为AI代理设计可认证、可审计的权限委托框架,确保其行为可控且责任可追溯。
Authenticated Delegation and Authorized AI Agents
- 基于OAuth 2.0和OpenID Connect扩展代理凭证与元数据,实现安全权限委托。
- 将自然语言权限转化为可审计的访问控制配置,支持多模态交互场景。
- 适合数字服务提供商快速部署可信AI代理,防范规模化交互风险。
自主AI代理的快速部署带来了授权、问责和访问控制方面的紧迫挑战。亟需新标准来明确AI代理代表谁行动,并合理引导其使用,以保护网络空间并释放任务委托的价值。本文提出一种可认证、可授权、可审计的AI代理权限委托框架,使用户能安全地授予和限制代理的权限范围,同时保持清晰的责任链条。该框架基于现有身份与访问管理协议,扩展了OAuth 2.0和OpenID Connect,引入代理专用凭证与元数据,兼容现有认证与网络基础设施。此外,我们提出一种将灵活自然语言权限转化为可审计访问控制配置的机制,支持在多样交互模式下对代理能力进行可靠约束。整体方案具备实用性,可立即部署,有效应对安全性与问责性问题,确保代理仅执行适当操作,为数字服务提供方可信支持代理交互而不承担规模性风险。
原文摘要 · Abstract (English)
The rapid deployment of autonomous AI agents creates urgent challenges around authorization, accountability, and access control in digital spaces. New standards are needed to know whom AI agents act on behalf of and guide their use appropriately, protecting online spaces while unlocking the value of task delegation to autonomous agents. We introduce a novel framework for authenticated, authorized, and auditable delegation of authority to AI agents, where human users can securely delegate and restrict the permissions and scope of agents while maintaining clear chains of accountability. This framework builds on existing identification and access management protocols, extending OAuth 2.0 and OpenID Connect with agent-specific credentials and metadata, maintaining compatibility with established authentication and web infrastructure. Further, we propose a framework for translating flexible, natural language permissions into auditable access control configurations, enabling robust scoping of AI agent capabilities across diverse interaction modalities. Taken together, this practical approach facilitates immediate deployment of AI agents while addressing key security and accountability concerns, working toward ensuring agentic AI systems perform only appropriate actions and providing a tool for digital service providers to enable AI agent interactions without risking harm from scalable interaction.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。