可验证的代理基础设施:基于证明的授权机制用于主权AI系统
Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems
AI总结:
本文提出Distributed Trust Framework,通过结构化可验证的艺术品计算执行权限,解决自主AI代理执行安全风险问题,实现授权过程的可验证、分布和可回放。
AI中文摘要:
现代云和企业系统依赖基于身份的授权,假设持有有效凭证的调用者可以安全执行命令。自主AI代理的出现使这一假设失效:代理可以生成语法有效但语义不安全的操作,使现有权限成为重大运营风险。在主权AI系统中,这种风险尤为突出,因为自主代理可能与云基础设施、受监管的数据、金融流程和国家级数字服务交互。受控突变基质通过介入代理操作来降低此风险:代理提交意图,基础设施评估上下文和政策,执行被中介。然而,这改变了信任边界:如何使授权意图的决定可验证、分布和可回放?我们引入了分布式信任框架(DTF),一种用于受控突变系统的验证框架,通过结构化、可验证的艺术品计算执行权限。DTF引入了证明来编码操作的可接受性基础,一种用于独立评估的一致性模型,一个从批准证明中衍生的短暂执行身份,以及一个只追加的证据链,以保存授权生命周期。在声明的基质假设下,该架构强制执行一个紧凑的授权不变量:没有证明对象的高风险执行,没有共识的衍生权限,以及没有证据的合法突变。我们定义了该模型,将其实例化在基于OpenKedge的受控突变基质上,并展示了其如何映射到云原生环境。通过将授权从现有身份转移到证明派生的权限,DTF为在主权AI部署中使代理执行可治理、可审计和受限制提供了基础设施基础。
英文摘要:
Modern cloud and enterprise systems rely on identity-centric authorization, assuming that callers possessing valid credentials are safe to execute commands. The emergence of autonomous AI agents invalidates this assumption: agents can generate syntactically valid but semantically unsafe actions, making standing privileges a significant operational risk. This risk becomes especially acute in sovereign AI systems, where autonomous agents may interact with cloud infrastructure, regulated data, financial workflows, and national-scale digital services. Governed mutation substrates reduce this risk by interposing on agent actions: agents submit intents, infrastructure evaluates context and policy, and execution is mediated. However, this shifts the trust boundary: how can the decision to authorize an intent be made verifiable, distributed, and replayable? We introduce a Distributed Trust Framework (DTF), a verification framework for governed mutation systems that computes execution authority from structured, verifiable artifacts. DTF introduces a Justification Proof to encode the admissibility basis of an action, a consensus model for independent evaluation, an ephemeral Execution Identity derived from the approved proof, and an append-only Evidence Chain that preserves the authorization lifecycle. Under stated substrate assumptions, this architecture enforces a compact authorization invariant: no high-stakes execution without a proof object, no derived authority without consensus, and no valid mutation detached from evidence. We define the model, instantiate it over an OpenKedge-based governed mutation substrate, and show how it maps onto cloud-native environments. By shifting authorization from standing identity to proof-derived authority, DTF provides an infrastructure foundation for making agentic execution governable, auditable, and bounded in sovereign AI deployments.