Spherity Research Paper

Beyond Single-Enterprise ZTA: Multi-Trust Architectures for Authorised Agentic Actors in Open, Cross-Domain Ecosystems

Extending Zero Trust with M-Trust, Business Wallets and verifiable authority for cross-domain agentic networks

Author
Affiliation
Dr. Carsten Stöcker — Spherity GmbH
Published
Updated
Research cut-off
· Sources, standards and market developments reviewed to this date
This version
https://spherity.github.io/spherity-research/beyond-zero-trust-m-trust-authorised-agentic-actors.html
Latest version
https://spherity.github.io/spherity-research/beyond-zero-trust-m-trust-authorised-agentic-actors.html
Browse this paper

In brief

What does this research establish?

Single-enterprise Zero Trust is necessary but insufficient when AI agents act across organizations, sectors and jurisdictions. The paper connects M-Trust’s multi-party, intent-aware and cross-domain model with Business Wallets, legal-person identity, task-bounded delegation, verifiable AI evidence, local policy enforcement and signed action receipts.

Key takeaways

  • Zero Trust protects enterprise resources and sessions; cross-domain agentic action additionally requires portable evidence of the accountable person, mandate, AI service, context and policy decision.
  • B2C and B2B share a bounded-delegation pattern, but enterprise transactions require legal-person identity, representative authority, organizational approval rules and a complete delegation chain.
  • M-Trust contributes multi-party evaluation, agentic intent-aware trust and cross-domain trust; Spherity’s proposed layer adds the legal and evidentiary semantics needed for attributable action.
  • A verifier creates transient trust for one purpose, audience and time window; source domains retain authority over their claims and the relying domain retains the authorization decision.

Download the full research paper

Download the PDF

44 pages · open access · CC BY 4.0. The complete architecture, standards-gap analysis, B2C and B2B comparison, use cases, geopolitical discussion and implementation roadmap.

Read the reference architecture

Go to the eight-layer architecture

A concise path from legal-person identity and task-bounded delegation to verifier policy, controlled action and signed accountability evidence.

First page of Beyond Single-Enterprise ZTA by Dr. Carsten Stöcker, on M-Trust and verifiable authority for agentic actors.
Open-access research paper. An architectural and geopolitical analysis of the GSMA Greater China M-Trust draft, with a Spherity reference architecture for verifiable cross-domain agent actions. Published under CC BY 4.0.

Abstract

AI agents can select tools, exchange data, initiate transactions and coordinate beyond a single enterprise. NIST Zero Trust Architecture provides the essential resource and session security foundation, but it does not by itself establish the legal person behind an enterprise agent, the complete delegation chain, the current state of the AI service or the cross-domain evidence used in a decision.

This paper applies a qualitative architecture and standards-gap analysis to the English- and Chinese-language drafts of GSMA Greater China’s Trust Paradigm Evolution for Agentic Networks. It treats M-Trust as a draft research direction—not a mandatory standard—and evaluates its three dimensions: Multi-party trust, Agentic Intent-aware trust and Cross-domain trust. It then proposes how Business Wallets, legal-person identity, Agent Powers of Attorney, AI Service Passports, W3C Verifiable Credentials, Decentralized Identifiers, verifier-sovereign policy, signed action receipts and post-quantum migration can turn that model into attributable B2B and B2G action.

The result is a reference architecture for transient cross-domain trust: source domains retain governance over their claims, while the relying verifier composes current identity, authority, evidence and context for one purpose, audience and time window.

