- LDAP
- Lightweight Directory Access Protocol, the protocol applications use to read and update directory entries. IETF RFC 4510 specifies LDAP in terms of the X.500 data and service models.
- X.500
- A family of directory-service standards that defines a distributed directory information model; LDAP provides practical access to such directories. It is published jointly as ITU-T Recommendation X.500 / ISO/IEC 9594-1.
- Directory Information Tree (DIT)
- The hierarchical arrangement of LDAP entries, identified by distinguished names.
- Distinguished Name (DN)
- The complete unique path to an LDAP entry, such as
cn=maple-quality-agent,ou=AI-Agents,o=Cequs,c=US. - Schema
- The set of permitted object classes, attributes, syntaxes, and matching rules for a directory.
- OpenLDAP
- An open-source LDAP directory-server implementation used here as an X.500-oriented stand-in.
- LDAPS
- LDAP protected by TLS from the start of the connection, conventionally on TCP port 636.
- Mutual TLS (mTLS)
- TLS in which both the server and client present certificates and validate the other party. mTLS uses TLS certificate-based client authentication; see IETF RFC 8446, Section 4.4.2. The local demonstration uses a private test CA and does not install it into the system trust store.
- TLS 1.3
- The current major TLS protocol version used by much web traffic. Mutual TLS adds client-certificate authentication to the encrypted connection.
- ISO/IEC and ITU-T
- ISO (the International Organization for Standardization) and IEC publish international standards together as ISO/IEC; ITU-T publishes aligned telecommunications recommendations. The X.500 Directory series is published as ITU-T X.500 / ISO/IEC 9594, and ITU-T X.509 / ISO/IEC 9594-8 defines public-key and attribute-certificate frameworks.
- IETF
- The Internet Engineering Task Force publishes open Internet standards that support use of these international standards in networked systems. RFC 4510 defines LDAP as an X.500 access mechanism; RFC 5280 profiles X.509v3 certificates and CRLs for the Internet PKI; and RFC 8446 defines TLS 1.3 and certificate-based client authentication.
- IHE International
- Integrating the Healthcare Enterprise, an international community that develops interoperability profiles for healthcare systems and application processes.
- AAL3
- Authentication Assurance Level 3 in NIST SP 800-63B. It describes very high confidence that a claimant controls bound authenticators; AAL3 is an authentication assurance level, not a certificate type, and applicability depends on the system and policy.
- Digital identity
- Information used to recognize a person, device, or software agent in a system.
- Authentication
- Checking that someone or something really controls an identity, such as by using a password, security key, or certificate.
- Authorization
- Deciding what an already authenticated identity is allowed to do.
- X.509v3 certificate
- A signed digital document that connects a public key to a name or service. The X.509 public-key certificate framework is defined by ITU-T X.509 / ISO/IEC 9594-8; the IETF’s RFC 5280 specifies the Internet PKI profile for X.509v3 certificates and CRLs. The local demo uses X.509v3 certificates.
- Public key
- A key that may be shared with others so they can verify signatures or encrypt information for its owner.
- Private key
- A secret key that proves control of a certificate. It must not be placed in browser code, web folders, or source control.
- Public-key infrastructure (PKI)
- The people, rules, certificates, and systems used to create and trust public keys.
- Certificate authority (CA)
- An organization or system that signs certificates after checking the requested identity.
- Certificate chain
- The trust path from an end certificate through an issuing CA to a trusted root CA.
- Certificate fingerprint
- A short SHA-256 value calculated from a certificate. The demo uses it to bind a certificate to a registered agent.
- Certificate revocation
- Marking a certificate as no longer trusted before its normal expiration date.
- Client authentication
- Using a client certificate to prove the identity of a calling device, person, or software agent.
- Certificate extended key usage
- A certificate field that states its intended purpose, such as client authentication or server authentication.
- Certificate subject alternative name (SAN)
- A certificate extension, defined by IETF RFC 5280, Section 4.2.1.6, that names what a certificate identifies. On a server certificate this is usually the host names or IP addresses the certificate is valid for. On a client certificate it can instead be a URI naming a workload or agent identity — the demo's agent certificates carry a
wimse://cequs.com/agents/<agentId>URI SAN, the identifier format described in draft-ietf-wimse-workload-creds. - Certificate validity period
- The start and end dates during which a certificate may be accepted.
- Grant window
- The start and end dates for a directory permission. A valid certificate does not override an expired grant.
