← 返回资料库
面向分布式 AI 智能体协同的密码绑定、身份可验证能力令牌:一份提案
Srikumar Subramanian, Shubhashis Sengupta
论文 2026 原文 2026-09-25 arXiv preprint (cs.CR) arXiv:2609.30824 收录 2026-10-05 agent-identitycapability-tokenOAuthW3C-DIDdelegationauthorization
摘要
在能力强大的语言模型出现之前,完全自主的交易型智能体并未进入视野。有了这类模型,自适应任务编排与受约束的独立决策对企业与个人都极具吸引力;但每个此类智能体都带有严峻的攻击面——提示注入,它能击破任何置于上下文中的「软护栏」,后果包括凭证外泄;若不缓解,整个类别的智能体都会因信任破裂而不可用。此外,考虑到自主智能体数量的增长,其安全框架需要某种去中心化才能扩展。作者借鉴尚在提案中的 OAuth Agent Authorization Profile 与 W3C 的 DID、VC 标准,提出一个基于能力安全(capability-based security)原则、以去中心化智能体身份为基础的框架:智能体凭令牌访问服务,令牌与智能体和签发者的身份密码绑定、并声明自身范围;服务在据任一令牌行动前,可验证委托链只涉及范围衰减。作者表明,这样一个位于大模型上下文窗口之外、置于安全模块中的层,可使智能体在可强制的安全边界内行动。
引用本文条目
GB/T 7714-2015
Srikumar Subramanian, Shubhashis Sengupta. Crypto-bound identity-verified capability tokens for coordinating distributed AI agents: A proposal[EB/OL]. arXiv preprint (cs.CR), 2026(2026-09-25)[2026-10-05]. https://arxiv.org/abs/2609.30824.
BibTeX
@misc{subramanian2026,
author = {Srikumar Subramanian and Shubhashis Sengupta},
title = {Crypto-bound identity-verified capability tokens for coordinating distributed AI agents: A proposal},
year = {2026},
organization = {arXiv preprint (cs.CR)},
howpublished = {\url{https://arxiv.org/abs/2609.30824}},
} 本条目为「智联观察」资料库收录,引用时请注明来源与本页链接。