AI 中文总结
研究关键基础设施中智能体人工智能系统的安全挑战,提出去中心化多层访问控制架构,含复合身份模型等四项创新,基于OWASP威胁分类法设计,经云提供商生产验证,能有效实施粒度访问控制并防止特权升级。
AI 中文摘要
在生产基础设施中部署自主人工智能智能体带来了传统基于角色的访问控制(RBAC)模型无法解决的基本安全挑战。与确定性自动化不同,人工智能智能体表现出随机行为,使得传统信任模型不足以管理它们对关键系统的访问。本文提出了一种专门为在关键云基础设施中运行的智能体人工智能系统设计的去中心化多层访问控制架构。我们的框架引入了四项关键创新:(1)将智能体动作与委托的人类权限绑定的复合身份模型;(2)从全局平台访问到每个参数约束的五个粒度级别的分层权限系统;(3)工具团队独立管理其授权边界的去中心化策略所有权模型;(4)带有安全联锁的渐进式信任升级,防止自主智能体执行高风险操作。我们将设计基于OWASP针对LLM应用的前10大威胁分类法,并展示每个架构决策如何减轻特定攻击向量。该系统部署在一家管理数百个数据中心网络基础设施的主要云提供商的生产环境中,对20多个专业人工智能智能体和60多个确定性剧本实施粒度访问控制,每天处理数千个操作,在八个月的生产部署中保持零未经授权的写操作。我们展示了关于访问模式分布、拒绝率以及分层授权在防止非确定性行为者特权升级方面有效性的实证数据。
英文摘要
The deployment of autonomous AI agents in production infrastructure introduces fundamental security challenges that traditional role-based access control (RBAC) models cannot address. Unlike deterministic automation, AI agents exhibit stochastic behavior, making conventional trust models insufficient for governing their access to critical systems. This paper presents a decentralized, multi-layered access control architecture designed specifically for agentic AI systems operating in critical cloud infrastructure. Our framework introduces four key innovations: (1) a compound identity model that binds agent actions to delegated human authority, (2) a hierarchical permission system spanning five granularity levels from global platform access to per-parameter constraints, (3) a decentralized policy ownership model where tool teams independently govern their authorization boundaries, and (4) progressive trust escalation with safety interlocks that prevent autonomous agents from executing high-risk operations. We ground our design in the OWASP Top 10 for LLM Applications (2025) threat taxonomy and demonstrate how each architectural decision mitigates specific attack vectors. Deployed in production at a major cloud provider managing network infrastructure across hundreds of datacenters, the system enforces granular access control for 20+ specialized AI agents and 60+ deterministic playbooks processing thousands of operations daily while maintaining zero unauthorized write operations over eight months of production deployment. We present empirical data on access pattern distributions, denial rates, and the effectiveness of layered authorization in preventing privilege escalation by non-deterministic actors.
Comments7 pages, 9 figures, 7 tables