🤖 AI Summary
This work proposes a unified verifiable delegation framework to address the challenge of enabling human users to securely delegate identity privileges to AI agents across centralized, federated, and self-sovereign identity (SSI) systems without exposing master credentials or private keys. The framework treats delegation grants (DGs) as first-class entities and integrates normative verification contexts (CVCs), a layered trust gateway architecture, and policy evaluation mechanisms, with optional blockchain anchoring to enhance integrity. It supports minimal-privilege, auditable, and context-aware authorization across heterogeneous identity systems, significantly improving interoperability. By providing a robust foundation for integrating AI agents into trusted digital identity infrastructures, this approach advances both standardization efforts and practical deployment in real-world scenarios.
📝 Abstract
Verifiable delegation in digital identity systems remains unresolved across centralized, federated, and self-sovereign identity (SSI) environments, particularly where both human users and autonomous AI agents must exercise and transfer authority without exposing primary credentials or private keys. We introduce a unified framework that enables bounded, auditable, and least-privilege delegation across heterogeneous identity ecosystems. The framework includes four key elements: Delegation Grants (DGs), first-class authorization artefacts that encode revocable transfers of authority with enforced scope reduction; a Canonical Verification Context (CVC) that normalizes verification requests into a single structured representation independent of protocols or credential formats; a layered reference architecture that separates trust anchoring, credential and proof validation, policy evaluation, and protocol mediation via a Trust Gateway; and an explicit treatment of blockchain anchoring as an optional integrity layer rather than a structural dependency. Together, these elements advance interoperable delegation and auditability and provide a foundation for future standardization, implementation, and integration of autonomous agents into trusted digital identity infrastructures.