DEMO ONLY · Conceptual explanations and test fixtures · Use source standards for production decisions

C=US technical glossary

Revision 2.4 · major milestone: state-endorsed identity and governed A2A information-flow concept · updated 2026-09-14

This glossary is written for readers at about a high-school reading level. It gives a helpful starting explanation, not a legal, compliance, engineering, or certification definition. For technical decisions, use the linked standards, regulations, and source documentation.

Demo disclosure: the local mTLS, CSAIL Liquid integration, Liquid Registry Lab, state-endorsed identity concept, and maple-quality workflow are conceptual demonstrations, not production authorization services.

Return to the proposal · Explore the registration lab · State-endorsed identity concept · Private project repository

LDAP
Lightweight Directory Access Protocol, the protocol applications use to read and update directory entries. IETF RFC 4510 specifies LDAP in terms of the X.500 data and service models.
X.500
A family of directory-service standards that defines a distributed directory information model; LDAP provides practical access to such directories. It is published jointly as ITU-T Recommendation X.500 / ISO/IEC 9594-1.
Directory Information Tree (DIT)
The hierarchical arrangement of LDAP entries, identified by distinguished names.
Distinguished Name (DN)
The complete unique path to an LDAP entry, such as cn=maple-quality-agent,ou=AI-Agents,o=Cequs,c=US.
Schema
The set of permitted object classes, attributes, syntaxes, and matching rules for a directory.
OpenLDAP
An open-source LDAP directory-server implementation used here as an X.500-oriented stand-in.
LDAPS
LDAP protected by TLS from the start of the connection, conventionally on TCP port 636.
Mutual TLS (mTLS)
TLS in which both the server and client present certificates and validate the other party. mTLS uses TLS certificate-based client authentication; see IETF RFC 8446, Section 4.4.2. The local demonstration uses a private test CA and does not install it into the system trust store.
TLS 1.3
The current major TLS protocol version used by much web traffic. Mutual TLS adds client-certificate authentication to the encrypted connection.
ISO/IEC and ITU-T
ISO (the International Organization for Standardization) and IEC publish international standards together as ISO/IEC; ITU-T publishes aligned telecommunications recommendations. The X.500 Directory series is published as ITU-T X.500 / ISO/IEC 9594, and ITU-T X.509 / ISO/IEC 9594-8 defines public-key and attribute-certificate frameworks.
IETF
The Internet Engineering Task Force publishes open Internet standards that support use of these international standards in networked systems. RFC 4510 defines LDAP as an X.500 access mechanism; RFC 5280 profiles X.509v3 certificates and CRLs for the Internet PKI; and RFC 8446 defines TLS 1.3 and certificate-based client authentication.
IHE International
Integrating the Healthcare Enterprise, an international community that develops interoperability profiles for healthcare systems and application processes.
AAL3
Authentication Assurance Level 3 in NIST SP 800-63B. It describes very high confidence that a claimant controls bound authenticators; AAL3 is an authentication assurance level, not a certificate type, and applicability depends on the system and policy.
Digital identity
Information used to recognize a person, device, or software agent in a system.
Authentication
Checking that someone or something really controls an identity, such as by using a password, security key, or certificate.
Authorization
Deciding what an already authenticated identity is allowed to do.
X.509v3 certificate
A signed digital document that connects a public key to a name or service. The X.509 public-key certificate framework is defined by ITU-T X.509 / ISO/IEC 9594-8; the IETF’s RFC 5280 specifies the Internet PKI profile for X.509v3 certificates and CRLs. The local demo uses X.509v3 certificates.
Public key
A key that may be shared with others so they can verify signatures or encrypt information for its owner.
Private key
A secret key that proves control of a certificate. It must not be placed in browser code, web folders, or source control.
Public-key infrastructure (PKI)
The people, rules, certificates, and systems used to create and trust public keys.
Certificate authority (CA)
An organization or system that signs certificates after checking the requested identity.
Certificate chain
The trust path from an end certificate through an issuing CA to a trusted root CA.
Certificate fingerprint
A short SHA-256 value calculated from a certificate. The demo uses it to bind a certificate to a registered agent.
Certificate revocation
Marking a certificate as no longer trusted before its normal expiration date.
Client authentication
Using a client certificate to prove the identity of a calling device, person, or software agent.
Certificate extended key usage
A certificate field that states its intended purpose, such as client authentication or server authentication.
Certificate subject alternative name (SAN)
A certificate extension, defined by IETF RFC 5280, Section 4.2.1.6, that names what a certificate identifies. On a server certificate this is usually the host names or IP addresses the certificate is valid for. On a client certificate it can instead be a URI naming a workload or agent identity — the demo's agent certificates carry a wimse://cequs.com/agents/<agentId> URI SAN, the identifier format described in draft-ietf-wimse-workload-creds.
Certificate validity period
