arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

InterSAGE:面向智能体互联网的安全可互操作且可验证的协议

InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents

Zhenhua Zou, Sheng Guo, Qiuyang Zhan, Lepeng Zhao, Shuo Li, Zhuotao Liu

arXiv 2608.13030首次发表:更新:

AI 中文总结

针对现有智能体互操作协议缺失安全底层的问题,提出InterSAGE四层协议套件,补充MCP等通信协议,经对比验证其为首个统一实现四大安全特性的架构。

AI 中文摘要

新兴的智能体互联网(Internet of Agents)使基于大语言模型(LLM)的智能体能够跨组织边界发现对等体、调用工具并委托任务。现有协议越来越多地定义智能体如何交换消息,但未明确智能体如何在委托后证明自身身份、授权情况、所宣传的能力或问责性。我们提出InterSAGE,这是一种原生信任的协议套件,提供缺失的安全底层,且不替代通信协议。InterSAGE包含四层:持久身份(Persistent Identity)、发现(Discovery)、信任协商(Trust Negotiation)和问责(Accountability)。其四个核心原语为:(1)智能体身份卡,将开发者、代码包、运营方和部署上下文绑定;(2)使用去中心化身份(DID)绑定的可验证凭证清单实现能力感知的发现;(3)结合单调能力衰减与两层访问控制的信任协商;(4)内核介导的密码审计轨迹,将使用、委托和执行轨迹绑定到智能体身份,无需共识账本。InterSAGE设计用于补充MCP、A2A、ANP和AG-UI,使通信协议可独立演进,同时保持信任语义明确、可移植且可验证。我们将InterSAGE与50余项相关工作对比,涵盖智能体协议、去中心化身份、OAuth/OIDC扩展、零信任治理、委托及审计架构,结果显示尚无现有架构能将持久身份、能力感知发现、信任协商和问责作为统一四层信任底层,共同用于安全的智能体互操作。

英文摘要

The emerging Internet of Agents enables LLM-powered agents to discover peers, invoke tools, and delegate tasks across organizational boundaries. Existing protocols increasingly define how agents exchange messages, but not how an agent proves its identity, authorization, advertised capabilities, or accountability after delegation. We present InterSAGE, a trust-native protocol suite that supplies this missing security substrate alongside, rather than in place of, communication protocols. InterSAGE comprises four layers: Persistent Identity, Discovery, Trust Negotiation, and Accountability. Its four core primitives are: (1) Agent Identity Cards that bind developer, code package, operator, and deployment context; (2) capability-aware discovery using DID-bound Verifiable Credential manifests; (3) trust negotiation combining monotonic capability attenuation with two-tier access control; and (4) kernel-mediated cryptographic audit trails that bind usage, delegation, and execution traces to agent identity without a consensus ledger. InterSAGE is designed to complement MCP, A2A, ANP, and AG-UI, allowing communication protocols to evolve independently while keeping trust semantics explicit, portable, and verifiable. We compare InterSAGE with more than 50 efforts spanning agent protocols, decentralized identity, OAuth/OIDC extensions, zero-trust governance, delegation, and audit architectures. We show that no prior architecture jointly enforces persistent identity, capability-aware discovery, trust negotiation, and accountability as a unified four-layer trust substrate for secure agent interoperability.

Comments35 pages, 4 figures, 7 tables. Positioning paper

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