arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

xChk:自带身份——基于验证者确定充分性的异构认证

xChk: Bring Your Own Identity -- Heterogeneous Assurance with Verifier-Determined Sufficiency

Sean MacGuire

arXiv 2607.13369首次发表:更新:

AI 中文总结

xChk作为自带身份的参考身份提供商,让用户通过异构证明注册并在OIDC令牌中披露声明,依赖方应用自身策略,支持人工参与高风险操作认证,生产部署实现双边RP评估及特定依赖方登录。

AI 中文摘要

我们提出了xChk,一个用于自带身份(BYOI)的参考身份提供商。用户通过异构证明(政府KYC、企业单点登录、WebAuthn/FIDO2、专业网络、实时验证、纵向活动、行为信号)进行注册,并在标准OAuth 2.0/OpenID Connect(OIDC)令牌中作为组合声明披露,每个依赖方应用自己的充分性策略。注册深度因方式而异。xChk还支持针对高风险操作的人工参与认证。在一个生产部署中,两种发起路径都带有同意时的双边RP评估,一个记录在案的依赖方使用xChk进行登录。

英文摘要

We present xChk, a reference identity provider for Bring Your Own Identity (BYOI): users enroll via heterogeneous proofs (government KYC, corporate SSO, WebAuthn/FIDO2, professional networks, live verification, longitudinal activity, behavioral signals) and disclose them as portfolio claims in standard OAuth 2.0 / OpenID Connect (OIDC) tokens, while each relying party applies its own sufficiency policy - the IdP transports claims and may evaluate an RP-supplied evidence policy for consent, but does not adjudicate access. Enrollment depth varies by modality (some paths are user-initiated; org KYB and officer binding are operator-assisted). xChk also supports human-in-the-loop attestation for high-risk actions: humans can initiate attestations directly (browser UI / POST /api/attestations), and AI agents acting under those principals can trigger the same gateway via scope-gated authorize/attest - hash-chained human approvals on a shared verification graph (humans via OIDC; agents via API keys). A production deployment at https://in.xchk.io ships both initiation paths with bilateral RP evaluation at consent; one documented relying party (https://crabbyed.com, Appendix B) exercises Login with xChk.

Comments19 pages, 4 figures. Reference implementation at https://in.xchk.io; one documented RP (crabbyed.com, Appendix B)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