arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.00287q-fin.GNcs.AIcs.CRcs.CY

多司法管辖区法律身份保障用于能力门控:关于自然人、法人和机器实体的分级、可复用身份保障的设计科学提案

Multi-Jurisdictional Legal Identity Assurance for Capability Gating: A Design-Science Proposal for Tiered, Reusable Identity Assurance of Natural, Juridical, and Machine Entities

  • Swissi Institute for AI(瑞士人工智能研究所)

机构由 AI 辅助整理,请以论文原文为准。

Walter Kurz

AI总结:

针对现有身份验证过度收集且无法跨境复用的问题,提出一种分级可复用的身份保障模型,使身份需求随行为后果动态调整,并满足法律合规要求。

AI中文摘要:

身份保障是数字系统为不诚实和不确定性所付出的代价:它的存在是为了在并非每个人都能言而有信时,使行为可被归因。支付这种代价的一种常见方式是扁平化最大验证,即在任何能力被行使之前,要求每个参与者在进入时达到单一的高级别身份识别。这种对所有人收取代价的方式会过度收集信息,将无法达到本无需跨越的门槛的参与者排除在外,使每次交互都承担最罕见高风险案例的成本,并将身份识别的强度与其解锁的活动绑定。现有框架通过以下方式加剧了这些问题:在单一法律空间内固定少量按凭证划分的等级,并将每次验证绑定到执行该验证的机构,从而未解决跨境复用以及数据擦除与证据保留之间的张力。本文作为一项设计科学提案,开发了一种针对跨司法管辖区自然人、法人和机器实体的分级、可复用身份保障模型。通过系统理论来解读该问题(系统仅在实体行动时发生变化),该模型将保障状态与消费该状态的能力门控分离开来,从而使身份需求跟随行为及其后果的权重,而非仅仅跟随存在本身:参与者可以以最低限度的披露参与,并仅在行为需要时提供更多信息。该模型包括一个类型化实体分类法、一个由披露断言范围和信息来源组成的双轴坐标、作为实体时间索引属性的司法管辖区,以及以双时态、责任分配、时点快照形式记录的信赖。需求源自反洗钱、电子身份和数据保护法律,并将该提案与扁平化最大验证、按凭证的保障等级设计以及机构可复用KYC信赖进行了评估比较。

英文摘要:

Identity assurance is the cost a digital system pays for dishonesty and uncertainty: it exists to make acts attributable when not everyone can be trusted at their word. A common way to pay that cost is flat maximum verification, asking each participant to meet a single high level of identification at entry, before any capability is exercised. Paid on everyone, it over-collects, excludes participants who cannot meet a bar they never needed to clear, taxes every interaction with the cost of the rarest high-risk case, and binds the strength of identification to the activity it unlocks. Existing frameworks compound this by fixing a small number of per-credential levels inside a single legal space and binding each verification to the institution that performed it, leaving cross-border reuse and the tension between data erasure and evidentiary retention unaddressed. This paper develops, as a design-science proposal, a tiered and reusable model of identity assurance for natural, juridical, and machine entities across jurisdictions. Reading the problem through systems theory, where a system changes only when an entity acts, the model holds the assurance state apart from the capability gate that consumes it, so that identity demand follows the act and the weight of its consequences rather than mere presence: a participant may take part with minimal disclosure and supply more only as an act requires. It comprises a typed entity taxonomy, a two-axis coordinate of disclosed assertion scope and source of information, jurisdiction as a time-indexed attribute of the entity, and reliance recorded as bitemporal, liability-allocated, point-in-time snapshots. Requirements are derived from anti-money-laundering, electronic-identity, and data-protection law, and the proposal is evaluated against flat maximum verification, per-credential level-of-assurance designs, and institutional reusable-KYC reliance.

补充信息

↑