Method and system for agent invocation based on identity binding and semantic routing

CN122601392BActive Publication Date: 2026-09-11SHANGHAI QUANJING ZHIYU TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202611082051.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-07-21
Publication Date
2026-09-11
Estimated Expiration
2046-07-21

AI Technical Summary

Technical Problem

这导致请求往往被强制路由至可见范围内能力匹配程度有限的局部智能体,而调用方对联邦网络中全局范围内实际存在的、语义匹配度更高的优质智能体资源毫无察觉

Benefits of technology

[0034]This invention constructs a global retrieval channel without entity affiliation filtering and a local retrieval channel with filtering conditions. It performs parallel similarity calculations on the task intent vector using these two channels, simultaneously acquiring the upper bound of capability matching across the entire network and the local matching results within the visibility range of specific permissions. By utilizing the global and local optimal similarity scores, a capability gap value is calculated, transforming the invisible cross-domain capability differences into a quantifiable criterion. This overcomes the shortcomings of traditional routing mechanisms where rigid identity boundary filtering limits callers to local suboptimal solutions, achieving precise semantic routing and capability matching, and improving the matching accuracy and service quality of agent calls. Combining the capability gap value with the experience gap threshold parameter, the system triggers a flexible recommendation process to issue recommendation instructions when necessary, and dynamically issues restricted verifiable credentials after obtaining the caller's response. This mechanism, while maintaining existing entity identity binding and access control isolation rules, constructs a controllable, perceptible, and selectable flexible semantic guidance path across organizational isolation boundaries. This allows callers to autonomously decide, under controlled conditions, whether to perceive and invoke more suitable candidate intelligent agent resources outside the boundary, avoiding unauthorized invocations without their knowledge, improving call transparency and user control. While ensuring data isolation security in multi-entity environments, it also meets the global optimization needs in open networks. Restricted verifiable credentials employ a one-time, short-term, and least-authority constraint design, coupled with multi-level authentication verification, effectively preventing credential abuse, unauthorized access, and repeated invocations. Full-process audit logs record information such as the calling entity, the belonging entity, capability gaps, and credential lifecycle, meeting compliance audit and accountability requirements. This invention is highly versatile and can be widely applied to various multi-entity scenarios such as distributed intelligent agent networks, federated intelligent agent ecosystems, cross-organizational collaboration platforms, and open intelligent agent service markets, without relying on specific industries or business models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122601392B_ABST
    Figure CN122601392B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of distributed network architecture, and discloses an agent calling method and system based on identity binding and semantic routing, which is suitable for distributed / federal agent network and comprises the following steps: constructing a task intention vector, performing cosine similarity calculation in parallel in a global search channel and a local search channel respectively, obtaining global and local optimal similarity scores and corresponding agent identifiers; calculating an ability gap value according to the two scores and comparing it with a preset experience gap threshold parameter; triggering a flexible recommendation process to send a recommendation instruction to the caller when the condition is met, and dynamically issuing a restricted verifiable credential according to the response information of the caller; under the premise of maintaining identity binding, entity isolation and permission security, the present application constructs a controllable cross-border ability discovery channel, takes into account security isolation and global optimization, improves the matching accuracy of agents and the resource utilization rate, and is suitable for various multi-organizational open agent ecology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of distributed network architecture technology, and more specifically, to a method and system for invoking intelligent agents based on identity binding and semantic routing. Background Technology

[0002] With the rapid development of multi-agent technology and distributed networks, intelligent agents have been widely used in general distributed intelligent agent network scenarios such as cross-organizational collaboration, open service markets, federated computing, and industrial interconnection. How to achieve accurate discovery and efficient scheduling of intelligent agent capabilities while ensuring identity security, entity isolation, and controllable permissions has become the core issue in the field of intelligent agent invocation.

[0003] In the prior art, patent application CN121664547A discloses a method, system, device, and medium for identity and access management in multi-agent cross-domain interaction scenarios. This invention establishes a full-lifecycle identity for agents, issues bound short-term access authorizations when the entry agent performs tasks, and establishes an auditable delegation chain containing permission transfer relationships to continuously verify and monitor the agent's cross-domain access behavior, preventing long-term credential abuse, permission diffusion, and unauthorized access. Additionally, patent application CN121396496A discloses a cross-domain identity authentication system and method capable of supporting certificate entities and agents. This system uses an identity provision module to issue credentials, maintains cross-domain trust policies through an on-chain trust registration module, and verifies access requests and generates access tokens in conjunction with a managed authorization management module and a cross-domain authentication gateway. This solves the problems of fragmented cross-domain trust, inconsistent credential states, and unverifiable agent identities, achieving unified management and full-process auditing of cross-domain trust.

[0004] However, in real-world deployments of general-purpose distributed intelligent agent networks with multiple coexisting organizations, when a caller inputs a natural language task to invoke an intelligent agent, the routing platform uses the caller's entity affiliation as a hard filter due to the system's default visibility rules and entity ownership boundaries, directly cutting off access to resources outside the entity's or unauthorized visibility range. This often results in requests being forcibly routed to local intelligent agents with limited capability matching within their visibility range, while the caller remains unaware of the high-quality intelligent agent resources with higher semantic matching that actually exist globally within the federated network. This forced routing, limited by local visibility range, results in insufficient accuracy in parsing complex task intents by intelligent agents, service quality is limited by the upper bound of local capabilities, and the caller is unable to perceive the existence of better resources, remaining locked in a suboptimal local solution for a long time. This not only leads to decreased semantic matching accuracy and limited service scheduling effectiveness but also blocks cross-boundary resource sharing and value transfer within the open intelligent agent ecosystem due to identity boundaries, resulting in low overall resource utilization and limited ecosystem collaboration efficiency. In summary, existing technologies cannot provide callers with a perceptible, selectable, controllable, and auditable cross-boundary optimal intelligent agent calling channel while maintaining identity binding, entity isolation, and access security, making it difficult to adapt to the development needs of general distributed intelligent agent networks. Summary of the Invention

[0005] In the aforementioned general distributed agent network scenario, the phenomenon where the caller is limited to local agents within its visible range and cannot perceive better capabilities and resources outside the boundary stems from the fact that existing routing query mechanisms forcibly treat identity affiliation boundaries as absolute constraints at the database level. When the system processes call requests, it often places rigid filtering rules based on identity containers (such as the requirement for consistent organizational identifiers) before or concurrently with the calculation of vector similarity ranking. This processing logic directly shields the potential candidate set outside the boundary in the underlying retrieval channel, resulting in the calculated optimal matching result being only the optimal solution within a limited visible range, rather than the globally optimal solution. This identity-based isolation security requirement is inherently opposed to the pursuit of superior capabilities in an open network environment. Under this architecture, the caller not only loses the calling path to obtain the globally optimal matching agent but also loses the perception of the existence of a globally better solution, ultimately causing the caller to be unknowingly locked into a locally suboptimal solution for resource matching for an extended period.

[0006] This invention aims to overcome the aforementioned shortcomings of existing technologies and provide a method and system for invoking intelligent agents based on identity binding and semantic routing, applicable to distributed / federated intelligent agent networks. The core technical problem this invention addresses is how to balance identity isolation, access security, and global optimal capability optimization in a multi-entity, multi-boundary, and multi-organizational general intelligent agent network. Specifically, it seeks to establish a controllable, secure, and user-perceptible cross-boundary intelligent agent discovery channel without disrupting existing entity isolation, identity binding, and access control rules. This allows the caller to obtain and invoke the globally optimal matching intelligent agent within authorized limits, achieving a balance between secure isolation and capability optimization. This invention is applicable to federated intelligent agent network environments with multiple organizations and entities coexisting and uneven capability distribution among entities, including but not limited to scenarios such as cross-agency collaboration, open intelligent agent service markets, federated data platforms, industrial interconnection collaboration, and cross-organizational business collaboration. This invention executes global retrieval without entity affiliation filtering conditions and local retrieval with entity affiliation filtering conditions in parallel. It dynamically triggers a flexible recommendation process using the capability difference value calculated from both methods and dynamically issues restricted verifiable credentials after the caller responds with agreement to complete cross-boundary scheduling. While maintaining existing entity identity binding and access control isolation rules, this invention constructs a flexible, controllable, and auditable semantic routing path that crosses organizational isolation boundaries. This enables callers to perceive and use more suitable candidate intelligent agent resources outside the boundaries in a secure and controlled state. While ensuring data isolation security in multi-entity environments, it meets the global optimization needs in open networks and adapts to the large-scale collaboration needs of general distributed intelligent agent networks.

[0007] To achieve the above objectives, the present invention provides the following technical solution:

[0008] The agent invocation method based on identity binding and semantic routing includes:

[0009] The system receives a task request text, vectorizes it to obtain a task intent vector, and performs cosine similarity calculation on the task intent vector in both the global and local retrieval channels to obtain the global optimal similarity score and corresponding global candidate agent identifier, and the local optimal similarity score and corresponding local target agent identifier. The capability gap value is then calculated based on the global optimal similarity score and the local optimal similarity score. The global retrieval channel does not apply entity attribution identifier filtering conditions, while the local retrieval channel does.

[0010] The capability gap value is compared with the preset experience gap threshold parameter. Based on the comparison result, it is determined whether to trigger the flexible recommendation process. If the flexible recommendation process is triggered, a recommendation instruction is generated through the flexible recommendation process and sent to the caller. The response information returned by the caller to the recommendation instruction is received, and a restricted verifiable credential is dynamically issued based on the response information.

[0011] The vectorization processing method includes:

[0012] A pre-trained bidirectional sequence semantic coding model is used to vectorize the task request text, and the hidden state vector corresponding to the classification label position in the output layer of the bidirectional sequence semantic coding model is taken as the task intent vector.

[0013] The method for performing cosine similarity calculation on the task intent vector in the global retrieval channel includes:

[0014] Obtain the full agent capability vector index, which contains the mapping relationship between the agent identifier and the agent capability vector of all registered agents, the entity ownership identifier to which the agent is bound, and the access endpoint address.

[0015] The task intent vector is compared with the cosine similarity of each agent's capability vector in the full agent capability vector index to obtain a global similarity score sequence. The global similarity score sequence is sorted in descending order, and the similarity score at the top of the sequence is taken as the global optimal similarity score. The agent identifier corresponding to the global optimal similarity score is recorded as the global candidate agent identifier.

[0016] The entity ownership identifier filtering condition is constructed using the entity ownership identifier of the caller;

[0017] The method for performing cosine similarity calculation on the task intent vector in a local retrieval channel includes:

[0018] The entity attribution identifier filtering condition is applied to the full agent capability vector index to filter out a subset of agent capability vectors within the visible range. The cosine similarity between the task intent vector and each agent capability vector in the subset of agent capability vectors within the visible range is calculated to obtain a local similarity score sequence. The local similarity score sequence is sorted in descending order, and the similarity score at the top of the sort is taken as the local optimal similarity score. The agent identifier corresponding to the local optimal similarity score is recorded as the local target agent identifier.

[0019] The capability gap value is obtained by subtracting the local optimal similarity score from the global optimal similarity score. When the local similarity score sequence is an empty set, the local optimal similarity score is set to zero.

[0020] The method for determining whether the flexible recommendation process has been triggered includes:

[0021] The system determines whether the capability gap value is greater than a preset experience gap threshold parameter. If the capability gap value is less than or equal to the experience gap threshold parameter, the local target agent identifier is used as the final routing target. If the capability gap value is greater than the experience gap threshold parameter, the system further determines whether the global candidate agent identifier exists in the agent blacklist and whether the global candidate agent identifier exists within the effective cooling period of the caller's corresponding recommendation cooling list. If it exists in the agent blacklist or exists within the effective cooling period of the recommendation cooling list, the local target agent identifier is used as the final routing target. The flexible recommendation process is activated only when the capability gap value is greater than the experience gap threshold parameter and the global candidate agent identifier does not exist in the agent blacklist and does not exist within the effective cooling period of the caller's corresponding recommendation cooling list.

[0022] The execution method of the flexible recommendation process includes:

[0023] The routing and forwarding operation to the access endpoint address corresponding to the local target intelligent agent identifier is suspended. The capability description document corresponding to the global candidate intelligent agent identifier is read. The capability description document is de-identified to obtain the de-identified capability description. The de-identified capability description is combined with the capability gap value to generate a recommendation instruction and send the recommendation instruction to the caller.

[0024] The response information can be either a rejection of recommendation or an agreement to recommendation; when the response information is an agreement to recommendation, a dynamic issuance process for restricted verifiable credentials is executed.

[0025] The dynamic issuance process of the restricted verifiable credential includes:

[0026] The decentralized identifier of the caller is obtained as the credential subject identifier. The entity to which the global candidate intelligent agent identifier belongs is obtained as the credential authorization scope. The global candidate intelligent agent identifier is obtained as the credential target intelligent agent identifier. The valid call count of the credential is set to one. The valid time window of the credential is set to a preset single authorization duration. The current time when the credential is issued is obtained as the issuance time. The credential subject identifier, credential authorization scope, credential target intelligent agent identifier, valid call count, valid time window and issuance time are combined into the credential payload. The credential payload is digitally signed to generate a restricted verifiable credential.

[0027] The method further includes:

[0028] The restricted verifiable credential is appended to the message header of the call request, the access endpoint address corresponding to the global candidate agent identifier is obtained, the call request carrying the restricted verifiable credential is routed to the access endpoint address, the authentication node where the global candidate agent is located performs five verifications on the restricted verifiable credential, and after all five verifications are passed, the global candidate agent executes the task and returns the execution result.

[0029] The five verifications include signature validity verification, credential subject identification verification, credential authorization scope and target agent identification verification, valid call count verification, and valid time window verification.

[0030] An agent invocation system based on identity binding and semantic routing is provided to implement the aforementioned agent invocation method based on identity binding and semantic routing. The system includes:

[0031] The gap quantification module receives the task request text, vectorizes it to obtain a task intent vector, and performs cosine similarity calculation on the task intent vector in both the global and local retrieval channels to obtain the global optimal similarity score and corresponding global candidate agent identifier, and the local optimal similarity score and corresponding local target agent identifier. The capability gap value is calculated based on the global optimal similarity score and the local optimal similarity score. The global retrieval channel does not apply entity attribution identifier filtering conditions, while the local retrieval channel does.

[0032] The credential issuance module compares the capability gap value with a preset experience gap threshold parameter. Based on the comparison result, it determines whether to trigger the flexible recommendation process. If the flexible recommendation process is triggered, it generates a recommendation instruction through the flexible recommendation process and sends the recommendation instruction to the caller. It also receives the response information returned by the caller to the recommendation instruction and dynamically issues restricted verifiable credentials based on the response information.

[0033] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0034] This invention constructs a global retrieval channel without entity affiliation filtering and a local retrieval channel with filtering conditions. It performs parallel similarity calculations on the task intent vector using these two channels, simultaneously acquiring the upper bound of capability matching across the entire network and the local matching results within the visibility range of specific permissions. By utilizing the global and local optimal similarity scores, a capability gap value is calculated, transforming the invisible cross-domain capability differences into a quantifiable criterion. This overcomes the shortcomings of traditional routing mechanisms where rigid identity boundary filtering limits callers to local suboptimal solutions, achieving precise semantic routing and capability matching, and improving the matching accuracy and service quality of agent calls. Combining the capability gap value with the experience gap threshold parameter, the system triggers a flexible recommendation process to issue recommendation instructions when necessary, and dynamically issues restricted verifiable credentials after obtaining the caller's response. This mechanism, while maintaining existing entity identity binding and access control isolation rules, constructs a controllable, perceptible, and selectable flexible semantic guidance path across organizational isolation boundaries. This allows callers to autonomously decide, under controlled conditions, whether to perceive and invoke more suitable candidate intelligent agent resources outside the boundary, avoiding unauthorized invocations without their knowledge, improving call transparency and user control. While ensuring data isolation security in multi-entity environments, it also meets the global optimization needs in open networks. Restricted verifiable credentials employ a one-time, short-term, and least-authority constraint design, coupled with multi-level authentication verification, effectively preventing credential abuse, unauthorized access, and repeated invocations. Full-process audit logs record information such as the calling entity, the belonging entity, capability gaps, and credential lifecycle, meeting compliance audit and accountability requirements. This invention is highly versatile and can be widely applied to various multi-entity scenarios such as distributed intelligent agent networks, federated intelligent agent ecosystems, cross-organizational collaboration platforms, and open intelligent agent service markets, without relying on specific industries or business models. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 This is a flowchart of the method invocation of the intelligent agent based on identity binding and semantic routing in this invention;

[0037] Figure 2 This is a flowchart of the task intent vector retrieval and capability gap value calculation in this invention;

[0038] Figure 3 This is a schematic diagram illustrating the output of the task intent vector by the bidirectional sequence semantic coding model in this invention.

[0039] Figure 4 This is a schematic diagram comparing the retrieval range of the global retrieval channel and the local retrieval channel in this invention;

[0040] Figure 5 This is a schematic diagram of the restricted verifiable credential structure in this invention;

[0041] Figure 6 This is a schematic diagram of the five verification operations of the authentication node in this invention;

[0042] Figure 7 This is a functional block diagram of the intelligent agent invocation system based on identity binding and semantic routing in this invention. Detailed Implementation

[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0044] Example 1:

[0045] Please see Figure 1 As shown, this embodiment provides an agent invocation method based on identity binding and semantic routing, including:

[0046] Step S10: Receive the task request text, vectorize the task request text to obtain the task intent vector, and perform cosine similarity calculation on the task intent vector in both the global retrieval channel and the local retrieval channel to obtain the global optimal similarity score and the corresponding global candidate agent identifier, and the local optimal similarity score and the corresponding local target agent identifier. Calculate the capability gap value based on the global optimal similarity score and the local optimal similarity score. The global retrieval channel does not apply entity attribution identifier filtering conditions, while the local retrieval channel applies entity attribution identifier filtering conditions.

[0047] Further, step S10 includes:

[0048] Step S11, see Figure 2 It receives the task request text in natural language form submitted by the caller, uses a pre-trained bidirectional sequence semantic coding model to vectorize the task request text, and takes the hidden state vector corresponding to the classification label position in the output layer of the bidirectional sequence semantic coding model as the task intent vector.

[0049] Specifically, the task request text submitted by the caller is unstructured natural language text. This text may contain multi-dimensional semantic information such as task objective descriptions, execution constraints, and expected output formats. This semantic information is interwoven unstructured within continuous text paragraphs. Vectorization is the process of mapping discrete natural language word sequences into dense vector representations of fixed dimensions in a continuous numerical space. The task intent vector obtained through vectorization encodes the semantic features of the task request text in the numerical space, resulting in semantically similar task requests having a smaller geometric distance in the vector space, while task requests with significantly different semantics have a larger geometric distance. See also... Figure 3 This is a schematic diagram of the task intent vector output by the bidirectional sequence semantic coding model provided in this application embodiment. Figure 3 The diagram illustrates how the task request text is split into an input sequence of category markers, word 1, word 2, word 3... word N. After multi-layer self-attention computation (bidirectional context fusion), the hidden state vectors corresponding to each position are output. Finally, the hidden state vector corresponding to the category marker position is taken as the task intent vector. The bidirectional sequence semantic coding model is a pre-trained language representation model employing a multi-layer self-attention mechanism. During the pre-training phase, the bidirectional sequence semantic coding model learns general semantic representation capabilities on a large-scale text corpus through masked language modeling and next-sentence prediction tasks. The masked language modeling task trains the model to capture the dependencies between words by randomly masking some words in the input sequence and requiring the model to predict the masked words based on the context. When processing the input text, the bidirectional sequence semantic coding model inserts a special category marker at the beginning of the input sequence. This category marker does not correspond to any actual word; its role is to aggregate the global semantic information of the entire input sequence after multi-layer self-attention computation.

