InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents
Zhenhua Zou, Sheng Guo, Qiuyang Zhan, Lepeng Zhao, Shuo Li, Zhuotao Liu
DeepKernel Lab · Tsinghua University
cs.CR, cs.MA, cs.NI
Submitted: 2026-08-14
Updated: 2026-08-17
Comments: 35 pages, 4 figures, 7 tables. Positioning paper
Code: https://github.com/agentclientprotocol/agent-client-protocol
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 95/100
The gist: InterSAGE is a trust-native protocol suite designed to provide the missing trust substrate for the Internet of Agents (IoA)—a global environment where LLM-powered agents discover peers, negotiate
Terminology
Summary
InterSAGE is a trust-native protocol suite designed to provide the missing trust substrate for the Internet of Agents (IoA)—a global environment where LLM-powered agents discover peers, negotiate trust, invoke tools, and delegate tasks across organizational boundaries. The paper argues that existing agent communication protocols (MCP, A2A, ANP, AG-UI) focus on communication interoperability but lack a foundation for secure interoperability: they do not specify how an agent proves what it is, what it is authorized to do, whether its advertised capabilities are genuine, or how its actions remain accountable after delegation.
InterSAGE is organized into four layers that address nine security aspects across the agent lifecycle:
-
Layer 0 (Persistent Identity): Introduces the Agent Identity Card (AIC), a verifiable credential that cryptographically binds four identity dimensions—developer, code package, operator, and operational context—into a single credential signed by the Global Agent Registry (GAR). The AIC is formally defined as
AIC = SignGAR DIDagent ∥ Kpub ∥ S max, whereDIDagentis derived from the ⟨developer, code pkg, deploy ctx⟩ triple,Kpubis the agent's Ed25519 public key, andS maxis the capability boundary (maximum permission set). This four-dimensional binding addresses threat T1 (identity spoofing):an attacker cannot forge an AIC without simultaneously controlling the developer’s signing key, producing a matching code digest, presenting valid OIDC credentials, and registering with the correct operational context.
The GAR serves as the trust anchor, analogous to a Certificate Authority, handling developer enrollment, AIC issuance, lookup/verification, and revocation with cascading guarantees. Key protection is tiered (OS file isolation, OS keychain, TEE enclave), with the invariant thatKprivnever leaves the isolated trust boundary. -
Layer 1 (Discovery): Provides capability-aware discovery where each skill and tool an agent advertises is a signed Verifiable Credential (VC) bound to the agent's DID. Skill manifest VCs are issued by skill distributors; tool manifest VCs are issued by tool providers. Both carry
credentialSubject.idset to the agent's DID, making them non-transferable and replay-resistant. During discovery, requesters verify each manifest VC via a four-check protocol: supply-chain verification (issuer signature and GAR endorsement), subject binding (credentialSubject.id matches presenter's DID), permission alignment (perms required ⊆ S max), and freshness (not expired/revoked). Thistransforms discovery from a trust-me directory into a verify-then-interact security boundary.
The paper states: "an agent cannot advertise skills it does not hold, tools it has not been authorized to use, or permissions it was not granted, because every claim is cryptographically bound to the agent’s identity and independently verifiable at discovery time." -
Layer 2 (Trust Negotiation): Combines mutual attestation via challenge-response over AICs, delegation via chains with monotonic capability attenuation, and a two-tier access control model. The mutual attestation protocol (Figure 3) involves each agent's kernel verifying both AICs against the GAR, generating fresh nonces, signing them, and computing the infrastructure capability bound
S infra = S max A ∩ S max B. An application-level policy (if registered) may further narrow this toS session = S policy ∩ S infra. Delegation allows a parent agent to issue a child AIC with strictly attenuated capabilities (S child ⊆ S max parent), forming a cryptographic chain with six structural properties: monotonic attenuation, tenant isolation, depth bounding, cascading revocation, validity capping, and cycle resistance. The two-tier access control separates infrastructure-tier cryptographic verification (mandatory, kernel-enforced) from application-tier declarative policy (optional, agent-defined), ensuringno policy edit, JIT decision, or misconfigured PDP downstream of issuance can grant capabilities the preceding stage did not authorize.
-
Layer 3 (Accountability): Ensures every agent action is traceable and attributable. Token-usage records bind LLM consumption to cryptographic agent identity, including a delegation chain field for cost attribution up the delegation tree. Payment primitives provide identity-aware metering that serves as cryptographically verifiable invoices, while remaining agnostic to the settlement mechanism (complementary to Google's AP2). Action accountability uses kernel-mediated signing: every action generates a trace entry signed by the agent's kernel-held private key, with a
prev hashfield chaining entries into a tamper-evident hash-linked log. The paper states: "because the application logic cannot access the raw signing key or rewrite historical logs, an attacker compromising the agent’s LLM or memory cannot forge retroactive trace entries, guaranteeing the integrity of the audit trail up to the exact moment of breach." Non-repudiation rests on kernel-mediated signing and AIC chain binding back to the GAR root key.
