Cryptographically verifiable authorization for autonomous AI agents: a falsifiable hypothesis and proof of concept
cs.CR, cs.AI
Submitted: 2026-07-23
Updated: 2026-09-24
Comments: 11 pages, 1 figure, 2 Tables. Keywords: autonomous AI agents, zero-knowledge proofs, verifiable authorization, agentic security, zk-SNARKs, access control, cryptographic authorization, cryptographic protocols
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight.
Terminology
Abstract
Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context. This paper hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, denoted R CVA, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. We introduce a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), define a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, and provide an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. We further identify and formalize the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem in the design of secure agentic systems (a distinction not explicitly addressed by current agentic security frameworks) and present a falsifiable research agenda for its resolution.
Sources
- DIAP: A Decentralized Agent Identity Protocol with Zero-Knowledge Proofs and a Hybrid P2P Stack
- Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility
- The Aegis Protocol: A Foundational Security Framework for Autonomous AI Agents
- Zero-Knowledge Proof Frameworks: A Systematic Survey
- Building a robust OAuth token based API Security: A High level Overview
- Zero-Knowledge Audit for Internet of Agents: Privacy-Preserving Communication Verification with Model Context Protocol
- AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs