基于零信任架构的大模型智能体统一安全代理方法及系统

CN122160184BActive Publication Date: 2026-07-17ZHONGKE NANJING SOFTWARE TECH RES INST

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHONGKE NANJING SOFTWARE TECH RES INST
Filing Date
2026-05-07
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing large-scale intelligent agents suffer from weak trust anchors, insufficient detection granularity, limited protection levels, passive protection modes, and rigid permission control in MCP interactions, resulting in a lack of security protection and an inability to effectively resist attacks.

Method used

A security proxy method based on zero-trust architecture is adopted. By deploying MCP Server in a trusted execution environment, adversarial fuzzing is performed to generate risk profiles. Remote proof credentials are generated by signing with the TEE's built-in hardware private key. Natural language intent is parsed in real time to generate least privilege tokens. Dynamic behavior heterogeneous graphs are constructed for anomaly detection, and resources are completely released when the session ends.

Benefits of technology

It enhances the trust foundation of the MCP interaction link, proactively discovers unknown vulnerabilities, dynamically controls permissions, defends against man-in-the-middle attacks, and achieves a complete security loop from access to release, thereby reducing the attack surface.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122160184B_ABST
    Figure CN122160184B_ABST
Patent Text Reader

Abstract

本发明公开了一种基于零信任架构的大模型智能体统一安全代理方法及系统。方法包括:MCP Server在可信执行环境中完成可信接入注册与硬件级远程证明,并通过对抗性模糊测试生成风险画像;响应于用户会话请求,安全网关利用专用大语言模型解析自然语言意图,动态生成一次性限时令牌;在指令执行前提取语义骨架并生成语义指纹进行完整性校验;在会话周期内实时构建动态行为异构图,调用预训练图神经网络进行跨工具行为链路异常检测;同时全链路审计日志经加密存储并区块链锚定存证。本发明解决了现有MCP交互全链路的安全防护缺失问题,显著提升了大模型智能体系统的整体安全性。
Need to check novelty before this filing date? Find Prior Art