arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

联邦信任边界:基于分布式账本治理扩展行业IAM

Federating Trust Perimeters: Extending Industry IAM with DLT-Based Governance

Carlo Segat

arXiv 2609.06595首次发表:更新:

发表机构

Technische Universität Berlin(柏林工业大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文探讨非人类实体间自发交互的信任建立问题,分析SPIRE、WIF和OpenID Federation 1.0等IAM方法,提出以SPIRE为基础,通过令牌交换、远程证明和分布式账本三层扩展实现无需预配置的跨组织联邦。

AI 中文摘要

数字系统正变得更加集成化、自主化和协作化。AI智能体、未来移动网络和机器对机器经济都指向一个趋势:非人类实体(NHEs)之间自发的、跨组织的、非计划性的交互。为它们建立信任仍然是一个开放问题。联邦是自然的候选方案,但已有的方法,从OpenID Federation 1.0和SAML到联邦身份管理,都预设了这种场景所不具备的条件:手动的、预先的配置以及共同的信任锚点,无论是预先建立的成员还是共享的提供商。因此,信任域必须在没有被预先配置的情况下进行联邦:为非计划性交互做好规划。本文考察了主流的身份与访问管理(IAM)方法,即SPIRE、工作负载身份联邦(WIF)和OpenID Federation 1.0,是否能够支持这种联邦。通过从不同领域(医疗、移动网络、智能体AI)提取需求,本文论证SPIRE是最有前景的起点,但需要三项扩展才能满足所有需求:令牌交换,允许本地域根据外部工作负载的SPIFFE可验证身份文档(SVID)铸造具有作用域和受众约束的令牌;远程证明,使信任决策针对特定工作负载而非整个域;以及一个分布式账本层,用于锚定信任根、承载联邦治理并发布其他两项所依赖的共享密钥。

英文摘要

Digital systems are becoming more integrated, autonomous, and cooperative. AI agents, future mobile networks, and machine-to-machine economies point to one trend: spontaneous, cross-organizational, unplanned interactions between non human entities (NHEs). Trust establishment for them remains an open problem. Federation is the natural candidate, but established approaches, from OpenID Federation 1.0 and SAML to Federated Identity Management, presuppose what this setting denies them: manual, ahead-of-time configuration and a common trust anchor, whether pre-established members or a shared provider. Trust domains must therefore federate without being prefigured to do so: plan for unplanned interactions. This paper examines whether prominent Identity and Access Management (IAM) approaches, namely SPIRE, Workload Identity Federation (WIF), and OpenID Federation 1.0, can support such federation. Drawing requirements from disparate fields (medical, mobile networks, agentic AI), it argues that SPIRE is the most promising starting point, but needs three extensions to meet them all: token exchange, letting a home domain mint scoped, audience-bound tokens from a foreign workload's SPIFFE Verifiable Identity Document (SVID); remote attestation, so a trust decision targets a specific workload rather than a whole domain; and a distributed-ledger layer that anchors trust roots, carries federation governance, and publishes the shared keys the other two depend on.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