMg/5ef1Ypg757FCrtxUZ6Z
OVKES4bXQFRYq1ZnnC4stV+yduR4tlwTL30tsS6SO3k7vJmqTjuPqVdGClg6
dfWB+MkLN5k2LdNOUSElhWHpc51xUwuDwlSiGxdtF3Wn3RX4sak5slT3rLu2
QPdK7r0UPFclYE5AGUQpsJuNQ03M1mSs8ZHFq5rtdeySx7kXjU3zx5WYFHk4
GH7Iu3om21BXgPhyHOA7O59pGzAgTk0Lbko/E95WlVLT/6AIRFHZKTAXX/HC
BcPAm6AkGAtU/KMMTxJG6hSHXsVUyotuKwssUxeCqVOpAVwIIOXt3gh22nuD
l2yY9CNuWZHWY3M5S5SiTkFojBcgmjbpLeVCBXemcAtC8ZV6iGH8POI1ozwt
xUW4wZGwyc053YUjZzlVryYGVLcioX5gNrt1agM/XHYcGFG2Al0ay7A0lgRa
5QUqqR1TMpye20nH7WbruvRcZNzs23e5mHcn6Q63NQzydbWXrzsRj6UrjARI
vDHpXd7VE6HUx7RXj7aalFNwPdrE+y2xtAP+lnLOZl1uSfri1tPEuw4B6GBb
JabfB93SxKYf3SoaejnOucbr5gF6P0xWq7nwyw8fSTEYGE6sFobeksZaVJKC
2FJMw/TTQi0DVmOgI9c7Y9PvM0ok40ta0H1xZbtQKUqTNK3hCUbwHuzhNTYr
/PHH1+bKUOyDeAkgPTitsLItOp4e4gXmUon1lrqrjAPfCnMH5foH2qgLpXpW
KSJ+GeF/O90mi7RFVkDrxiZhoK8MIcjU2hbSo0ByUDu9T8KGcoqDVYN+41Wn
6xjn5XJZPI7XudECu/v7VzNRZ4qwk5nVWI3HgY/aLMldlK4O7OapvlHYGT2E
DRsmUnJDMf+Jf3+XU7vGcmNoPNSqcjV82cQ0bN7s326mWG2y27cKA6lKqfSd
kIBg7JIw2ZRYxYsa8QrNoFOutwADeq1t96c0sSU8rl5IlJB419gqavvqRMWr
VrLX4zrPTCmQ9yL6u4y57m4Zk5iLVCqRcJyqs9brxK7zbFEjZuIlT81gwFUu
73MXkXKoYuK1SuAzFssSXQ7osRHyidCPFRKPpRkO+5ilsMOrDjvWSV+N/sKm
g/1gxX5zETkr7JXXXl/8b16Lfbl+ibi4550KGpkiTf9UpcX7FDlTS4V7TjDZ
G8b5VvMqzjHoEG92JsAYL6OyTfMxt/TLY65NIzork3hn7sSyN8X/zH35sLOl
d1Os4aGEIaRuHusDlKRixY39G1PD+3+8mOfn7lvHO8EyV3Ug/n/lYrLktgMe
GNE9GssYe8pQq4PKNl7CtR1ZFPQG56z1+5cUHLx4++3YroVOhEzc09MXKrx8
pHuJYxaYI7FZTJTHO8QzY8CgAPeal8p9wrEJcJo7W99+u6cW4TnrRzZrgrsX
yc2NPAbTK9/vPFhiQRYQ3dqEKKFIk8SGHsP1RXQVa69FNhtRzpuH+/JiFCyv
KcDHerIBnsMYutZlqHqPQYh+HSeKpYvlRMhYNm/bynLR1QCGKg8XPCuVnF62
NgePYpfa60u5z+0XYbC5mBdILStyuba0ZdpRo/ffvuTrxFdbWqy9j2DUwSEi
UWpbKe5KTGUnU7Nt8W5Knzi5/0FiNs9AEwvU4Bc7lPnS1n+nJlvimBDXAzx0
PbGdNIPRs8ZepMyxOellI0A2R6DEI+Wr6Bi8IYViYionQdGI0G+U+KQZcTNQ
3BzjtAHDV43n7HS3AH8zdqXW0tZRHLdy2DP0ALFFLn1GWWWpsqKwHcImHXZi
nmSHrkOXthtDEztlha4ef7fiBdpkzQZ7YAHavg1XoQ9sP2JxvvEapKfO3rQA
xX1Jgu+sZhzkChiTx/gmx70CpB6VjWaUYaa9CoGZpNiNFkAn5XXzMXv4AxaZ
