🤖 AI Summary
Existing access control mechanisms fail to enforce authenticated authorization at the moment of change, enabling non-deterministic agents to perform unauthorized operations in production environments. This work proposes the Sovereign Execution Broker (SEB), a runtime enforcement boundary that validates certificates issued by a Sovereign Assurance Boundary (SAB) to ensure changes strictly conform to certified execution contracts and derive scoped execution identities for invoking infrastructure APIs. SEB is the first system to decouple proposal, admission, and execution into distinct phases, transforming authorization into short-lived, revocable, and auditable runtime capabilities. It integrates certificate binding, policy and validity verification, state drift detection, and tamper-resistant deployment to prevent bypassing. Evaluations on AWS and Kubernetes demonstrate that SEB enforces least-privilege access with low latency overhead, supports rapid revocation, enables real-time drift detection, and provides strong security guarantees.
📝 Abstract
Autonomous agents are increasingly connected to cloud, deployment, and data-control workflows, but production mutation authority should not reside inside non-deterministic reasoning processes. Existing access-control mechanisms authorize identities, while assurance layers certify proposed actions; neither alone provides a mandatory enforcement point for certified authority at the moment of mutation. This paper introduces the Sovereign Execution Broker (SEB), a runtime enforcement boundary for certificate-bound agentic infrastructure. SEB consumes certificates issued by the Sovereign Assurance Boundary (SAB), verifies that the requested mutation matches the certified execution contract, checks validity windows, policy epochs, revocation epochs, and live-state drift, mints scoped execution identity, invokes infrastructure APIs, and records signed decision and outcome records. By separating proposal, admission, and execution, SEB turns certified authority into a short-lived, revocable, auditable runtime capability, provided that production mutation APIs reject non-broker identities. We present the SEB execution model, certificate and replay-verification predicates, scoped identity semantics, bypass-prevention deployment patterns, failure behavior, and a concrete prototype implementation. We evaluate the prototype on AWS and Kubernetes clusters, measuring latency overheads, revocation propagation, drift detection, and security under fault injection.