让AI代理的权限请求可密码学验证,确保操作合法且不可抵赖。
Cryptographically verifiable authorization for autonomous AI agents: A falsifiable hypothesis and proof-of-concept

- 提出可密码学验证的授权关系 $R_{CVA}$,绑定代理、请求、上下文与策略。
- 基于Groth16 zk-SNARK实现零知识证明原型,支持隐私保护下的授权验证。
- 揭示身份、请求、运行时三者绑定的分离难题,提供可验证的研究路径。
自主AI代理在缺乏人类监督的情况下执行操作、调用工具并访问受保护资源。现有认证与授权机制虽能建立身份和授权委托,但无法内生地提供密码学证据,证明某特定代理在特定执行上下文中发出的具体请求符合适用策略。本文提出假设:代理授权可形式化为一个可密码学验证的关系 $R_{CVA}$,该关系联合绑定代理主体、具体授权请求、执行上下文以及策略满足性,同时选择性地保护私有授权属性的机密性。我们引入初步的可密码学验证代理授权(CVA)形式抽象,定义了一组紧凑的安全属性(包括授权正确性、主体绑定、请求绑定、策略绑定与重放抵抗),并基于Groth16 zk-SNARK构建了可执行的零知识证明概念验证。此外,我们识别并形式化了身份绑定、授权请求绑定与运行时执行绑定之间的结构性分离问题,这是当前自主系统安全框架未明确解决的核心挑战,并提出了可证伪的研究议程以推动其解决。
原文摘要 · Abstract (English)
Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context. This paper hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, denoted $R_{CVA}$, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. We introduce a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), define a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, and provide an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. We further identify and formalize the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem in the design of secure agentic systems (a distinction {not explicitly addressed by} current agentic security frameworks) and present a falsifiable research agenda for its resolution.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。