Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Preprint
Data sources: ZENODO
addClaim

Meet-Oracle Scope Inference: A Membership-Query Side Channel in Intersection-Based Multi-Agent Authorization

Authors: Jain, Akshay;

Meet-Oracle Scope Inference: A Membership-Query Side Channel in Intersection-Based Multi-Agent Authorization

Abstract

Multi-agent authorization protocols increasingly compose separately issued grants by set intersection, because intersection can only narrow authority. This paper shows that the same property turns a correctly functioning verifier into a perfect membership-query oracle. An attacker holding a verifier-trusted grant that covers a given tag reads one bit of a victim's confidential scope with a single call on that tag. A finite, public action vocabulary bounds how many calls it takes to disclose the victim's entire scope, once the attacker's grant covers the whole vocabulary. We call this mechanism the meet-oracle and pin it exhaustively at the code level with a permanent regression test. An unmodified, general-purpose LLM agent, given only tool access and a task, carries out the extraction strategy end to end on its own. Nine of nine trials reconstruct a hidden victim scope exactly over the Model Context Protocol (MCP), reproduced identically by three attacker models; nine of nine reconstruct exactly again at a structurally different enforcement point, the Agent2Agent protocol (A2A), against real cross-process peers. Every probe in the attack is an individually legitimate, correctly authorized or denied action, so it leaves no crash or timing signature for a monitor tuned to conventional anomalies to catch. We argue, but do not test against a second real system, that the vulnerable shape, strict-intersection composition plus a per-action binary decision, is structural rather than specific to one implementation.

Powered by OpenAIRE graph
Found an issue? Give us feedback