TL;DR:Agentic Identity 为 AI 智能体赋予可识别、可验证、可授权的数字身份,支撑企业自动化、跨组织协作与链上操作。核心依托 DID、可验证凭证(VC)与行为凭证审计,并附完整 Python 落地路径。
SEO 摘要:Agentic Identity 以 DID 与可验证凭证,为智能体构建可信数字身份。
- [1. 引言](#1. 引言)
- [2. 什么是 Agentic Identity](#2. 什么是 Agentic Identity)
- [2.1 概念定义](#2.1 概念定义)
- [2.2 与传统身份体系的区别](#2.2 与传统身份体系的区别)
- [2.3 为什么现在需要它](#2.3 为什么现在需要它)
- [3. 核心技术](#3. 核心技术)
- [3.1 去中心化标识符(DID)](#3.1 去中心化标识符(DID))
- [3.2 可验证凭证(Verifiable Credentials)](#3.2 可验证凭证(Verifiable Credentials))
- [3.3 密钥管理与签名](#3.3 密钥管理与签名)
- [3.4 行为凭证与审计溯源](#3.4 行为凭证与审计溯源)
- [3.5 信任框架与声誉系统](#3.5 信任框架与声誉系统)
- [4. 应用场景](#4. 应用场景)
- [4.1 企业自动化流程](#4.1 企业自动化流程)
- [4.2 跨组织数据协作](#4.2 跨组织数据协作)
- [4.3 智能合约与链上操作](#4.3 智能合约与链上操作)
- [4.4 个人数字助理](#4.4 个人数字助理)
- [4.5 安全合规与监管](#4.5 安全合规与监管)
- [5. 实践操作](#5. 实践操作)
- [5.1 技术选型](#5.1 技术选型)
- [5.2 最小实现步骤](#5.2 最小实现步骤)
- [5.3 常见挑战与应对](#5.3 常见挑战与应对)
- [6. 未来展望](#6. 未来展望)
- [6.1 标准化与互操作](#6.1 标准化与互操作)
- [6.2 与 AI 治理深度融合](#6.2 与 AI 治理深度融合)
- [6.3 自主身份与自我主权](#6.3 自主身份与自我主权)
- [6.4 与 Web3 和去中心化生态融合](#6.4 与 Web3 和去中心化生态融合)
- [6.5 安全挑战持续升级](#6.5 安全挑战持续升级)
- [6.6 攻击案例:供应链智能体身份伪造](#6.6 攻击案例:供应链智能体身份伪造)
- [7. 总结](#7. 总结)
- [8. 参考链接](#8. 参考链接)随着大语言模型(LLM)与智能体(Agent)技术的迅猛发展,AI 系统正从被动响应指令的工具,进化为能够自主规划、调用工具、协同完成复杂任务的"数字员工"。在这一范式转移中,一个关键问题浮出水面:当 AI 开始自主行动,我们如何确认"它是谁"、"它被授权做什么"、"它的行为由谁负责"?Agentic Identity(智能体身份) 正是回应这一问题的核心基础设施。
简言之,Agentic Identity 赋予智能体在数字世界中可识别、可验证、可授权的身份,如同人类拥有身份证与银行账户一般。它定义了"这个智能体是谁""它能做什么""它代表谁""它的行为如何被追溯"。本文将从概念定义、核心技术、应用场景、实践操作与未来展望五个维度,系统拆解 Agentic Identity 的技术全貌与落地路径。
下图展示了 Agentic Identity 的整体架构:智能体作为身份主体,通过 DID 实现去中心化标识,由密钥管理保障签名安全,借助 VC 完成授权验证,行为审计记录操作轨迹,最终由信任框架评估可信度。
#mermaid-svg-EztX6RwpDzSP0wGu{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-EztX6RwpDzSP0wGu .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-EztX6RwpDzSP0wGu .error-icon{fill:#552222;}#mermaid-svg-EztX6RwpDzSP0wGu .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-EztX6RwpDzSP0wGu .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-EztX6RwpDzSP0wGu .marker{fill:#333333;stroke:#333333;}#mermaid-svg-EztX6RwpDzSP0wGu .marker.cross{stroke:#333333;}#mermaid-svg-EztX6RwpDzSP0wGu svg{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-EztX6RwpDzSP0wGu p{margin:0;}#mermaid-svg-EztX6RwpDzSP0wGu .label{font-family:"trebuchet ms",verdana,arial,sans-serif;color:#333;}#mermaid-svg-EztX6RwpDzSP0wGu .cluster-label text{fill:#333;}#mermaid-svg-EztX6RwpDzSP0wGu .cluster-label span{color:#333;}#mermaid-svg-EztX6RwpDzSP0wGu .cluster-label span p{background-color:transparent;}#mermaid-svg-EztX6RwpDzSP0wGu .label text,#mermaid-svg-EztX6RwpDzSP0wGu span{fill:#333;color:#333;}#mermaid-svg-EztX6RwpDzSP0wGu .node rect,#mermaid-svg-EztX6RwpDzSP0wGu .node circle,#mermaid-svg-EztX6RwpDzSP0wGu .node ellipse,#mermaid-svg-EztX6RwpDzSP0wGu .node polygon,#mermaid-svg-EztX6RwpDzSP0wGu .