~/enjay
All publications
2026IEEE ICAISET 2026 · IEEE

Future-Proofing Identity Security for Agentic AI Systems: Design, Implementation, and Evaluation of an Identity Fabric

Agentic AI systems composed of dynamically instantiated, tool-enabled agents operating across trust boundaries introduce identity failures that exceed the assumptions of existing identity and access management frameworks. This paper identifies five identity gaps in agentic AI systems and introduces six composable security primitives that address ephemeral identity, delegation integrity, capability-level control, cross-domain trust, behavioral assurance, and content provenance: Ephemeral Attested Agent Identity (EAAI), Intent-Bound Delegation Tokens (IBDT), Identity-Constrained Capability Sandboxes, Decentralized Agent Identity Registries (DAIR), Continuous Behavioral Attestation, and Content Provenance Binding. We implement the architecture on Kubernetes using SPIFFE/SPIRE workload identity and mutual TLS for all inter-service communication. Across 33 mTLS test cases (n=100 per operation), the system achieved 100% delegation fidelity (20/20 narrowing tests), sub-25 ms mean latency for credential issuance and delegation, and 6/6 abuse-resistance rejections. In an end-to-end pipeline with Claude Sonnet, total identity overhead was 203 ms, representing 2.6% of inference latency.

agentic AIidentityIAMSPIFFE/SPIREworkload attestation

DOI0 citations