The paper's core contribution is the conjunction of four layer-aligned design primitives: "Agent Identity Cards with four-dimensional binding; capability-aware discovery through DID-bound skill/tool manifest VCs; trust negotiation that combines monotonic capability attenuation with two-tier access control; and kernel-mediated cryptographic audit trails. The paper emphasizes that each primitive has antecedents in prior work, but
the conjunction of persistent identity, capability-aware discovery, trust negotiation with monotonic attenuation and two-tier access control, and kernel-mediated accountability appears in no prior single architecture."
InterSAGE is guided by five design principles: (P1) trust as a binding layer, not an add-on; (P2) complementary to existing Internet layers; (P3) general cryptographic primitives with no infrastructure lock-in; (P4) deny-by-default, converge-on-strict (authority can only be attenuated, never amplified—monotonic capability attenuation); (P5) structural guarantees over policy-based assurances.
The paper positions InterSAGE as complementary to existing protocols: "InterSAGE does not replace existing agent protocols such as MCP, A2A, ANP, or AG-UI; it defines the missing trust-relevant primitives that those protocols need: AIC capability boundaries, DID-bound manifest VCs, least-privilege session tokens, and signed execution traces." The trust primitives embed into host protocol messages: MCP invocations carry AIC capability boundaries, ANP discovery responses carry manifest VCs, A2A interactions carry Layer 2 session tokens, and AG-UI streams attach signed execution traces.
The security analysis (§8) evaluates InterSAGE under a Dolev-Yao network adversary augmented with LLM-level compromise capabilities (controlling application logic, issuing arbitrary API calls, observing context data), but assuming the attacker cannot extract Kpriv from the kernel. The paper proves properties including: Identity Integrity (four-dimensional AIC binding neutralizes T1, T4), Capability Confinement (monotonic attenuation chain neutralizes T2), Delegation Safety (subset enforcement, depth bounds, tenant isolation neutralize T2, T3), Discovery Integrity (verifiable credentials neutralize T1, T2), and Accountability (kernel-mediated signing, hash-linked logs neutralize T5, T6). The paper also demonstrates composition safety: The guarantees of higher layers rely only on the invariants of lower layers, never the reverse.
The related work comparison (§9) organizes prior efforts into six clusters and uses a uniform three-step pattern (shared goal, divergence, observable consequence) to contrast InterSAGE with each. Table 7 compares InterSAGE against representative approaches (AgentMesh, AIP, HDP, ANP, Agent-OSI, ZT-IAM, BlockA2A) across thirteen evaluation dimensions. The paper's joint-coverage argument states: "each individual primitive in InterSAGE is anticipated by some prior work, but the conjunction of persistent identity, capability-aware discovery, trust negotiation with monotonic attenuation and two-tier access control, and kernel-mediated accountability appears in no prior single architecture."
Key comparisons include:
-
AgentMesh (Microsoft): Shares the goal of a trust layer but differs in identity model (SPIFFE binds a single workload instance vs. AIC's four dimensions), bound enforcement (runtime policy vs. structural credential-level attenuation), access-control architecture (single policy plane vs. two-tier), protocol relationship (explicit translators vs. protocol-agnostic), and scope (includes reward/learning engine vs. confined to trust layer).
-
AIP: Shares attenuation goals but AIP's attenuation is invocation-scoped and policy-evaluated (Datalog rules re-evaluated per hop), while InterSAGE's is lifecycle-scoped and intersection-evaluated (set-intersection plus signature verification, no Datalog runtime). AIP also lacks developer/operator separation.
-
BlockA2A (prior work): InterSAGE preserves core security ambitions but removes blockchain dependency, introduces layer-aligned primitives, and adds DID-bound manifest VCs, payment, and token-usage tracing.
The paper acknowledges limitations: it is a positioning paper (formal verification, performance benchmarks, implementation details, and adversarial evaluation are deferred to companion publications); the GAR is a centralized/federated trust anchor with PKI-like trade-offs; adoption faces a chicken-and-egg problem; and semantic tag governance requires curation. Future directions include formal verification (TLA+, ProVerif, Tamarin), attestation deployment topologies (co-located, remote-mediated via Trusted Attestation Service, direct peer-to-peer), privacy-preserving extensions (zero-knowledge proofs for selective disclosure), integration with agent frameworks (LangGraph, AutoGen, CrewAI, Semantic Kernel), GAR scalability, cross-GAR federation, agentic payment infrastructure, and post-quantum readiness (ML-DSA, SLH-DSA).
