arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.02690cs.CR

ACLE-MCP:用于远程大语言模型工具使用执行时信任的已验证能力租赁

ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use

Zhiyang Ding, Yang Luo, Guangpu Chen, Qingni Shen, Zhonghai Wu

AI总结:

针对远程LLM工具使用的授权后执行信任缺口,提出ACLE-MCP架构,通过绑定调用权限与当前工作负载状态,可阻止评估的攻击且延迟仅增加25.7%,是OAuth的实用补充。

AI中文摘要:

远程模型上下文协议(MCP)服务使大语言模型智能体能够调用外部工具,但仅OAuth授权无法确保后续工具调用由依赖方打算信任的提供方工作负载执行。执行可能转移至替换后的工作负载、依赖过时的评估状态、重用从其他发送方传递的权限、或遍历未声明的下游组件时,端点仍可能保持授权,我们将此问题称为授权后执行信任缺口。我们提出ACLE-MCP,一种调用范围架构,结合委托授权、工作负载评估和资源侧执行准入。对于受保护调用,ACLE-MCP会颁发短期、发送方受限的能力租赁,绑定预期工作负载、新鲜度要求、操作、对象和参数范围、下游约束及接收义务。提供方侧的执行网关在受保护工具逻辑开始前立即验证该租赁。我们实现了一个可运行原型,包含Keycloak/OIDC验证、MCP Python SDK服务器及可选的vTPM quote验证后端。受控安全实验和智能体工具使用扩展显示,较弱的授权或连接时验证模式会留下明显的授权后攻击漏洞,而完整ACLE-MCP可阻止所有评估的攻击系列,同时保留所有良性任务。在本地模拟的智能体扩展中,完整设计相对于仅OAuth的情况,正常允许调用的请求级汇总p95延迟增加25.7%。这些结果表明,调用时将调用权限与当前工作负载状态绑定,是OAuth保护的远程工具使用的实用补充。

英文摘要:

Remote Model Context Protocol (MCP) services enable large language model agents to invoke external tools, but OAuth authorization alone does not ensure that a later tool call is executed by the provider-side workload that the relying party intended to trust. An endpoint may remain authorized even after execution shifts to a substituted workload, relies on stale appraisal state, reuses authority transferred from another sender, or traverses an undeclared downstream component. We call this problem the post-authorization execution trust gap. We present ACLE-MCP, an invocation-scoped architecture that couples delegated authorization, workload appraisal, and resource-side execution admission. For protected calls, ACLE-MCP issues a short-lived, sender-constrained capability lease that binds the expected workload, freshness requirement, operation, object and parameter bounds, downstream constraints, and receipt obligations. A provider-side Execution Gate consumes the lease immediately before protected tool logic begins. We implement a runnable prototype with Keycloak/OIDC validation, an MCP Python SDK server, and an optional vTPM quote-verification backend. Controlled security experiments and an agent tool-use extension show that weaker authorization or connect-time attestation modes leave distinct post-authorization attacks open, whereas full ACLE-MCP blocks all evaluated attack families while preserving all benign tasks. In the locally simulated agent extension, the complete design increases request-level pooled p95 latency on normal allowed calls by 25.7% relative to OAuth-only. These results indicate that invocation-time binding between call authority and current workload state is a practical complement to OAuth-protected remote tool use.

↑