Runtime Authorization for Resources Acquired by AI Agents
面向 AI 智能體所取得資源的執行階段授權
完成付款或交付,並不意味著資源可以安全地成為可用授權。執行階段授權填補了資源取得與能力啟用之間的空白。
研究概覽
自主智能體可以取得運算資源、憑證、帳戶、服務或其他智能體。既有付款、預算、OAuth、委派與交付檢查能夠驗證交易條件,卻不一定判斷回傳資源是否應在目前任務中成為可用授權。
該架構會先隔離所有取得結果,透過帶版本的解析器從經過認證的服務商證據中解析真實能力;隨後只有在目前啟用交易同時滿足來源、epoch、已解析 manifest,以及身分、效果、資料、委派和整體資源圖的關聯限制時,資源才會被啟用。
核心貢獻
- 01
啟用空白的形式化
將成功取得或交付,與允許回傳資源向智能體任務引入新授權的安全決策明確分離。
- 02
隔離與能力解析
讓取得結果保持不可用狀態,直到帶版本的解析器能夠依據經過認證的服務商證據確定其真實能力。
- 03
關係型授權邊界
把啟用綁定到來源、epoch 與向下封閉的圖約束,從而維持身分、效果、資料、委派及全圖範圍限制之間的關聯。
- 04
效果發生時執行
在效果線性化時重新驗證並消耗一次性許可,同時透過參考軌跡、獨立檢查器、竄改測試、MCP 用戶端、分階段 Docker 組合和多來源欄位稽核進行驗證。
執行階段授權如何擴展治理技術棧
OpenPort、IGAC 與 EBTE 分別治理工具存取、使用者意圖與行動聲明,ClosureBound 則把授權綁定到執行技能的依賴閉合身分。資源取得引入了另一種轉移:任務在交付完成後可能接收到新的主體或能力來源。
執行階段授權會讓該資源保持隔離,直到一次目前、受來源約束的啟用證明其能力圖符合許可邊界。交易成功本身不會讓資源自動繼承授權。
- 01取得資源
- 02隔離
- 03已解析能力清單
- 04綁定啟用
- 05受控效果
證據與適用範圍
本文目前是 arXiv 預印本與參考架構,並未宣稱已具備生產就緒性。其保證依賴經過認證的服務商證據、完整中介、正確的解析與規範化、權威 epoch 與線性化,以及關係型邊界的可靠執行。文中的 MCP 與 Docker 研究屬於確定性或分階段評估;欄位稽核也不代表任何單一受調查單元已經提供完整的生產啟用設定。
英文摘要
By acquiring compute, credentials, accounts, services, and other agents, autonomous AI agents can introduce new authority into a task. Payment, budget, OAuth, mandate, and fulfillment checks can validate transaction conditions without deciding whether a returned resource may become usable authority. This post-fulfillment activation gap spans tool-mediated creation, inter-agent delegation, and agentic commerce. We present a provenance-bounded runtime authorization architecture. It quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a downward-closed relational envelope over a typed resource-capability hypergraph. The envelope preserves correlated identity, effect, data, delegation, and graph-wide limits. Single-use effect permits are revalidated and consumed at effect linearization. Under explicit assumptions, we prove eight safety properties covering quarantine, backing, non-amplification, split non-evasion, crash/retry, refunds, epochs, and effect confinement. Across five resource classes, reference semantics accepted 20/20 benign traces and rejected 40/40 registered unsafe traces over 810 events; an independent checker agreed on 60 base and 40 refinement traces and rejected 89/89 tamper tests. Frozen Codex and Gemini Model Context Protocol (MCP) client components completed 54/54 deterministic local stdio calls. In a registered 18-case staged MCP-to-Docker composition, both benign paths completed, and none of the 16 unsafe paths added an unauthorized Docker start request. A five-source audit classified 1,248 field pairs across 32 units; no unit alone supplied a complete activation profile.
引用本文
請透過 DOI 記錄取得穩定的書目資訊和引用格式。