Keywords: Zero Trust for AI agents; M-Trust; AI agent security; verifiable authority; Business Wallets; legal-person identity; cross-domain trust; agentic AI; data spaces; Digital Product Passports; Trusted AI

中文摘要

中文标题: 超越单一企业零信任架构:面向开放跨域生态系统中授权智能体的多元信任架构

AI 智能体能够选择工具、交换数据、发起交易,并在单一企业边界之外协同运行。NIST 零信任架构为资源与会话安全提供了必要基础,但其本身并不能证明企业智能体背后的法人实体、完整的授权委托链、AI 服务的当前状态,或跨域决策所依据的证据。

本文对 GSMA 大中华区《面向未来智能体网络的信任范式演进(征求意见稿)》的中英文版本进行定性架构分析和标准差距分析。本文将 M-Trust 视为仍在讨论中的研究方向,而非强制性标准,并分析其三个维度:多方信任基于智能体意图感知的信任跨域信任。本文进一步提出,如何将企业数字钱包、法人身份、任务范围受限的智能体授权委托、AI 服务护照、W3C 可验证凭证、去中心化标识符、由验证方自主执行的策略、签名行动回执以及后量子迁移机制结合起来,使 B2B 和 B2G 智能体行动可归责、可验证且可审计。

研究最终提出一种临时跨域信任参考架构:来源域继续治理其声明与凭证;依赖方(验证方)则针对特定目的、受众和时间窗口,组合最新的身份、授权、证据与上下文,并依据本地策略作出和执行授权决策。

中文关键词: AI 智能体安全;AI Agent 安全;零信任架构;面向 AI 智能体的零信任;M-Trust 多元信任架构;多方信任;基于智能体意图感知的信任;跨域信任;企业智能体身份;B2B AI 智能体;可验证授权;企业数字钱包;法人身份;智能体授权委托;AI 服务护照;可验证凭证;去中心化标识符;数据空间;数字产品护照;可信人工智能

Beyond single-enterprise Zero Trust Architecture

NIST SP 800-207 moves security away from implicit trust based on network location and focuses authorization on users, devices, assets and resources. That remains the foundation: every request must be evaluated, least privilege enforced and runtime state monitored.

The problem changes when an agent crosses organizational boundaries. A relying party may recognize the agent’s workload identity and still lack answers to the questions that determine accountable action:

The paper’s central proposition is therefore:

Trusted agentic execution requires verifiable authority + verifiable evidence + local policy enforcement + bounded autonomy.

This is not a replacement for Zero Trust. It is a cross-domain extension that carries attributable authority and evidence into the resource decision.

B2C and B2B authority: a shared pattern with different legal roots

Consumer agents and enterprise agents both need scoped delegation, but they do not present equivalent identity or governance evidence.

Branch Accountable principal Evidence chain Additional decision requirements
B2C agentic commerce A natural person Natural person → authenticated wallet or account → scoped intent or delegation → agent → cart or payment action → receipt User authentication, agent identity, freshness and scope of the instruction, transaction-specific confirmation, status and consumer/payment rules.
B2B/B2G agentic action A legal person Legal person → authorised representative or governed system → organizational approval → task-bounded mandate → agent or workload → controlled action → signed receipt Company identity, representation authority, internal approval policy, governed role credentials, complete delegation chain, AI-service evidence and local verifier policy.

Google AP2, Mastercard Verifiable Intent, Visa Trusted Agent Protocol, Amazon Buy for Me and Apple App Intents/StoreKit illustrate different B2C mechanisms. They do not form one uniform protocol or legal regime. The paper uses verifiable intent as an analytical category for evidence that links a person’s instruction to an agent and resulting action; applicable law determines legal effect.

For B2B and B2G, a technical agent identity proves which workload controls a key. It does not prove which company stands behind the workload or whether the company authorized this action. That gap motivates reusable organizational identity, representation and mandate credentials.

The three M-Trust dimensions—and how Spherity operationalises them

The GSMA Greater China draft proposes M-Trust as an extension of Zero Trust for autonomous, multi-party and cross-domain environments. Its contribution is a systems model, while the Spherity research asks which legal, credential, wallet, registry and evidence components are needed for cross-company execution.