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-EztX6RwpDzSP0wGu .rough-node .label text,#mermaid-svg-EztX6RwpDzSP0wGu .node .label text,#mermaid-svg-EztX6RwpDzSP0wGu .image-shape .label,#mermaid-svg-EztX6RwpDzSP0wGu .icon-shape .label{text-anchor:middle;}#mermaid-svg-EztX6RwpDzSP0wGu .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-EztX6RwpDzSP0wGu .rough-node .label,#mermaid-svg-EztX6RwpDzSP0wGu .node .label,#mermaid-svg-EztX6RwpDzSP0wGu .image-shape .label,#mermaid-svg-EztX6RwpDzSP0wGu .icon-shape .label{text-align:center;}#mermaid-svg-EztX6RwpDzSP0wGu .node.clickable{cursor:pointer;}#mermaid-svg-EztX6RwpDzSP0wGu .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-EztX6RwpDzSP0wGu .arrowheadPath{fill:#333333;}#mermaid-svg-EztX6RwpDzSP0wGu .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-EztX6RwpDzSP0wGu .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-EztX6RwpDzSP0wGu .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-EztX6RwpDzSP0wGu .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-EztX6RwpDzSP0wGu .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-EztX6RwpDzSP0wGu .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-EztX6RwpDzSP0wGu .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-EztX6RwpDzSP0wGu .cluster text{fill:#333;}#mermaid-svg-EztX6RwpDzSP0wGu .cluster span{color:#333;}#mermaid-svg-EztX6RwpDzSP0wGu div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-EztX6RwpDzSP0wGu .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-EztX6RwpDzSP0wGu rect.text{fill:none;stroke-width:0;}#mermaid-svg-EztX6RwpDzSP0wGu .icon-shape,#mermaid-svg-EztX6RwpDzSP0wGu .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-EztX6RwpDzSP0wGu .icon-shape p,#mermaid-svg-EztX6RwpDzSP0wGu .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-EztX6RwpDzSP0wGu .icon-shape .label rect,#mermaid-svg-EztX6RwpDzSP0wGu .image-shape .label rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-EztX6RwpDzSP0wGu .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-EztX6RwpDzSP0wGu .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-EztX6RwpDzSP0wGu :root{--mermaid-font-family:"trebuchet ms",verdana,arial,sans-serif;} 审计与信任层
凭证与授权层
身份标识层
智能体层
AI 智能体
DID 去中心化标识符
密钥管理与签名
可验证凭证 VC
授权与权限模型
行为凭证与审计溯源
信任框架与声誉系统
2. 什么是 Agentic Identity
2.1 概念定义
Agentic Identity 是指赋予 AI 智能体一套可验证的数字身份体系,使其能够在跨系统、跨组织、跨信任域的环境中完成身份认证、权限授权、行为审计与责任追溯。它并非"给 AI 起个名字"这般简单,而是一整套涵盖身份签发、密钥管理、权限模型、行为凭证与信任机制的完整技术栈。
2.2 与传统身份体系的区别
