arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.22944cs.SEcs.AIcs.MA

NostrAgent:面向自主智能体系统的去中心化身份与委托架构

NostrAgent: A Decentralized Identity and Delegation Architecture for Sovereign Agentic Systems

Oliver Aleksander Larsen, Mahyar Tourchi Moghaddam

首次发表
浏览论文内容

中文总结 AI 辅助

针对自主智能体跨组织协作中身份、委托、信任、发现与支付分散且依赖中心化权威的问题,提出基于Nostr中继和三种自定义事件类型的去中心化统一架构,实现亚毫秒验证与线性扩展,提供可审计的可信基础。

中文摘要 AI 辅助

自主AI智能体日益代表人类操作者在组织边界之外行动:它们调用第三方服务、将子任务委托给其他智能体,并为计量资源付费。安全部署此类智能体需要五种能力,而目前这些能力分散在不同系统中:持久身份、范围限定委托、对等信任、发现和支付。现有方法要么植根于中心化权威机构,要么仅覆盖部分能力,因此权威、信任和支付恰恰在自主性需要连续性的地方出现断裂:例如在密钥轮换或委托必须被撤销时。我们提出NostrAgent,一种去中心化架构,通过三种自定义事件类型在Nostr中继上统一上述五种能力:Kind 38100身份声明,由BIP340 Schnorr签名认证并带有预轮换承诺;Kind 38101范围限定委托链,其每一跳都可验证地收窄授予的能力;以及Kind 38102对等证明,形成具有Sybil威慑力的信任图,并通过Lightning HTTP 402(L402)将支付绑定到智能体身份。身份保持操作者主权,无需任何注册权威机构;中继是可替换的传输层而非信任根;每个授权决策都可从签名事件离线重放。我们使用混合方法设计评估了一个Python原型:采用两轮迷你德尔菲小组的ATAM质量分析、跨越三个信任边界的STRIDE威胁建模、带非参数统计的十一个基准测试以及19种故障模式。结果显示离线验证亚毫秒级完成,委托链线性扩展,L402在regtest上以闪电网络结算的中位时间为157毫秒。19种故障模式中17种通过实证检验,一种通过分析界定,一种被披露为架构局限性。NostrAgent展示了一个无需中心化信任根即可实现可信智能体系统的可审计原型基础。

英文摘要

Autonomous AI agents increasingly act across organizational boundaries on behalf of human operators: they invoke third-party services, delegate subtasks to other agents, and pay for metered resources. Deploying such agents safely requires five capabilities that today live in separate systems: persistent identity, scoped delegation, peer trust, discovery, and payment. Existing approaches root these in centralized authorities or cover only subsets, so authority, trust, and payment fracture exactly where autonomy needs continuity: when a key rotates or a delegation must be revoked. We present NostrAgent, a decentralized architecture that unifies all five over Nostr relays using three custom event kinds: Kind 38100 identity declarations authenticated by BIP340 Schnorr signatures with pre-rotation commitments, Kind 38101 scoped delegation chains whose every hop verifiably narrows granted capabilities, and Kind 38102 peer attestations forming a Sybil-deterrent trust graph, with Lightning HTTP 402 (L402) binding payment to agent identity. Identity remains operator-sovereign without any registration authority; relays are substitutable transport rather than a trust root; and every authorization decision is replayable offline from signed events. We evaluate a Python prototype with a mixed-method design: ATAM quality analysis with a two-round mini-Delphi panel, STRIDE threat modeling across three trust boundaries, eleven benchmarks with non-parametric statistics, and 19 failure modes. Results show sub-millisecond offline verification, linear delegation-chain scaling, and Lightning-settled L402 at 157 ms median on regtest. 17 of 19 failure modes pass empirically, one is bounded analytically, and one is disclosed as an architectural limitation. NostrAgent demonstrates an auditable prototype substrate for trustworthy agentic systems without centralized trust roots.

发表机构

  • University of Southern Denmark(南丹麦大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