Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture
- 类型:arxiv
- 标识:2608.06130
- 链接:http://arxiv.org/abs/2608.06130v1
- 主分类:agent
- 形态:application
- 被引:0
- 被引来源:Semantic Scholar
- S2被引:0
- 影响力被引:0
- TLDR:This work replaces software-resident keys with hardware-confined keys accessible through a vendor-neutral PKCS#11 interface, enabled by a surrounding five-layer Zero-Trust enforcement stack comprising session identity, scope bounds, semantic validation, taint tracking, and the hardware execution boundary.
- 待LLM分类:否
- 标题中文:面向 AI Agent 签名工作流的硬件密钥存储:一种零信任 MCP 强制执行架构
- TLDR中文:将软件侧密钥替换为硬件受限的密钥,通过厂商中立的 PKCS#11 接口访问,并由包含会话身份、作用域边界、语义验证、污点追踪和硬件执行边界的五层 Zero-Trust 执行栈提供保护。
- 来源文件:
- /inbox/tom/_candidates/2026-08-07-agent-rag-longcontext-candidates.json
- /inbox/tom/_candidates/2026-08-08-agent-rag-longcontext-candidates.json
- [S2 enrich]