[0050] like Figure 3 As shown, each layer of the bidirectional sequence semantic coding model performs self-attention computation on the representation vectors of all positions in the input sequence, including the classification label, word 1, word 2, word 3... word N. This self-attention computation allows the representation vector at each position to simultaneously focus on all positions before and after it in the sequence, thus fusing bidirectional contextual information in the output of each layer. This differs from unidirectional language models, which can only focus on information from the preceding positions in the sequence. Figure 3After the multi-layer self-attention computation shown, the hidden state vector corresponding to the classification label position in the output layer of the bidirectional sequence semantic coding model has fully integrated the semantic information of all word positions (word 1, word 2, word 3... word N) in the input sequence. The hidden state vector corresponding to the classification label position is taken as the task intent vector, and the dimension of the task intent vector is the hidden state dimension of the output layer of the bidirectional sequence semantic coding model. The hidden state vector of the classification label position of the bidirectional sequence semantic coding model is used as the task intent vector, instead of the average value of word-level vectors or the end position vector, because the hidden state vector of the classification label position has aggregated the contextual dependencies of the entire sequence after multi-layer self-attention computation, which can more completely represent the overall semantic intent expressed by the task request text. This avoids the dilution of key semantic signals after the average pooling operation arithmetically averages the vectors of different semantic components, and also avoids the end position vector from focusing on representing the local semantics of the last word due to the influence of position bias. Step S11 converts the unstructured natural language task request text into a dense vector representation of fixed dimensions. This allows the task intent vector in subsequent steps S12 and S13 to be semantically matched with the agent's ability vector in the same numerical space using cosine similarity calculation. Without the vectorization process in step S11, the task request text would exist as a discrete word sequence, making it impossible to perform cosine similarity calculation with the agent's ability vector. This would render the retrieval processes in steps S12 and S13 computationally unfeasible. The quality of the task intent vector representation fundamentally determines whether the global optimal similarity score in step S12 and the local optimal similarity score in step S13 accurately reflect the true semantic matching degree between the task requirements and the agent's capabilities. This, in turn, determines whether the capability gap value in step S14 truly reflects the capability difference within and outside the visible range, ultimately affecting whether the flexible recommendation process in step S20 can be triggered at the appropriate time.

[0051] Step S12, see below. Figure 2 The system retrieves the full agent capability vector index, which contains the mapping relationship between the agent identifiers and capability vectors of all registered agents, the entity affiliation identifiers bound to the agents, and the access endpoint addresses. It then calculates the cosine similarity between the task intent vector and each agent capability vector in the full agent capability vector index to obtain a global similarity score sequence. The global similarity score sequence is then sorted in descending order, and the first similarity score is taken as the global optimal similarity score. The agent identifier corresponding to the global optimal similarity score is recorded as the global candidate agent identifier.

[0052] In step S12, the full agent capability vector index is a data structure pre-constructed during the agent registration phase. The full agent capability vector index stores the mapping relationship between the agent identifiers of all registered agents and the agent capability vectors, the entity affiliation identifiers bound to the agent, and the access endpoint addresses in key-value pairs. The agent identifier is a unique identifier assigned to each agent during registration. The entity affiliation identifier bound to the agent is the registration identifier of the organization to which the agent belongs in the agent network system. The access endpoint address is the network communication address registered by the agent in the agent network system. The agent identifier adopts the form of a decentralized identifier, which is a globally unique identifier that does not depend on a centralized registration authority. The decentralized identifier of the agent is bound to the agent's public key, so that the agent identifier can be cryptographically verified and associated with the agent's identity. The agent capability vector is a dense vector representation obtained during agent registration after vectorizing the agent's capability description document using the same bidirectional sequence semantic coding model as in step S11. The agent capability vector and the task intent vector reside in the same vector space and have the same dimension, making their cosine similarity calculations geometrically comparable. Using the same bidirectional sequence semantic coding model to vectorize both the task request text and the capability description document ensures that the task intent vector and the agent capability vector are encoded in the same semantic space, eliminating similarity calculation biases caused by inconsistent encoding spaces. This allows the cosine similarity score to faithfully reflect the semantic matching degree between the two texts. Cosine similarity calculations are performed sequentially on the task intent vector and each agent capability vector in the full agent capability vector index. Each cosine similarity calculation generates a similarity score, and all similarity scores are arranged in the order of calculation to form a global similarity score sequence. The global similarity score sequence is sorted in descending order of score value. The similarity score at the top of the sorted sequence is the highest score in the global similarity score sequence. This top-ranked similarity score is taken as the global optimal similarity score, and the agent identifier corresponding to the global optimal similarity score is recorded as the global candidate agent identifier. The global optimal similarity score represents the upper bound of the matching degree corresponding to the agent capability vector that is semantically closest to the task intent vector across the entire network without any entity attribution label filtering conditions. The global candidate agent identifier points to the agent with the capability that best matches the semantics of the task request text. The global retrieval channel does not apply entity attribution label filtering conditions, allowing the global optimal similarity score to reflect the upper limit of the actual capability supply in the entire network, providing a benchmark for calculating the capability gap value in subsequent step S14.If only a local retrieval channel exists and a global retrieval channel is lacking, the caller cannot know whether there are agents with higher capabilities outside the visible range. The calculation of the capability gap value in step S14 will be impossible due to the lack of a globally optimal similarity score. The flexible recommendation process in step S20 will lose its triggering basis, and the system will degenerate into a closed retrieval mode that only performs retrieval within the visible range. The capability discovery path across entity ownership boundaries will be completely blocked. The global candidate agent identifier will also be used in the flexible recommendation process of step S20 to read the corresponding capability description document and send recommendation instructions to the caller, as well as serve as the target endpoint for cross-boundary routing after the caller agrees to the recommendation. Therefore, the global candidate agent identifier undertakes the information transmission function from step S10 to step S20.

[0053] Step S13: Obtain the entity ownership identifier of the caller and construct the entity ownership identifier filtering condition; apply the entity ownership identifier filtering condition to the full intelligent agent capability vector index to filter out the subset of intelligent agent capability vectors within the visible range; calculate the cosine similarity between the task intent vector and each intelligent agent capability vector in the subset of intelligent agent capability vectors within the visible range to obtain a local similarity score sequence; sort the local similarity score sequence in descending order, take the similarity score at the top of the sort as the local optimal similarity score, and record the intelligent agent identifier corresponding to the local optimal similarity score as the local target intelligent agent identifier;

[0054] In step S13, the entity affiliation identifier is the registration identifier of the organization to which the caller belongs in the agent network system. The entity affiliation identifier is used to define the organizational affiliation boundary of the caller. Different organizational entities have their own independent entity affiliation identifiers in the agent network system. After obtaining the entity affiliation identifier of the caller, an entity affiliation identifier filtering condition is constructed based on the entity affiliation identifier. The construction logic of the entity affiliation identifier filtering condition is as follows: from the full agent capability vector index, agent capability vectors that meet the following conditions are selected: the entity affiliation identifier bound to the agent is the same as the entity affiliation identifier of the caller, or the entity affiliation identifier bound to the agent is an agent capability vector in the authorized visibility list of the caller's entity affiliation identifier. The filtering results constitute a subset of agent capability vectors within the visibility range. The authorized visibility list is a set of identifiers agreed upon by both parties and written into the system configuration when establishing a trust relationship between entities. The agent capability vectors corresponding to the entity affiliation identifiers in the authorized visibility list are visible to the caller, but the caller and the agent are not required to belong to the same entity. The process of applying entity affiliation identifier filtering to the full agent capability vector index essentially involves performing row-level filtering on the full agent capability vector index based on the caller's organizational affiliation boundary. The subset of agent capability vectors retained after filtering only contains capability vectors corresponding to agents that the caller can directly invoke within the current permission scope. Cosine similarity is calculated for each agent capability vector in the visible subset of agent capability vectors, with each cosine similarity calculation generating a similarity score. All similarity scores are arranged in the order of calculation to form a local similarity score sequence. The local similarity score sequence is sorted in descending order of score value, and the first similarity score is taken as the local optimal similarity score. The agent identifier corresponding to the local optimal similarity score is recorded as the local target agent identifier. The agent pointed to by the local target agent identifier is the agent with the highest semantic matching degree with the task request text within the visible scope defined by the current entity affiliation identifier. In a normal scenario without triggering the flexible recommendation process, the local target agent identifier will be directly used as the final routing target in the routing and forwarding operation in step S20. By applying entity affiliation identifier filtering conditions to construct local retrieval channels, the local optimal similarity score and local target agent identifier are always within the caller's permission boundaries. This ensures that under the default routing path, the call request will not be forwarded to an agent that the caller does not have permission to access, thus maintaining the access control boundary in a multi-entity coexistence environment.Without the local retrieval channel constructed in step S13, the default route in step S20 will lack a target endpoint constrained by the entity ownership identifier. The call request may be directly routed to the agent pointed to by the global candidate agent identifier, which may belong to an entity that the caller has no right to access, resulting in unauthorized cross-boundary calls. The restricted verifiable credential verification performed by the authentication node in step S24 will reject the request due to the lack of a valid credential. The dynamic issuance process of the restricted verifiable credential in step S20 will also fail to start under controlled conditions due to the lack of a pre-judgment of the flexible recommendation process. The local retrieval channel and the global retrieval channel in step S12 jointly perform parallel retrieval on the same task intent vector. The retrieval objects of both retrieval channels are derived from the full agent capability vector index. The only difference is whether or not entity ownership identifier filtering conditions are applied. This differentiated filtering strategy makes the local optimal similarity scores and the global optimal similarity scores produced by the two retrieval channels form a set of comparable numerical pairs. The output results of the two retrieval channels will be used together in step S14 to calculate the capability gap value.

