为关键基础设施中的智能体AI设计去中心化细粒度访问控制,防范非确定性行为风险。
Decentralized Granular Access Control for Agentic AI Systems in Critical Infrastructure
- 用复合身份绑定智能体动作与人类授权,实现责任可追溯。
- 支持从全局到参数级共五层权限控制,覆盖20多个专业智能体。
- 去中心化策略管理+渐进信任机制,零越权写操作持续8个月。
自主智能体在生产环境中的部署带来传统基于角色的访问控制(RBAC)无法应对的安全挑战。由于智能体具有随机行为,现有信任模型难以有效管控其对关键系统的访问。本文提出一种专为关键云基础设施中运行的智能体AI设计的去中心化、多层访问控制架构。框架包含四项核心创新:(1)复合身份模型,将智能体行为与委托的人类权威绑定;(2)涵盖五个粒度层级的分层权限体系,从平台级到单个参数级约束;(3)去中心化策略所有权,由工具团队自主管理授权边界;(4)带安全锁的渐进信任升级机制,防止智能体执行高风险操作。设计基于OWASP LLM应用2025年十大威胁分类,并验证各决策如何缓解特定攻击向量。该系统已在大型云服务商生产环境中部署,管理数百个数据中心的网络基础设施,对20多个专用智能体和60多个确定性剧本进行日均数千次操作的访问控制,连续八个月保持零未经授权的写操作。通过实证数据展示了访问模式分布、拒绝率及多层授权在阻止非确定性主体权限提升方面的有效性。
原文摘要 · Abstract (English)
The deployment of autonomous AI agents in production infrastructure introduces fundamental security challenges that traditional role-based access control (RBAC) models cannot address. Unlike deterministic automation, AI agents exhibit stochastic behavior, making conventional trust models insufficient for governing their access to critical systems. This paper presents a decentralized, multi-layered access control architecture designed specifically for agentic AI systems operating in critical cloud infrastructure. Our framework introduces four key innovations: (1) a compound identity model that binds agent actions to delegated human authority, (2) a hierarchical permission system spanning five granularity levels from global platform access to per-parameter constraints, (3) a decentralized policy ownership model where tool teams independently govern their authorization boundaries, and (4) progressive trust escalation with safety interlocks that prevent autonomous agents from executing high-risk operations. We ground our design in the OWASP Top 10 for LLM Applications (2025) threat taxonomy and demonstrate how each architectural decision mitigates specific attack vectors. Deployed in production at a major cloud provider managing network infrastructure across hundreds of datacenters, the system enforces granular access control for 20+ specialized AI agents and 60+ deterministic playbooks processing thousands of operations daily while maintaining zero unauthorized write operations over eight months of production deployment. We present empirical data on access pattern distributions, denial rates, and the effectiveness of layered authorization in preventing privilege escalation by non-deterministic actors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。