posture: 110100
dims: protection delegation connection
by: keeper
Architecture Guide
System design, data flow, and security model
Document Alignment: [Whitepaper v4.3], [Research Paper v3.2], [Glossary v2.1]
System Overview
The Proof of Proverb Revelation Protocol implements the dual-agent architecture [Whitepaper v4.3, ยง3] with a three-layer design achieving hardware-enforced privacy with AI-powered verification:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Layer 3: Knowledge (IPFS/Pinata) โ
โ - Spellbook v4.0.1-canonical (immutable) โ
โ - NO access to keys โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Layer 2: AI Verification (NEAR Cloud AI) โ
โ - Semantic proverb matching โ
โ - Quality scoring โ
โ - NO access to keys โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Layer 1: TEE (Nillion nilCC) โ Optional โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ AMD SEV-SNP Confidential Compute โ โ
โ โ - Zcash keys in SecretSigner (distributed MPC) โ โ
โ โ - Calls Layer 2 (AI) โ โ
โ โ - Calls Layer 3 (Knowledge) โ โ
โ โ - Signs transactions with threshold ECDSA โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Dual-Agent Model
The Separation Principle [Whitepaper v4.3, ยง3]
โโโโโโโโโโโโโโโโโโ
โ FIRST PERSON โ
โ (You - ๐๏ธ) โ
โโโโโโโโโโฌโโโโโโโโ
โ
Private State X (complete context)
โ
โโโโโโโโโโโโโโผโโโโโโโโโโโโโ
โ โ
โผ โผ
โโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโ
โ SWORDSMAN โ๏ธ โ โ MAGE ๐ง โ
โ (Protect) โ โ (Delegate) โ
โ Soulbis โ โ Soulbae โ
โโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโ
โ โ
Observes X completely Acts using authorized info
Reveals nothing directly Public coordination
โ โ
โโโโโโโโโโโโโโฌโโโโโโโโโโโโโ
โ
THE GAP (conditional independence)
โ
s โฅ m | X
โ
Additive information bounds:
I(X; s,m) โค I(X;s) + I(X;m)
โ
Reconstruction ceiling: R < 1
Mathematical Guarantee [Research Paper v3.2, Theorem 2.2]:
When observations are conditionally independent, information leakage becomes additive rather than multiplicative. Combined with budget constraints, this creates a reconstruction ceiling that cannot be exceeded.
Components
1. Mage Agent (Frontend)
Technology: Next.js + React
Purpose: First Person interface for proverb submission
Location: src/
Features:
- Spellbook reader (18 Acts + 30 Tales)
- Soulbae chat (optional AI assistance)
- Signal flow UI
- Proverbs gallery (VRC viewer)
Security:
- No keys stored
- No transaction data visible
- HTTPS only
- CORS configured
2. Oracle Swordsman (Backend)
Technology: TypeScript/Express
Purpose: TEE worker that processes signals
Location: oracle-swordsman/
Core Functions [Whitepaper v4.3, ยง3.2]:
- Monitor Zcash shielded pool for incoming signals (zโz)
- Decrypt and extract proverb from memo field
- Fetch spellbook from IPFS
- Call NEAR Cloud AI for verification
- Execute golden split (61.8% transparent, 38.2% shielded)
- Sign and broadcast inscription
Address Requirements:
- Shielded Address (z-addr): Receives signal submissions from First Persons (private)
- Transparent Address (t-addr): Posts public inscriptions with proverb + proof
Security:
- Runs inside Nillion nilCC (TEE) โ optional
- Keys stored in SecretSigner (distributed)
- Attestation verified
- Zero-trust external calls
3. NEAR Cloud AI
Technology: openai/gpt-oss-120b via NEAR Cloud AI API
Purpose: Intelligent proverb verification
Integration: REST API
Verification Process:
// Oracle calls NEAR Cloud AI
const response = await verifier.verify({
proverb: "First Person's proverb text...",
spellbook: canonicalSpellbook,
actId: "act-5-golden-split"
});
// Returns:
{
quality_score: 0.85, // 0.0 - 1.0
matched_act: "act-5", // Act ID
reasoning: "Demonstrates understanding...",
approved: true
}
Privacy Guarantee:
I(Soulbae; Transaction_Amount) = 0
I(Soulbae; First_Person_Identity) = 0
I(Soulbae; Wallet_Address) = 0
I(Soulbae; Transaction_Timing) = 0
4. IPFS/Pinata
Technology: InterPlanetary File System
Purpose: Immutable knowledge storage
Spellbook:
- Version: 4.0.1-canonical
- IPFS CID:
