Fetching from the wire…
Policy2026-07-25 · source-backed
Llambí-Morillas and Fernández-Fernández formalize CVA as a relation jointly binding an agent principal, a concrete authorization request, an execution context, and policy satisfaction while keeping private authorization attributes confidential. They define authorization soundness, principal binding, request binding, policy binding and replay resistance, and ship an executable zero-knowledge proof of concept over Groth16. Their central claim is structural: existing agentic security frameworks don't explicitly separate identity binding from authorization-request binding from runtime execution binding, and that conflation is the open problem. If you're building agent auth, that three-way split is the design constraint.
Each link below shares sources, entities, or timing with this story.
Shared entity: Their / Same source domain / Shared topic / Earlier coverage
Both cover Their; reported by the same outlet (arxiv.org); overlapping topics (agent, execution).
Shared entity: Their / Shared topic / Earlier coverage / Tension
Both cover Their; overlapping topics (agent, claim); earlier Their coverage from 2026-06-24.
Both cover Their; overlapping topics (binding, central); earlier Their coverage from 2026-03-02.
Shared entity: Their / Shared topic / Earlier coverage
Both cover Their; overlapping topics (agent, agentic, policy); earlier Their coverage from 2026-05-28.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (agent, agentic, binding); pushes against this story (but).
Shared entity: Their / Same source domain / Tension
Both cover Their; reported by the same outlet (arxiv.org); pushes against this story (against).
Same source domain / Shared topic
Reported by the same outlet (arxiv.org); overlapping topics (agent, agentic, execution, policy).
Shared entity: Their / Shared topic / Earlier coverage
Both cover Their; overlapping topics (agent, auth); earlier Their coverage from 2026-07-22.