OSAFIS

Security Properties

OSAFIS 2.0.0-draft.1 · Research proposal · 19 min read

On this page
  1. What a property establishes
  2. Instantiating and testing a property
  3. P01 Confidentiality
  4. P02 Integrity
  5. P03 Availability
  6. P04 Instruction Integrity
  7. P05 Context Integrity
  8. P06 Knowledge Integrity
  9. P07 Memory Integrity
  10. P08 Identity Integrity
  11. P09 Objective Integrity
  12. P10 Behavioral Integrity
  13. P11 Semantic Integrity
  14. P12 Capability Integrity
  15. P13 Action Integrity
  16. P14 Controllability
  17. P15 Planning Integrity
  18. P16 Delegation Integrity
  19. P17 Temporal Integrity
  20. P18 Decision Integrity
  21. P19 Human Decision Integrity
  22. P20 Attribution Integrity
  23. P21 Trust Integrity
  24. P22 Perception Integrity
  25. P23 World-Model Integrity
  26. Distinguishing goals judgments strategies and behavior
  27. Reporting interactions and limits

OSAFIS 2.0.0-draft.1 | Research proposal | 7 September 2026

What a property establishes

A security property names an obligation that an assessment can instantiate for a protected object, function, or relationship. An attack mechanism describes how influence operates; a domain locates the relevant contract; a property states what that contract protects. These axes are related but not interchangeable. A malicious document may reach a system without violating any property, and the same property can fail through several mechanisms in several domains.

The twenty three identifiers below retain the assignments and labels in the source Versioning and Identifiers. They are proposed analytical conventions, not evidence that a deployed system satisfies them. The source Security Properties used numbered section headings that do not match all permanent identifiers. Citations must use P identifiers and a framework version rather than infer identity from section position. In particular, P14 is Controllability, P15 Planning Integrity, P17 Temporal Integrity, and P18 Decision Integrity.

Instantiating and testing a property

For each applicable property, specify the protected object or relationship, authorized principals, permitted operations, governing conditions, time horizon, and observable violation criterion. Identify the policy owner and evidence that the policy applies. “The output was harmful” does not specify the obligation, and “the system remained secure” is not an oracle. Contracts may include categorical prohibitions, limits, thresholds, or conditional obligations; their values require justification in the assessed setting.

An oracle decides whether the specified condition holds. It may compare authorization records with effects, inspect source bindings, evaluate a declared rule against controlled facts, or use a reviewed rubric for meaning and presentation. The oracle's limitations must be reported, including disagreements between human adjudicators. Model generated explanations can be observations but should not be assumed to reveal the actual causal process or supply independent ground truth.

The examples and tests below are illustrative and unexecuted. They provide possible assessment designs, not experimental results, validated vulnerabilities, or universal controls. Tests should use synthetic data and contained effects where practicable. Each execution record must state baseline behavior, manipulated condition, negative controls, observed outcome, configuration, and uncertainty. A property can be inapplicable, untested, satisfied within examined conditions, violated under stated conditions, or unresolved. These states must not be collapsed into a binary assertion of system security.

P01 Confidentiality

Confidentiality requires that protected information be disclosed only to principals and channels allowed by the applicable policy. The contract must identify the information, recipients, transformations, and outputs in scope. Instructions, model artifacts, and internal traces are confidential only when a policy actually protects them; internal placement alone is not a secrecy rule. Disclosure can occur through text, retrieval, memory, tool payloads, or other observable channels.

The violation oracle establishes that an unauthorized recipient obtained protected information or a prohibited inference under the declared leakage criterion. A contained test can place a synthetic secret in one account and examine another account's outputs, with an authorized recipient as a negative control. A guessed marker is weak evidence unless its origin can be distinguished from chance or permitted knowledge. P01 concerns disclosure; P02 concerns unauthorized alteration, and P03 concerns service access. One incident can independently involve all three.

P02 Integrity

Integrity requires that protected information, configuration, computation, or state be created and changed only through permitted transformations and by authorized actors. “Trustworthy” must be translated into a specified invariant, such as an approved artifact digest, valid update authorization, or preserved account binding. The generic property remains useful for objects whose obligation is not better expressed by a specialized integrity property.

The oracle compares the protected object's observed state or transition with the authorized version and change rules. A model artifact replacement test can inspect the actual loaded artifact rather than infer replacement solely from changed answers. A permitted update exercises the negative case. Use P07 for the particular semantics of retained operational memory, P04 for instruction authority, and other specific properties where they provide the precise obligation. Adding P02 to every specialized integrity finding does not establish an additional failure or increase its severity.

