arXiv:2504.19997cs.CRcs.AI2025-04被引 10

为企事业单位自建MCP服务器提供安全简化方案

Simplified and Secure MCP Gateways for Enterprise AI Integration

  • 设计安全网关架构,集成认证与入侵检测机制
  • 实现私有部署不暴露基础设施的远程连接
  • 适合关注AI代理安全接入的企业技术团队

随着模型上下文协议(MCP)在AI代理中的广泛应用,企业级集成的安全性愈发重要。本文提出MCP网关,旨在简化自托管MCP服务器的集成流程。所提架构融合安全原则、身份认证、入侵检测及安全隧道技术,支持无需暴露基础设施的私有化部署。主要贡献包括参考架构设计、威胁模型映射、简化集成策略以及开源实现建议。本工作聚焦企业级自托管AI集成的独特挑战,区别于现有的公共MCP服务器解决方案。

原文摘要 · Abstract (English)

The increased adoption of the Model Context Protocol (MCP) for AI Agents necessitates robust security for Enterprise integrations. This paper introduces the MCP Gateway to simplify self-hosted MCP server integration. The proposed architecture integrates security principles, authentication, intrusion detection, and secure tunneling, enabling secure self-hosting without exposing infrastructure. Key contributions include a reference architecture, threat model mapping, simplified integration strategies, and open-source implementation recommendations. This work focuses on the unique challenges of enterprise-centric, self-hosted AI integrations, unlike existing public MCP server solutions.

MCP企业AI安全网关

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。