企业MCP认证的网关架构:统一异构认证、身份委托与用户/非用户角色问题
A Gateway Architecture for Enterprise MCP Authentication: Unifying Heterogeneous Auth, Identity Delegation, and the User / Non-User Persona Problem
浏览论文内容
中文总结 AI 辅助
本文提出一种集中式MCP网关架构,通过双轴认证模型、多SSO授权与令牌供应模式、三类身份流及部署演进方案,解决企业MCP认证碎片化问题,已在数十个MCP服务器场景投入生产。
中文摘要 AI 辅助
模型上下文协议(MCP)已成为连接大语言模型(LLM)智能体与企业工具的事实标准接口,其采用速度极为迅猛:一年内,大型组织内部署的自研MCP服务器数量从零增至数十个。这种部署速度引发了治理危机:各团队独立实现认证机制,部分无认证、部分采用API密钥、部分使用完整OAuth,形成碎片化格局,缺乏一致的调用者授权、操作追踪或员工离职后全 fleet 人员移除的方案。本文报告一项解决该危机的行业部署方案:通过集中式MCP网关——一个聚合、治理与认证层,为所有下游MCP服务器提供前端服务。基于生产经验,本文作出四项贡献:其一,构建双轴认证模型,涵盖角色(交互式用户与自动化非用户)及凭证类型(无认证、静态/动态API密钥、PKCE、客户端凭证、平台应用上下文);其二,网关认证层支持三种企业单点登录(SSO)授权类型与三种令牌供应模式:自带令牌、生成令牌及通过RFC 8693令牌交换实现的委托OAuth;其三,三种端到端身份流——用户到OAuth2、非用户到服务账户、用户到服务账户,涉及客户端、网关与服务器;其四,部署演进路径:从CDN/WAF/边缘 perimeter 到私有MCP隧道及企业级连接器。该架构已投入生产,为数十个面向网页、桌面、自定义SDK及低代码客户端的MCP服务器提供前端服务。
英文摘要
The Model Context Protocol (MCP) has become the de-facto interface for connecting LLM agents to enterprise tools, and adoption has been explosive: within a year, large organizations went from zero to dozens of internally built MCP servers. That speed created a governance crisis. Each team implemented authentication independently -- some with no auth, some with API keys, some with full OAuth -- producing a fragmented landscape with no consistent way to authorize callers, track who did what, or offboard a departing employee across the fleet. This paper reports an industry deployment that resolves the crisis with a centralized MCP gateway: a single aggregation, governance, and authentication layer that fronts every downstream MCP server. We make four contributions grounded in production experience. First, a two-axis authentication model crossing persona (interactive user vs. automated non-user) with credential type (no-auth, static/dynamic API key, PKCE, client credentials, platform app-context). Second, a gateway authentication layer supporting three enterprise SSO grants and three token-provisioning models: Bring-Your-Own-Token, Generate-Your-Own-Token, and delegated OAuth via RFC 8693 token exchange. Third, three end-to-end identity flows -- User-to-OAuth2, Non-user-to-Service-Account, and User-to-Service-Account -- composing client, gateway, and server. Fourth, the deployment evolution from CDN/WAF/edge perimeter to private MCP tunnels and enterprise-wide connectors. The architecture is in production, fronting dozens of MCP servers across web, desktop, custom-SDK, and low-code clients.
发表机构
- Enterprise AI Platform Engineering(企业人工智能平台工程)
机构由 AI 辅助整理,请以论文原文为准。