M-Trust dimension Core idea Example Spherity-aligned implementation
Multi-party trust Several evaluators, trust inputs, endorsements and risk signals contribute to the decision. A data-space transaction depends on company-register identity, sector role, conformity evidence and counterparty risk. Authoritative issuers, trust lists and registries, verifiable data registries, multi-issuer credential presentations and evidence graphs.
Agentic Intent-aware trust Purpose, task, context, requested resource, risk and execution state constrain authorization. An energy agent may read one dataset for balancing a named asset but may not change another operator’s control settings. A task-bounded Power of Attorney, declared purpose, tool and value limits, AI Service Passport state, runtime context, policy decision point and enforcement point.
Cross-domain trust Portable evidence crosses heterogeneous roots of trust without forcing one universal hierarchy. A manufacturer presents company identity, market role and product evidence to an independently governed customer or regulator. Business and Agent Wallets, W3C Verifiable Credentials and presentations, DIDs, credential status, semantic profiles and verifier-sovereign policy.
Architecture progression from a Zero Trust foundation through M-Trust's multi-party, intent-aware and cross-domain dimensions to Business Wallet identity, agent delegation, AI service evidence, policy enforcement and signed receipts.
Figure 1. Progression from Zero Trust through M-Trust to verifiable authority for B2B use cases. Zero Trust supplies identity-centric security, least privilege, continuous verification and dynamic risk control. M-Trust adds multi-party, agentic intent-aware and cross-domain trust. The verifiable-authority layer adds Business Wallet and legal-person identity, Agent Wallet and Power of Attorney, AI Service Passport evidence, local policy enforcement and signed action receipts. Source: Author’s synthesis based on NIST SP 800-207, the GSMA Greater China M-Trust draft and Spherity research.

The lower loop in Figure 1 is continuous: collect and evaluate identity, authority, evidence and risk; compute effective scope under local policy; enforce the bounded action outside the agent’s own reasoning; and feed back status, drift, incidents and outcomes. New threat intelligence, a revoked credential, an updated model risk profile or a runtime anomaly can therefore change the decision state during a task.

Use cases for authorised agentic actors

The paper tests the architecture across telecom, commerce, industrial and regulated-data contexts.

  1. Cross-domain telecom resources. An agent requests scheduling, bandwidth, encryption or monitoring across operators. A human or legal-person credential, agent identity and task mandate establish authority; local operators still enforce their own policy.
  2. Temporary multi-agent teams. Agents from several domains form a short-lived team for access, security or demand coordination. Portable credentials create transient trust, and permissions are reclaimed when the task ends.
  3. Cross-operator high-definition services. A workflow narrows authority as it advances from scheduling to resource use, producing signed evidence at material steps.
  4. Roaming vehicle and mobile agents. SIM/eSIM, hardware roots and workload identity establish technical provenance; organizational credentials establish accountable legal authority.
  5. B2C agentic commerce. A natural person’s authenticated, scoped instruction is bound to an agent, cart or payment action and receipt, subject to applicable consumer and payment law.
  6. Energy and industrial data spaces. A Business Wallet presents company and market-role credentials, while a connector evaluates purpose, mandate and data-use policy before releasing BESS, grid or supply-chain data.
  7. Digital Product Passports. An enterprise agent retrieves or updates product evidence only when both product-linked facts and organizational authority are verifiable.
  8. Trusted AI and Physical AI. A relying party checks the agent’s mandate, AI Service Passport, TEVV and runtime evidence before a gateway permits a bounded digital or cyber-physical action.

Comparative results: convergence without a single regional standard

The reviewed sources converge on recurring control patterns but emphasize different layers. The comparison does not claim regional consensus or equivalent maturity.

Source or ecosystem Strongest contribution Material gap relative to the target architecture
GSMA Greater China M-Trust draft Multi-party evaluation, intent-aware authorization, cross-domain trust, continuous decision loop and telecom use cases. Leaves W3C VC profiles, Business Wallets, legally grounded delegation and concrete PQC profiles unspecified.
United States B2C initiatives Signed intent, agent recognition, cart/payment confirmation and platform enforcement. Portability, legal effect, organizational authority and common cross-provider status remain uneven.
Anthropic Zero Trust for AI Agents Cryptographically rooted agent identity, task-scoped permissions, sandboxing, memory and input/output controls, and enterprise security operations. Does not by itself supply portable legal-person identity and cross-company mandate chains.
WE BUILD non-paper European wallets, verifiable credentials, trusted identities, mandates and provable intent for AI agents. Profiles, adoption governance and interoperable production implementations still need development and validation.
Manufacturing-X and sector data spaces Federated industrial governance, Identity & Trust functions, connectors, roles and governed data exchange. Shared agent-mandate, evidence-graph and cross-ecosystem cryptographic profiles remain development priorities.
Spherity joint-research proposal LPID → PoA → AISP; Business and Agent Wallets; verifier policy; evidence graphs; signed receipts; crypto-agile, cross-domain corridors. Requires published profiles, conformance tests, reference implementations and cross-jurisdiction pilots.