- Identity binding
- The recorded connection between a verified certificate fingerprint and a registered directory entry.
- OpenSSL
- Software for creating and checking keys, certificates, and encrypted connections. The local demo uses the Windows 64-bit OpenSSL binary.
- mTLS gateway
- A server that requires certificates from both sides of a connection, checks the certificate, and then applies authorization rules.
- Protected channel
- An encrypted connection that also confirms the intended server, and sometimes the client, before data is exchanged.
- Webhook
- An HTTP address that receives an event or request from another application, such as the maple-quality mock sending data to n8n.
- API
- An application programming interface: a defined way for one program to request data or an action from another program.
- JSON
- A plain-text format commonly used to exchange structured data between web applications.
- n8n
- A workflow automation tool used here to receive a request, query LDAP, evaluate policy, and return a decision.
- Policy decision
- The result of checking identity, status, scope, and time limits before allowing or denying an action.
- Human-in-the-loop
- A design in which a person reviews or approves an important action before it is completed.
- YubiKey
- A physical security key that can perform strong cryptographic authentication and requires the user to touch the device.
- FIDO2
- An open security-key standard that supports phishing-resistant sign-in without sending a password to the service.
- Federation
- A trust arrangement in which one identity system accepts authentication performed by another identity system.
- OAuth 2.0
- A standard that lets an application receive limited access to a resource without receiving the user's password.
- Single sign-on (SSO)
- A login arrangement in which one identity provider can sign a user into several applications.
- Identity provider (IdP)
- A service that authenticates users or agents and sends trusted identity information to another service.
- Assurance level
- A rating of how strongly a system established an identity. NIST separates identity proofing, authentication, and federation assurance.
- Major/minor revision
- A simple project version label. The major number changes for a large capability or design change; the minor number changes for smaller updates within that major stage. This project is at Revision 2.4 while the state-endorsed identity and governed A2A information-flow concept is in progress.
- Agentic AI
- An AI system that can plan, use tools, take actions, and continue work toward a goal within assigned authority and controls.
- Deep learning and agentic-AI research
- The poster's maple-syrup use case references deep-learning analysis of Raman measurements in Xiao et al., Food Chemistry 463 (2025), article 141289. The broader agentic-AI registry context is presented in the hosted proposal poster.
- AI agent registration
- Recording an agent identity, owner, status, authorized scope, and relevant evidence in a registry. The Liquid Registry Lab is an interactive conceptual walkthrough of this proposed flow.
- Authorization scope
- The bounded action or resource permission assigned to an identity, such as proposing a maple-lot grade.
- State-endorsed identity
- A proposed model in which a state or recognized issuer attests an identity or role, an accountable operator binds the evidence to an AI agent, and local policy controls each permitted exchange. It is a design concept, not a claim of an existing cross-border A2A identity service. See the concept note and its primary policy sources.
- Least privilege
- Granting only the permissions necessary for a defined task and duration.
- Sandbox escape
- Unauthorized movement from an isolated execution environment into a broader host, network, or production environment.
- Credential theft
- Unauthorized acquisition of passwords, keys, tokens, or certificates used to authenticate an identity.
- Incident response
- Coordinated detection, containment, investigation, recovery, and lessons-learned activities after a security event.
- GDPR
- European Union General Data Protection Regulation governing personal-data processing.
- CCPA
- California Consumer Privacy Act, a California privacy law.
- HIPAA
- US health-information privacy and security requirements for covered entities and business associates.
- ISO/IEC 27001
- International standard for an information-security management system.
- SOC 2
- Attestation framework evaluating controls relevant to trust-services criteria.
- NIST SP 800-64
- NIST guidance for integrating security into the system development life cycle.
- PCI DSS
- Payment Card Industry Data Security Standard for protecting cardholder data.
- CIS Controls
- A prioritized set of safeguards published by the Center for Internet Security.
- Raman spectroscopy
- An analytical technique that measures inelastic light scattering to characterize material composition. Read the Wikipedia overview of Raman spectroscopy.
- Raman scanning research status
- Raman scanning in this project remains a research-stage method and is not presented as a production SCI Division inspection method. See the USDA ARS publication on line-scan hyperspectral Raman systems.
- USDA AMS maple syrup grades and standards
- The U.S. Department of Agriculture Agricultural Marketing Service reference for maple syrup grade requirements and standards. Open the official USDA AMS Maple Syrup Grades & Standards page.
- Provenance
- Recorded origin, custody, transformation, and evidence history for data or a physical lot.