信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2026, Vol. 52 ›› Issue (8): 2-10.doi: 10.12267/j.issn.2096-5931.2026.08.001

专题:数字安全与应用 上一篇    下一篇

智能体互联场景中的用户授权机制与身份伪造风险研究

Research on user authorization mechanisms and identity forgery risks in agent interconnection scenarios

吴寒冰, 冯艺卓   

  1. 中国信息通信研究院泰尔终端实验室, 北京 100191
  • 收稿日期:2026-07-02 出版日期:2026-08-25 发布日期:2026-09-02
  • 作者简介:
    吴寒冰,中国信息通信研究院泰尔终端实验室工程师,主要从事人工智能、信息通信领域相关标准研制、验证及测试能力建设等方面的研究工作;
    冯艺卓,中国信息通信研究院泰尔终端实验室工程师,主要从事AI场景应用、AI治理、企业数字化转型等方面的研究工作

WU Hanbing, FENG Yizhuo   

  1. CTTL Terminal Labs, China Academy of Information and Communications Technology, Beijing 100191, China
  • Received:2026-07-02 Online:2026-08-25 Published:2026-09-02

摘要:

智能体互联成为人工智能应用的重要发展方向,不同部署方式下的用户授权流程存在显著差异,现有的智能体授权模式在互联场景中面临多重安全风险。首先,从智能体部署方式差异出发,对比云平台快速部署与企业私有化部署的授权流程;分析智能体在调用与被调用场景下的安全风险,并分析智能体身份码、工作流、模型上下文协议服务等实体身份的风险;从人员核身与身份认证两个维度总结身份伪造的风险点,重点关注多模态伪造及具备自主执行长链路任务能力的智能助理所带来的安全挑战。最后,从身份码动态管理、工作流授权粒度、服务间认证、多模态活体检测和操作可追溯性等方面提出技术改进建议,为智能体互联环境下的安全设计提供参考。

关键词: 智能体互联, 用户授权, 身份伪造, Claw类智能体

Abstract:

Agent interconnection has become a key development direction for artificial intelligence applications, with significant differences existing in user authorization processes under various deployment models. Current agent authorization models face multiple security risks in interconnection scenarios. Firstly, starting from the differences in agent deployment models, compares the authorization processes of rapid deployment on cloud platforms and enterprise private deployment; analyzes the security risks of intelligent agents in calling and being called scenarios, and analyzes the risks associated with entity identities such as agent identity codes, workflows, model context protocol services, etc; summarizes the risk points of identity forgery from two dimensions: personnel identity verification and identity authentication, with a focus on multimodal forgery and the security challenges posed by intelligent assistants with the ability to autonomously execute long-chain tasks. Finally, technical improvement suggestions are proposed from the aspects of dynamic management of identity codes, workflow authorization granularity, inter service authentication, multimodal liveness detection, and operational traceability, providing reference for security design in agent interconnection environments.

Key words: agent interconnection, user authorization, identity forgery, Claw agents

中图分类号: