Identity Infrastructure for Autonomous AI Agents: Threat Model, Requirements, and Reference Architecture

Fuente: Zenodo
Guardado en:
Detalles Bibliográficos
Autores principales: Kirste, Daniel, Fendt, Thomas
Formato: Recurso digital
Lenguaje:inglés
Publicado: Zenodo 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866901989672091648
author Kirste, Daniel
Fendt, Thomas
author_facet Kirste, Daniel
Fendt, Thomas
contents <div> <div>AI agents increasingly operate as autonomous economic actors: making purchases, calling APIs, and delegating tasks to sub-agents on behalf of human principals. The identity infrastructure they inherit was built for humans, web applications, and static workloads. None of those principals can be duplicated across concurrent instances, spawned in milliseconds, or have their behavior altered by prompt injection or model modification while their credentials remain valid.</div> <br> <div>This paper makes four contributions. First, a threat model for autonomous AI agent identity comprising six adversary capabilities grounded in published incidents and aligned with reference-monitor and capability-based security theory. Second, six requirements derived from the threat model: instance multiplicity, ephemeral lifecycle, delegated origin, robustness to non-persistence of intent, scope--identity coupling, and real-time revocability. Third, a comparative analysis of fourteen existing frameworks spanning legacy identity, on-chain enforcement, TEE-based enforcement, and emerging agent-specific proposals, identifying a structural \emph{identity-enforcement gap}: frameworks that richly represent agent identity cannot enforce behavioral constraints, while frameworks that enforce constraints lack agent-aware semantics. Fourth, a reference architecture that specifies a design under which the six requirements admit a joint realization for on-chain economic actions through coupling identity, delegation, and economic enforcement at a shared anchor; alternative realizations are presented at each layer, and off-chain enforcement is identified as an open problem.</div> <div> </div> </div>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19919616
institution Zenodo
language eng
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Identity Infrastructure for Autonomous AI Agents: Threat Model, Requirements, and Reference Architecture
Kirste, Daniel
Fendt, Thomas
AI Agents
agent identity
identity infrastructure
delegated authority
multi-agent systems
<div> <div>AI agents increasingly operate as autonomous economic actors: making purchases, calling APIs, and delegating tasks to sub-agents on behalf of human principals. The identity infrastructure they inherit was built for humans, web applications, and static workloads. None of those principals can be duplicated across concurrent instances, spawned in milliseconds, or have their behavior altered by prompt injection or model modification while their credentials remain valid.</div> <br> <div>This paper makes four contributions. First, a threat model for autonomous AI agent identity comprising six adversary capabilities grounded in published incidents and aligned with reference-monitor and capability-based security theory. Second, six requirements derived from the threat model: instance multiplicity, ephemeral lifecycle, delegated origin, robustness to non-persistence of intent, scope--identity coupling, and real-time revocability. Third, a comparative analysis of fourteen existing frameworks spanning legacy identity, on-chain enforcement, TEE-based enforcement, and emerging agent-specific proposals, identifying a structural \emph{identity-enforcement gap}: frameworks that richly represent agent identity cannot enforce behavioral constraints, while frameworks that enforce constraints lack agent-aware semantics. Fourth, a reference architecture that specifies a design under which the six requirements admit a joint realization for on-chain economic actions through coupling identity, delegation, and economic enforcement at a shared anchor; alternative realizations are presented at each layer, and off-chain enforcement is identified as an open problem.</div> <div> </div> </div>
title Identity Infrastructure for Autonomous AI Agents: Threat Model, Requirements, and Reference Architecture
topic AI Agents
agent identity
identity infrastructure
delegated authority
multi-agent systems
url https://doi.org/10.5281/zenodo.19919616