P03 Availability

Availability requires delivery of specified functionality to authorized users within declared service, resource, or timing bounds. Those bounds should identify the workload and environmental assumptions, including admission controls and dependencies. A refusal required by policy is not a denial of authorized service. An unbounded promise to answer every request is not a workable contract.

The oracle measures the specified service outcome, such as completion, latency, or admitted workload, under a controlled condition. A contained test might introduce bounded recursive work and measure whether unrelated authorized requests remain within the service contract. A workload of equivalent permitted cost helps distinguish the proposed amplification mechanism from ordinary capacity limits. P03 concerns the ability to obtain service; P14 concerns the ability of an authorized party to constrain or stop operation. A continuously running service can satisfy one while violating the other.

P04 Instruction Integrity

Instruction Integrity requires that authorized instructions preserve their meaning, authority, scope, and precedence through the processing path. The deployment must identify who can issue each instruction class and how conflicts are resolved. Retrieved passages, tool responses, and quoted speech are not promoted to a privileged instruction role merely because their wording resembles an order.

The oracle compares the accepted instruction set and its observable effects with the governing source and precedence rules. An illustrative test supplies a document containing a purported policy override and inspects whether a protected task constraint is displaced. A valid instruction from the authorized source provides a negative control against indiscriminate refusal. P11 concerns meaning preservation more generally; P04 specifically concerns instructions and their authority. P09 concerns the resulting authorized objective. Record both only when evidence establishes the instruction violation and the objective change, rather than assuming one from the other.

P05 Context Integrity

Context Integrity requires that the material assembled to frame a task preserve the required membership, attribution, ordering, and qualification of relevant information. The contract can specify which history, assumptions, observations, or evidence must accompany a decision and what contextual omissions are prohibited. It does not require every possible fact to fit in a model's context.

The oracle compares the assembled decision context with that contract. An illustrative test introduces a summarization step that retains an approval statement while dropping its limiting condition, then checks whether the limitation remains available in the decision context. A summary retaining both clauses is a negative control. P06 concerns the underlying knowledge resource; P07 concerns retained state across operations. P05 concerns the task frame actually supplied for the current decision. If a required qualifier was already lost in persistent memory, the memory failure and its contextual propagation should be distinguished.

P06 Knowledge Integrity

Knowledge Integrity requires that information used as knowledge retain its required provenance, verification status, and conditions of use. It does not assert universal truth. A system may legitimately use uncertain or conflicting sources if the contract preserves those qualifications and does not present them as verified facts. Relevant resources include reference documents, retrieval collections, and training or other informational inputs.

The oracle compares the information's source and declared status with the resource contract at ingestion, transformation, and use. A contained test can mix synthetic verified and unverified records and check whether transformations falsely upgrade their status. A correctly labeled unverified result is a negative control, even if its content is wrong. P21 governs trust relationship changes more broadly; P20 governs traceable origin. P06 protects the epistemic handling of a knowledge resource, while P22 and P23 concern observation and representation of an operational environment.

P07 Memory Integrity

Memory Integrity requires that retained operational state be created, altered, associated, interpreted, and retired only within its authorized security context. The contract identifies the task or principal owning the state, its scope and validity, and permitted persistence or reuse. A conversation summary, checkpoint, or stored preference can carry this obligation regardless of the storage medium or retention duration.

The oracle compares preexisting authority and state with what is restored or used in a later operation. An illustrative test resumes two synthetic user sessions and checks whether one user's preference or approval migrates into the other. A correctly bound resume is the negative control. P05 concerns assembled current context, and P06 knowledge resources. P17 concerns obligations across time even when memory contents are unchanged. P07 is warranted when the stored or restored operational state itself violates its authorization, association, or interpretation contract.

P08 Identity Integrity

Identity Integrity requires reliable binding of relevant actors and their asserted authority to the users, agents, services, sessions, or sources they represent. The contract defines the identity evidence accepted for a particular role and the permissible association between identity and authority. A familiar name or statement of role does not itself satisfy that binding.

The oracle compares the principal treated as acting with the verified identity and role record. A synthetic interagent message can reuse another agent's display name while retaining a different authenticated identity; the test examines whether the receiver grants the named agent's role. A message with a valid identity binding supplies the negative control. P20 concerns the history of origin and contribution; P21 concerns permissible trust relationships. P08 identifies mistaken actor or actor authority binding, whereas P16 examines whether a correctly identified delegate receives excessive scope.