The paper concludes: "communication interoperability is necessary for agents to talk, but secure interoperability is necessary for agents to act across organizational boundaries. InterSAGE is a step toward making the underlying trust layer explicit, composable, and verifiable."
Improvements for AI systems
Improvements to AI Systems:
-
Identity-Bound Tool Invocation: AI agents will be cryptographically bound to a four-dimensional identity (developer, code package, operator, operational context) via an Agent Identity Card (AIC). This prevents impersonation and ensures that any tool or skill an agent calls is verifiably authorized for that specific agent instance, not just any agent claiming the same name.
-
Capability-Aware Discovery with Zero False Advertising: When an AI agent searches for peers or tools, it will only see and interact with agents whose advertised skills and permissions are cryptographically signed and bound to their identity. The improved system will reject any agent that cannot prove it holds the claimed capability, eliminating
trust-me
directories and reducing the risk of malicious or hallucinated capability claims. -
Monotonic Capability Attenuation for Delegation: When an AI agent delegates a subtask to another agent, the improved system will automatically issue a child credential with strictly reduced permissions (set intersection, not amplification). This ensures that a compromised or misbehaving sub-agent cannot escalate privileges beyond what the parent explicitly authorized, and any chain of delegation is provably bounded in depth and scope.
-
Two-Tier Access Control with Kernel-Enforced Mandates: The AI system will separate mandatory, kernel-enforced cryptographic checks (identity, capability boundary, session token) from optional, application-level policy. This means that even if an LLM's prompt injection or policy misconfiguration occurs, the underlying infrastructure will refuse any action that exceeds the cryptographically authorized permission set, providing a hard security floor.
-
Tamper-Evident Action Audit Trails: Every action taken by an AI agent (tool call, API request, token usage) will be signed by a kernel-held private key and chained into a hash-linked log. The improved system can provide non-repudiable, forensic-grade evidence of what the agent did, when, and with which delegation chain—even if the LLM itself is later compromised, the audit trail remains intact up to the exact moment of breach.
-
Freshness and Revocation Enforcement: AI agents will automatically check credential expiration and revocation status (via the Global Agent Registry) before every interaction. This prevents the use of stale or revoked identities, ensuring that an agent whose operator has been removed or whose code has been patched cannot continue to act with old privileges.
-
Cross-Organizational Least-Privilege Sessions: When two agents from different organizations negotiate a session, the improved system will compute the intersection of their maximum capabilities and optionally apply a policy-defined subset. This ensures that no session ever grants more than the minimum necessary permissions, and that no single compromised agent can leverage a session to exceed its own bound.
-
Protocol-Agnostic Trust Embedding: The improved AI system will embed these trust primitives (AIC boundaries, manifest VCs, session tokens, signed traces) into existing communication protocols (MCP, A2A, ANP, AG-UI) without replacing them. This means the security improvements are additive and can be adopted incrementally by existing agent frameworks without a full protocol overhaul.
-
Cost Attribution and Verifiable Invoicing: Token-usage records will be bound to cryptographic agent identity and include delegation chains. The improved system can accurately attribute compute costs to the originating agent and provide cryptographically verifiable invoices, enabling fair billing and accountability in multi-agent economic interactions.
-
Resilience to LLM-Level Compromise: The system assumes the attacker may control the LLM's logic, issue arbitrary API calls, and observe context. Despite this, the improved AI system will still enforce identity integrity, capability confinement, and audit integrity because the private key and signing logic reside in a separate kernel that the LLM cannot access. This means a prompt-injected agent cannot forge credentials, escalate permissions, or rewrite its own audit history.
Sources
- ReAct: Synergizing Reasoning and Acting in Language Models
- AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
- MetaGPT: Meta Programming for A Multi-Agent Collaborative Framework
- Internet of Agents: Weaving a Web of Heterogeneous Agents for Collaborative Intelligence
- Agent Network Protocol Technical White Paper
- Internet of Agents: Fundamentals, Applications, and Challenges
- Agent-OSI: An Interoperability Architecture for Communication and Settlement in the Decentralized Internet of Agents
- A Layered Protocol Architecture for the Internet of Agents
- A Survey of AI Agent Protocols
- A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)
- ACPs: Agent Collaboration Protocols for the Internet of Agents
- AgentRFC: Security Design Principles and Conformance Testing for Agent Protocols
- Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP
- Toward a Safe Internet of Agents
- Fortifying the Agentic Web: A Unified Zero-Trust Architecture Against Logic-layer Threats
- AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A
- BlockA2A: Towards Secure and Verifiable Agent-to-Agent Interoperability
- OpenID Connect for Agents (OIDC-A) 1.0: A Standard Extension for LLM-Based Agent Identity and Authorization
- Identity Management for Agentic AI: The new frontier of authorization, authentication, and security for an AI agent world
- Interoperable Architecture for Digital Identity Delegation for AI Agents with Blockchain Integration
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs