Identity Infrastructure for Autonomous AI Agents: Threat Model, Requirements, and Reference Architecture
Fuente:
Zenodo
Guardado en:
| Autores principales: | , |
|---|---|
| Formato: | Recurso digital |
| Lenguaje: | inglés |
| Publicado: |
Zenodo
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866901989672091648 |
|---|---|
| author | Kirste, Daniel Fendt, Thomas |
| author_facet | Kirste, Daniel Fendt, Thomas |
| contents | <div> <div>AI agents increasingly operate as autonomous economic actors: making purchases, calling APIs, and delegating tasks to sub-agents on behalf of human principals. The identity infrastructure they inherit was built for humans, web applications, and static workloads. None of those principals can be duplicated across concurrent instances, spawned in milliseconds, or have their behavior altered by prompt injection or model modification while their credentials remain valid.</div> <br> <div>This paper makes four contributions. First, a threat model for autonomous AI agent identity comprising six adversary capabilities grounded in published incidents and aligned with reference-monitor and capability-based security theory. Second, six requirements derived from the threat model: instance multiplicity, ephemeral lifecycle, delegated origin, robustness to non-persistence of intent, scope--identity coupling, and real-time revocability. Third, a comparative analysis of fourteen existing frameworks spanning legacy identity, on-chain enforcement, TEE-based enforcement, and emerging agent-specific proposals, identifying a structural \emph{identity-enforcement gap}: frameworks that richly represent agent identity cannot enforce behavioral constraints, while frameworks that enforce constraints lack agent-aware semantics. Fourth, a reference architecture that specifies a design under which the six requirements admit a joint realization for on-chain economic actions through coupling identity, delegation, and economic enforcement at a shared anchor; alternative realizations are presented at each layer, and off-chain enforcement is identified as an open problem.</div> <div> </div> </div> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_19919616 |
| institution | Zenodo |
| language | eng |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | Identity Infrastructure for Autonomous AI Agents: Threat Model, Requirements, and Reference Architecture Kirste, Daniel Fendt, Thomas AI Agents agent identity identity infrastructure delegated authority multi-agent systems <div> <div>AI agents increasingly operate as autonomous economic actors: making purchases, calling APIs, and delegating tasks to sub-agents on behalf of human principals. The identity infrastructure they inherit was built for humans, web applications, and static workloads. None of those principals can be duplicated across concurrent instances, spawned in milliseconds, or have their behavior altered by prompt injection or model modification while their credentials remain valid.</div> <br> <div>This paper makes four contributions. First, a threat model for autonomous AI agent identity comprising six adversary capabilities grounded in published incidents and aligned with reference-monitor and capability-based security theory. Second, six requirements derived from the threat model: instance multiplicity, ephemeral lifecycle, delegated origin, robustness to non-persistence of intent, scope--identity coupling, and real-time revocability. Third, a comparative analysis of fourteen existing frameworks spanning legacy identity, on-chain enforcement, TEE-based enforcement, and emerging agent-specific proposals, identifying a structural \emph{identity-enforcement gap}: frameworks that richly represent agent identity cannot enforce behavioral constraints, while frameworks that enforce constraints lack agent-aware semantics. Fourth, a reference architecture that specifies a design under which the six requirements admit a joint realization for on-chain economic actions through coupling identity, delegation, and economic enforcement at a shared anchor; alternative realizations are presented at each layer, and off-chain enforcement is identified as an open problem.</div> <div> </div> </div> |
| title | Identity Infrastructure for Autonomous AI Agents: Threat Model, Requirements, and Reference Architecture |
| topic | AI Agents agent identity identity infrastructure delegated authority multi-agent systems |
| url | https://doi.org/10.5281/zenodo.19919616 |