| 维度 | 传统数字身份(人类) | Agentic Identity(智能体) |
|---|---|---|
| 身份主体 | 自然人 | AI 智能体 / 自动化程序 |
| 认证方式 | 密码、生物识别、OTP | 密钥对、DID、可验证凭证 |
| 授权模型 | 基于角色的访问控制(RBAC) | 基于能力/意图的动态授权 |
| 行为审计 | 人工操作日志 | 自动化的行为凭证与溯源 |
| 信任建立 | 中心化 CA / 身份提供商 | 去中心化信任网络 / 可验证凭证 |
| 生命周期 | 与人生周期绑定 | 随智能体部署、升级、销毁而动态变化 |
2.3 为什么现在需要它
- 智能体规模化:当企业同时运行数百个自动化智能体时,必须能区分"谁在做什么"。
- 跨组织协作:智能体需要代表不同组织完成交易、签约、数据交换,需要可信身份背书。
- 责任追溯:智能体出错或造成损失时,需要明确责任主体,否则无法追责。
- 安全边界:恶意智能体或被盗用的智能体身份可能造成严重安全事件,需要身份层防护。
3. 核心技术
Agentic Identity 的完整工作流程可概括为:签发方(Issuer)为智能体签发可验证凭证(VC),智能体持有 DID 与 VC,在调用 API 时携带身份凭证,服务端验证签名与授权后放行,并生成行为凭证用于审计溯源。整体流程如下图所示:
#mermaid-svg-lBPzN6OrVNwx4mqz{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-lBPzN6OrVNwx4mqz .error-icon{fill:#552222;}#mermaid-svg-lBPzN6OrVNwx4mqz .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-lBPzN6OrVNwx4mqz .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-lBPzN6OrVNwx4mqz .marker{fill:#333333;stroke:#333333;}#mermaid-svg-lBPzN6OrVNwx4mqz .marker.cross{stroke:#333333;}#mermaid-svg-lBPzN6OrVNwx4mqz svg{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-lBPzN6OrVNwx4mqz p{margin:0;}#mermaid-svg-lBPzN6OrVNwx4mqz .label{font-family:"trebuchet ms",verdana,arial,sans-serif;color:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz .cluster-label text{fill:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz .cluster-label span{color:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz .cluster-label span p{background-color:transparent;}#mermaid-svg-lBPzN6OrVNwx4mqz .label text,#mermaid-svg-lBPzN6OrVNwx4mqz span{fill:#333;color:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz .node rect,#mermaid-svg-lBPzN6OrVNwx4mqz .node circle,#mermaid-svg-lBPzN6OrVNwx4mqz .node ellipse,#mermaid-svg-lBPzN6OrVNwx4mqz .node polygon,#mermaid-svg-lBPzN6OrVNwx4mqz .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-lBPzN6OrVNwx4mqz .rough-node .label text,#mermaid-svg-lBPzN6OrVNwx4mqz .node .label text,#mermaid-svg-lBPzN6OrVNwx4mqz .image-shape .label,#mermaid-svg-lBPzN6OrVNwx4mqz .icon-shape .label{text-anchor:middle;}#mermaid-svg-lBPzN6OrVNwx4mqz .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-lBPzN6OrVNwx4mqz .rough-node .label,#mermaid-svg-lBPzN6OrVNwx4mqz .node .label,#mermaid-svg-lBPzN6OrVNwx4mqz .image-shape .label,#mermaid-svg-lBPzN6OrVNwx4mqz .icon-shape .label{text-align:center;}#mermaid-svg-lBPzN6OrVNwx4mqz .node.clickable{cursor:pointer;}#mermaid-svg-lBPzN6OrVNwx4mqz .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-lBPzN6OrVNwx4mqz .arrowheadPath{fill:#333333;}#mermaid-svg-lBPzN6OrVNwx4mqz .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-lBPzN6OrVNwx4mqz .