为自主AI代理构建可信身份体系,解决安全授权难题
Identity Management for Agentic AI: The new frontier of authorization, authentication, and security for an AI agent world
- 提出以代理为中心的身份管理框架,重构认证授权机制
- 聚焦高自主代理的权限控制与委托授权问题
- 适合关注AI安全与访问管理的开发者与决策者
AI代理的快速发展带来了认证、授权与身份管理的紧迫挑战。现有以代理为中心的协议(如MCP)凸显了认证与授权最佳实践的缺失。展望未来,高度自主代理的发展提出了可扩展访问控制、代理专属身份、AI工作负载区分及权限委托等长期难题。本OpenID基金会白皮书面向人工智能代理与访问管理交叉领域的利益相关方,梳理了当前可用于保障代理安全的资源,并提出一项战略议程,旨在解决未来广泛自主系统所依赖的核心认证、授权与身份管理问题。
原文摘要 · Abstract (English)
The rapid rise of AI agents presents urgent challenges in authentication, authorization, and identity management. Current agent-centric protocols (like MCP) highlight the demand for clarified best practices in authentication and authorization. Looking ahead, ambitions for highly autonomous agents raise complex long-term questions regarding scalable access control, agent-centric identities, AI workload differentiation, and delegated authority. This OpenID Foundation whitepaper is for stakeholders at the intersection of AI agents and access management. It outlines the resources already available for securing today's agents and presents a strategic agenda to address the foundational authentication, authorization, and identity problems pivotal for tomorrow's widespread autonomous systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。