Skip to content

From Review to Authorization: Key-Isolated Threshold Signing for LLM Agents

Sep 2026 · 1 citation · 28 references
Computer Science

TL;DR

KITA is presented, a review-to-authorization architecture that keeps the user's personal secret signing key and every threshold signing-key share outside all LLM processes and establishes execution-bound authorization integrity.

Abstract

Autonomous LLM agents can turn untrusted content into effectful actions such as payments and permission changes. If the same process interprets this content and controls a reusable signing credential, prompt injection can cross the judgment boundary and reach execution authority. We present KITA, a review-to-authorization architecture that keeps the user's personal secret signing key and every threshold signing-key share outside all LLM processes. Under threshold signature unforgeability and our system assumptions, compromising the proposer and fewer than t reviewer-signer domains cannot produce a valid authorization for a new action without signing contributions from t distinct domains. Thus, any such authorization includes a share from an uncompromised domain, bound to the canonical action and released only after authenticated reviewer approval. This establishes execution-bound authorization integrity. We implement the complete reviewer-to-executor path with a structured-output LLM adapter and threshold BLS. Six system tests validate quorum gating and message binding at this interface, while cryptographic microbenchmarks measure the online signing path and its scaling behavior.

View source

Similar papers

#artificial intelligence Review Sep 2026

Zero-Trust Authorization and Discovery for Enterprise MCP

LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its...

Huang-Jian Li, Yu-Wei Wang, Srinivasan Manoharan · 1 citation
Preprint Sep 2026

CATP: Design and Evaluation of Local Agent Authorization and Audit Evidence

A signed authorization record authenticates what a signer asserted, but does not by itself establish that the assertion agrees with the policy and action used for a runtime decision. CATP specifies the bindings needed to carry a local pre-execution decision into offline-verifiable evidence. Its hook commits to the enfo...

Ling-Feng Zhou · 0 citations
Preprint Sep 2026

AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents

LLM agents can produce harmful effects through sequences of ordinary operations. Judging such actions requires establishing both the authority that permits them and the origin of the data they carry. We present AGATE, an authorization and data-provenance gate at instrumented agent-harness boundaries. Operator declarati...

Xiao-Ru Zhang, Zhuo-Ran Cheng, Kai-Lin Liu et al. · 0 citations
#artificial intelligence Preprint Sep 2026

ToolFence: Fine-Grained Authorization for Secure Tool-Using LLM Agents

This work introduces ToolFence, which compiles a typed authorization blueprint before execution, enforces it through a deterministic monitor, and when the blueprint is incomplete asks a judge to grant new capabilities rather than adjudicate each concrete call, improving runtime efficiency.

Yan-Jie Li, Xiang-Yu He, Xue-Long Dai et al. · 0 citations
Preprint Oct 2026

Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay

A tool-using model can follow a malicious instruction even when its credentials are valid. We study whether task-scoped authorization contains the resulting tool execution. Our paired-replay testbed samples a model request once and submits the same action, resource, and arguments to broad bearer, scoped JWT, sender-con...

Tural Hagverdiyev · 0 citations
#artificial intelligence Preprint Sep 2026

API Secrets Should Never Become Tokens in the LLM's Vocabulary: A Threat Analysis of API Credential Handling in LLM Agent Systems and an Empirical Evaluation of a Vault-Mediated Execution Boundary

Tool-using large language model (LLM) agents turn credential hygiene from a storage problem into an execution-security problem. A key pasted into a prompt, or embedded in a system prompt or tool configuration, crosses from an authentication boundary into a data pipeline, where it may persist in conversation history, lo...

P. Kenney, Hadi Ahmadi, Denis Lusson et al. · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.