Standards requirements and verifiable trust chains

The target architecture does not rely on one technology or ledger. It requires interoperable primitive classes with clear governance:

The paper expresses the trust chain as:

authoritative source → legal person → authorised representative → agent or workload → task mandate → verifier policy → controlled action → signed receipt

Each arrow must be independently checkable, current and semantically understood by the relying party. A signature proves integrity and control of a key; it does not alone prove legal identity, authority, compliance or fitness for purpose.

Business Wallets, organizational identity and verifiable authority

The proposed B2B model separates four questions that are often collapsed:

  1. Who is the organization? A Legal-Person Identity (LPID) credential is rooted in an authoritative company register or an accepted cross-jurisdiction identity framework.
  2. Who may delegate? A representative, role or governed system must have current authority under the organization’s rules and applicable law.
  3. What may the agent do? A task-bounded Power of Attorney or capability specifies purpose, resource, tool, value, time, geography, delegation depth and termination conditions.
  4. What evidence supports execution now? The verifier evaluates AI Service Passport, TEVV, runtime, product, data-space and transaction evidence under its own policy.

A Business Wallet can carry organizational identity and governed credentials. An Agent Wallet or workload identity can hold the task capability and present the required evidence. The relying verifier resolves issuer and credential status and computes the effective permission as the intersection of all applicable limits. This preserves verifier sovereignty: no wallet, credential or external agent decides access on behalf of the relying domain.

Applications in Data Spaces, Digital Product Passports and Trusted AI

The architecture is reusable because the legal-person root and delegation chain can stay stable while sector evidence remains under its own governance.

Reference Architecture for Verifiable Agentic Networks

The proposed architecture contains eight layers. Each answers a distinct trust question and supplies inputs to the decision and enforcement loop.

Layer Core components Required outcome
1. Governance and trust Laws, domain rulebooks, reciprocal recognition, trust registries, issuer accreditation and semantic governance Recognized authority across autonomous trust domains.
2. Organizational identity Business Wallet, register-backed company identity, vLEI, roles, licences, electronic signatures and seals Verifiable legal person and representation across jurisdictions.
3. Agent identity and delegation Agent Wallet, DID or workload identity, Power of Attorney and task capability Bounded technical agency linked to accountable authority.
4. AI service assurance AI Service Passport, TEVV, risk profile, incidents and monitoring Verifiable system provenance and current assurance state.
5. Data and product evidence Data spaces, DPP/DBP systems, provenance, semantic validation and evidence graph A verifiable basis for the requested decision.
6. Decision and enforcement M-Trust evaluation, policy decision point, policy enforcement point, connector or gateway Local, context-aware and transient cross-domain authorization.
7. Registry and cryptographic resilience VDR or governed registry, optional ledger, trusted execution, attestation, crypto-agility and PQC corridors Current shared state, durable integrity, authenticity and confidentiality.
8. Accountability evidence Signed action receipt, timestamp, policy version, evidence and status snapshot Reconstructable decision and execution history.

An end-to-end transaction follows seven steps: the agent proposes a specific action; the gateway requests authority and assurance evidence; the Agent Wallet presents identity and mandate; the verifier resolves issuers, status, semantics and evidence references; policy computes effective authority and transient trust; the enforcement point executes only the bounded capability; and the gateway produces a signed receipt and updates continuous monitoring.