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-lBPzN6OrVNwx4mqz .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-lBPzN6OrVNwx4mqz .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-lBPzN6OrVNwx4mqz .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-lBPzN6OrVNwx4mqz .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-lBPzN6OrVNwx4mqz .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-lBPzN6OrVNwx4mqz .cluster text{fill:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz .cluster span{color:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-lBPzN6OrVNwx4mqz .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-lBPzN6OrVNwx4mqz rect.text{fill:none;stroke-width:0;}#mermaid-svg-lBPzN6OrVNwx4mqz .icon-shape,#mermaid-svg-lBPzN6OrVNwx4mqz .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-lBPzN6OrVNwx4mqz .icon-shape p,#mermaid-svg-lBPzN6OrVNwx4mqz .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-lBPzN6OrVNwx4mqz .icon-shape .label rect,#mermaid-svg-lBPzN6OrVNwx4mqz .image-shape .label rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-lBPzN6OrVNwx4mqz .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-lBPzN6OrVNwx4mqz .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-lBPzN6OrVNwx4mqz :root{--mermaid-font-family:"trebuchet ms",verdana,arial,sans-serif;} Issuer 签发 VC
智能体持有 DID + VC
调用 API 携带凭证
服务端验证签名与授权
生成行为凭证并审计
3.1 去中心化标识符(DID)
DID(Decentralized Identifier,去中心化标识符)是 W3C 制定的去中心化身份标识标准。每个智能体拥有一个全局唯一的 DID,不依赖任何中心化注册机构,通过分布式账本或分布式哈希表实现解析与验证。
text
did:example:123456789abcdefghi
DID 的核心价值在于:身份标识与身份验证分离,智能体可以自主生成和管理自己的标识,而不需要向某个中心化平台申请。
3.2 可验证凭证(Verifiable Credentials)
VC(Verifiable Credentials,可验证凭证)是 W3C 的另一项核心标准。它允许可信的签发方(Issuer)为智能体签发经数字签名的凭证,例如"该智能体已通过安全审计""该智能体有权访问财务系统"。验证方无需联系签发方,即可通过密码学手段独立验证凭证的真实性与完整性。
json
{
"@context": ["https://www.w3.org/2018/credentials/v1"],
"id": "http://example.edu/credentials/1872",
"type": ["VerifiableCredential", "AgentPermissionCredential"],
"issuer": "did:example:issuer123",
"issuanceDate": "2026-01-01T00:00:00Z",
"credentialSubject": {
"id": "did:example:agent456",
"permission": "read_financial_reports",
"scope": "internal_analytics"
}
}
3.3 密钥管理与签名
智能体身份的核心是公私钥对。私钥用于签名行为凭证,公钥用于验证。密钥管理需要解决以下问题:
- 密钥生成:在可信环境中生成高强度密钥对。
- 密钥存储:使用硬件安全模块(HSM)或安全飞地保护私钥。
- 密钥轮换:定期更换密钥,防止长期暴露风险。
- 密钥恢复:智能体迁移或重建时的身份恢复机制。
3.4 行为凭证与审计溯源
每个智能体的关键操作都应生成经过签名的行为凭证(Action Receipt),记录"谁、何时、做了什么、基于什么授权"。这些凭证构成不可篡改的审计链,支持事后追溯和责任认定。
text
ActionReceipt {
agent_did: "did:example:agent456",
action: "execute_trade",
params_hash: "0x8f3a...",
authorization_ref: "vc:permission:read_financial_reports",
timestamp: "2026-10-03T14:30:00Z",
signature: "0x9b2c..."
