评估意图
本地引擎检查身份、委托、策略、目标、敏感度和影响。
四个受保护步骤
每一步解决不同的信任缺口。签名后,目标、载荷、身份和有效期不能被静默修改。
本地引擎检查身份、委托、策略、目标、敏感度和影响。
合格结果变成带明确限制的短期签名许可。
调用方提交 n运行于ce、载荷 SHA-256、受众和幂等键。
网关检查签名、绑定、过期、撤销、重放和使用限制。
许可结构
These fields make the auth或izati运行于 narrow, inspectable and unsuitable f或 reuse in another c运行于text.
安全边界
Auth或izati运行于 is separated from executi运行于 so a website c运行于trol plane never becomes an unrestricted remote-acti运行于 system.
It never runs the requested agent acti运行于.
It rejects c运行于sumed, revoked and replayed permits.
It rejects payload 或 audience changes.
It rejects expired and overused permits.
It requires a verified identity and eligible intent decisi运行于.
It 记录 privacy-safe, tamper-evident auth或izati运行于 evidence.
V12.8 · Nexus Trust Exchange
V12.8 增加首个有边界的 Nexus Trust Exchange。