[0055] For example, see Figure 4 Assume that the full agent capability vector index contains several agents belonging to entities A, B, and C respectively. The global search channel range is entity A + entity B + entity C, and the local search channel range is entity A + entity B. Entity C is in an invisible state. The caller's entity affiliation identifier is entity A, and entity A's authorized visibility list includes entity B but not entity C. Table 1 compares the two search channels in terms of filtering conditions, search scope, and output results.

[0056] Table 1. Comparison of the two search channels in terms of filtering conditions, search scope, and output results.

[0057]

[0058] If the global candidate agent identifier corresponding to the global optimal similarity score happens to belong to Figure 4 If entity C is not visible in the table, there will be a difference between the global optimal similarity score and the local optimal similarity score. The capability gap value calculated in step S14 will reflect the leading margin of the intelligent agent under entity C in the task matching dimension.

[0059] Step S14: Subtract the local optimal similarity score from the global optimal similarity score to obtain the capability gap value. When the local similarity score sequence is an empty set, the local optimal similarity score is set to zero.

[0060] In step S14, the difference between the global optimal similarity score and the local optimal similarity score is the capability gap value. Since the retrieval scope of the global retrieval channel is a superset of the retrieval scope of the local retrieval channel, the global optimal similarity score is numerically greater than or equal to the local optimal similarity score, therefore the capability gap value is a non-negative value. When the capability gap value is zero, it indicates that the caller has been able to obtain the agent with the highest capability matching degree in the entire network within the visible range. The limitation of the visible range has not caused a loss in the capability supply level. At this time, the local target agent identifier and the global candidate agent identifier may point to the same agent or different agents, but the cosine similarity scores of the two agents with the task intent vector are equal. When the capability gap value is greater than zero, it indicates that there is an agent outside the visible range with a higher degree of semantic matching with the task request text. The larger the capability gap value, the greater the lead of the agent outside the visible range in the semantic matching dimension, and the greater the gap between the service quality obtained by the caller within the visible range and the service quality that may be obtained in the entire network. When the local similarity score sequence is empty, it indicates that the caller does not have any registered agents within the visible range defined by the current entity attribution identifier. In this case, the local optimal similarity score is set to zero, and the capability gap value is equal to the value of the global optimal similarity score itself. Setting the local optimal similarity score to zero when the local similarity score sequence is empty, instead of keeping it undefined, is to ensure that the capability gap value is a non-negative real number with a definite value under any circumstances. This ensures that the comparison operation between the capability gap value and the experience gap threshold parameter in step S20 will not be interrupted due to the input data being undefined. When the local similarity score sequence is empty, the capability gap value is equal to the value of the global optimal similarity score itself. At this time, as long as there is at least one agent in the entire network with a positive similarity score to the task intent vector, the capability gap value will be greater than the experience gap threshold parameter, triggering the flexible recommendation process. This processing logic ensures that even in extreme scenarios where there are no usable agents within the visible range, the flexible recommendation process in step S20 can still be activated, providing the caller with a path to obtain the required capabilities across boundaries. The capability gap value is an intermediate quantitative indicator connecting the retrieval results of step S10 and the routing decision of step S20. In step S20, the capability gap value is compared with a preset experience gap threshold parameter. When the capability gap value is greater than the experience gap threshold parameter, the flexible recommendation process is triggered. When the capability gap value is less than or equal to the experience gap threshold parameter, the default route to the local target agent is maintained.The method for determining the experience gap threshold parameter is as follows: During the trial operation phase of the agent network system, at least two weeks and at least one thousand effective calls are collected to gather caller satisfaction feedback data. The lower limit of the collection period is set at two weeks to cover the differences in task distribution between working days and non-working days, and the lower limit of the number of effective calls is set at one thousand to ensure that there is a sufficient sample size within each capability gap value range to generate a statistically reliable distribution trend. The satisfaction feedback data is collected as follows: After the caller receives the execution result returned by the local target agent, a satisfaction evaluation request is pushed to the caller. The caller provides feedback by selecting a preset rating level. The rating level uses an integer score from one to five, where one point indicates that the execution result does not meet the task requirements at all, and five points indicate that the execution result fully meets the task requirements. The satisfaction feedback data was grouped and statistically analyzed according to the corresponding capability gap values. The grouping method was to divide the range of capability gap values ​​into several intervals with a step size of 0.05, and the width of each interval was 0.05. Since the range of cosine similarity is -1 to 1, the capability gap value, as the difference between two cosine similarity scores, theoretically ranges from 0 to 2. However, in practical applications, the cosine similarity between the agent's capability vector and the task intent vector is usually positive. The actual distribution range of capability gap values ​​is usually concentrated between 0 and 0.5. Therefore, grouping intervals covering the range of 0 to 0.5 can meet the statistical needs of most scenarios. The arithmetic mean of all satisfaction scores within each interval is calculated as the average satisfaction score for that interval. The distribution trend of the average satisfaction score within intervals with different capability gap values ​​is observed to determine the capability gap value corresponding to the point where the average satisfaction score shows a significant downward inflection point. The criterion for determining the significant downward inflection point is as follows: observe the change in the average satisfaction score of adjacent intervals sequentially along the direction from the smallest to the largest capability gap value. When the decrease in the average satisfaction score of a certain interval relative to the previous interval first exceeds twice the average decrease of the preceding intervals, the initial capability gap value of that interval is taken as the downward inflection point. The meaning of this criterion is that when the rate of satisfaction decline accelerates significantly, it indicates that the caller's perception of insufficient capability matching has moved from a non-sensitive area to a sensitive area. The capability gap value at the satisfaction decline inflection point is used as a reference value for the experience gap threshold parameter. The specific value of the experience gap threshold parameter is determined by the system operator based on operating data and business needs and set in the system configuration. For example, the experience gap threshold parameter can be set to 0.15, which means that when the difference between the global optimal similarity score and the local optimal similarity score is greater than 0.15, the gap between the capability matching level obtained by the caller within the visible range and the capability matching level obtainable across the entire network has reached a perceptible level, triggering the flexible recommendation process.If the capability gap value calculation in step S14 is missing, the global optimal similarity score produced in step S12 and the local optimal similarity score produced in step S13 will exist as two isolated values. The routing decision in step S20 will lack quantitative basis for determining whether it is necessary to cross the entity ownership boundary, and the triggering condition of the flexible recommendation process will not be expressed in a computable way.

[0061] Step S10 converts the task request text from natural language into a task intent vector that can participate in numerical calculations. It then performs cosine similarity calculations in both the global and local retrieval channels, simultaneously obtaining the upper bound of capability matching across the entire network and the capability matching results within the visible range. Based on this, the calculated capability gap value quantifies the difference between the results of the two retrieval channels into a single numerical indicator. Step S10 provides three inputs for the routing decision in step S20: the capability gap value determines whether to trigger the flexible recommendation process; the global candidate agent identifier is used to identify the recommended object and cross-boundary routing target in the flexible recommendation process; and the local target agent identifier is used to determine the default routing target in non-recommendation scenarios and as the endpoint for suspending routing operations in the flexible recommendation process. The dual-channel parallel retrieval structure allows step S10 to simultaneously perceive the capability distribution differences within and outside the visible range during a single retrieval. This perception capability is a prerequisite for initiating the flexible recommendation process in step S20. If only a local retrieval channel is used for single-channel retrieval, the caller will always be routed to the local target agent within the visible range. Even if there are other agents in the entire network with a much higher degree of capability matching than the local target agent, the caller will not know of this difference. The flexible recommendation process in step S20 will not be able to start due to the lack of triggering basis, and the dynamic issuance process of restricted verifiable credentials in step S23 will never be executed because the recommendation process is not activated. The capability sharing path across entity ownership boundaries will be completely blocked. If only a global retrieval channel is used for single-channel retrieval without building a local retrieval channel, the retrieval results will not distinguish entity ownership boundaries, and the call request may be directly routed to an agent that the caller does not have the right to access, thus destroying the access control boundary in a multi-entity coexistence environment. Step S10 transforms the qualitative judgment of "whether there is a perceptible gap between the capability level within the visible range and the capability level of the entire network" into a numerical comparison problem through dual-channel parallel retrieval and quantitative calculation of the capability gap value. This allows the routing decision in step S20 to switch between the default route and flexible recommendation based on the numerical relationship between the capability gap value and the experience gap threshold parameter. While maintaining entity ownership boundary access control, this provides a quantifiable and adjustable pre-judgment basis for the subsequent flexible recommendation process and the dynamic issuance of restricted verifiable credentials. In an agent network environment where multiple entities coexist and there is an uneven distribution of capabilities among them, step S10, without violating entity ownership boundary access control, enables the caller to promptly perceive more suitable capability resources outside the visible range and provides a quantifiable judgment basis for subsequent cross-boundary capability sharing decisions.

[0062] Step S20: Compare the capability gap value with the preset experience gap threshold parameter. Determine whether to trigger the flexible recommendation process based on the comparison result. If the flexible recommendation process is triggered, suspend the routing forwarding operation to the access endpoint address corresponding to the local target intelligent agent identifier, read the capability description document corresponding to the global candidate intelligent agent identifier, perform desensitization processing on the capability description document, send the recommendation instruction to the caller, receive the response information returned by the caller to the recommendation instruction, and dynamically issue a restricted verifiable credential based on the response information.