}
3.5 信任框架与声誉系统
Agentic Identity 还需要一套信任评估机制,帮助系统判断"这个智能体是否可信"。常见手段包括:
- 凭证链验证:追溯凭证签发链,确认签发方可信。
- 声誉评分:基于历史行为记录计算智能体的可信度评分。
- 风险分级:根据智能体的权限范围、历史异常行为进行风险分级。
在实际落地中,信任框架的选择往往需要在安全性与效率之间权衡。下表对比了中心化信任、去中心化信任图谱与混合信任三种主流框架:
| 维度 | 中心化信任 | 去中心化信任图谱 | 混合信任 |
|---|---|---|---|
| 信任来源 | 单一权威 CA / 身份提供商 | 分布式账本、凭证链、声誉网络 | 中心化背书 + 去中心化验证 |
| 优点 | 部署简单、验证快、责任主体明确 | 无单点故障、跨域互操作强、抗审查 | 兼顾效率与开放性,可渐进式落地 |
| 缺点 | 单点故障、易受攻击、跨组织信任难 | 实现复杂、性能开销大、冷启动难 | 架构复杂,需同时维护两套信任机制 |
| 适用场景 | 单一企业内部的封闭系统 | 跨组织、跨信任域的开放协作 | 大型企业联盟、供应链、监管合规场景 |
| 实现复杂度 | 低 | 高 | 中 |
4. 应用场景
4.1 企业自动化流程
企业部署大量自动化智能体处理订单、客服、财务对账等任务。Agentic Identity 确保每个智能体只能访问其职责范围内的数据,且所有操作可审计。
4.2 跨组织数据协作
多个企业之间通过智能体交换数据时,需要验证对方智能体的身份和授权范围。例如,供应链上下游的智能体自动同步库存数据,必须确认"对方确实有权访问我的库存接口"。
4.3 智能合约与链上操作
在区块链场景中,智能体代表用户或组织执行链上交易。Agentic Identity 将链下授权与链上操作绑定,确保智能体的链上行为有明确的授权依据。
4.4 个人数字助理
个人 AI 助理需要代表用户处理邮件、预约、支付等事务。Agentic Identity 让助理能够"证明自己是经过用户授权的",同时用户可以随时撤销授权。
4.5 安全合规与监管
金融、医疗等强监管行业要求所有自动化操作可追溯。Agentic Identity 提供完整的操作凭证链,满足审计合规要求。
5. 实践操作
5.1 技术选型
| 组件 | 可选方案 |
|---|---|
| DID 方法 | did:key、did:web、did:ethr、did:ion |
| 凭证格式 | W3C VC、JWT-VC |
| 密钥管理 | HSM、云 KMS、安全飞地 |
| 信任网络 | 中心化 CA、去中心化信任图谱 |
| 存储 | 分布式账本、IPFS、关系型数据库 |
5.2 最小实现步骤
第一步:生成智能体身份
python
from cryptography.hazmat.primitives.asymmetric import rsa
from cryptography.hazmat.primitives import serialization
# 生成密钥对
private_key = rsa.generate_private_key(public_exponent=65537, key_size=2048)
public_key = private_key.public_key()
# 导出公钥
public_pem = public_key.public_bytes(
encoding=serialization.Encoding.PEM,
format=serialization.PublicFormat.SubjectPublicKeyInfo
)
print(public_pem.decode())
第二步:注册 DID
python
import hashlib
import base58
# 基于公钥生成 did:key
public_bytes = public_key.public_bytes(
encoding=serialization.Encoding.DER,
format=serialization.PublicFormat.SubjectPublicKeyInfo
)
multihash = hashlib.sha256(public_bytes).digest()
did_key = "did:key:z" + base58.b58encode(b"\x12\x20" + multihash).decode()
print(did_key)
第三步:签发授权凭证
python
import json
import time
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives.asymmetric import padding
vc = {
"id": "http://issuer.example/credentials/1001",
"type": ["VerifiableCredential", "AgentPermissionCredential"],
"issuer": "did:key:zIssuerPublicKey",
"issuanceDate": time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime()),
"credentialSubject": {
"id": did_key,
"permission": "read_inventory_api",
"scope": "supply_chain"
}
}
# 对凭证内容签名
payload = json.dumps(vc, sort_keys=True).encode()
signature = private_key.sign(
payload,
padding.PSS(mgf=padding.MGF1(hashes.SHA256()), salt_length=padding.PSS.MAX_LENGTH),
hashes.SHA256()
)
print("VC 签名完成:", signature.hex()[:32], "...")
