International Scientific Journal of Engineering and Management

An International Scholarly || Multidisciplinary || Open Access || Indexing in all major Database & Metadata
The journal follows the UGC Guidelines and is evaluated for inclusion in the Web of Science
ISSN: 2583-6129

Impact Factor: 8.072

A Layered Cryptographic Trust Architecture (LCTA) for Secure Agentic Commerce in Autonomous AI Marketplaces

Version
Download 1
File Size 473.87 KB
File Count 1
Download
or download free

Manuscript Title

A Layered Cryptographic Trust Architecture (LCTA) for Secure Agentic Commerce in Autonomous AI Marketplaces

 

 

Anath Bandhu Chatterjee

Payment Systems Architecture

San Jose, California, USA

 

 

Abstract—The emergence of agentic commerce — autonomous AI agents discovering, negotiating, and settling purchases on behalf of users — has progressed from prototype to production within twelve months. Visa's Trusted Agent Protocol (TAP), Google's Agent Payments Protocol (AP2), Stripe / OpenAI's Agentic Commerce Protocol (ACP), Coinbase's x402, and Cloudflare's Web Bot Auth now deliver fragments of a trust fabric, yet no single specification spans the full lifecycle from user intent to settled payment with non-repudiable evidence. This paper presents LCTA, a four-layer cryptographic trust architecture that composes existing primitives into a coherent end-to-end framework. Layer 1 (Cryptographic Agent Identity) anchors every agent to a Decentralized Identifier (DID) and signs every HTTP request via RFC 9421 Message Signatures. Layer 2 (Verifiable Intent Binding) introduces the Intent-Bound Transaction Token (IBTT), a hash-chained construction that fuses Intent, Cart, and Payment Mandates into a single non-malleable artifact whose modification voids the transaction. Layer 3 (Risk-Adaptive Authorization) computes a composite risk score R(t) over five orthogonal signal classes and emits an allow / step-up / deny decision aligned with PSD3 Strong Customer Authentication and EMV 3-DS v2.3. Layer 4 (Continuous Verification) records every decision to an append-only attestation log, supplying chargeback and dispute-grade evidence. We present a formal threat model spanning the OWASP Agentic AI top-15 categories, indirect prompt injection (IDPI), and replay / confused-deputy attacks; demonstrate a 25.0 / 26.0 threat-coverage score versus 17.0 for the strongest prior single-protocol baseline; and discuss compliance alignment with PCI-DSS v4.0.1, GDPR Article 22, and the EU AI Act. The paper is intended as an actionable design reference for payment networks, issuers, and merchants integrating agent-initiated commerce in 2026 and beyond.

Index Terms—Agentic commerce, AI security, payment systems, verifiable credentials, decentralized identity, trust architecture, AP2, Trusted Agent Protocol, risk-based authorization, PSD3, EMV 3-DS, intent binding.

[changelog]

Categories & Tags

Similar Downloads

No related download found!

Author's Blog

What is the difference between a Research Paper and a Review Paper?

A research paper and a review paper are both scholarly documents, but they serve different purposes and have different characteristics....
Read More
Author's Blog

What is DOI?

A Digital Object Identifier (DOI) is a unique alphanumeric string that is used to identify and provide a persistent link...
Read More
Author's Blog

What do you need to do during production of your Research Paper?

During the production of a research paper, the following steps need to be taken: conducting research, organizing and analyzing data,...
Read More
Author's Blog

What are the advantages of publishing a research paper?

Publishing a research paper can have many advantages for researchers, including: Career advancement, professional recognition, opportunities for collaboration, increased visibility,...
Read More
Author's Blog

Ways to Support your Academic Wellbeing which preparing the Research Paper/Article

To support your academic wellbeing while publishing a research paper, it's important to set realistic goals, manage your time effectively,...
Read More
Author's Blog

How to improve your Research Paper writing Skills?

Read extensively: One of the best ways to improve your research paper skills is to read extensively in your field...
Read More
Author's Blog

Is DOI compulsory to publish a research paper in a Journal?

DOI is not strictly required to publish a research paper, but it is highly recommended. Basically, the International Scientific Journal...
Read More
Author's Blog

In what ways does research paper give weight to career development?

Publishing a research paper can give weight to a researcher's career development in several ways, such as: establishing oneself as...
Read More
Author's Blog

How to develop a Research Paper from Scratch

Developing a research paper involves several steps including: choosing a topic, conducting background research, formulating a research question or hypothesis,...
Read More
Author's Blog

How Plagiarism report plays crucial role in Research Paper Publication?

Plagiarism is a major concern in the academic and research community, as it undermines the integrity of the research and...
Read More