用于具身机器人能力市场的联邦信任机制
Federated Trust for Embodied Robot Capability Marketplaces
浏览论文内容
中文总结 AI 辅助
针对具身机器人集群提出联邦信任机制,实现本地验证,经5000次对抗试验验证其安全性,性能与存储占用优于对比方案。
中文摘要 AI 辅助
机器人能力市场作为“机器人技能应用商店”,正成为大语言模型(LLM)驱动的机器人集群的部署载体。针对“此软件包是否可安全安装?”这一问题,默认的云原生解决方案是集中式公钥基础设施(PKI):单一证书颁发机构、单一透明度日志、单一信任根。我们认为这一模型不适用于具身机器人集群,因为集群运营商面临异构监管制度、 air-gapped(气隙)部署、运营商人员规模极小,以及信任错误发布者可能带来的物理世界后果。我们提出联邦信任机制:每个已部署的桥节点维护自身本地的可接受签名者信任目录;签名者通过嵌入分离式Ed25519签名信封的公钥标识自身;安装时的验证是本地集合成员检查,而非向证书颁发机构发起网络往返。所使用的密码学原语为标准方案(Ed25519分离式签名及SSH风格信任文件),核心贡献在于该组合架构专门适配具身机器人集群。我们在运行时治理层实现了该模型,包含含5个子命令的命令行界面(CLI)、注册服务器、每个桥节点的安装网关及80项测试。多部署评估显示,同一注册流在具有不同信任目录的桥节点上会产生不同的安装判定,这是该机制的核心设计特性。在5000次对抗性试验中,严格模式网关100%拒绝恶意发布者、被篡改、伪造及签名者撤销攻击,且在最小版本固定扩展下拒绝96.6%的降级尝试。与Sigstore-Cosign和python-TUF的同硬件对比显示,联邦信任的单次验证成本介于两者之间,且其单发布者存储占用低于两者。
英文摘要
Robot capability marketplaces, the "app store for robot skills," are emerging as the deployment vector for LLM-driven robot fleets. The default cloud-native answer to "is this package safe to install?" is centralised PKI: one certificate authority, one transparency log, one root of trust. We argue this is the wrong model for embodied robot fleets, where operators face heterogeneous regulatory regimes, air-gapped deployments, tiny operator headcounts, and physical-world consequences for trusting the wrong publisher. We present federated trust: each deployed bridge maintains its own local trust directory of acceptable signers; signers identify themselves with a public key embedded in a detached Ed25519 signature envelope; install-time verification is a local set-membership check rather than a network round trip to a certificate authority. The cryptographic primitives are deliberately standard (Ed25519 detached signatures and SSH-style trust files); the contribution is the architectural commitment that this composition fits embodied robot fleets specifically. We implement the model in a runtime governance layer with a five-subcommand CLI, a registry server, a per-bridge install gate, and 80 tests. A multi-deployment evaluation shows the same registry stream producing divergent install verdicts on bridges with different trust directories, the load-bearing design property. Across 5000 adversarial trials, the strict-mode gate rejects 100% of rogue-publisher, tampered, forged, and revoked-signer attacks, and 96.6% of downgrade attempts under a minimum-version pin extension. A same-hardware comparison against Sigstore-Cosign and python-TUF locates federated trust's per-verify cost between the two and its per-publisher storage footprint below both.
发表机构
- School of Software, Harbin Institute of Technology(哈尔滨工业大学软件学院)
- School of Computer Science and Technology, Harbin Institute of Technology(哈尔滨工业大学计算机科学与技术学院)
- School of Future Science and Engineering, Soochow University(苏州大学未来科学与工程学院)
机构由 AI 辅助整理,请以论文原文为准。