The architecture’s scope is deliberately bounded. It is a design and standards proposal, not evidence of production performance, legal qualification, interoperability or political coordination. Those claims require profiles, reference implementations, conformance results and pilots across jurisdictions.

Research method, evidence boundary and Google Trends

The paper uses a qualitative architecture and standards-gap analysis. It distinguishes documented design, architectural inference and normative proposal. The English- and Chinese-language M-Trust drafts were compared for identity, credential, ledger, classical-cryptography and post-quantum content; comparative sources were reviewed for B2C intent, enterprise agent security, European wallet identity, industrial data-space governance and cross-jurisdiction organizational authority.

Google Trends was reviewed on 16 September 2026 as an editorial input. Worldwide and German Web Search comparisons showed the strongest relative interest around AI agents, AI agent security, agentic AI and zero trust. M-Trust and verifiable authority had insufficient or very low reported interest. The page therefore uses the higher-demand language for discovery while retaining the specialist terms because they precisely name the paper’s contribution. Google Trends values are normalized relative-interest signals, not absolute search volumes or evidence of market size.

Selected primary references

  1. Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. (2020). NIST SP 800-207: Zero Trust Architecture. National Institute of Standards and Technology.
  2. GSMA Greater China (2026). Trust Paradigm Evolution for Agentic Networks — Draft for Comments. English- and Chinese-language drafts reviewed.
  3. García-Herrero, A.; Storella, T. (2026). “China’s artificial intelligence goals and strategic choices for Europe”. Bruegel, 10 September 2026.
  4. GSMA Greater China (2026). The Value of Mobile AI. Chinese-language white paper.
  5. Anthropic (2026). “Zero Trust for AI Agents: A Security Framework for Deploying Autonomous AI Agents in the Enterprise”, 27 May 2026.
  6. Magård, D.; Busch, P.; Hannemann, D.; Scalongne, W.; Fjelkner, B.; Parikh, S.; Stöcker, C.; Bailly, L. (2026). Trusted Identities for AI Agents: An Opportunity for Europe. WE BUILD non-paper, 27 February 2026.
  7. Plattform Industrie 4.0 (2026). Manufacturing-X Framework. Federal Ministry for Economic Affairs and Energy.
  8. GLEIF and contributing authors (2026). Agentic AI in Payments: Establishing Interoperable Trust and Control. Working Paper Series, version 1.0.
  9. W3C (2022). Decentralized Identifiers (DIDs) v1.0.
  10. W3C (2025). Verifiable Credentials Data Model v2.0.

The PDF contains the complete 52-source bibliography, including post-quantum standards, EBSI and eIDAS ledger provisions, Dataspace Protocol and Decentralized Claims Protocol, B2C payment and commerce initiatives, Catena-X, European Business Wallet sources and related Spherity Research.

How to cite this work

Stöcker, Carsten (2026). “Beyond Single-Enterprise ZTA: Multi-Trust Architectures for Authorised Agentic Actors in Open, Cross-Domain Ecosystems.” Spherity GmbH. https://spherity.github.io/spherity-research/beyond-zero-trust-m-trust-authorised-agentic-actors.html. Licensed CC BY 4.0.

Creative Commons Attribution 4.0 International

Open research

License and citation

This open research publication package—including the research page, linked PDF and Spherity reference figure— is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.

How to cite this work

Dr. Carsten Stöcker (2026-09-16). “Beyond Single-Enterprise ZTA: Multi-Trust Architectures for Authorised Agentic Actors in Open, Cross-Domain Ecosystems: Extending Zero Trust with M-Trust, Business Wallets and verifiable authority for cross-domain agentic networks.” Spherity GmbH. https://spherity.github.io/spherity-research/beyond-zero-trust-m-trust-authorised-agentic-actors.html. Licensed CC BY 4.0.

Direct answers

Questions this research answers

Why is single-enterprise Zero Trust insufficient for cross-domain AI agents?

Zero Trust can verify a subject, device and request before access to an enterprise resource. A cross-domain AI agent also requires portable evidence of the accountable natural or legal person, the delegation chain, task scope, AI-service state, source-domain claims and the policy decision that permits the action.

