arXiv:2605.11487cs.CRcs.AI2026-05

为自主智能体设计可移植的授权标准,解决跨系统信任难题

Digital Identity for Agentic Systems: Toward a Portable Authorization Standard for Autonomous Agents

论文配图:Digital Identity for Agentic Systems: Toward a Portable Authorization Standard for Autonomous Agents
图 1 · 摘自论文原文
  • 用可携带的授权凭证实现跨系统身份与权限统一
  • 支持权限可审计、可撤销、可传递且执行结果一致
  • 适合需要多系统协作的AI代理场景,如保险理赔

企业级AI正从辅助工具转向能自主执行流程、协商结果并决策的智能体。当这些系统跨越组织边界时,仅靠身份已不足:智能体的权限必须明确、受限、可审计、可撤销,并被各方一致理解。本文通过保险理赔和供应链完整性等典型场景,揭示现有身份访问模型的结构性缺陷。提出一种面向自主智能体的可移植授权模型,基于发行方生成的授权载荷、类型化约束代数、一致性评估语义、权限降级机制、受控语义解析、默认封闭处理及预飞行发现。该模型分离凭证容器、授权语义与执行引擎,使JWT/JWS、可验证凭证、OAuth富授权请求或策略引擎绑定均能保持跨信任边界的统一授权含义。

原文摘要 · Abstract (English)

Enterprise AI is shifting from copilots to autonomous agents capable of executing workflows, negotiating outcomes, and making decisions with limited human oversight. As these systems extend across organizational boundaries, identity alone is insufficient: an agent's authority must also be explicit, constrained, auditable, revocable, and consistently interpretable by independent receivers. This paper analyzes representative enterprise use cases in insurance claims processing and supply chain integrity to surface structural gaps in existing identity and access models. It proposes a portable authorization model for autonomous agents based on issuer-authored authorization payloads, typed constraint algebra, decision-consistent evaluation semantics, delegation attenuation, governed semantic resolution, fail-closed processing, and pre-flight discovery. The model separates credential containers, authorization payload semantics, and enforcement engines, allowing profiles such as JWT/JWS, Verifiable Credentials, OAuth Rich Authorization Requests, or policy-engine bindings to preserve a common authorization meaning across trust boundaries.

自主智能体授权模型可验证凭证AI安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。