Authorization Revocation for Long-Running AI Agents: Root-Scoped Quiescence under Delegation and Asynchronous Execution
面向长时运行 AI 智能体的授权撤销:委托与异步执行下的根作用域静止性
停止进程并不等于撤销其授权。根作用域静止性会核验每一条可能比长时运行智能体存续更久的已登记路径。
研究概览
长时运行智能体会把授权留在发起进程之外:凭证、委托任务、队列、回调、预留与服务商侧操作,都可能在取消任务或撤销凭证后继续存在。同时,一些共享工作可能还拥有独立于已撤销根授权的有效支持。
该协议首先线性化一次根切断,对旧根授权的继续扩张设置围栏,并为每条已登记路径收集服务商前沿证据。旧根效果会被终止;只有能够证明拥有当前且独立充分授权的工作,才可以精确重新绑定并继续。
核心贡献
- 01
根作用域静止性
将撤销定义为覆盖全部切断相关接受事件的 manifest 绑定证书,而不是简单取消进程,也不把它误表述为全局空闲。
- 02
感知委托的授权表示
使用最小充分根集合的反链表示替代性与合取性授权,使共享工作能够在不混淆授权来源的前提下被终止或保留。
- 03
可组合证据
将服务商前沿证书组合为覆盖旧根路径的割集,并通过精确通道令牌核算对异步转移进行对账;证据缺失或冲突时保持不确定状态。
- 04
可执行撤销检查
通过已登记轨迹和独立实现的检查器,覆盖延迟效果、切断、围栏、重启、陈旧进程、重放行为与语义回归。
授权撤销如何补全运行时授权生命周期
运行时授权管理新获取资源何时可以成为可用授权。根作用域静止性处理相反的转移:授权已经通过委托与异步执行扩散后,应当如何被可靠撤销。
已撤销的根授权无法在本地围栏之后继续扩张或触达受保护接收端。精确重新绑定只会保留能够证明拥有当前、独立且充分授权的工作。
- 01长时运行授权根
- 02线性化切断
- 03封堵旧根路径
- 04静止性证书
证据与适用范围
本文目前是 arXiv 预印本。其证书只在绑定的 manifest 与配置范围内证明相对于特定根授权的静止性,并不证明全局空闲、状态回滚或业务完成。相关保证依赖完整登记旧根路径、精确通道守恒、可靠的服务商前沿证据,以及论文声明的围栏与线性化条件。当前评估以无服务商依赖的轨迹实验为主,并非生产部署研究。
英文摘要
Long-running AI agents outlive initiating processes through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations. Cancellation, process exit, and credential revocation neither close every pre-cut carrier nor distinguish independently authorized shared work. We define root-scoped authorization quiescence: for each manifested sink, a certificate accounts for every cut-relevant acceptance under the retired root-epoch atom that precedes its local fence and excludes protected acceptance under that atom after the fence, while permitting exact rebind to a current, independently sufficient support. The root-scoped quiescence protocol linearizes a root cut, fences old-root expansion and protected sinks, represents alternative and conjunctive authority as antichains of minimal sufficient root sets, and composes provider-frontier certificates into a cutset over registered old-root paths. Exact channel-token accounting reconciles transfers; missing or conflicting evidence remains indeterminate. Under stated assumptions, we prove post-cut issuer non-expansion, support-sound projection, compositional soundness under exact channel conservation, independent-support preservation, merge-order independence, and crash/replay stability. A provider-free late-effect test suite matches 17/17 registered outcomes. Two cancellation-only and one cut-only execution accept the same class of already scheduled late effect; two cut-plus-fence executions, one restart, and one stale-process execution reject it. A separately implemented checker verifies 17/17 traces and rejects 44/44 consistently rehashed semantic regressions. The certificate establishes root-relative authorization quiescence within its bound manifest and configuration, not global idleness, rollback, or business completion.
引用本文
请通过 DOI 记录获取稳定的书目信息和引用格式。
