连续性证明:分布式系统和人工智能代理中权限传播的时间模型
Proof-of-Continuity: A Temporal Model for Authority Propagation in Distributed Systems and AI Agents
浏览论文内容
中文总结 AI 辅助
研究分布式系统和AI代理中权限传播问题,提出连续性证明模型,引入关系证明原语,其传递组合构成连续性证明,补充拥有证明,确保权限传播因果关系,避免混淆代理条件,解决源存在后权限传播问题。
中文摘要 AI 辅助
拥有证明授权模型从拥有令牌、凭证或能力等工件中获取权限。本文认为,对于离散执行链而言,拥有是不够的,无论这些链跨越多个服务还是在同一机器内作为单独步骤出现,因为它不能保证请求源与后续步骤所行使权限之间的因果关系得以保留。我们引入了连续性证明,这是一种用于溯源身份连续性(PIC)模型的最小权限传播规则,其中每个执行步骤必须与前一步骤有因果联系,并且只能传播从源接收的权限的非扩展子集。它引入了关系证明,这是一种单跳因果原语,其传递组合就是连续性证明;这些补充了拥有证明而不是取代它。在这个模型下,混淆代理条件不能作为有效的模型行为得到满足:在后续步骤中行使的任何特权必须已经存在于源权限上下文中。这与分布式系统和人工智能代理直接相关,在这些系统中,执行器在持有多个权限源的同时调用工具和下游服务,因此相同的权限/因果关系不匹配会在服务边界反复出现。在连续性证明下,这些源可以一起携带,但永远不会合并成一个组合权限,因为每个步骤仅根据导致它的血统的权限上下文进行授权。本文关注的是授权传播而非身份验证:诸如OIDC、可验证凭证、钱包和工作负载身份等身份和身份验证机制仍然是用于确定源的补充机制,而连续性证明解决的是源存在后权限如何传播的问题。
英文摘要
Proof-of-Possession authorization models derive authority from the possession of artifacts such as tokens, credentials, or capabilities. This paper argues that possession is insufficient for discrete execution chains, whether they span multiple services or occur as separated steps within the same machine, because it does not guarantee preservation of the causal relationship between the origin of a request and the authority exercised at later steps. We introduce Proof-of-Continuity, a minimal authority-propagation discipline for the Provenance Identity Continuity (PIC) model, in which each execution step must be causally linked to the previous step and may only propagate a non-expansive subset of the authority received from the origin. It introduces Proof of Relationship, a single-hop causal primitive whose transitive composition is Proof-of-Continuity; these complement Proof-of-Possession rather than replace it. Under this model, the confused deputy condition cannot be satisfied as valid model behavior: any privilege exercised at a later step must already be present in the origin authority context. This is directly relevant to distributed systems and AI agents, where executors invoke tools and downstream services while holding multiple authority sources, so that the same authority/causality mismatch recurs across service boundaries. Under Proof-of-Continuity these sources may be carried together but are never merged into a combined authority, since each step is authorized only against the authority context of the lineage that caused it. This paper concerns authorization propagation rather than authentication: identity and authentication mechanisms such as OIDC, verifiable credentials, wallets, and workload identity remain complementary mechanisms for establishing the origin, while Proof-of-Continuity addresses how authority propagates after that origin exists.