bafkreigopjrfwjsz56oft7nmv26q2oddq6j4fexj27zjirzgkdeogm2myq - Content: 18 Acts + 30 Tales with canonical proverbs
5. Zcash Network
Technology: Zcash blockchain
Purpose: Transaction layer + inscription storage
Client: Zebra full node + Zallet wallet
Transaction Types:
- Incoming Signal: Shielded z-addr receives 0.01 ZEC + encrypted memo
- Outgoing Inscription: t-addr receives OP_RETURN with proverb + proof (61.8%)
- Outgoing Fee: z-addr receives shielded transfer (38.2%)
Signal Flow
Complete Transaction Path (10 Steps)
1. FIRST PERSON READS
First Person โ Spellbook
- Reads tale from Acts or Zero Spellbook
- Clicks "Learn" to copy content
- Forms understanding through context
โ
2. PROVERB FORMATION
First Person โ Mage Agent (optional)
- Crafts proverb expressing principle
- (Optional) Consults Soulbae for assistance
- Generates formatted memo
โ
3. SIGNAL SENT (SHIELDED)
First Person Wallet โ Zcash Network
- 0.01 ZEC to Oracle shielded address (z-addr)
- Proverb in encrypted memo field
- Transaction is private (zโz)
โ
4. ORACLE DETECTS (SHIELDED)
Zcash โ Oracle Database
- Monitors shielded pool via viewing key
- Decrypts memo to extract proverb
- Stores in submissions table
โ
5. FETCH KNOWLEDGE
Oracle โ IPFS (via Pinata Gateway)
- Retrieves spellbook v4.0.1-canonical
- Fetches canonical proverb for matched act
- Validates CID integrity
โ
6. AI VERIFICATION
Oracle โ NEAR Cloud AI API
- Sends proverb + spellbook context
- NO transaction data sent
- Returns quality score + reasoning
โ
7. GOLDEN SPLIT CALCULATION [Tokenomics v2.0, ยง2]
Oracle calculates split:
- Signal amount: 0.01 ZEC
- Transparent portion: 0.00618 ZEC (61.8%)
- Shielded portion: 0.00382 ZEC (38.2%)
- Network fee: ~0.0001 ZEC
โ
8. TRANSACTION SIGNING
Oracle โ Nillion SecretSigner (or local)
- Prepares inscription transaction (t-addr)
- Prepares shielded return (z-addr)
- Requests threshold signature
โ
9. BROADCAST
Oracle โ Zcash Network
- Broadcasts inscription to transparent address
- Broadcasts fee to shielded pool
- Records TXIDs
โ
10. VRC CREATION
Inscription confirmed โ VRC exists
- Proverb permanently onchain
- First Person has verifiable proof of understanding
- Bilateral trust credential established
Economic Model
Golden Ratio Split [Tokenomics v2.0, ยง2]
Mathematical Basis:
ฯ (phi) = 1.618033988749895
1/ฯ = 0.618033988749895
Per Signal (0.01 ZEC):
โโโ 61.8% (0.00618 ZEC) โ Transparent Pool
โ โโโ Public inscription with proverb
โ
โโโ 38.2% (0.00382 ZEC) โ Shielded Pool
โโโ Protocol operations
Why This Ratio [Glossary v2.1, ยงEconomic Parameters]:
- Balance between openness and privacy
- Mathematically elegant (golden ratio ฯ)
- Visible accountability (61.8% public)
- Operational privacy (38.2% shielded)
Transaction Economics
Per Signal:
First Person payment: 0.01 ZEC
Public inscription: 0.00618 ZEC (61.8%)
Shielded return: 0.00382 ZEC (38.2%)
Network fee: ~0.0001 ZEC
AI verification: ~$0.03 USD
Security Model
Threat Model
What We Protect Against:
- โ Key extraction from TEE
- โ AI provider accessing keys or amounts
- โ IPFS provider accessing keys
- โ Database compromise revealing keys
- โ Network eavesdropping on keys
- โ Reconstruction of First Person state (R < 1)
Trust Assumptions:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ TRUST REQUIRED โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. AMD (SEV-SNP hardware) โ if TEE โ
โ 2. Nillion (TEE platform) โ if TEE โ
โ 3. Zcash Foundation (protocol) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ NO TRUST REQUIRED โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ 1. NEAR Cloud AI (sees no keys/amounts)โ
โ 2. IPFS/Pinata (public data only) โ
โ 3. Mage Frontend (no sensitive access) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Information Bounds [Research Paper v3.2, Theorem 2.1]
The dual-agent separation ensures:
I(X; Y_S, Y_M) = I(X; Y_S) + I(X; Y_M)
This means information leakage is additive, not multiplicative. Combined with budget constraints:
C_S + C_M < H(X)
We get a reconstruction ceiling:
R_max = (C_S + C_M) / H(X) < 1
No adversary can perfectly reconstruct the First Person's private state.
