让AI代理在不暴露密钥的情况下安全传递权限,支持跨系统审计与控制。
Interoperable Architecture for Digital Identity Delegation for AI Agents with Blockchain Integration
- 用可撤销的授权凭证实现权限精准转移,最小化权限范围。
- 统一验证请求格式,使不同身份系统间可互操作。
- 将区块链作为可选数据锚点,不强制依赖,适合部署于多种环境。
数字身份中的可验证委托在中心化、联邦和自我主权身份(SSI)环境中仍未能有效解决,尤其是在人类用户与自主AI代理需在不暴露主凭证或私钥的前提下行使并转移权限时。本文提出一个统一框架,实现跨异构身份生态系统的有限度、可审计、最小权限委托。框架包含四个核心组件:委托许可(DGs),作为首类授权实体,编码可撤销的权限转移并强制缩小作用范围;标准验证上下文(CVC),将验证请求标准化为与协议或凭证格式无关的统一结构;分层参考架构,通过信任网关分离信任锚定、凭证与证明验证、策略评估及协议中介;以及显式处理区块链锚定作为可选完整性层,而非结构性依赖。这些元素共同推动了可互操作的委托与可审计性,为未来标准制定、实现与自主代理融入可信数字身份基础设施奠定基础。
原文摘要 · Abstract (English)
Verifiable delegation in digital identity systems remains unresolved across centralized, federated, and self-sovereign identity (SSI) environments, particularly where both human users and autonomous AI agents must exercise and transfer authority without exposing primary credentials or private keys. We introduce a unified framework that enables bounded, auditable, and least-privilege delegation across heterogeneous identity ecosystems. The framework includes four key elements: Delegation Grants (DGs), first-class authorization artefacts that encode revocable transfers of authority with enforced scope reduction; a Canonical Verification Context (CVC) that normalizes verification requests into a single structured representation independent of protocols or credential formats; a layered reference architecture that separates trust anchoring, credential and proof validation, policy evaluation, and protocol mediation via a Trust Gateway; and an explicit treatment of blockchain anchoring as an optional integrity layer rather than a structural dependency. Together, these elements advance interoperable delegation and auditability and provide a foundation for future standardization, implementation, and integration of autonomous agents into trusted digital identity infrastructures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。