arXiv AI

Cryptographic certificates of validity for trustworthy AI

arXiv:2606. 23768v1 Announce Type: cross Abstract: We propose cryptographic certificates of validity for agentic AI systems.

arXiv AI
Jun 11

Sovereign Assurance Boundary: Certificate-Bound Admission for Agentic Infrastructure

arXiv:2606. 11632v1 Announce Type: cross Abstract: Agentic infrastructure introduces a critical control-plane authorization problem: non-deterministic reasoning systems can propose high-stakes mutations to production resources, yet existing security mechanisms -- such as identity and access management (IAM), policy engines, consensus protocols, and audit logs -- either enforce static, context-unaware permissions or merely record actions post-execution.

By Jun He, Deying Yu
arXiv AI
Aug 17

Mandato: Protocol-Level Enforcement of Digitally Signed Mandates on AI Agent Actions with Cryptographically Chained Audit Trails

arXiv:2608. 14074v1 Announce Type: new Abstract: AI agents increasingly act on external systems through standardized tool-calling protocols such as the Model Context Protocol (MCP), yet no infrastructure layer constrains their actions to what a principal has verifiably authorized: authorization logic lives in application code, is neither signed nor independently auditable, and the resulting logs lack evidentiary value.

By Giovanni Racioppi
arXiv AI
6d ago

Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains

The paper introduces a blockchain-backed agentic security framework that protects the entire software development lifecycle and the AI components monitoring it. It coordinates specialized security agents—covering source integrity, dependency and SBOM analysis, CI configuration auditing, artifact verification, and runtime policy evaluation—each powered by a large language model that interprets artifacts, reasons over tool outputs, and generates structured security reports. Every agent produces a cryptographically signed attestation recorded on a permissioned blockchain via smart contracts, creating an immutable attestation log, an agent registry, and an enforceable release‑policy module, while communication is secured through a consortium‑operated certificate authority.

By Toqeer Ali Syed, Asadullah Abdullah Khan