arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

迈向自主人工智能代理的加密可验证授权:安全假设、初步形式化模型及概念验证实现

Cryptographically verifiable authorization for autonomous AI agents: a falsifiable hypothesis and proof of concept

M. Llambí-Morillas, D. Fernández-Fernández

arXiv 2607.21325首次发表:更新:

发表机构

Universidad Tecnológica Atlántico-Mediterráneo (UTAMED); Universidad de Santiago de Compostela (USC)(西班牙阿塔兰蒂卡-地中海技术大学; 圣地亚哥-德孔波斯特拉大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究自主AI代理加密可验证授权问题,提出将其形式化为关系$R_{CVA}$的假设,引入CVA形式化抽象,定义安全属性,给出零知识概念验证,还识别出身份等绑定间结构分离问题并提出研究议程。

AI 中文摘要

自主人工智能代理在人类监督有限的情况下越来越多地执行操作、调用工具并对受保护资源进行操作。现有认证和授权机制可建立身份和委托权限,但无法提供加密证据证明特定代理发出的具体请求在特定执行上下文中符合适用策略。本文假设代理授权可形式化为加密可验证关系$R_{CVA}$,它联合绑定代理主体、具体授权请求、执行上下文和适用策略的满足情况,同时选择性地保护私有授权属性的机密性。我们引入了加密可验证代理授权(CVA)的初步形式化抽象,定义了一组紧凑的候选安全属性,包括授权健全性、主体绑定、请求绑定、策略绑定和抗重放性,并提供了一个可执行的零知识概念验证,在Groth16 zk-SNARK构造上实例化模型的选定元素。我们进一步将身份绑定、授权请求绑定和运行时执行绑定之间的结构分离识别并形式化为安全代理系统设计中的一个核心开放问题(当前代理安全框架未明确解决的区别),并提出了一个可证伪的研究议程来解决它。

英文摘要

Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context. This study hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, denoted $R_{CVA}$, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. We introduce a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), define a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, and provide an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. We further identify and formalize the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem in the design of secure agentic systems, a distinction to our knowledge, has not been formalized within a cryptographically verifiable authorization relation by current agentic security frameworks, and present a falsifiable research agenda for its resolution.

Comments13 pages, 1 figure, 3 tables. Author version (v3) of the article published in Frontiers in Computer Science 8:1966725 (2026). Keywords: access control, agentic security, autonomous AI agents, cryptographic authorization, cryptographic protocols, verifiable authorization, zero-knowledge proofs, zk-SNARKs

Journal refFront. Comput. Sci. 8 (2026) 1966725

DOI:10.3389/fcomp.2026.1966725

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