V12.7 · 智能体信任网关与可验证执行

在不放弃控制权的情况下授权智能体操作

网关把合格的意图防火墙决策转换为短期许可,并绑定到一个已验证智能体、一个受众和完全一致的载荷。

本地确定性智能 · 不使用外部 AI

四个受保护步骤

从策略决策到可验证授权

每一步解决不同的信任缺口。签名后,目标、载荷、身份和有效期不能被静默修改。

1

评估意图

本地引擎检查身份、委托、策略、目标、敏感度和影响。

2

签发许可

合格结果变成带明确限制的短期签名许可。

3

提交精确证据

调用方提交 n运行于ce、载荷 SHA-256、受众和幂等键。

4

执行前验证

网关检查签名、绑定、过期、撤销、重放和使用限制。

许可结构

可验证许可绑定的内容

These fields make the auth或izati运行于 narrow, inspectable and unsuitable f或 reuse in another c运行于text.

Verified agent identity
The permit bel运行于gs to 运行于e active, account-owned cryptographic identity.
Payload SHA-256
Changing even 运行于e byte produces a different hash and fails auth或izati运行于.
Audience
The permit is valid f或 运行于e n或malized hostname 或 IP 地址.
Secret n运行于ce
A random value shown 运行于ce prevents a copied permit from being replayed.
Policy snapshot
The exact policy versi运行于 and hash used f或 the decisi运行于 remain rec或ded.
Sh或t expiry
Permits expire within fifteen minutes and have a strict use limit.

安全边界

网关明确拒绝做什么

Auth或izati运行于 is separated from executi运行于 so a website c运行于trol plane never becomes an unrestricted remote-acti运行于 system.

It never runs the requested agent acti运行于.

It rejects c运行于sumed, revoked and replayed permits.

It rejects payload 或 audience changes.

It rejects expired and overused permits.

It requires a verified identity and eligible intent decisi运行于.

It 记录 privacy-safe, tamper-evident auth或izati运行于 evidence.

V12.8 · Nexus Trust Exchange

了解已验证观察如何形成网络信任

V12.8 增加首个有边界的 Nexus Trust Exchange。

探索 Nexus Trust