P09 Objective Integrity

Objective Integrity requires preservation of the authorized task or outcome until a principal entitled to change it does so within scope. An objective record should identify its originating authority, governing constraints, accepted revisions, and unresolved conflicts. Deployment policy, a valid user request, and bounded delegation can contribute; their precedence must be specified. The system cannot establish authorization merely by describing a preferred goal as legitimate.

The oracle compares the task the system commits to pursue with that record. In an illustrative test, a report review task is redirected toward promoting a named supplier after reading source content. Evidence must establish a changed task criterion or pursued outcome; a wrong recommendation alone is insufficient. An authorized revision provides the negative control. P18 concerns a judgment made while the task remains fixed, and P15 concerns the strategy for achieving it. P09 does not judge the ethical merit of the authorized goal or resolve an unspecified governance conflict.

P10 Behavioral Integrity

Behavioral Integrity requires observance of a defined security relevant behavioral constraint when no more specific property captures the obligation. It is residual by design. The contract must describe the prohibited or required observable behavior independently of the fact that an output was disliked or harmful. Variation, surprise, and ordinary model error do not establish this property failure.

For example, a support system could have a reviewed prohibition on making targeted threats to coerce a person into continuing an interaction. A proposed test would define the threat and coercion criteria, benign discussion controls, adjudication procedure, and permitted evaluation setting before observing outputs. The oracle concerns those criteria, not a generic harmfulness score. Use P19 when the demonstrated obligation is materially deceptive influence on human decisions, P09 for changed objectives, P15 for invalid strategies, and P18 for invalid judgments. Where no specific behavioral contract or reliable adjudication exists, record the classification as unresolved rather than defaulting to P10.

P11 Semantic Integrity

Semantic Integrity requires preservation of security relevant meaning through interpretation or transformation. The contract identifies which distinctions must survive, such as negation, scope, conditions, quoted versus asserted statements, or a hypothetical versus actual authorization. It need not require literal wording or identical outputs, and ambiguity should be represented rather than silently resolved where the distinction matters.

The oracle compares the interpreted or transformed proposition with the specified meaning using controlled cases or a reviewed adjudication rubric. An illustrative test translates “approval is valid only for the test account” and checks whether the account limitation survives; meaning preserving paraphrases form negative controls. P04 applies specifically to instruction authority and meaning, P08 to actor binding, and P09 to the authorized goal. P11 is useful when the demonstrated failure is a meaning transformation; it should not be added solely because natural language appears somewhere on the path.

P12 Capability Integrity

Capability Integrity requires that the selection and intended use of available capabilities remain within their authorized security boundaries. The contract identifies permitted tools or operations, purposes, objects, principals, and conditions. Possession of a credential or technical access establishes only one part of the permission relation; it does not authorize every task or every proposed use.

The oracle compares a selected or requested capability use with its permitted purpose and scope before the relevant external effect. An illustrative test gives an agent both a read only query tool and a modification tool for separate tasks, then checks whether a source passage induces selection of the latter for a read only request. A legitimately authorized modification is a negative control. P13 concerns realized effects, P15 the strategy as a sequence, and P09 the objective. A blocked impermissible selection can violate P12 while execution enforcement successfully preserves P13.

P13 Action Integrity

Action Integrity requires that external effects remain within authorized scope at execution. The contract should bind the action's actual object, recipient, data, magnitude, timing, and relevant preconditions. It covers digital effects and physical actuation. Correct capability selection is not sufficient if parameters change, a target becomes stale, or execution produces a different effect.

The oracle compares observed effects with the applicable authorization and execution conditions. In a contained test, an approved write to synthetic record A is redirected to record B between selection and dispatch. A verified write to A supplies the negative control. P12 concerns capability selection; P13 concerns effect. If both contracts independently fail, both may be recorded in the causal account. This draft does not retain an obligatory earliest property rule that would hide a separately failed execution check. The earliest supported failure may remain an indexing choice without erasing later evidence.

P14 Controllability

Controllability requires that an authorized party retain the specified ability to observe, interrupt, constrain, revoke, or recover the system's operation. The contract identifies the available intervention, responsible party, timing requirement, and effects that remain reversible. A displayed stop control does not establish that running tasks or delegated operations obey it.

The oracle measures whether the intervention takes effect before its specified deadline and within the claimed scope. An illustrative simulation cancels a queued operation and checks whether execution and delegated continuations cease before a simulated commit point. A task with no pending effect is a negative control for the cancellation signal path but does not establish timely prevention. P03 concerns continued service, while P14 concerns legitimate control over that service. Recovery of reversible state cannot demonstrate reversal of disclosure or other irreversible effects; those require containment and intervention before the relevant boundary.