NNFx9LYuo9eEHHn05Nvo++8/fDfjWycoY1338v9h+Ltql4b/eRVNR8+ePVo9
e5r+/W//hdcmchb4zKR/38qkkl1Hk7l9dPPh+xP2V+tlv5vBh4oEDNS0y9um
ySlPeYY5g9h8PN9QJx+T6qsPp08eTw+9dQzkJM/CFEuzCt1N+6bpvFzhGWWH
Lts7wNrJA4Y3uEXSna8E6cEI0nUMhzd7tnhycnS8eorn4q+xmxI+03/6hX68
Vfh/kmyIhBB9d3r2oyU7apRnSa7vxvdqpNj/Qf39TPYakiIWkyMRgUIneK8e
PoRxx907H8wdtMQTitLlZlIC0oznFCcCDoGlvmEjHP/eD8+J7+EOULsrnZiq
mzsp759LMvj/FIFmMQ77xvWQcWarprxQBr4aRjP2gGNvqk+xwzG8fJ/9ANpL
fQHdMRgN7UkXVEN0R5bihqmNIoVbP1n51gfScqy7SC2Zauyxu6tabgZ/4yBe
XMTcMy3hZ1MLh2Dyam3QNmQtQzRbHMUUwv3/hU4DHLjPVN3OPsNUhzmILPOm
X0CbFRRTD/KmpZRWNrKvoDbYZw8wPgAO4R+zOf2LjxnJWO/3Vn+Oy+AIPqP5
LVzmN5FNT4qo+7N52b3ki5+dvjntBQJDPVbuxKQnOVWjmQ7b+6hlUpdNU+Po
3R9pWrt697e5JAc2sw5sTulYGp4ovy2NsTVsknEnBum1E/Uaf7rYneTQ8rve
yqb6PEx9LAIu6neBVxLIti3qs9RZNe5S0+4F1X5vdowXdCwH4iPGGU9gFoU8
M1YrJ5lnKz8VRfm5MOQVnhq70muaE9w6Tb36WECbRmvRscmK1vF1nInzytpk
1NsXgJfKtcSBQwFdyNiyBKt3qHQ2+zQUHlbqnWy00dHhCUEkOvzGeTzuzqX2
mgnscTJx7LGTpm5cxZJom6FpwmlAahmgu9XCyU/Akb4JX7bejT07uBD9K3PD
uYneE/Z2XQmYH5ab4t/EXlXuYftk+HL1MWeQxFtYXs0uwA2MKOkq0eHjobZI
CnUlMjTDszd9TLwFlBhayhOXyW177oNSocRDyDUXA14x3+ae+d7TtqwivrpX
bngh/5nn8HroXLiex8zcEnE/b90el5xHE3grRAsmISpIOTwCE3QjA+RK00Ms
plFyw9z9nYfXaZ7jrWF4iyiFLOD82DHHLeX0K3EG3jwQuderJJd4izzHzR3M
20Ooz41t/h+Yh7bI3DOS9puO6m4pHf7cUVYOT54cnyyOjt1joerCVolMHZSg
wxPhom31ubckv5R4BpbdoZsGC4Rn+uQ4mMEpSOa5zxuqd5mn9pnu0sOhgjXc
35J1CtKXWrSdOlxc8vHhSbx88hjO5GR1/Gjx5PjRF5nAvjLXr8b1F4tgzqoL
YBCLnM4A0xztr7feQL3TGHh5uEr+VnVG26NReT/ts8+9cl5ntnQvbxiCLZb4
whvdSxb8Rz9r6d9D4zs6fnTyzeMnT0efBVy4z/1el3DHdzzX2ekdT3Y36h9a
8GB3v5aS7jhar3I+ONeB6ma0LwwbBCYXPVkEJ9erdZ75a/strJRe5KJkUuyp
I+oFtzxF9nN0DFYM90d13z59GpBBWKIsQKGmpp8/82EY3HWmfRgM9acI3jH7
+9xzvY30n7/jmK1hGByyrReeUfGya4Xnw8YvHIbnTvE5/fpEv44/hUzOqyGe
6eOnz54dHR4/Oz55+lk4+8vYi9ydZex9rrOOe7O4/W49ES39biizoBOK7/0D
1eZ0ie4fDOryfSHKV1fRS/SRTS28xkF0RtFY92RKTNgdo+xVZe5+K0/AmDvB
2I9Yg82EKuqAxTZRrkKQQ8x2Ae9O35/7V6KYumFTFuPlZ3ed9tLBaqr+D4X6
ydrVngAA

-->

</rfc>
