为非人类智能体设计可验证的交互溯源机制,保障多代理系统安全。
Context Lineage Assurance for Non-Human Identities in Critical Multi-Agent Systems
- 用只增不改的梅克尔树模拟证书透明日志,追踪非人类身份演化路径。
- 支持多方验证跨跳调用链完整性和一致性,生成可审计的紧凑证明。
- 适合需合规监管的高安全场景,如联邦云环境中的智能体治理。
自主软件代理的普及要求建立安全且可验证的代理间(A2A)交互框架,尤其当代理以非人类身份(NHI)存在时。本文扩展传统A2A范式,提出一种基于密码学的溯源验证机制,将NHI的来源与演化锚定在类证书透明(CT)日志的只增不改梅克尔树结构中。相比仅保障点对点通信的传统模型,该方法使代理和外部验证者能对多跳调用链进行密码学验证,确保完整调用链的可信性。一个联邦化证明服务器作为跨多个梅克尔日志的审计节点,聚合包含性证明与一致性检查,生成可被外部方验证的紧凑签名声明,无需访问完整执行轨迹。同时,我们在A2A代理卡中引入显式的身份验证原语,使同行代理与人工审批者可标准化地认证NHI表征的合法性。这些贡献共同构建了集成身份认证、溯源验证与独立审计的统一模型,提升了代理生态系统的安全性,并为联邦风险、授权与管理计划(FedRAMP)等受监管环境中非人类身份的稳健治理提供基础。
原文摘要 · Abstract (English)
The proliferation of autonomous software agents necessitates rigorous frameworks for establishing secure and verifiable agent-to-agent (A2A) interactions, particularly when such agents are instantiated as non-human identities(NHIs). We extend the A2A paradigm [1 , 2] by introducing a cryptographically grounded mechanism for lineage verification, wherein the provenance and evolution of NHIs are anchored in append-only Merkle tree structures modeled after Certificate Transparency (CT) logs. Unlike traditional A2A models that primarily secure point-to-point interactions, our approach enables both agents and external verifiers to cryptographically validate multi-hop provenance, thereby ensuring the integrity of the entire call chain. A federated proof server acts as an auditor across one or more Merkle logs, aggregating inclusion proofs and consistency checks into compact, signed attestations that external parties can verify without access to the full execution trace. In parallel, we augment the A2A agent card to incorporate explicit identity verification primitives, enabling both peer agents and human approvers to authenticate the legitimacy of NHI representations in a standardized manner. Together, these contributions establish a cohesive model that integrates identity attestation, lineage verification, and independent proof auditing, thereby advancing the security posture of inter-agent ecosystems and providing a foundation for robust governance of NHIs in regulated environments such as FedRAMP.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。