Protocol · UMP v0.1 draft

The Universal Machine Protocol.

UMP lets a skill be written once and run on any machine whose body can physically do it. It has two levels: an exchange where tasks, skills, offers and evidence move between owners, and a machine layer that translates a skill to one body and admits it only when physics allows.

Working name, formerly URPopen specificationspecified · partly demonstrated in simulation2026-10-11

What travels · how it runs

The exchange carries what to do. Each machine decides how, on board. Nobody standardizes why.

Judgment and planning stay in each operator's own stack. Mixing these levels is how protocols grow out of control: a skill that also decides whether to act becomes a planner, and a planner cannot be certified.

Exchange level · what

Tasks, offers, bids, evidence

Robots, services, skills and knowledge move between independent owners. Publish → qualify → bid → award → run → verify → record → propose → review.

Concept · no schemas yet

Machine level · how

Skill packet → manifest → translation → admission → run

Per machine, in real time, offline if needed. The safety path is local (hot); governance and distribution are remote (cold).

Specified · reach and hold demonstrated in simulation

Four axes · versioned

A skill packet describes a physical action without naming a body: "apply 5 N", never "turn motor 3".

AxisCarriesStatus
SSensing: what must be perceived, and how wellSpecified
KKinematics: positions, paths and tolerances in a named frameDemonstrated (sim), reach
FForce: targets and limits; a coupled impedance mode for contact with unknown stiffnessSpecified, untested
TTime and logic: sequence, timeouts, hold or abort per stepSpecified

Example, the reach skill used in run E3

skill: reach
fkst_version: 0.1
K:
  target: cartesian_position
  frame: world
  value_m: [0.40, 0.00, 0.50]
  tolerance_mm: 20
T:
  on_refusal: hold_state_safe

Illustrative fields; the schema is frozen in phase 0 of the next experiment.

Declared per machine, in numbers

Every machine declares what its body can do in numbers. The tool tip is a mandatory, verified frame.

In simulation, measuring from the last joint instead of the tip silently hid one degree of freedom from every check. The fix became a protocol rule.

FieldMeaning
workspace_envelopeWhere the tool can reach
max_force_per_actuatorForce and torque limits
degrees_of_freedomJoints that move the tool
precision_classRepeatability
end_effector_capabilitiesGrippers, tools
sensing_modalitiesWhat it can perceive
reaction_time_msHow fast it responds
mobility_classFixed, wheeled, legged
environmental_restrictionsWhere it may not operate

Mandatory since run E3

end_effector_reference_frame:
  frame_type: fixed_tip_joint
  link_ref: tip_link
  verified_dof_coverage: true
  # perturb each declared DOF;
  # the reference point must move
Five stages · on board

Cheap checks run before expensive ones, and nothing moves until the robot itself admits it.

Three end states are always kept apart: rejected before running, failed while trying, and unverified when the result cannot be shown.

StageWhat it doesResultStatus
1Read the skill's requirements and the capability manifestcapability matchDemonstrated (sim)
2aGeometric reachability: distance to the target against declared reach. Necessary, not sufficientreachable | geometric_infeasibleDemonstrated (sim)
2bSolver convergence, only if 2a passes (damped least squares)converged | non_convergentConverged (sim)
3Translation into this body's joint targets; learned models allowed inside if the result still passes 4 and 5full | partial | rejectedDemonstrated (sim)
4Admission against the physical validity envelope, re-checked during the runadmit | refuseJoint limits only
5Translation fidelity certificate: the translator qualified on 3 or more categorically different bodiesfull | partial | provisionalNot demonstrated
Physical validity envelope

Physics cannot be voted on. A valid signature proves who sent a skill, not that it can be done.

Every limit is tagged with its class, so a contract, price or governance vote can never make something physically impossible allowed.

Envelope partContents
Stability certificateDynamics class: hold a point, steady cycle, or fixed-duration manoeuvre
Safety certificateMapped to ISO 10218 and ISO/TS 15066 parameters; a mapping, not compliance
Actuation constraintsActuator limits
Environmental assumptionsQuantitative values, not tags
Temporal validityMaximum state age, latency, revalidation interval
Invariant classWho can change it
physics_enforcedNobody: a law of nature or a measured fact
protocol_negotiatedGovernance, by renegotiation
hybridOnly the negotiated margin on a physical quantity

If no safe action exists, the robot falls back to a declared safe abort or hold. In shared tasks an abort is announced first: a robot that lowers its side of a shared load alone is more dangerous than one that holds.

Concept schemas in phase 0

Ten objects carry a job from request to verified outcome, and carry what was learned back to the next machine.

ObjectPurposeGood
TaskContractOutcome, acceptance criteria, constraints, site and safety context, evidence required, bid rulesServices
CapabilityAndStateOfferCertified capability plus live state: health, energy, availability, location, uncertainty, state ageRobots
ExecutionBidMethod, predicted time, cost, energy and risk with uncertainty; evidence from comparable jobsServices
AwardAndExecutionContractAccepted obligations, plan, evidence plan, abort rightsServices
AdmissionDecisionThe robot's own permit or refusal, with a reasonAll
ExecutionTraceTimestamped measured events, changes and abortsKnowledge
OutcomeEvidenceVerified, failed or unverified, with uncertainty and proofsKnowledge
VariantProposalAn improved skill: lineage, metric changes, scope, negative results, review statusSkills
TaskPatternA reusable way to break down and coordinate a taskKnowledge
RobotAssetRecordIdentity, manifest, wear state, ownership and a verified track recordRobots

Improvements are never deployed automatically. A variant enters only as a competing option after independent review, and only within the scope it was reviewed for.

Reuse before inventing

UMP composes existing standards through profiles instead of competing with them.

What stays ours: admission before award across owners, evidence as a tradable asset, governed reuse that pays skill authors, and one loop linking robots, services, skills and knowledge.

ProfileUsesWhere UMP differs
Skill payloadRFL skill instruction set, SkillCrate packages, qualified learned policiesMarket, many owners, settlement, evidence reuse
CompatibilityECM contract dimensionsPhysical admission, outcome evidence
VerificationRFL certificates, independent evaluation gatesField data from real jobs
Execution inside a siteOpen-RMF bridge, VDA 5050Between sites, with money, contracts and proof
Industrial integrationOPC UA, ISA-95, Asset Administration Shell (IEC 63278)—
SafetyISO 10218, ISO/TS 15066, ISO 13849Admission stays local and never depends on payment

The name Universal Machine Protocol is descriptive and will not be a trademark; "machine" widens the scope to forklifts, cranes and drones. Open questions: who governs the specification, and which standards to map first.