Writing agent authorization as a verifiable relation: a Groth16 prototype binds principal and plan in a 531-constraint circuit, leaving execution binding open
Synopsis
The authors propose the Cryptographically Verifiable Agent Authorization (CVA) hypothesis, formalizing authorization as a relation RCVA that jointly binds an agent principal, a concrete authorization request, an execution context, and policy satisfaction, and provide candidate security properties plus an executable zero-knowledge proof of concept over Groth16 zk-SNARK; the prototype implements principal binding and plan-level request binding while context binding and runtime execution binding remain unimplemented.
Interpretation
The paper characterizes agent authorization as a request-bound cryptographically verifiable relation RCVA, compactly BindPrincipal ∧ BindRequest ∧ BindContext ∧ SatisfyPolicy, where the public statement x carries the principal identifier, request commitment, context commitment, policy identifier, and freshness parameters, and the private witness w carries the agent secret, private authorization attributes, and commitment preimages. The authors stress that the contribution is not applying zero-knowledge proofs to agentic systems but isolating authorization itself from identity authentication, capability delegation, and post-hoc audit as an independent security relation. This is a hypothesis-and-theory paper offering formal definitions and equations; the authors state that complete security reductions, including explicit extractor and simulator arguments, remain future work.
The paper defines a compact set of candidate security properties: authorization soundness, principal binding, authorization-request binding, policy binding, context binding, and replay resistance, with informal reduction sketches bounding adversary advantage by Groth16 soundness plus hash-collision or commitment-binding advantage. These properties are explicitly labeled candidate definitions whose status as established guarantees depends on reduction arguments not yet completed, a caveat the authors repeat throughout. The sketches rest on Groth16 knowledge-soundness and the binding property of Pedersen-style commitments, but the authors note the sketches omit an explicit extractor or simulator construction.
The paper provides an executable zero-knowledge proof of concept: a Groth16 circuit over the bn128 curve written in Circom 2.x with snarkjs, with public statement xPoC = (idi, hplan, n, t) and private witness wPoC = (ski, ρi, attrsi, plan), principal binding via two-input Poseidon(ski, ρi), plan binding via SHA256(plan), policy satisfaction as arithmetic circuit constraints, and replay protection enforced outside the circuit by gateway nonce state. The prototype is the experimental precursor publicly presented at RootedCON Madrid, mapped here onto the CVA abstraction as constructive evidence of feasibility for principal and plan-level request binding. Single circuit configuration: 531 constraints, 537 wires, nine private inputs, five outputs; over n = 20 runs, witness generation 61.9 ± 1.1 ms, proof generation 351.9 ± 26.6 ms, verification 309.4 ± 22.6 ms, proof size 805 bytes, with timings measured via command-line invocation and therefore including Node.js process startup overhead.
The paper identifies the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem: a valid proof shows that a committed request satisfies the authorization relation but not that the runtime executed the same request, and closing the gap requires an execution-time trust anchor such as remote attestation, a trusted execution environment, or verifiable execution receipts. The authors state that to their knowledge current agentic security frameworks have not formalized this distinction within a cryptographically verifiable authorization relation, and they derive a falsifiable research agenda with questions on necessary bindings, representable policies, and operational viability. The separation is stated as equations and as a structural observation rather than a game-based property; the authors also note that multi-hop delegation chains would need an additional BindDelegationScope and recursive proof composition, deliberately left unformalized here.
Perspective
The work addresses researchers and designers of agent authorization mechanisms, applies to a single agent-gateway authorization interaction, and its prototype targets one circuit configuration on Groth16 over the bn128 curve, assuming a partially trusted gateway and unbreakable underlying cryptographic primitives. It offers a starting point for formalizing the candidate properties, implementing context commitments, comparing proof systems, and integrating execution-time trust anchors.
Readers should watch for when the candidate security properties receive complete reductions, how the context commitment hc will be constructed (fixed-length padding or a Poseidon sponge), and which execution-time evidence mechanism will be used for runtime execution binding. The authors also list limits including a policy language restricted to static arithmetic circuits, Groth16's trusted setup and lack of post-quantum security, a partially trusted gateway, no evaluation of multi-agent delegation chains, and a prototype using a single plan-level commitment rather than the model's decomposition into resource and action components. These are scope and open questions rather than faults.