[0063] Further, step S20 includes:

[0064] Step S21, see below. Figure 2 The system determines whether the capability gap value is greater than the preset experience gap threshold parameter. If the capability gap value is less than or equal to the experience gap threshold parameter, the local target agent identifier is used as the final routing target. If the capability gap value is greater than the experience gap threshold parameter, the system further determines whether the global candidate agent identifier exists in the agent blacklist and whether the global candidate agent identifier exists within the effective cooling period of the caller's corresponding recommendation cooling list. If it exists in the blacklist or exists within the effective cooling period of the recommendation cooling list, the local target agent identifier is used as the final routing target. The flexible recommendation process is activated only when the capability gap value is greater than the experience gap threshold parameter and the global candidate agent identifier does not exist in the agent blacklist and does not exist within the effective cooling period of the caller's corresponding recommendation cooling list.

[0065] In step S21, the capability gap value quantifies the difference between the capability matching level that the caller can obtain within the visible range defined by the entity's attribution identifier and the capability matching level that exists across the entire network. The capability gap value is compared numerically with the experience gap threshold parameter. When the capability gap value is less than or equal to the experience gap threshold parameter, it indicates that the difference between the capability matching level obtained by the caller within the visible range and the capability matching level that can be obtained across the entire network has not yet reached the level requiring a cross-boundary call recommendation. In this case, the local target agent identifier is directly used as the final routing target, and the call request is forwarded to the access endpoint address corresponding to the local target agent identifier according to the default routing path. When the capability gap value is greater than the experience gap threshold parameter, it indicates that there is an agent outside the visible range with a significantly higher semantic matching degree to the task request text than the local target agent. In this case, it is necessary to further determine whether the global candidate agent identifier exists in the agent blacklist. The agent blacklist is a set of agent identifiers maintained by the system. It records agent identifiers that are prohibited from being recommended due to security incidents, compliance requirements, or substandard service quality. The agent blacklist is maintained and updated by the system operator based on security audit results and compliance policies. The process of determining whether a global candidate agent identifier exists in the agent blacklist is as follows: The agent blacklist maintained in the system configuration is read, and each global candidate agent identifier is compared with each agent identifier in the blacklist. If a global candidate agent identifier matches any agent identifier in the blacklist, it is determined that the global candidate agent identifier exists in the blacklist, and the local target agent identifier is used as the final routing target, abandoning the recommendation of the global candidate agent. After completing the agent blacklist check, it is further determined whether the global candidate agent identifier is within the effective cooldown period of the caller's corresponding recommendation cooldown list. The recommended cooling-off list is a set of agent identifiers with timestamps maintained by the system. The recommended cooling-off list uses the combination of the caller's decentralized identifier and the global candidate agent identifier as the record key. Each record in the recommended cooling-off list contains the global candidate agent identifier and the write timestamp.The process of determining whether the global candidate agent identifier exists within the valid cooldown period of the caller's corresponding recommendation cooldown list is as follows: The caller's decentralized identifier and the current global candidate agent identifier are used as the search key to query the recommendation cooldown list. If a matching record is found, the write timestamp of the record is obtained, and the time difference between the current time and the write timestamp is calculated. If the time difference is less than the preset cooldown period, the global candidate agent identifier is determined to be within the valid cooldown period, and the local target agent identifier is used as the final routing target, abandoning the recommendation of the global candidate agent. If the time difference is greater than or equal to the cooldown period, the cooldown record is determined to have expired, and the expired record is deleted from the recommendation cooldown list without affecting the activation judgment of the flexible recommendation process. If no matching record is found, the global candidate agent identifier is determined not to be within the cooldown period. The write operation of the record in the recommendation cooldown list is executed in step S23 when the caller rejects the recommendation. The method for determining the cooldown period is explained in detail in step S23.

[0066] The flexible recommendation process is activated only when the capability gap value exceeds the experience gap threshold parameter, and the global candidate agent identifier is not in the agent blacklist and is not within the effective cooldown period of the caller's corresponding recommendation cooldown list. The flexible recommendation process is a set of ordered operations initiated when the capability gap value exceeds the experience gap threshold parameter. Its purpose is to convey more suitable agent capability information that exists outside the caller's visible scope to the caller without bypassing the caller's decision-making authority, allowing the caller to decide whether to accept cross-boundary calls. Step S21 sets three layers of filtering conditions. The first layer filters out scenarios with insignificant differences by comparing the capability gap value with the experience gap threshold parameter, avoiding frequent disturbances to the caller. The second layer filters out recommended objects with security or compliance risks through the agent blacklist, preventing the call request from being directed to an untrusted agent. The third layer filters out recommended objects that the caller has explicitly rejected within the cooldown period through the recommendation cooldown list, avoiding repeated recommendations of the same recommended object and preventing interference to the caller. The superposition of three layers of filtering conditions ensures that the flexible recommendation process is activated only when a capability gap truly exists, the recommended object is safe and trustworthy, and it is not in a recommendation cooling-off period. Without the three-layer judgment in step S21, the recommendation instruction in step S22 might be frequently triggered in scenarios with minimal capability gaps, interfering with the caller's normal use; or it might guide the caller to an untrusted endpoint in scenarios where there are security risks in the global candidate agents; or it might repeatedly trigger recommendations for the same global candidate agent in a short period after the caller has explicitly rejected the recommendation, thus degrading the caller's user experience. Step S21 transforms the capability gap value produced in step S10 from a purely numerical indicator into a branch condition for routing decisions, giving the flexible recommendation and cross-boundary call process in steps S22 to S24 a controllable start-up entry point.

[0067] Step S22: After the flexible recommendation process is activated, the routing forwarding operation to the access endpoint address corresponding to the local target intelligent agent identifier is suspended, the capability description document corresponding to the global candidate intelligent agent identifier is read, the capability description document is de-identified to obtain the de-identified capability description, the de-identified capability description is combined with the capability gap value to generate a recommendation instruction and send the recommendation instruction to the caller.

[0068] In step S22, after the flexible recommendation process is activated, a suspension operation is performed. The object of the suspension operation is the routing forwarding operation to the access endpoint address corresponding to the local target agent identifier. The suspension operation is the process of switching the routing forwarding operation from an immediately executed state to a paused waiting state. The suspension operation retains the access endpoint address corresponding to the local target agent identifier and the complete message content of the call request, so that if the caller rejects the recommendation, the routing forwarding to the local target agent identifier can be resumed immediately without re-executing the retrieval process in step S10. The suspension operation preserves the path for the caller to fall back to the local target agent within the visible range, avoiding the loss of default routing capabilities due to the activation of the flexible recommendation process. The capability description document corresponding to the global candidate agent identifier is read. The capability description document is a text document submitted by the agent during the registration stage, describing the scope of capabilities possessed by the agent. The capability description document may contain internal information of the entity to which the agent belongs, technical implementation details, or commercially sensitive content. Anonymization is performed on the capability description document to obtain an anonymized capability description. Anonymization involves masking or replacing sensitive information in the capability description document. Specific operations include: identifying sensitive fields such as entity names, internal numbers, technical architecture details, and commercial contract terms in the capability description document based on pre-configured sensitive field identification rules. These sensitive field identification rules are submitted by the entity to which the agent belongs during agent registration. The rules specify the content areas in the capability description document that need to be anonymized, either as a list of field names or text tags. After locating the corresponding content areas in the capability description document according to the sensitive field identification rules, the system replaces the sensitive fields with generic descriptions or deletes the sensitive fields while retaining the functional description portion. Anonymization allows the caller to understand the capability scope and applicable scenarios of the global candidate agents, while preventing the leakage of internal information of the entities to which the global candidate agents belong to the caller, thus establishing a balance between information transmission and information protection. Anonymization is particularly necessary in multi-entity agent network environments, where different entities often have business competition or confidentiality obligations. Sending unanonymized capability descriptions directly to the caller could result in the caller's entity acquiring the technical secrets or business information of the global candidate agent. The anonymized capability description is combined with a capability gap value to generate a recommendation instruction. This instruction includes both the anonymized capability description and the capability gap value. The anonymized capability description allows the caller to understand the capabilities offered by the global candidate agent, while the capability gap value allows the caller to understand the difference in task matching between the global candidate agent and the local target agent. Together, these two elements form the information basis for the caller to make a decision to accept or reject the recommendation. After sending the recommendation instruction to the caller, step S22 enters a state of waiting for the caller's response, during which the call request remains suspended.Without the desensitization process in step S22, cross-boundary recommendations would face information security risks, potentially damaging trust relationships between entities. Without the suspension operation in step S22, the caller would be unable to revert to the default route of the local target agent after receiving the recommendation instruction, limiting the caller's choices. Step S22 works in conjunction with the global retrieval channel in step S10. The global candidate agent identifiers generated by the global retrieval channel in step S10 are used to locate the capability description document in step S22, and the capability gap value calculated in step S10 is incorporated into the recommendation instruction in step S22. This cross-step data transfer ensures that the recommendation instruction includes both capability description and quantification gap information, allowing the caller to make decisions that simultaneously consider the capability suitability of the recommended object and the improvement compared to currently available agents.

[0069] Step S23: Receive the response information returned by the caller to the recommendation instruction, and determine whether the response information is a rejection of the recommendation or an agreement to the recommendation. If the response information is a rejection of the recommendation, release the suspended state of the routing forwarding operation, resume routing forwarding to the access endpoint address corresponding to the local target intelligent agent identifier, and write the global candidate intelligent agent identifier into the recommendation cooling-off list. If the response information is an agreement to the recommendation, execute the dynamic issuance process of the restricted verifiable credential, specifically including: obtaining the caller's decentralized identifier as the credential subject identifier; obtaining the entity ownership identifier to which the global candidate intelligent agent identifier belongs as the credential authorization scope; obtaining the global candidate intelligent agent identifier as the credential target intelligent agent identifier; setting the valid call count of the credential to one; setting the valid time window of the credential to a preset single authorization duration; obtaining the current time when the credential is issued as the issuance time; combining the credential subject identifier, credential authorization scope, credential target intelligent agent identifier, valid call count, valid time window, and issuance time into the credential payload; and performing digital signature on the credential payload to generate a restricted verifiable credential.