What are the three M-Trust dimensions?

Multi-party trust combines several evaluators and trust inputs. Agentic intent-aware trust evaluates purpose, context, risk and task scope. Cross-domain trust carries portable evidence across heterogeneous trust roots while each verifier applies its own policy.

How do B2C and B2B agent authorization differ?

A B2C chain links a natural person’s authenticated instruction to an agent, transaction and receipt. B2B and B2G additionally require legal-person identity, representative authority, organizational approval rules, governed credentials and a complete task-bounded delegation chain.

What is verifiable authority for an enterprise AI agent?

It is evidence that links the agent or workload to an accountable legal person, an authorized representative, a current mandate, explicit limits, applicable organizational policy and the resulting action receipt. It complements technical agent identity rather than replacing it.

How does the architecture apply to data spaces, DPPs and Trusted AI?

A Business Wallet supplies organizational identity and mandates; Agent Wallets and credentials establish bounded agency; DPP, DBP and data-space evidence supports the requested decision; an AI Service Passport and runtime evidence describe the deployed AI service; local policy and enforcement remain verifier-sovereign.

Which architecture patterns converge across GSMA M-Trust, WE BUILD, Manufacturing-X, Anthropic and Spherity for enterprise agent identity and B2B use cases?

They converge on a recurring pattern: strong agent or workload identity; task-scoped and context-aware authorization; independently verifiable evidence; enforcement outside the model's reasoning; continuous status and risk evaluation; and auditable outcomes. GSMA M-Trust frames multi-party, intent-aware and cross-domain trust; Anthropic emphasizes enterprise agent security controls; WE BUILD contributes wallet-based trusted identity, mandates and provable intent; Manufacturing-X contributes federated industrial governance, connectors and data-sovereignty controls; and Spherity connects these layers to legal-person identity, Business and Agent Wallets, task-bounded Powers of Attorney, AI Service Passports, evidence graphs, verifier-sovereign policy and signed action receipts. This is architectural convergence, not a claim of formal standards alignment, endorsement or demonstrated interoperability.

Is M-Trust already a standard?

No. The reviewed GSMA Greater China publication is a draft reference architecture and research direction. This paper evaluates it, identifies standards gaps and proposes an aligned Spherity architecture; it does not claim that M-Trust is a mandatory standard or established regional consensus.

中文直答

中文常见问题

以下问答概括本研究对企业智能体身份、跨域授权、M-Trust 与可验证信任链的核心结论。

为什么单一企业零信任架构不足以支持跨域 AI 智能体?

零信任可以在访问企业资源之前验证主体、设备和请求。跨域 AI 智能体还需要提供可移植证据,以证明应承担责任的自然人或法人、完整的授权委托链、任务范围、AI 服务状态、来源域声明,以及允许该行动的策略决策。

M-Trust 的三个信任维度是什么?

多方信任结合多个评估方、信任输入、背书和风险信号。基于智能体意图感知的信任根据任务目的、上下文、风险和范围进行授权。跨域信任则在异构信任根之间传递可移植证据,同时由每个验证方依据自身策略作出决定。

B2C 与 B2B 智能体授权有何不同?

B2C 授权链将自然人的已认证指令与智能体、交易和回执连接起来。B2B 和 B2G 还需要法人身份、代表权限、组织内部审批规则、受治理的角色凭证,以及完整且受任务范围约束的授权委托链。

企业 AI 智能体的“可验证授权”是什么?

可验证授权是一组可独立验证的证据,用于将智能体或工作负载与承担责任的法人、获授权代表、当前有效的授权委托、明确限制、适用的组织策略以及最终行动回执连接起来。它补充技术性智能体身份,而不是取代技术性身份。

该架构如何应用于数据空间、数字产品护照和可信人工智能?

