为智能体网络构建零信任安全架构,防范逻辑层攻击。
Fortifying the Agentic Web: A Unified Zero-Trust Architecture Against Logic-layer Threats
- 用去中心化身份和可验证凭证构建可信智能体身份体系。
- 通过动态行为认证与因果链审计,实现攻击可追踪、可防御。
- 适合研究智能体安全或构建可信AI系统的开发者参考。
本文提出一种统一的安全架构,通过零信任身份与访问管理(IAM)框架强化智能体网络。该架构基于丰富的可验证智能体身份,采用去中心化标识符(DIDs)和可验证凭证(VCs),并通过协议无关的智能体名称服务(ANS)实现身份发现。安全机制由多层次的信任基础设施支撑,引入创新技术包括信任自适应运行环境(TARE)、因果链审计及基于行为证明的动态身份。通过在形式化安全模型中明确关联LPCI威胁与对应防护措施,本工作提供了一个全面且前瞻性的安全蓝图,确保智能体生态系统的可信、弹性与安全。形式化分析表明,该架构对LPCI攻击具备可证明的安全性保障,成功概率被限制在可控范围内。
原文摘要 · Abstract (English)
This paper presents a Unified Security Architecture that fortifies the Agentic Web through a Zero-Trust IAM framework. This architecture is built on a foundation of rich, verifiable agent identities using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), with discovery managed by a protocol-agnostic Agent Name Service (ANS). Security is operationalized through a multi-layered Trust Fabric which introduces significant innovations, including Trust-Adaptive Runtime Environments (TARE), Causal Chain Auditing, and Dynamic Identity with Behavioral Attestation. By explicitly linking the LPCI threat to these enhanced architectural countermeasures within a formal security model, we propose a comprehensive and forward-looking blueprint for a secure, resilient, and trustworthy agentic ecosystem. Our formal analysis demonstrates that the proposed architecture provides provable security guarantees against LPCI attacks with bounded probability of success.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。