[0070] In step S23, the caller receives a response from the caller to the recommendation instruction. The response information can be either a rejection of the recommendation or an agreement to the recommendation. When the response is a rejection, the suspension of the routing forwarding operation is lifted, and routing forwarding to the access endpoint address corresponding to the local target agent identifier is resumed. The call request is sent to the access endpoint address corresponding to the local target agent identifier according to the complete message content retained before the suspension in step S22, and the local target agent executes the task. Simultaneously with the resumption of routing forwarding, the global candidate agent identifier and the current timestamp are written as a cooling-off record to the caller's corresponding recommendation cooling-off list. The writing operation uses the combination of the caller's decentralized identifier and the global candidate agent identifier as the record key, and the timestamp is used in step S21 to determine whether the record is within the valid cooling-off period. The cooldown period is a preset time parameter, determined by combining the average frequency of task requests submitted by callers in the agent network system with the update cycle of the capability description document. The cooldown period should be greater than or equal to the typical time interval between consecutive submissions of similar task requests by callers to avoid repeated recommendations of the same agent within a short period. Simultaneously, the cooldown period should be less than or equal to the average update cycle of the capability description document to ensure that the agent can re-enter the recommendation candidate range after its capabilities are updated globally. For example, the cooldown period can be set to twenty-four hours. Adding the global candidate agent identifier to the recommendation cooldown list prevents repeated recommendations of the same global candidate agent from occurring after the caller has explicitly rejected the recommendation, thus reducing redundant interference to the caller.

[0071] When the response is "agree to recommendation," the dynamic issuance process of the restricted verifiable credential is executed. The restricted verifiable credential is a data structure containing a credential subject identifier, authorization scope, valid constraints, and a digital signature. It follows the structural specifications of the verifiable credential data model. A key feature of the restricted verifiable credential is the imposition of strict constraints on the number of valid calls and the valid time window. The specific operations of the dynamic issuance process include: obtaining the caller's decentralized identifier as the credential subject identifier. This decentralized identifier is a globally unique identifier registered by the caller in the intelligent agent network system, independent of a centralized registration authority. The decentralized identifier is bound to the caller's public key, enabling the credential subject identifier to be cryptographically verified and associated with the caller's identity; obtaining the entity ownership identifier to which the global candidate intelligent agent identifier belongs as the credential authorization scope. This authorization scope limits the range of entity ownership identifiers accessible to the restricted verifiable credential holder; that is, the restricted verifiable credential only authorizes... The caller accesses agents within the scope of the credential authorization, rather than all resources under the entity to which the global candidate agent belongs. The credential target agent identifier further limits the authorized access object to the global candidate agent itself. That is, the restricted verifiable credential only authorizes the caller to access the specific agent specified by the credential target agent identifier under the entity corresponding to the credential authorization scope. The superposition of the credential authorization scope and the credential target agent identifier refines the authorization granularity of the restricted verifiable credential from the entity level to the individual agent level, which is consistent with the caller's authorization intention in step S23 to make an agreement decision only for a specific global candidate agent.The valid call count for credentials is set to one. The rationale for setting the valid call count to one, rather than multiple, is as follows: In cross-boundary call scenarios, each call authorization stems from the caller's explicit consent to the recommendation instruction. One consent action corresponds to one call authorization, conforming to the principle of least privilege between the authorized action and the scope of authorization. If the valid call count is set to two or more, subsequent calls beyond the initial call will no longer have the prior explicit consent of the caller, effectively granting additional cross-boundary access rights without the caller's knowledge. This contradicts the design intent of step S21, which requires the caller to independently decide whether to accept cross-boundary calls. For retry scenarios where the initial call fails to return a result due to network transmission failure or agent execution anomalies, the system handles this by re-initiating the recommendation decision. That is, the caller needs to resubmit the task request and go through the retrieval process in step S10 and the recommendation process in step S20 again to obtain a new restricted verifiable credential. While this approach adds a retry step, it ensures that each cross-boundary call undergoes an independent authorization decision. This avoids the security risk of credentials being intercepted and used by unintended parties if multiple uses are reserved, ensuring that restricted verifiable credentials are marked as invalid after one use, preventing repeated reuse and breach of authorization. A preset single authorization duration is set for the validity window of the credential. This duration is determined by combining the average time taken for an agent to execute a single task in the agent network system with the expected network transmission latency. The single authorization duration should be greater than or equal to the sum of the average time taken for an agent to execute a single task and the network transmission latency to ensure that the call request can be completed within the valid time window under normal execution scenarios. Simultaneously, the single authorization duration should be shorter than the typical interval between two consecutive task requests submitted by the caller to prevent the credential from remaining valid after the current call and being used unintended. For example, the single authorization duration can be set to 300 seconds. The current time when the voucher is issued is obtained as the issuance time. The issuance time is used by the authentication node to calculate the start and end time interval of the valid time window in step S24; see below. Figure 5The credential payload is composed of the credential subject identifier, credential authorization scope, credential target agent identifier, valid call count, valid time window, and issuance time. A digital signature algorithm is used to sign the credential payload to generate a restricted verifiable credential. The digital signature algorithm uses the issuing private key held by the routing scheduling node of the agent network system to perform the signature operation on the credential payload. The generated digital signature is appended to the credential payload to form a complete restricted verifiable credential. The restricted verifiable credential's dual constraints of setting the valid call count to one and the valid time window are superimposed. Triggering either constraint invalidates the restricted verifiable credential. This superimposed constraint ensures that even if the restricted verifiable credential is intercepted during transmission, the interceptor can only use it once within the valid time window. Furthermore, if the legitimate caller uses it first, the interceptor's use will be rejected by the authentication node because the valid call count has been consumed. Without the dynamic credential issuance in step S23, the caller, after agreeing to the recommendation, will not have a legitimate credential to access the global candidate agent across entity ownership boundaries. In step S24, the authentication node where the global candidate agent is located will reject the call request because it cannot verify the caller's authorization, and cross-boundary calls will not be completed. Step S23 works in conjunction with step S21. The three-layer filtering in step S21 ensures that the flexible recommendation process is only initiated when there is a genuine capability gap, the recommended object is safe and trustworthy, and it is not in the recommendation cooling-off period. The dynamic issuance of credentials in step S23 ensures that cross-boundary calls are carried out under the protection of cryptographic verification. The combination of the two steps ensures that the cross-boundary call path will not be easily opened, nor will it fail to execute due to a lack of credentials.

[0072] Step S24: Append the restricted verifiable credential to the header of the call request, obtain the access endpoint address corresponding to the global candidate agent identifier, and route the call request carrying the restricted verifiable credential to the access endpoint address. The authentication node where the global candidate agent is located verifies the restricted verifiable credential. The specific verification content includes: verifying the signature validity of the restricted verifiable credential; verifying whether the credential subject identifier in the restricted verifiable credential is consistent with the decentralized identifier of the caller; verifying whether the entity ownership identifier of the agent pointed to by the call request is within the scope of the credential authorization and whether the agent identifier pointed to by the call request is consistent with the target agent identifier of the credential; and verifying the restricted verifiable credential. The system verifies whether the valid call count of the verification credential has not been consumed and whether the current time is within the valid time window. After successful verification, the global candidate agent executes the task and returns the execution result. The system writes a cross-boundary call record to the audit log, which includes the caller's decentralized identifier, the caller's entity ownership identifier, the global candidate agent's decentralized identifier, the global candidate agent's entity ownership identifier, the credential target agent identifier, the capability gap value, and the limited verifiable credential lifecycle information. The limited verifiable credential lifecycle information includes the issuance time and expiration time of the limited verifiable credential. The limited verifiable credential is marked as expired after being used once or after the valid time window expires.

[0073] In step S24, the restricted verifiable credential dynamically issued in step S23 is appended to the header of the call request message. The header is the area in the call request data message used to carry metadata information. Appending the restricted verifiable credential to the header ensures that it is transmitted to the target endpoint along with the call request without changing the task request content in the call request message body. The access endpoint address corresponding to the global candidate agent identifier is obtained. This access endpoint address is the network communication address registered by the global candidate agent in the agent network system. The access endpoint address is obtained by querying the access endpoint address record stored in the full agent capability vector index using the global candidate agent identifier as the search key. The call request carrying the restricted verifiable credential is routed to the access endpoint address corresponding to the global candidate agent identifier. The authentication node where the global candidate agent resides verifies the restricted verifiable credential. The authentication node is a verification service node deployed on the network boundary of the entity to which the global candidate agent belongs. The authentication node performs a verification operation on the restricted verifiable credential before the call request reaches the global candidate agent. This verification operation constitutes an access control barrier for the call request to enter the entity to which the global candidate agent belongs.

