arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.05901cs.CRcs.AI

从审查到授权:面向LLM智能体的密钥隔离阈值签名

From Review to Authorization: Key-Isolated Threshold Signing for LLM Agents

Yu Zheng, Qizhi Zhang

首次发表
浏览论文内容

中文总结 AI 辅助

KITA通过将签名密钥隔离于LLM进程外,采用阈值BLS签名,实现审查到授权的安全架构,防止提示注入越权执行,并验证了门控与绑定机制。

中文摘要 AI 辅助

自主LLM智能体可以将不可信内容转化为有效操作,例如支付和权限更改。如果同一进程既解释该内容又控制可重用的签名凭证,提示注入就可能跨越判断边界并触及执行权限。我们提出了KITA,一种审查到授权的架构,将用户的个人秘密签名密钥和所有阈值签名密钥份额都隔离在所有LLM进程之外。在阈值签名不可伪造性和我们的系统假设下,攻击者即使攻陷提议者及少于t个审查者签名域,也无法在不获得来自t个不同域的签名贡献的情况下,为新的操作生成有效授权。因此,任何此类授权都包含来自未受攻陷域的份额,该份额绑定到规范操作,并且仅在经过认证的审查者批准后才释放。这确立了执行绑定的授权完整性。我们使用结构化输出LLM适配器和阈值BLS实现了完整的审查者到执行者路径。六项系统测试验证了该接口处的法定人数门控和消息绑定,而密码学微基准测试衡量了在线签名路径及其扩展行为。

英文摘要

Autonomous LLM agents can turn untrusted content into effectful actions such as payments and permission changes. If the same process interprets this content and controls a reusable signing credential, prompt injection can cross the judgment boundary and reach execution authority. We present KITA, a review-to-authorization architecture that keeps the user's personal secret signing key and every threshold signing-key share outside all LLM processes. Under threshold signature unforgeability and our system assumptions, compromising the proposer and fewer than t reviewer-signer domains cannot produce a valid authorization for a new action without signing contributions from t distinct domains. Thus, any such authorization includes a share from an uncompromised domain, bound to the canonical action and released only after authenticated reviewer approval. This establishes execution-bound authorization integrity. We implement the complete reviewer-to-executor path with a structured-output LLM adapter and threshold BLS. Six system tests validate quorum gating and message binding at this interface, while cryptographic microbenchmarks measure the online signing path and its scaling behavior.

发表机构

  • University of California, Berkeley(加州大学伯克利分校)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