paper-with-me

Papers

SUDP: Secret-Use Delegation Protocol for Agentic Systems

2026-04-27 · Xiaohang Yu, Hejia Geng, Xinmeng Zeng, William Knottenbelt arxiv

Agentic systems increasingly act with user secrets for APIs, messaging platforms, and cloud services. Today's agent runtimes typically implement authorization by exposure: enabling action often means placing a reusable secret, or a reusable artifact derived from it, inside the runtime, so a transient prompt-injection or tool-side compromise becomes durable account compromise. Existing defenses cover adjacent pieces such as secret storage, scoped delegation, sender-constrained tokens, and runtime monitoring, but leave the combined agentic obligation without a common specification: an untrusted autonomous requester should be able to cause a user-authorized secret-backed operation without gaining reusable authority over it. We formalize this as the Agent Secret Use (ASU) problem and identify seven security properties any solution must satisfy, spanning authorization integrity and secret confidentiality. We propose the Secret-Use Delegation Protocol (SUDP), in which a requester proposes a canonical operation, the user authorizes it with a fresh authenticator-backed grant, and a custodian redeems the grant to perform the bounded use; reusable authority never crosses the requester boundary. We specialize SUDP for LLM-driven agents, where it applies whenever a tool call would exercise user-enrolled authority-bearing material. Under standard cryptographic assumptions, SUDP satisfies all seven properties when integrated with a hardware-rooted runtime. A reference implementation is available at https://github.com/xhyumiracle/sudp.

📄 PDF Abstract BibTeX arXiv:2604.24920

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI

2026-06-02 · Amjad Ibrahim, Yong Li arxiv

As AI systems evolve from passive models into autonomous active agents capable of initiating actions, collaborating, and delegating tasks, the traditional boundaries of software systems blur. Traditional authorization an…

Observability for Delegated Execution in Agentic AI Systems

2026-06-08 · Abhinav Mishra, Kumar Sharad arxiv

Delegation-scoped execution is not identifiable from standard observables: audit logs and execution traces can be identical under multiple incompatible delegation assignments. This gap is especially acute in LLM-based ag…

Revisiting Gossip Protocols: A Vision for Emergent Coordination in Agentic Multi-Agent Systems

2025-08-03 · Mansura Habiba, Nafiul I. Khan arxiv

As agentic platforms scale, agents are evolving beyond static roles and fixed toolchains, creating a growing need for flexible, decentralized coordination. Today's structured communication protocols (e.g., direct agent-t…

Intelligent AI Delegation

2026-02-12 · Nenad Tomašev, Matija Franklin, Simon Osindero arxiv

AI agents are able to tackle increasingly complex tasks. To achieve more ambitious goals, AI agents need to be able to meaningfully decompose problems into manageable sub-components, and safely delegate their completion …

Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents

2025-09-16 · Abhishek Goswami arxiv

Autonomous LLM agents can issue thousands of API calls per hour without human oversight. OAuth 2.0 assumes deterministic clients, but in agentic settings stochastic reasoning, prompt injection, or multi-agent orchestrati…