为大模型工具协议设计安全增强接口,防范恶意工具劫持与诈骗攻击
ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control
- 通过OAuth增强工具定义实现身份验证与版本锁定
- 引入策略驱动的动态访问控制,支持运行时上下文判断
- 适合关注AI应用安全、大模型外接工具管控的开发者
模型上下文协议(MCP)通过集成外部工具和数据源,显著扩展了大语言模型(LLMs)的能力。然而,标准MCP规范存在严重安全漏洞,特别是工具污染和拉高出逃攻击。本文提出增强型工具定义接口(ETDI),作为MCP的安全扩展。ETDI结合密码学身份验证、不可变版本化工具定义及显式权限管理,常基于OAuth 2.0实现。我们进一步提议在MCP中引入细粒度、策略驱动的访问控制,利用专用策略引擎对工具能力进行动态评估,考虑运行时上下文而非仅静态OAuth范围。该分层方法旨在建立更安全、可信且可控的AI应用生态,使大模型与外部工具交互更加可靠。
原文摘要 · Abstract (English)
The Model Context Protocol (MCP) plays a crucial role in extending the capabilities of Large Language Models (LLMs) by enabling integration with external tools and data sources. However, the standard MCP specification presents significant security vulnerabilities, notably Tool Poisoning and Rug Pull attacks. This paper introduces the Enhanced Tool Definition Interface (ETDI), a security extension designed to fortify MCP. ETDI incorporates cryptographic identity verification, immutable versioned tool definitions, and explicit permission management, often leveraging OAuth 2.0. We further propose extending MCP with fine-grained, policy-based access control, where tool capabilities are dynamically evaluated against explicit policies using a dedicated policy engine, considering runtime context beyond static OAuth scopes. This layered approach aims to establish a more secure, trustworthy, and controllable ecosystem for AI applications interacting with LLMs and external tools.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。