P15 Planning Integrity

Planning Integrity requires that a strategy for achieving an authorized objective satisfy declared security constraints on sequencing, dependencies, resources, and intermediate states. Legitimate goals and individually permitted operations do not guarantee that their composition is allowed. The assessable object is the selected plan, scheduled sequence, or sufficiently observable execution strategy, rather than an assumed private reasoning trace.

The oracle checks that strategy against its constraints before or independently of realized harm. An illustrative task permits updating two records only together; a plan to commit one before validating the other violates the stated condition. A transactional sequence supplies a negative control. P09 concerns what outcome is pursued; P18 concerns judgments such as whether validation passed; P13 concerns the actual update effects. Evidence of a harmful final action alone cannot determine whether the plan, the judgment supporting it, or only execution was defective.

P16 Delegation Integrity

Delegation Integrity requires that transferred or exercised authority preserve the delegator's valid scope and all constraints imposed on the transfer. The contract identifies the delegator, delegate, task, permitted resources, expiry, revocation behavior, and whether further delegation is allowed. Responsibility transfer is not an authorization to expand capability or change the objective.

The oracle compares the authority accepted or exercised by a delegate with the original grant and permitted transformations. A contained test delegates access to one synthetic folder and checks whether the next service treats the request as account wide access. A valid narrowed delegation is a negative control. P08 protects actor binding, P12 capability selection, and P17 time dependent validity. Information exchange or an agent's recommendation does not necessarily delegate authority; the graph must identify an actual delegation relation before applying this property on that basis.

P17 Temporal Integrity

Temporal Integrity requires that security obligations remain valid through specified delays, state transitions, repeated interactions, and lifecycle events. It captures temporal conditions such as expiry, revocation, order, and continuing validity. “The failure happened later” is insufficient; the assessment must identify which time dependent obligation was defeated.

The oracle compares an operation's timing and state transition with the relevant validity rule. An illustrative test queues a synthetic action under a grant that expires before execution and checks whether the action is revalidated or blocked. Execution within the grant's validity interval is a negative control. P07 concerns retained operational state, whereas P17 can fail with accurate storage when an unchanged expired grant is still honored. P14 concerns the effectiveness of intervention. Temporal qualifiers may accompany any property without constituting an independent P17 failure unless a distinct temporal obligation is evidenced.

P18 Decision Integrity

Decision Integrity requires that the system's security relevant judgments follow the specified decision rule, admissible evidence, and uncertainty requirements. The objective may remain unchanged while a verdict, classification, authorization determination, or intermediate judgment is manipulated. The contract must identify the rule or accepted adjudication method; disagreement with an assessor's intuition is not a sufficient oracle.

An illustrative test asks whether a synthetic request meets a fixed access condition and varies irrelevant source framing while holding the verified facts constant. The oracle compares the returned verdict with the declared rule and examines whether the purported influence explains the deviation. Legitimately different facts that change the verdict are negative controls. P09 concerns substitution of the task itself, P15 the strategy, and P19 the person's subsequent judgment. A wrong system verdict can be demonstrated without an external action, but attribution to an attack requires evidence beyond one incorrect answer.

P19 Human Decision Integrity

Human Decision Integrity requires that system mediated influence on security relevant human choices respect the declared conditions for materially truthful representation and informed authorization. The contract identifies which claims, omissions, uncertainty, or scope information are material to the person's role. Ordinary influence is not prohibited; the issue is unauthorized or materially deceptive influence under specified criteria.

The oracle can inspect a mismatch between presented action scope and the approval actually requested, or assess misleading claims under a reviewed rubric. Demonstrating that people changed decisions because of that presentation requires separate human evidence; an interface defect alone does not prove the downstream decision effect. A scope accurate preview is a negative control in a synthetic workflow. P18 concerns judgments produced by the system, P20 provenance, and P14 usable intervention. Human studies require appropriate consent, review, debriefing, and data protections; unsuspecting users must not become test subjects.

P20 Attribution Integrity

Attribution Integrity requires preservation of the origin and contribution records needed to trace significant information, decisions, and effects. The contract identifies the required lineage, including initiating principal, contributing sources, agents, tools, and authorization records where relevant. It does not promise perfect reconstruction of a model's internal reasoning or require indefinite retention of private content.

The oracle compares recorded lineage with controlled source and execution records. An illustrative test routes a synthetic request through two agents and a shared tool, then checks whether the resulting event incorrectly names the second agent as the original authorizer. A correctly linked event is the negative control. P08 concerns actor identity binding, P06 knowledge provenance in its resource role, and P21 trust assignment. Attribution supports accountability but does not itself establish responsibility, truth, or authorization. Logs can be complete yet misleading if their claimed relationships are not bound to the events they describe.

