English

Fortifying the Agentic Web: A Unified Zero-Trust Architecture Against Logic-layer Threats

Cryptography and Security 2025-08-22 v3 Artificial Intelligence Emerging Technologies

Abstract

This paper presents a Unified Security Architecture that fortifies the Agentic Web through a Zero-Trust IAM framework. This architecture is built on a foundation of rich, verifiable agent identities using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), with discovery managed by a protocol-agnostic Agent Name Service (ANS). Security is operationalized through a multi-layered Trust Fabric which introduces significant innovations, including Trust-Adaptive Runtime Environments (TARE), Causal Chain Auditing, and Dynamic Identity with Behavioral Attestation. By explicitly linking the LPCI threat to these enhanced architectural countermeasures within a formal security model, we propose a comprehensive and forward-looking blueprint for a secure, resilient, and trustworthy agentic ecosystem. Our formal analysis demonstrates that the proposed architecture provides provable security guarantees against LPCI attacks with bounded probability of success.

Keywords

Cite

@article{arxiv.2508.12259,
  title  = {Fortifying the Agentic Web: A Unified Zero-Trust Architecture Against Logic-layer Threats},
  author = {Ken Huang and Yasir Mehmood and Hammad Atta and Jerry Huang and Muhammad Zeeshan Baig and Sree Bhargavi Balija},
  journal= {arXiv preprint arXiv:2508.12259},
  year   = {2025}
}
R2 v1 2026-07-01T04:53:32.085Z