이기종 멀티 에이전트 협업 환경을 위한 소유권 기반 보안 수준 협약 (Agent-SecSLA) 프레임워크
Agent-SecSLA: An Ownership-Based Security Level Agreement Framework for Heterogeneous Multi-Agent Collaboration
The AI paradigm is expanding beyond language generation toward action-capable agent environments that perform file-system access, external tool invocation, and payment authorization, while heterogeneous multi-agent systems require Personal Agents (PAs) and Service Agents (SAs) to collaborate under different policies, audit criteria, and data-retention rules. As a result, policy mismatches, prompt injection, supply-chain attacks, and misconfigurations may lead to cascading damage; therefore, this paper proposes Agent-SecSLA, an ownership-based security level agreement framework. The proposed framework consists of a bivariate classification of data sensitivity and action risk, three security levels, the DSPN (Discover-Settle-Pin-Notify) protocol, event-level PEP/PDP policy enforcement, depth/fanout control for delegation tokens, hash-pointer-based Chain of Custody (CoC), and a graduated penalty mechanism. In addition, this paper analyzes the framework’s applicability through comparison with existing policy negotiation and enforcement techniques, formal safety propositions, proof sketches, and preliminary quantitative evaluation using a synthetic simulator.
한국어
AI 패러다임은 언어 생성을 넘어 파일 시스템 접근, 외부 도구 호출, 결제 권한 등을 수행하는 실행형 에이전트 환경으로 확장되고 있으며, 이기종 멀티 에이전트 시스템에서는 개인 에이전트(PA: Personal Agent)와 서비스 에이전트(SA: Service Agent)가 서로 다른 정책, 감사 기준, 데이터 보존 규칙하에서 협업한다. 이로 인해 정책 불일치, 프롬프트 주입, 공급망 공격, 설정 오류가 연쇄적 피해로 이어질 수 있으므로, 본 논문은 소유권 기반 보안 수준 협약 프레임워크인 Agent-SecSLA를 제안한다. 제안 프레임워크는 데이터 민감도와 실행 위험도의 이원 분류, 3단계 보안 레벨, DSPN(Discover-Settle-Pin-Notify) 프로토콜, 사건 단위 PEP/PDP 정책 집행, 위임 토큰의 depth/fanout 제어, 해시 포인터 기반 연계보관성(CoC: Chain of Custody), 단계적 패널티 메커니즘으로 구성된다. 또한 기존 정책 협상·집행 기법과의 비교, 형식적 안전성 명제와 증명 스케치, 합성 시뮬레이터 기반 예비 정량 평가를 통해 제안 프레임워크의 적용 가능성을 분석한다.
목차
요약 ABSTRACT 1. 서론 2. 관련 연구 3. Agent-SecSLA 프레임워크 3.1 소유권 기반 이기종 MAS 3.2 사건 중심 자산 모델과 위협 모델 3.3 보안 레벨 산정 및 요구사항 3.4 Agent-SecSLA 참조 아키텍처 3.5 DSPN 프로토콜 3.6 PEP/PDP 기반 런타임 집행 3.7 데이터 변환과 보안-유틸리티 절충 3.8 위임 토큰과 연계보관성(CoC) 감사 체인 3.9 보안 레벨 계약 조항과 패널티 매트릭스 3.10 시나리오 및 집행 시퀀스 예시 4. 프레임워크 평가 및 고찰 4.1 형식적 안전성 분석 4.2 재현 가능한 벤치마크 설계 4.3 시뮬레이션 기반 정량 평가 4.4 고찰 및 향후 연구 방향 5. 결론 참고문헌