[0074] See Figure 6The authentication node performs five verification operations on the restricted verifiable credential. The first verification is the signature validity verification. The authentication node uses the issuing public key published by the routing scheduling node of the intelligent agent network system to verify the digital signature in the restricted verifiable credential. The issuing public key and the issuing private key held by the routing scheduling node in step S23 form a key pair. If the verification operation passes, it confirms that the content of the restricted verifiable credential has not been tampered with after issuance and was indeed issued by a legitimate issuer. If the verification operation fails, the call request is rejected. The second verification step is the verification of the credential subject identifier. The authentication node extracts the caller's decentralized identifier from the call request and compares it with the credential subject identifier recorded in the restricted verifiable credential. If the two do not match, it indicates that the initiator of the call request is not the legitimate holder of the restricted verifiable credential, and the call request is rejected. The specific method of credential subject identifier verification is as follows: the authentication node requires the caller to sign the random challenge value in the call request using the private key bound to its decentralized identifier. The authentication node uses the public key corresponding to the credential subject identifier to verify the signature. If the verification is successful, it confirms that the caller does indeed possess the private key corresponding to the credential subject identifier, thus proving that its identity is consistent with the credential subject identifier. The third verification step is the verification of the authorized scope of the credential and the identity of the target intelligent agent. The authentication node compares the entity ownership identifier of the intelligent agent targeted by the call request with the authorized scope of the credential recorded in the restricted verifiable credential. Simultaneously, it compares the intelligent agent identifier targeted by the call request with the target intelligent agent identifier recorded in the restricted verifiable credential. If the entity ownership identifier is not within the authorized scope of the credential, or if the intelligent agent identifier does not match the target intelligent agent identifier, it indicates that the intelligent agent targeted by the call request is not within the authorized object scope of the restricted verifiable credential, and the call request is rejected. The fourth verification step is the verification of the number of valid calls. The usage status record is a key-value store maintained locally by the authentication node, using the digital signature value of the restricted verifiable credential or the unique identifier of the credential as the retrieval key. The usage status record is created by the authentication node when the restricted verifiable credential first passes the signature validity verification and its usage status is initialized to unconsumed. After the call request is allowed to pass, the authentication node updates the usage status to consumed. The authentication node queries the usage status record of the restricted verifiable credential to determine if the valid call count of the restricted verifiable credential has been consumed. If the valid call count has been consumed, it indicates that the restricted verifiable credential has been used in a previous call, and the current call request is rejected. The fifth verification is the valid time window verification. The authentication node obtains the current time, reads the issuance time and valid time window from the credential payload of the restricted verifiable credential, adds the issuance time and valid time window to obtain the expiration time, and determines whether the current time is within the time interval formed by the issuance time and the expiration time. If the current time has exceeded this time interval, the call request is rejected. After all five verification operations pass, the authentication node allows the call request to reach the global candidate agent, which executes the task and returns the execution result.The five verification operations form a multi-dimensional verification structure for signature authenticity, subject identity legitimacy, authorized object consistency, usage frequency compliance, and time validity. Failure of any one of these verifications will result in the call request being rejected. The combination of the five verification operations ensures that forged credentials cannot pass signature verification, call requests initiated by non-credential holders cannot pass subject identity verification, call requests pointing to unauthorized intelligent agents cannot pass authorization scope and target intelligent agent identity verification, used credentials cannot pass usage frequency verification, and expired credentials cannot pass time verification. This blocks possible paths for illegal cross-boundary calls from different dimensions.

[0075] Upon successful verification, the global candidate agent executes the task and returns the execution result, while simultaneously writing a cross-boundary call record to the audit log. The cross-boundary call record includes the following fields: caller's decentralized identifier, caller entity affiliation identifier, global candidate agent's decentralized identifier, global candidate agent entity affiliation identifier, capability gap value, and restricted verifiable credential lifecycle information. The restricted verifiable credential lifecycle information includes the issuance time and expiration time of the restricted verifiable credential. The issuance time is the timestamp when the credential payload is signed in step S23, and the expiration time is the timestamp obtained by adding the issuance time to the effective time window. The cross-boundary call record fully records the identity information of both parties, organizational affiliation information, the capability gap value triggering the cross-boundary call, and the validity period of the credential in the audit log, enabling post-event auditing to trace the initiator, recipient, triggering reason, and authorization validity period of each cross-boundary call. Once a restricted verifiable credential is used once or its validity period expires, it is marked as expired. Expired restricted verifiable credentials will fail the valid call count verification or validity period window verification by the authentication node in subsequent call requests, thus preventing the credential from being reused continuously or used beyond its expiration date. Without the five verification operations in step S24, cross-boundary calls will lack access control barriers, allowing any requester holding a credential to access global candidate agents without restriction. Without the audit log writing operation in step S24, the history of cross-boundary calls will be untraceable, making it impossible to determine the call chain and responsibility after a security incident. Step S24 works in conjunction with step S23. The restricted verifiable credential issued in step S23 is verified by the authentication node in step S24. The pairing of issuance and verification enables cross-boundary calls to be completed in a closed loop of cryptographic verification. The restricted verifiable credential obtained by the caller through step S23 is the only legitimate credential to enter the boundary of the entity to which the global candidate intelligent agent belongs. The authentication node confirms the authenticity of the credential, the legitimacy of the holder's identity, the consistency of the authorized object, its one-time use, and its timeliness through the five verifications in step S24 before allowing the call request to pass. This closed loop ensures that cross-boundary calls will not be rejected outright due to a lack of credentials, nor will they be used without restriction due to unrestricted credentials.

[0076] Step S20 transforms the capability gap value produced in step S10 into branch conditions for routing decisions, and establishes a controlled cross-boundary call path under the constraints of entity ownership boundary access control through a flexible recommendation process, dynamic issuance and authentication verification of restricted verifiable credentials. In step S21, the comparison of the capability gap value and the experience gap threshold parameter, the filtering of the agent blacklist, and the checking of the recommendation cooling list limit the start conditions of the flexible recommendation process to the range where capability gaps do exist, the recommended object is safe and trustworthy, and has not been rejected by the caller during the cooling period. In step S22, the suspension operation retains the fallback path of the default route, and the desensitization process establishes a balance between transmitting capability information and protecting entity privacy. In step S23, the effective call count of the restricted verifiable credential is set to a dual constraint of one time and an effective time window, which controls the granularity of cross-boundary authorization within the scope of a single call. The characteristic that the credential expires after one use means that each cross-boundary call must go through an independent recommendation decision and credential issuance process, preventing the single authorization from being repeatedly used to bypass the decision control of the flexible recommendation process. In step S24, the five verification operations of the authentication node constitute the access control barrier for cross-boundary calls, and the writing of audit logs provides a traceable record basis for cross-boundary calls. The dual-channel parallel retrieval structure of step S20 and step S10 works together. Step S10 quantifies the capability difference between the visible range and the outside into a capability gap value. Step S20 transforms the capability gap value into a control signal for routing decision. The combination of the two steps enables the caller to obtain capability resources outside the visible range in a multi-entity coexisting intelligent agent network environment, while maintaining access control at the entity ownership boundary. This is done in a single-authorization, time-limited manner. Each cross-boundary call is subject to the caller's explicit consent, the issuance and verification of cryptographic credentials, and complete recording in the audit log. This ensures that cross-boundary capability sharing is carried out within a controllable, traceable, and auditable framework. Step S20 combines a flexible recommendation mechanism driven by capability gap values ​​with a one-time authorization mechanism based on restricted verifiable credentials. This allows capability sharing in a multi-entity coexistence environment to no longer rely on pre-established static authorization relationships between entities. Instead, it is dynamically triggered based on capability gap values ​​generated by actual task requirements. The scope and duration of authorization for each cross-boundary call are determined by the specific conditions at the time of the call. Authorization terminates immediately after the call is completed, leaving no persistent authorization relationship between the caller and the entity to which the global candidate intelligent agent belongs. Thus, while opening up capability sharing paths, the time range and number of uses of authorization are constrained to the granularity of a single call, achieving a balance between security isolation and global optimization. This adapts to the large-scale collaboration needs of multiple entities and multiple boundaries in general distributed intelligent agent networks.

[0077] Example 2:

[0078] This embodiment, based on embodiment 1, provides an intelligent agent invocation system based on identity binding and semantic routing, such as... Figure 7 As shown, it includes:

[0079] The gap quantification module receives the task request text, vectorizes it to obtain a task intent vector, and performs cosine similarity calculation on the task intent vector in both the global and local retrieval channels to obtain the global optimal similarity score and corresponding global candidate agent identifier, and the local optimal similarity score and corresponding local target agent identifier. The capability gap value is calculated based on the global optimal similarity score and the local optimal similarity score. The global retrieval channel does not apply entity attribution identifier filtering conditions, while the local retrieval channel does.

[0080] The credential issuance module compares the capability gap value with a preset experience gap threshold parameter. Based on the comparison result, it determines whether to trigger the flexible recommendation process. If the flexible recommendation process is triggered, it generates a recommendation instruction through the flexible recommendation process and sends the recommendation instruction to the caller. It also receives the response information returned by the caller to the recommendation instruction and dynamically issues restricted verifiable credentials based on the response information.

[0081] Furthermore, in the drop quantization module, the method for performing cosine similarity calculation on the task intent vector in the global retrieval channel includes:

[0082] Obtain the full agent capability vector index, which contains the mapping relationship between the agent identifier and the agent capability vector of all registered agents, the entity ownership identifier to which the agent is bound, and the access endpoint address.

[0083] The task intent vector is compared with the cosine similarity of each agent's capability vector in the full agent capability vector index to obtain a global similarity score sequence. The global similarity score sequence is sorted in descending order, and the similarity score at the top of the sequence is taken as the global optimal similarity score. The agent identifier corresponding to the global optimal similarity score is recorded as the global candidate agent identifier.

[0084] The entity ownership identifier filtering condition is constructed using the entity ownership identifier of the caller;

[0085] The method for performing cosine similarity calculation on the task intent vector in a local retrieval channel includes:

[0086] The entity attribution identifier filtering condition is applied to the full agent capability vector index to filter out a subset of agent capability vectors within the visible range. The cosine similarity between the task intent vector and each agent capability vector in the subset of agent capability vectors within the visible range is calculated to obtain a local similarity score sequence. The local similarity score sequence is sorted in descending order, and the similarity score at the top of the sort is taken as the local optimal similarity score. The agent identifier corresponding to the local optimal similarity score is recorded as the local target agent identifier.

[0087] The capability gap value is obtained by subtracting the local optimal similarity score from the global optimal similarity score. When the local similarity score sequence is an empty set, the local optimal similarity score is set to zero.

