Agent 与自动化 3.0 · 值得看 2026-07-23 · 论文

Toward cryptographically verifiable authorization for autonomous AI agents: A security hypothesi...

论文尝试把自主 Agent 授权形式化为可验证关系,绑定 agent principal具体请求执行上下文和策略满足,并用 Groth16 zk-SNARK 做概念验证它不是成熟产品方案,但为工具调用受保护资源访问和有限人工监督下的授权边界提供了一个可讨论模型

打开原文回到归档

Toward cryptographically verifiable authorization for autonomous AI agents: A security hypothesis, preliminary formal model, and proof-of-concept implementation

AAIF 摘要

论文尝试把自主 Agent 授权形式化为可验证关系,绑定 agent principal、具体请求、执行上下文和策略满足,并用 Groth16 zk-SNARK 做概念验证。它不是成熟产品方案,但为工具调用、受保护资源访问和有限人工监督下的授权边界提供了一个可讨论模型。

English abstract

Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context. This paper hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, denoted $R_{CVA}$, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. We introduce a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), define a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, and provide an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. We further identify and formalize the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem in the design of secure agentic systems (a distinction {not explicitly addressed by} current agentic security frameworks) and present a falsifiable research agenda for its resolution.

Intake rationale

Agent 授权需要绑定主体、请求、上下文和策略满足关系,密码学证明提供了一个可讨论边界。

Obsidian evidence excerpt: 论文尝试把 agent 授权形式化成可密码学验证的关系,绑定 agent principal、具体请求、执行上下文和策略满足关系,并用 Groth16 zk-SNARK 做 proof-of-concept。它不是成熟系统论文,但能给“agent 工具调用如何授权”提供一个可讨论的模型边界。

Metadata

  • Authors: M. Llambí-Morillas, D. Fernández-Fernández
  • Original date: 2026-07-23
  • Source: https://arxiv.org/abs/2607.21325
  • Local intake source: OpenClaw定时任务/论文流水线/2026-07-25-论文流水线.md