The start and end dates during which a certificate may be accepted.
Grant window
The start and end dates for a directory permission. A valid certificate does not override an expired grant.
Identity binding
The recorded connection between a verified certificate fingerprint and a registered directory entry.
OpenSSL
Software for creating and checking keys, certificates, and encrypted connections. The local demo uses the Windows 64-bit OpenSSL binary.
mTLS gateway
A server that requires certificates from both sides of a connection, checks the certificate, and then applies authorization rules.
Protected channel
An encrypted connection that also confirms the intended server, and sometimes the client, before data is exchanged.
Webhook
An HTTP address that receives an event or request from another application, such as the maple-quality mock sending data to n8n.
API
An application programming interface: a defined way for one program to request data or an action from another program.
JSON
A plain-text format commonly used to exchange structured data between web applications.
n8n
A workflow automation tool used here to receive a request, query LDAP, evaluate policy, and return a decision.
Policy decision
The result of checking identity, status, scope, and time limits before allowing or denying an action.
Human-in-the-loop
A design in which a person reviews or approves an important action before it is completed.
YubiKey
A physical security key that can perform strong cryptographic authentication and requires the user to touch the device.
FIDO2
An open security-key standard that supports phishing-resistant sign-in without sending a password to the service.
Federation
A trust arrangement in which one identity system accepts authentication performed by another identity system.
OAuth 2.0
A standard that lets an application receive limited access to a resource without receiving the user's password.
Single sign-on (SSO)
A login arrangement in which one identity provider can sign a user into several applications.
Identity provider (IdP)
A service that authenticates users or agents and sends trusted identity information to another service.
Assurance level
A rating of how strongly a system established an identity. NIST separates identity proofing, authentication, and federation assurance.
Major/minor revision
A simple project version label. The major number changes for a large capability or design change; the minor number changes for smaller updates within that major stage. This project is at Revision 2.4 while the state-endorsed identity and governed A2A information-flow concept is in progress.
Agentic AI
An AI system that can plan, use tools, take actions, and continue work toward a goal within assigned authority and controls.
Deep learning and agentic-AI research
The poster's maple-syrup use case references deep-learning analysis of Raman measurements in Xiao et al., Food Chemistry 463 (2025), article 141289. The broader agentic-AI registry context is presented in the hosted proposal poster.
AI agent registration
Recording an agent identity, owner, status, authorized scope, and relevant evidence in a registry. The Liquid Registry Lab is an interactive conceptual walkthrough of this proposed flow.
Authorization scope
The bounded action or resource permission assigned to an identity, such as proposing a maple-lot grade.
State-endorsed identity
A proposed model in which a state or recognized issuer attests an identity or role, an accountable operator binds the evidence to an AI agent, and local policy controls each permitted exchange. It is a design concept, not a claim of an existing cross-border A2A identity service. See the concept note and its primary policy sources.
Least privilege
Granting only the permissions necessary for a defined task and duration.
Sandbox escape
Unauthorized movement from an isolated execution environment into a broader host, network, or production environment.
Credential theft
Unauthorized acquisition of passwords, keys, tokens, or certificates used to authenticate an identity.
Incident response
Coordinated detection, containment, investigation, recovery, and lessons-learned activities after a security event.
GDPR
European Union General Data Protection Regulation governing personal-data processing.
CCPA
California Consumer Privacy Act, a California privacy law.
HIPAA
US health-information privacy and security requirements for covered entities and business associates.
ISO/IEC 27001
International standard for an information-security management system.
SOC 2
Attestation framework evaluating controls relevant to trust-services criteria.
NIST SP 800-64
NIST guidance for integrating security into the system development life cycle.
PCI DSS
Payment Card Industry Data Security Standard for protecting cardholder data.
CIS Controls
A prioritized set of safeguards published by the Center for Internet Security.
Raman spectroscopy
An analytical technique that measures inelastic light scattering to characterize material composition. Read the Wikipedia overview of Raman spectroscopy.
Raman scanning research status
Raman scanning in this project remains a research-stage method and is not presented as a production SCI Division inspection method. See the USDA ARS publication on line-scan hyperspectral Raman systems.
USDA AMS maple syrup grades and standards
The U.S. Department of Agriculture Agricultural Marketing Service reference for maple syrup grade requirements and standards. Open the official USDA AMS Maple Syrup Grades & Standards page.
Provenance
Recorded origin, custody, transformation, and evidence history for data or a physical lot.