[0088] Furthermore, in the certificate issuance module, the method for determining whether the flexible recommendation process is triggered includes:

[0089] The system determines whether the capability gap value is greater than a preset experience gap threshold parameter. If the capability gap value is less than or equal to the experience gap threshold parameter, the local target agent identifier is used as the final routing target. If the capability gap value is greater than the experience gap threshold parameter, the system further determines whether the global candidate agent identifier exists in the agent blacklist and whether the global candidate agent identifier exists within the effective cooling period of the caller's corresponding recommendation cooling list. If it exists in the agent blacklist or exists within the effective cooling period of the recommendation cooling list, the local target agent identifier is used as the final routing target. The flexible recommendation process is activated only when the capability gap value is greater than the experience gap threshold parameter and the global candidate agent identifier does not exist in the agent blacklist and does not exist within the effective cooling period of the caller's corresponding recommendation cooling list.

[0090] The execution method of the flexible recommendation process includes:

[0091] The routing and forwarding operation to the access endpoint address corresponding to the local target intelligent agent identifier is suspended. The capability description document corresponding to the global candidate intelligent agent identifier is read. The capability description document is de-identified to obtain the de-identified capability description. The de-identified capability description is combined with the capability gap value to generate a recommendation instruction and send the recommendation instruction to the caller.

[0092] The methods and systems of this application may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the method is for illustrative purposes only, and the steps of the method of this application are not limited to the order specifically described above, unless otherwise specifically stated.

[0093] In addition, the parts of the technical solutions provided in the embodiments of this application that are consistent with the implementation principles of the corresponding technical solutions in the prior art have not been described in detail, so as to avoid excessive elaboration.

[0094] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the invention. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. An identity binding and semantic routing based agent invocation method, characterized in that, The method includes: The system receives a task request text, vectorizes it to obtain a task intent vector, and performs cosine similarity calculation on the task intent vector in both the global and local retrieval channels to obtain the global optimal similarity score and corresponding global candidate agent identifier, and the local optimal similarity score and corresponding local target agent identifier. The capability gap value is then calculated based on the global optimal similarity score and the local optimal similarity score. The global retrieval channel does not apply entity attribution identifier filtering conditions, while the local retrieval channel does. The capability gap value is compared with the preset experience gap threshold parameter. Based on the comparison result, it is determined whether to trigger the flexible recommendation process. If the flexible recommendation process is triggered, a recommendation instruction is generated through the flexible recommendation process and sent to the caller. The response information returned by the caller to the recommendation instruction is received, and a restricted verifiable credential is dynamically issued based on the response information. The method for performing cosine similarity calculation on the task intent vector in the global retrieval channel includes: obtaining a full-scale agent capability vector index, which contains the mapping relationship between agent identifiers and agent capability vectors of all registered agents, entity affiliation identifiers bound to the agent, and access endpoint addresses; performing cosine similarity calculation on the task intent vector and each agent capability vector in the full-scale agent capability vector index to obtain a global similarity score sequence; arranging the global similarity score sequence in descending order, taking the similarity score at the top of the sequence as the global optimal similarity score, and recording the agent identifier corresponding to the global optimal similarity score as the global candidate agent identifier; The entity ownership identifier filtering condition is constructed using the entity ownership identifier of the caller; The method for performing cosine similarity calculation on the task intent vector in the local retrieval channel includes: applying entity attribution identifier filtering conditions to the full agent capability vector index to filter out a subset of agent capability vectors within the visible range; performing cosine similarity calculation on the task intent vector and each agent capability vector in the subset of agent capability vectors within the visible range to obtain a local similarity score sequence; arranging the local similarity score sequence in descending order, taking the similarity score at the top of the sequence as the local optimal similarity score, and recording the agent identifier corresponding to the local optimal similarity score as the local target agent identifier; The capability gap value is obtained by subtracting the local optimal similarity score from the global optimal similarity score. When the local similarity score sequence is an empty set, the local optimal similarity score is set to zero. 2.The identity binding and semantic routing based agent invocation method of claim 1, wherein, The vectorization processing method includes: A pre-trained bidirectional sequence semantic coding model is used to vectorize the task request text, and the hidden state vector corresponding to the classification label position in the output layer of the bidirectional sequence semantic coding model is taken as the task intent vector. 3.The identity binding and semantic routing based agent invocation method of claim 1, wherein, The method for determining whether the flexible recommendation process has been triggered includes: The system determines whether the capability gap value is greater than a preset experience gap threshold parameter. If the capability gap value is less than or equal to the experience gap threshold parameter, the local target agent identifier is used as the final routing target. If the capability gap value is greater than the experience gap threshold parameter, the system further determines whether the global candidate agent identifier exists in the agent blacklist and whether the global candidate agent identifier exists within the effective cooling period of the caller's corresponding recommendation cooling list. If it exists in the agent blacklist or exists within the effective cooling period of the recommendation cooling list, the local target agent identifier is used as the final routing target. The flexible recommendation process is activated only when the capability gap value is greater than the experience gap threshold parameter and the global candidate agent identifier does not exist in the agent blacklist and does not exist within the effective cooling period of the caller's corresponding recommendation cooling list.

4. The method of claim 3, wherein, The execution method of the flexible recommendation process includes: The routing and forwarding operation to the access endpoint address corresponding to the local target intelligent agent identifier is suspended. The capability description document corresponding to the global candidate intelligent agent identifier is read. The capability description document is de-identified to obtain the de-identified capability description. The de-identified capability description is combined with the capability gap value to generate a recommendation instruction and send the recommendation instruction to the caller.

5. The agent invocation method based on identity binding and semantic routing according to claim 1, characterized in that, The response information can be either a rejection of recommendation or an agreement to recommendation; when the response information is an agreement to recommendation, a dynamic issuance process for restricted verifiable credentials is executed.

6. The agent invocation method based on identity binding and semantic routing according to claim 5, characterized in that, The dynamic issuance process of the restricted verifiable credential includes: The decentralized identifier of the caller is obtained as the credential subject identifier. The entity to which the global candidate intelligent agent identifier belongs is obtained as the credential authorization scope. The global candidate intelligent agent identifier is obtained as the credential target intelligent agent identifier. The valid call count of the credential is set to one. The valid time window of the credential is set to a preset single authorization duration. The current time when the credential is issued is obtained as the issuance time. The credential subject identifier, credential authorization scope, credential target intelligent agent identifier, valid call count, valid time window and issuance time are combined into the credential payload. The credential payload is digitally signed to generate a restricted verifiable credential.

7. The agent invocation method based on identity binding and semantic routing according to claim 1, characterized in that, The method further includes: The restricted verifiable credential is appended to the message header of the call request, the access endpoint address corresponding to the global candidate agent identifier is obtained, the call request carrying the restricted verifiable credential is routed to the access endpoint address, the authentication node where the global candidate agent is located performs five verifications on the restricted verifiable credential, and after all five verifications are passed, the global candidate agent executes the task and returns the execution result. The five verifications include signature validity verification, credential subject identification verification, credential authorization scope and target agent identification verification, valid call count verification, and valid time window verification.

8. An agent invocation system based on identity binding and semantic routing, used to implement the agent invocation method based on identity binding and semantic routing as described in any one of claims 1-7, characterized in that, The system includes: The gap quantification module receives the task request text, vectorizes it to obtain a task intent vector, and performs cosine similarity calculation on the task intent vector in both the global and local retrieval channels to obtain the global optimal similarity score and corresponding global candidate agent identifier, and the local optimal similarity score and corresponding local target agent identifier. The capability gap value is calculated based on the global optimal similarity score and the local optimal similarity score. The global retrieval channel does not apply entity attribution identifier filtering conditions, while the local retrieval channel does. The certificate issuance module compares the capability gap value with the preset experience gap threshold parameter, determines whether to trigger the flexible recommendation process based on the comparison result, and if the flexible recommendation process is triggered, generates a recommendation instruction through the flexible recommendation process and sends the recommendation instruction to the caller; it receives the response information returned by the caller to the recommendation instruction and dynamically issues restricted verifiable certificates based on the response information. The method for performing cosine similarity calculation on the task intent vector in the global retrieval channel includes: obtaining a full-scale agent capability vector index, which contains the mapping relationship between agent identifiers and agent capability vectors of all registered agents, entity affiliation identifiers bound to the agent, and access endpoint addresses; performing cosine similarity calculation on the task intent vector and each agent capability vector in the full-scale agent capability vector index to obtain a global similarity score sequence; arranging the global similarity score sequence in descending order, taking the similarity score at the top of the sequence as the global optimal similarity score, and recording the agent identifier corresponding to the global optimal similarity score as the global candidate agent identifier; The entity ownership identifier filtering condition is constructed using the entity ownership identifier of the caller; The method for performing cosine similarity calculation on the task intent vector in the local retrieval channel includes: applying entity attribution identifier filtering conditions to the full agent capability vector index to filter out a subset of agent capability vectors within the visible range; performing cosine similarity calculation on the task intent vector and each agent capability vector in the subset of agent capability vectors within the visible range to obtain a local similarity score sequence; arranging the local similarity score sequence in descending order, taking the similarity score at the top of the sequence as the local optimal similarity score, and recording the agent identifier corresponding to the local optimal similarity score as the local target agent identifier; The capability gap value is obtained by subtracting the local optimal similarity score from the global optimal similarity score. When the local similarity score sequence is an empty set, the local optimal similarity score is set to zero.

Citation Information

Patent Citations

  • Cross-domain identity authentication system and method capable of bearing certificate entity and agent

    CN121396496A

  • Identity and access management method, system and equipment for multi-agent cross-domain interaction scene and medium

    CN121664547A

  • Intelligent agent tool call recall method and system and computer readable storage medium

    CN121188501A

  • Intelligent agent cross-domain interaction identity authentication and data verification method

    CN121418160A