arXiv:2601.14982cs.CRcs.AI2026-01被引 1

让AI代理在不暴露密钥的情况下安全传递权限,支持跨系统审计与控制。

Interoperable Architecture for Digital Identity Delegation for AI Agents with Blockchain Integration

  • 用可撤销的授权凭证实现权限精准转移,最小化权限范围。
  • 统一验证请求格式,使不同身份系统间可互操作。
  • 将区块链作为可选数据锚点,不强制依赖,适合部署于多种环境。

数字身份中的可验证委托在中心化、联邦和自我主权身份(SSI)环境中仍未能有效解决,尤其是在人类用户与自主AI代理需在不暴露主凭证或私钥的前提下行使并转移权限时。本文提出一个统一框架,实现跨异构身份生态系统的有限度、可审计、最小权限委托。框架包含四个核心组件:委托许可(DGs),作为首类授权实体,编码可撤销的权限转移并强制缩小作用范围;标准验证上下文(CVC),将验证请求标准化为与协议或凭证格式无关的统一结构;分层参考架构,通过信任网关分离信任锚定、凭证与证明验证、策略评估及协议中介;以及显式处理区块链锚定作为可选完整性层,而非结构性依赖。这些元素共同推动了可互操作的委托与可审计性,为未来标准制定、实现与自主代理融入可信数字身份基础设施奠定基础。

原文摘要 · Abstract (English)

Verifiable delegation in digital identity systems remains unresolved across centralized, federated, and self-sovereign identity (SSI) environments, particularly where both human users and autonomous AI agents must exercise and transfer authority without exposing primary credentials or private keys. We introduce a unified framework that enables bounded, auditable, and least-privilege delegation across heterogeneous identity ecosystems. The framework includes four key elements: Delegation Grants (DGs), first-class authorization artefacts that encode revocable transfers of authority with enforced scope reduction; a Canonical Verification Context (CVC) that normalizes verification requests into a single structured representation independent of protocols or credential formats; a layered reference architecture that separates trust anchoring, credential and proof validation, policy evaluation, and protocol mediation via a Trust Gateway; and an explicit treatment of blockchain anchoring as an optional integrity layer rather than a structural dependency. Together, these elements advance interoperable delegation and auditability and provide a foundation for future standardization, implementation, and integration of autonomous agents into trusted digital identity infrastructures.

身份认证AI代理区块链权限管理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。