arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.22573cs.CRcs.AI

企业级 MCP 的零信任授权与发现

Zero-Trust Authorization and Discovery for Enterprise MCP

Huan Li, Yuwei Wang, Srinivasan Manoharan

首次发表
浏览论文内容

中文总结 AI 辅助

针对 MCP 授权缺陷,提出 FastMCP 扩展实现零信任授权与发现,通过权限过滤可见性将禁止工具暴露率从 21.1% 降至 0。

中文摘要 AI 辅助

LLM 智能体将自然语言上下文(可能包含攻击者控制的文本)转换为特权工具调用,因此即使在智能体被提示注入或受到对抗性引导时,授权也必须保持有效。模型上下文协议(MCP)已成为这一边界的广泛采用的接口,但其官方 SDK 的认证和授权原语未能满足企业零信任要求,最严重的是双角色模型,其中一个服务器必须同时服务人类用户(企业 SSO)和自动化智能体(不同标头下的服务账户凭据)。我们对六个被调查的 MCP SDK(Python、TypeScript、Go、Rust、C#、Swift)进行了系统性差距分析,并识别出三个结构性缺陷:凭据提取绑定到单个 Authorization 标头,使得在没有自定义中间件的情况下双角色部署复杂化;缺乏认证前的工具发现;以及基础 SDK 中缺乏细粒度的逐工具授权。我们通过 FastMCP 的可组合扩展来弥补这些差距:为服务人类和服务账户调用者的企业部署提供跨标头凭据标准化,跨异构 IdP 的缓存令牌验证,用于无凭据注册表发现的未认证元数据端点,以及通过单个声明式注解保持与逐工具调用执行一致性的权限过滤工具可见性,所有这些都无需修改协议或 SDK 内部。在四个前沿 LLM 的 2160 次尝试中,仅进行体内检查的服务器仍暴露禁止工具(152/720,21.1%),而权限感知可见性将比率降至 0/720;仅可见性过滤仍可被脚本化客户端绕过,而模型在可从提示中推断时,在高达 94% 的设置中通过名称引用隐藏工具,确认发现控制不能替代调用时执行。

英文摘要

LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its official SDKs' authentication and authorization primitives fall short of enterprise zero-trust requirements, most acutely a dual-persona model in which one server must serve human users (corporate SSO) and automated agents (service-account credentials on a different header). We conduct a systematic gap analysis of six surveyed MCP SDKs (Python, TypeScript, Go, Rust, C#, Swift) and identify three structural shortcomings: credential extraction bound to a single Authorization header, complicating dual-persona deployment without custom middleware; the absence of pre-authentication tool discovery; and the lack of fine-grained per-tool authorization in the base SDKs. We close these gaps with composable extensions to FastMCP: cross-header credential normalization for enterprise deployments serving both human and service-account callers, cached token verification across heterogeneous IdPs, an unauthenticated metadata endpoint for credential-free registry discovery, and permission-filtered tool visibility kept consistent with per-tool invocation enforcement by a single declarative annotation, all without modifying the protocol or SDK internals. Across four frontier LLMs over 2160 attempts, an in-body-check-only server still exposes forbidden tools (152/720, 21.1%), whereas permission-aware visibility drives the rate to 0/720; visibility-only filtering remained bypassable by scripted clients, while models referenced the hidden tool by name in up to 94% of settings when inferable from the prompt, confirming that discovery controls cannot replace invocation-time enforcement.

发表机构

  • PayPal Inc.(贝宝公司)

机构由 AI 辅助整理,请以论文原文为准。

↑