长期运行AI代理的授权撤销:委托与异步执行下的根作用域静止
Authorization Revocation for Long-Running AI Agents: Root-Scoped Quiescence under Delegation and Asynchronous Execution
浏览论文内容
中文总结 AI 辅助
针对长期运行AI代理的授权撤销问题,提出根作用域授权静止协议,通过证书与栅栏机制确保切割后授权不扩展,并验证其组合健全性与崩溃稳定性。
中文摘要 AI 辅助
长期运行的AI代理通过凭据、委托任务、队列、回调、预留和提供方侧操作而比发起进程存活更久。取消、进程退出和凭据撤销既不能关闭每个切割前载体,也不能区分独立授权的共享工作。我们定义根作用域授权静止:对于每个显现的接收端,一个证书为在退休根纪元原子下、位于其本地栅栏之前的每个切割相关接受负责,并排除该原子在栅栏之后的受保护接受,同时允许精确重新绑定到当前、独立充分的支撑。根作用域静止协议线性化根切割,栅栏化旧根扩展和受保护接收端,将替代和合取权威表示为最小充分根集合的反链,并将提供方前沿证书组合成注册旧根路径上的割集。精确的通道令牌核算调和转移;缺失或冲突的证据保持不确定。在所述假设下,我们证明切割后签发者不扩展、支撑健全投影、在精确通道守恒下的组合健全性、独立支撑保持、合并顺序无关性以及崩溃/重放稳定性。一个无提供方延迟效应测试套件匹配17/17个注册结果。两个仅取消和一个仅切割执行接受同一类已调度的延迟效应;两个切割加栅栏执行、一个重启和一个过期进程执行拒绝它。一个单独实现的检查器验证17/17条轨迹并拒绝44/44个一致重哈希的语义回归。该证书在其界限清单和配置内建立根相对授权静止,而非全局空闲、回滚或业务完成。
英文摘要
Long-running AI agents outlive initiating processes through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations. Cancellation, process exit, and credential revocation neither close every pre-cut carrier nor distinguish independently authorized shared work. We define root-scoped authorization quiescence: for each manifested sink, a certificate accounts for every cut-relevant acceptance under the retired root-epoch atom that precedes its local fence and excludes protected acceptance under that atom after the fence, while permitting exact rebind to a current, independently sufficient support. The root-scoped quiescence protocol linearizes a root cut, fences old-root expansion and protected sinks, represents alternative and conjunctive authority as antichains of minimal sufficient root sets, and composes provider-frontier certificates into a cutset over registered old-root paths. Exact channel-token accounting reconciles transfers; missing or conflicting evidence remains indeterminate. Under stated assumptions, we prove post-cut issuer non-expansion, support-sound projection, compositional soundness under exact channel conservation, independent-support preservation, merge-order independence, and crash/replay stability. A provider-free late-effect test suite matches 17/17 registered outcomes. Two cancellation-only and one cut-only execution accept the same class of already scheduled late effect; two cut-plus-fence executions, one restart, and one stale-process execution reject it. A separately implemented checker verifies 17/17 traces and rejects 44/44 consistently rehashed semantic regressions. The certificate establishes root-relative authorization quiescence within its bound manifest and configuration, not global idleness, rollback, or business completion.
发表机构
- Accentrust
- Georgia Institute of Technology(佐治亚理工学院)
- University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)
机构由 AI 辅助整理,请以论文原文为准。