企业数字钱包提供组织身份和授权委托;智能体钱包与凭证建立受限的行动权限;数字产品护照、数字电池护照和数据空间证据支持具体决策;AI 服务护照与运行时证据描述所部署 AI 服务的当前状态;最终授权与策略执行仍由依赖方(验证方)自主控制。

GSMA M-Trust、WE BUILD、Manufacturing-X、Anthropic 和 Spherity 在企业智能体身份及 B2B 用例方面汇聚出哪些架构模式?

这些工作汇聚出一组反复出现的架构模式:强智能体或工作负载身份;任务范围受限且上下文感知的授权;可独立验证的证据;位于模型推理之外的策略执行;持续的状态与风险评估;以及可审计的结果。GSMA M-Trust 描述多方、意图感知和跨域信任;Anthropic 强调企业智能体安全控制;WE BUILD 提供基于钱包的可信身份、授权委托和可证明意图;Manufacturing-X 提供联邦式工业治理、连接器和数据主权控制;Spherity 则把这些层与法人身份、企业钱包和智能体钱包、任务范围受限的授权委托、AI 服务护照、证据图谱、验证方自主策略及签名行动回执连接起来。这种关系表示架构模式的趋同,并不表示正式标准已对齐、相关机构相互背书或系统已经实现互操作。

M-Trust 已经是正式标准吗?

不是。本文审阅的 GSMA 大中华区材料是一份征求意见稿、参考架构和研究方向。本文对其进行评估、识别标准差距并提出与之相关的 Spherity 架构,但不声称 M-Trust 已成为强制性标准,也不声称它代表已经形成的区域共识。

中文参考架构

面向可验证智能体网络的八层参考架构

该架构将跨域企业智能体行动拆分为八个可验证、可治理且可独立实施的层。每一层回答一个不同的信任问题,并向持续的“采集与评估—策略决策—策略执行—运行时反馈”闭环提供输入。

提示:在窄屏设备上可左右滑动查看全部三列。

表 1:面向跨域 B2B 与 B2G 智能体行动的八层参考架构。
层级 核心组件 必须实现的结果
1. 治理与信任 法律、域规则手册、互认机制、信任注册表、签发者资质认可和语义治理 在自治信任域之间建立可被识别和接受的权威来源与授权关系。
2. 组织身份 企业数字钱包、由权威登记册支持的企业身份、可验证法人机构标识符(vLEI)、角色、许可证、电子签名和电子印章 跨司法管辖区验证法人身份及其代表权。
3. 智能体身份与授权委托 智能体钱包、去中心化标识符(DID)或工作负载身份、授权委托书(PoA)和任务能力凭证 将受限的技术代理能力与可问责的授权主体相连接。
4. AI 服务保障 AI 服务护照(AISP)、测试、评估、验证与确认(TEVV)、风险概况、事件记录和监测 验证系统来源及其当前保障状态。
5. 数据与产品证据 数据空间、数字产品护照/数字电池护照(DPP/DBP)系统、来源信息、语义校验和证据图谱 为请求的决策提供可验证的证据基础。
6. 决策与执行 M-Trust 信任评估、策略决策点(PDP)、策略执行点(PEP)、连接器或网关 实现由本地策略主导、上下文感知且具有时限的跨域授权。
7. 注册表与密码韧性 可验证数据注册表(VDR)或受治理注册表、可选分布式账本、可信执行环境、远程证明、密码敏捷性和后量子密码(PQC)迁移走廊 维护当前共享状态,以及持久的完整性、真实性和机密性。
8. 可问责性证据 签名行动回执、时间戳、策略版本、证据快照和状态快照 形成可重建的决策与执行历史。

端到端流程:端到端交易遵循七个步骤:智能体提出一项具体行动;网关请求授权与保障证据;智能体钱包出示身份与授权委托;验证者解析签发者信息、凭证状态、语义和证据引用;策略引擎计算有效权限并建立临时信任;策略执行点仅执行范围受限的能力;网关生成签名行动回执并更新持续监测状态。

范围说明:本架构有意限定其主张范围:它是一项设计与标准化建议,并不构成生产性能、法律资格、互操作性或政治协调已经实现的证据。相关主张需要跨司法管辖区的公开技术配置文档、参考实现、一致性测试结果和试点验证。