第四步:智能体操作时携带身份凭证
python
import requests
# 智能体调用 API 时携带 DID 和签名
headers = {
"X-Agent-DID": did_key,
"X-Agent-Signature": signature.hex(),
"X-Agent-VC": json.dumps(vc)
}
response = requests.get("https://api.example.com/inventory", headers=headers)
print(response.status_code)
第五步:服务端验证身份
python
from cryptography.hazmat.primitives.asymmetric import rsa
from cryptography.exceptions import InvalidSignature
def verify_agent(public_key_pem, signature_hex, payload):
public_key = serialization.load_pem_public_key(public_key_pem)
try:
public_key.verify(
bytes.fromhex(signature_hex),
payload,
padding.PSS(mgf=padding.MGF1(hashes.SHA256()), salt_length=padding.PSS.MAX_LENGTH),
hashes.SHA256()
)
return True
except InvalidSignature:
return False
# 服务端验证签名
is_valid = verify_agent(public_pem, signature.hex(), payload)
print("身份验证结果:", is_valid)
5.3 常见挑战与应对
- 私钥泄露:使用 HSM 或安全飞地存储,定期轮换。
- 凭证滥用:设置凭证有效期和用途约束(scope)。
- 跨域信任:建立可信签发方列表,或使用去中心化信任图谱。
- 性能开销:对高频操作使用缓存验证结果,减少重复验签。
6. 未来展望
6.1 标准化与互操作
随着 W3C DID、VC 标准的成熟,以及更多 DID 方法的落地,Agentic Identity 有望形成跨平台、跨行业的统一标准,实现"一次签发、处处可用"。
6.2 与 AI 治理深度融合
Agentic Identity 将成为 AI 治理的重要基础设施。监管机构可以通过身份层追踪智能体的行为轨迹,实现"可解释、可审计、可追责"的 AI 治理目标。
6.3 自主身份与自我主权
未来的智能体可能拥有"自我主权身份"(Self-Sovereign Identity),即智能体自主管理自己的身份和凭证,无需依赖任何中心化机构,实现真正意义上的自主协作。
6.4 与 Web3 和去中心化生态融合
Agentic Identity 与区块链、DAO、去中心化应用天然契合。智能体可以作为 DAO 的"数字成员"参与投票、执行治理决策,其身份和权限由链上凭证保障。
6.5 安全挑战持续升级
随着智能体数量激增,身份伪造、凭证窃取、恶意智能体攻击等威胁也将升级。未来需要更强大的密钥管理、行为分析和异常检测能力,构建纵深防御体系。
6.6 攻击案例:供应链智能体身份伪造
攻击场景:攻击者截获了某供应链智能体在调用库存 API 时携带的 VC 凭证,并利用重放攻击(Replay Attack)在凭证有效期内冒充该智能体,向合作伙伴的库存接口发起越权查询,窃取敏感库存数据。
影响:被冒充的智能体所属企业面临数据泄露与商业机密外泄风险;合作伙伴因无法区分真实与伪造身份,可能向攻击者开放本应受限的接口,导致信任链被破坏,甚至引发连锁性的供应链数据污染。
防御措施:
- 绑定会话与随机数(Nonce):在凭证中绑定一次性随机数与时间戳,防止重放攻击。
- 双向认证(mTLS):在传输层建立双向 TLS,确保通信双方身份互验。
- 行为基线检测:对智能体的调用频率、访问路径建立行为基线,偏离基线即触发告警。
- 凭证短期化:缩短凭证有效期,并配合动态轮换,缩小攻击窗口。
下面给出一个在服务端校验随机数与时间戳、抵御重放攻击的代码示例:
python
import time
import hmac
import hashlib
# 服务端为每次会话签发的随机数(一次性使用)
ISSUED_NONCES = set()
def verify_agent_request(agent_did, signature, payload, nonce, timestamp, secret):
# 1. 校验时间戳,拒绝超过 60 秒的旧请求
if abs(time.time() - timestamp) > 60:
return False, "请求已过期"
# 2. 校验随机数是否已被使用(防重放)
if nonce in ISSUED_NONCES:
return False, "随机数已被使用,疑似重放攻击"
ISSUED_NONCES.add(nonce)
# 3. 校验签名是否由该智能体私钥生成
expected = hmac.new(secret.encode(), f"{agent_did}:{nonce}:{timestamp}".encode(), hashlib.sha256).hexdigest()
if not hmac.compare_digest(expected, signature):
return False, "签名校验失败"
return True, "身份验证通过"
通过上述措施,即使攻击者截获了凭证,也无法在缺少有效随机数与时间戳的情况下完成重放,从而有效阻断身份伪造攻击。
7. 总结
Agentic Identity 是智能体从"工具"走向"数字公民"的关键基础设施。它通过 DID、可验证凭证、密钥管理和行为审计等核心技术,为智能体赋予可识别、可验证、可授权的身份,支撑企业自动化、跨组织协作、链上操作和 AI 治理等广泛场景。虽然当前仍处于早期探索阶段,但随着标准成熟和生态完善,Agentic Identity 有望成为下一代 AI 基础设施的核心组件。