为单用户AI助手网关打造可配置的强安全框架,保障数据与信任可控。
enclawed: A Configurable, Sector-Neutral Hardening Framework for Single-User AI Assistant Gateways
- 基于OpenClaw构建,支持严格白名单与签名验证机制。
- 内置356项测试用例,覆盖篡改检测、数据泄露规避等关键漏洞。
- 适合金融、医疗等需高合规性的行业部署使用。
我们提出enclawed,一个基于OpenClaw AI助手网关的可配置硬化框架,针对需要可验证同行信任、默认拒绝外部连接、模块签名加载及防篡改审计日志的场景——通常为金融、医疗、国防、政府等受监管领域。该框架提供两种模式:开放模式保持OpenClaw兼容性,同时输出审计、分类与数据防泄漏(DLP)信号;封闭模式激活严格白名单、FIPS加密模块认证、强制清单签名验证及模型上下文协议的高保证同行证明。分类层级由数据驱动:部署者可选择五个预设或自定义JSON配置。我们提供包含356个测试案例的测试套件(261个单元测试 + 95个对抗渗透测试),涵盖篡改检测、签名伪造、出口绕过、日志截断、信任根篡改、DLP规避、提示注入、代码注入以及具备双向条件的网络扩展准入。系统支持实时人工干预控制、内存受限的事务缓冲区与回滚机制、严格模式的TypeScript类型检查及持续集成流程。双向扩展准入机制将技能信任模型扩展至非技能扩展。四层验证体系现已闭环:四个技能形式化*原语配合命令行工具生成带证明的签名打包包,运行时重新验证,通过静态效应封闭性、精炼类型分发和有界模型检查实现从测试到形式化的跃迁。enclawed是硬化框架,非认证产品;硬件、经验证的加密、设施及评估员签字仍由部署方负责。
原文摘要 · Abstract (English)
We present enclawed, a hard-fork hardening framework built on the OpenClaw AI assistant gateway. enclawed targets deployments that need attestable peer trust, deny-by-default external connectivity, signed-module loading, and a tamper-evident audit trail -- typically regulated industries (financial services, healthcare, defense, government). The framework ships in two flavors: an open flavor preserving OpenClaw compatibility while emitting audit, classification, and data-loss-prevention (DLP) signals, and an enclaved flavor activating strict allowlists, FIPS cryptographic-module assertion, mandatory manifest signature verification, and high-assurance peer attestation for the Model Context Protocol. The classification ladder is data-driven: deployers pick from five built-in presets or supply their own JSON. We ship a 356-case test suite (261 unit + 95 adversarial pen-tests) covering tamper detection, signature forgery, egress bypass, audit-log truncation, trust-root mutation, DLP evasion, prompt injection, code injection, and biconditional admission for net-capable extensions; real-time human-in-the-loop control; a memory-bounded transaction buffer with rollback; strict-mode TypeScript typecheck; and a CI workflow. The biconditional extension-admission gate extends the skill trust schema to non-skill extensions. The four-level verification lattice is now closed at the top: four skill-formal-* primitives plus a CLI produce a signed proof-carrying bundle the runtime re-checks at load, raising a skill from tested to formal via static effect-containment, refinement-typed dispatch, and bounded model checking. enclawed is a hardening framework, not an accredited certification; hardware, validated crypto, facilities, and assessor sign-off remain the deployer's responsibility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。