arXiv:2608.14074cs.AI2026-08被引 1

为AI代理行动建立可验证的授权审计链,防止越权操作。

Mandato: Protocol-Level Enforcement of Digitally Signed Mandates on AI Agent Actions with Cryptographically Chained Audit Trails

  • 在协议层通过数字签名授权书控制代理调用工具的行为
  • 每步操作均被记录并形成不可篡改的审计日志链
  • 适合关注合规性与安全审计的AI系统设计者

AI代理通过标准化工具调用协议(如MCP)与外部系统交互,但缺乏对权限的可信约束:授权逻辑嵌入应用代码,未签名且无法独立审计,日志无法律证据效力。我们提出Mandato,一个在协议层强制执行数字签名授权指令的治理代理。授权书是机器可读、经加密签名的授权凭证,明确指定代理可调用的工具、参数限制、上下文条件、有效期及代表身份;代理在每次调用时验证其关联的授权链,阻断不合规请求,并将允许、拒绝及依据记录于追加式哈希链审计日志中,支持证据使用,并通过合格时间戳定期锚定。授权书参照民法中的授权制度设计,便于律师和审计人员理解。本文给出授权模型与决策语义、基于MCP透明的参考架构(决策与执行分离)、与欧盟人工智能法案第12、14条、GDPR问责原则、NIS2及eIDAS 2的映射关系,并提出通过合格信任服务提供商(QTSPs)实现合格认证的路线图。描述了参考系统的实现进展及量化评估计划,涵盖执行开销、审计完整性与抗篡改验证成本。

原文摘要 · Abstract (English)

AI agents increasingly act on external systems through standardized tool-calling protocols such as the Model Context Protocol (MCP), yet no infrastructure layer constrains their actions to what a principal has verifiably authorized: authorization logic lives in application code, is neither signed nor independently auditable, and the resulting logs lack evidentiary value. We present Mandato, a governance proxy that enforces digitally signed mandates on agent actions at the protocol level. A mandate is a machine-readable, cryptographically signed authorization artifact specifying which tools an agent may invoke, under which parameter constraints and contextual conditions, for how long, and on whose behalf; the proxy evaluates every tool call against the applicable mandate chain, blocks non-conforming calls in line, and records every decision -- permit, deny, and the evidence for each -- in an append-only, hash-chained audit log designed for evidentiary use and periodically anchored via qualified timestamps. The mandate is deliberately modeled on the civil-law institution of delegation of authority, making the artifact legible to lawyers and auditors, not only to engineers. We give the mandate model and its decision semantics, the reference architecture as an MCP-transparent proxy with separated decision and enforcement points, and a mapping of the mechanism onto EU AI Act Articles 12 and 14, GDPR accountability, NIS2, and eIDAS 2, including a roadmap to qualified attestation through Qualified Trust Service Providers (QTSPs). We describe the implementation status of the reference system and a quantitative evaluation plan covering enforcement overhead, audit completeness, and tamper-evidence verification cost.

AI治理授权审计区块链合规

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。