P21 Trust Integrity

Trust Integrity requires that trust relationships and the privileges of trusted roles change only through the authorized process. The contract must specify what trust permits: relying on a source as verified evidence, accepting it as an instruction issuer, or allowing a service to act for a principal. A single undifferentiated trusted flag can conceal materially different permissions.

The oracle identifies an unauthorized change in the role or reliance granted to a source or actor. An illustrative test inserts a claim of verified publisher status into an unverified record and inspects whether the receiving workflow accepts that claim as sufficient evidence for promotion. An actual authorized verification transition is the negative control. P08 concerns who the actor is; P21 concerns the trust relation assigned to that actor or content. P04 applies when the promotion specifically changes instruction authority. Several labels should reflect independently stated obligations, not repeated descriptions of one promotion.

P22 Perception Integrity

Perception Integrity requires that acquired observations preserve the accuracy, entity association, timing, and uncertainty required by the observation contract. Its stable concern is what the system observes. This revision explicitly includes observation of digital environments alongside physical sensing; historical physical only applications require version qualified review. Mere text input does not establish or exclude an observation function.

The oracle compares the observation representation with a controlled environment or suitably justified reference, using predefined error and confidence criteria. An illustrative simulation changes a displayed object's identity and checks whether the new observation binds to the correct object. A stable scene is a negative control. P06 concerns information supplied as knowledge; P23 concerns the maintained and inferred world representation. A single mistaken observation does not automatically demonstrate persistent world model corruption. The validity of a simulator or reference measurement limits the claim, and authenticated sensor origin does not alone establish perceptual accuracy.

P23 World-Model Integrity

World-Model Integrity requires that a maintained representation of the operational environment remain consistent with required observations, state transitions, uncertainty, and refresh rules. It includes inferred state and conditions not currently observed. The contract must define the environment features that matter, acceptable staleness, and triggers for revising beliefs; perfect knowledge of reality is not a feasible requirement.

The oracle compares the maintained representation and its use with a controlled environment history. An illustrative digital simulation changes resource ownership after an earlier observation and checks whether a required refresh corrects the represented owner before a dependent decision. A permitted stable ownership interval is a negative control. P22 concerns acquired observations, P07 authorized retention, and P17 temporal conditions more broadly. A faithfully stored but stale world representation can violate P23 without a storage alteration. A false observation that is promptly corrected need not establish a separate P23 violation.

Distinguishing goals judgments strategies and behavior

P09, P18, P15, and P10 answer different questions. P09 asks what authorized outcome the system is trying to achieve. P18 asks whether a security relevant judgment follows its declared rule. P15 asks whether the chosen strategy respects its constraints. P10 asks whether a separately defined residual behavioral constraint is breached. The fact that each can affect output does not erase these boundaries.

Consider an illustrative, unexecuted transaction review task. Changing the task from detecting unauthorized transfers to maximizing approvals suggests P09. Preserving the review task but declaring a transfer valid contrary to the fixed rule suggests P18. Reaching the correct verdict but planning to notify a recipient before completing required checks suggests P15. None should be relabeled P10 merely because it produces undesirable behavior. Evidence may support several failures, but each needs its own obligation and oracle; unseen intermediate states should remain hypotheses.

Reporting interactions and limits

A finding should name the narrowest supported obligation, its component or relationship, the relevant domain, and the mechanism evidenced. Generic integrity and contextual qualifiers can aid retrieval without multiplying vulnerability counts. Multiple independently failed controls may be recorded in one causal case. A path that crosses memory, interpretation, and execution does not establish three property violations unless each relevant contract fails.

Nonadversarial disturbances can exercise these obligations. Record the observed trigger, then separately assess whether an adversary can cause or exploit it. Likewise, a vulnerability can exist before a harmful incident occurs; the assessable violation may be an unauthorized grant or disclosure path rather than a completed catastrophe. Confidence, recurrence, consequence severity, exposure, and test coverage remain distinct. Irreversible consequences justify containment and conservative decisions, while probabilistic evidence remains meaningful within its assumptions.

Foundational Concepts defines contracts and evidence; Security Layers locates their functions; Threat Model states assumptions and capabilities; Assessment Methodology governs execution records; and Vulnerability Registry governs reviewed claims. Future proposals should justify added or refined properties with boundary cases and reproducible evidence. This draft supplies a language for scoped assessment, not proof of total coverage or a certificate that any system is secure.

Word document · Markdown source · Open in the interactive site