PulseAugur
实时 03:56:26
English(EN) MCP is rebuilding its authorization around agents instead of people in browsers

模型上下文协议 (Model Context Protocol) 彻底改革了基于代理的系统的授权

模型上下文协议 (MCP) 概述了新的路线图,解决了其授权模型中的关键安全漏洞。当前为浏览器中用户交互设计的系统,难以应对在没有直接人工监督下运行的云代理和子代理的现实。MCP 计划实施诸如 possession 证明令牌 (proof-of-possession tokens) 和工作负载身份联合 (workload identity federation) 等解决方案,以防止在代理跳跃中未经授权地重放授权令牌。此外,该协议旨在统一本地和远程交互的传输语义,朝着所有服务器的单一 HTTP 原生绑定 (HTTP-native binding) 发展。 AI

影响 增强了代理间通信的安全性,这对于 AI 系统的安全扩展至关重要。

排序理由 该条目详细介绍了协议解决技术挑战的路线图,属于研发范畴。[lever_c_demoted from research: ic=1 ai=1.0]

在 dev.to — MCP tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

模型上下文协议 (Model Context Protocol) 彻底改革了基于代理的系统的授权

报道来源 [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Breach Protocol ·

    MCP正围绕代理而非浏览器中的用户重建其授权

    <p>The Model Context Protocol published a new roadmap on August 22 that names its authorization model as a core problem: the spec assumes a human clicking approve in a browser, while the callers showing up in production are cloud agents and sub-agents with no human anywhere in th…