Performance Characteristics
Latency
Signal Submission โ Confirmation
โ <1s Mage Agent โ Zcash Network
โ 75s Zcash mempool โ Block (avg)
โ 10s Oracle detects transaction
โ 2s Fetch spellbook from IPFS
โ 3s AI verification (NEAR Cloud AI)
โ 1s Database recording
โ 2s Sign transactions
โ 1s Broadcast to network
โ 75s Zcash confirmation (avg)
โ 1s Update database
โโโโโ
~170s total (under 3 minutes)
Throughput
Light Client Sync: 4-6 hours (first time), then <1 minute
Signal Processing: 10-15 seconds per signal
Concurrent Capacity: Limited by Zcash block time (75s)
Max Throughput: ~40 signals per hour (conservative)
Deployment Architecture
Development
localhost:
โโโ PostgreSQL (Docker or local)
โโโ Oracle Swordsman (local process :3001)
โโโ Mage Agent (npm run dev :5000)
โโโ Zcash Light Client (testnet)
Production
VPS (Ubuntu 20.04+):
โโโ Nginx (reverse proxy)
โโโ Oracle Swordsman (systemd service)
โ โโโ Optionally deployed to Nillion nilCC
โโโ Mage Agent (Next.js production build)
โโโ PostgreSQL (managed or local)
โโโ Zcash (Zebra + Zallet, mainnet)
API Boundaries
Mage Agent โ Oracle
POST /api/status
{
"tracking_code": string
}
Response:
{
"status": "pending" | "verified" | "inscribed",
"quality_score": number,
"txid": string
}
Oracle โ NEAR Cloud AI
POST /api/verify
{
"proverb": string,
"spellbook": Spellbook,
"actId": string
}
Response:
{
"quality_score": number, // 0.0 - 1.0
"matched_act": string, // Act ID
"reasoning": string, // Explanation
"approved": boolean
}
Oracle โ IPFS
GET https://gateway.pinata.cloud/ipfs/{CID}
Response: JSON (spellbook v4.0.1-canonical)
Configuration
Environment Variables
# Critical (required)
NEAR_SWORDSMAN_API_KEY # AI verification
PINATA_JWT # IPFS access
DATABASE_URL # PostgreSQL
ZEBRA_RPC_URL # Blockchain
ZALLET_RPC_URL # Wallet
# Economic [Tokenomics v2.0]
SIGNAL_COST=0.01 # ZEC per signal
PUBLIC_SPLIT=0.618 # 61.8% transparent
PRIVATE_SPLIT=0.382 # 38.2% shielded
# Optional
NILLION_API_KEY # TEE access (if using)
ORACLE_CHECK_INTERVAL=30 # seconds
LOG_LEVEL=info
Next Steps
โ Architecture Understood!
You now understand:
- Dual-agent separation model [Whitepaper v4.3]
- Complete signal flow (10 steps)
- Security guarantees [Research Paper v3.2]
- Economic model [Tokenomics v2.0]
- Performance characteristics
Next: Read 03-BUILD_GUIDE.md to start implementing
Reference: Use 04-API_REFERENCE.md for code patterns