Agent authorization recast as a cryptographically verifiable relation R_CVA, with an executable Groth16 zk-SNARK proof of concept
Synopsis
The study hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, R_CVA, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy while selectively preserving the confidentiality of private authorization attributes; it introduces a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), defines a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, provides an executable zero-knowledge proof of concept instantiating selected elements of the model over a Groth16 zk-SNARK construction, and formalizes the structural separation among
Figure 1: Proof-of-concept authorization workflow, showing the offline setup phase and the runtime authorization flow. (0) A one-time setup ceremony produces the proving and verification key pair p p = ( p k , v k ) pp=(pk,vk) via Equation 5 ; p k pk is provided to the prover (Agent) and v k vk to the verifier (Gateway). (1) The Agent, acting as prover, holds the private witness (see Equation 49 ). (2) The Circuit (Groth16) evaluates the arithmetic constraints described in Subsection 5.2 over this witness. (3) The resulting public statement and proof ( x P o C , π ) (x_{PoC},\pi) are transmitted to the Gateway (see Equation 6 ). (4) The Gateway, acting as verifier, evaluates a stateless proof-verification check (see Equation 7 ) together with a stateful freshness check against its nonce store N N (see Equation 38 ); both must hold for acceptance (see Equation 26 ). (5) The Gateway issues an authorization decision, { P e r m i t , D e n y } \{Permit,Deny\} . Circuit execution occurs locally, on the prover’s side; the verifier never accesses the circuit itself, only the verification key v k vk .
arXivInterpretation
The paper formalizes agent authorization as a cryptographically verifiable relation, R_CVA, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. Existing authentication and authorization mechanisms establish identity and delegate authority, but as the authors state, they do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context; R_CVA writes that evidential requirement into the relation itself. This is the hypothesis and formal abstraction explicitly stated in the paper, a conceptual modeling contribution whose strength rests on the definition rather than on experimental measurement.
The paper defines a compact set of candidate security properties, including authorization soundness, principal binding, request binding, policy binding, and replay resistance. These properties are organized as a set of discussable, testable candidate goals for what the CVA relation should satisfy. The properties are offered as a candidate set and framed as targets to be examined rather than as proven results.
The paper provides an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. The proof of concept places selected elements of the abstract model onto a concrete proof system, giving part of the model a runnable form. The evidence comes from an executable proof-of-concept implementation covering selected elements of the model rather than all of them.
The paper formalizes the structural separation among identity binding, authorization-request binding, and runtime execution binding, positions it as a central open problem in the design of secure agentic systems, and presents a falsifiable research agenda. The authors state that, to their knowledge, this distinction has not been formalized within a cryptographically verifiable authorization relation by current agentic security frameworks. This is the authors' problem framing and research agenda based on their reading of the literature, an open question for later work to examine.
Perspective
The work addresses autonomous agents that execute actions, invoke tools, and operate on protected resources with limited human oversight, in authorization settings where cryptographic evidence of policy satisfaction for a concrete request is needed; what it offers subsequent research is a formal abstraction, a list of candidate security properties, a Groth16 zk-SNARK proof of concept covering selected elements, and a falsifiable research agenda for researchers to define, instantiate, and examine within the same relational framework.
The visible text is only the abstract and does not include the concrete content of the formal definitions, the formal statements of the candidate security properties, the implementation details of the proof of concept, or any experimental or quantitative results, so the extent to which those properties are covered in the implementation cannot be judged; the structural separation among identity binding, authorization-request binding, and runtime execution binding is listed by the authors as a central open problem, and the path to resolving it and the concrete ways of testing the falsifiable research agenda remain for later work.
