Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture

  • 类型:arxiv
  • 标识:2608.06130
  • 链接:http://arxiv.org/abs/2608.06130v1
  • 主分类:agent
  • 形态:application
  • 被引:0
  • 被引来源:Semantic Scholar
  • S2被引:0
  • 影响力被引:0
  • TLDR:This work replaces software-resident keys with hardware-confined keys accessible through a vendor-neutral PKCS#11 interface, enabled by a surrounding five-layer Zero-Trust enforcement stack comprising session identity, scope bounds, semantic validation, taint tracking, and the hardware execution boundary.
  • 待LLM分类:否
  • 标题中文:面向 AI Agent 签名工作流的硬件密钥存储:一种零信任 MCP 强制执行架构
  • TLDR中文:将软件侧密钥替换为硬件受限的密钥,通过厂商中立的 PKCS#11 接口访问,并由包含会话身份、作用域边界、语义验证、污点追踪和硬件执行边界的五层 Zero-Trust 执行栈提供保护。
  • 来源文件
  • /inbox/tom/_candidates/2026-08-07-agent-rag-longcontext-candidates.json
  • /inbox/tom/_candidates/2026-08-08-agent-rag-longcontext-candidates.json
  • [S2 enrich]