Zero-Trust Agent Gateway: Identity-Centric Access Control for Multi-Actor AI Ecosystems Aligned with SASE Principles
DOI:
https://doi.org/10.64751/ajaccm.2024.v4.n2.pp36-45Keywords:
zero trust architecture, SASE, SPIFFE, workload identity, mutual TLS, RBAC, ABAC, service mesh, AI agent security, microservice gateway, continuous verification.Abstract
Contemporary AI agent platforms operate across hostile multi-actor environments in which traditional perimeter-based security controls offer inadequate protection. Agents, KOL accounts, brand wallets, and third-party protocol integrations form a distributed trust surface that cannot be defended by network boundary assumptions. This paper presents the Zero-Trust Agent Gateway (ZTAG), an identity-centric access control architecture for AI agent platforms aligned with Secure Access Service Edge (SASE) principles. ZTAG enforces mutual TLS for all agent-to-platform and agent-to-agent communication, assigns cryptographically verifiable workload identities using SPIFFE/SPIRE, and implements fine-grained Role-Based and Attribute-Based Access Control (RBAC/ABAC) across a microservice mesh. Continuous context verification evaluates trust posture at every request boundary rather than at session establishment, eliminating implicit trust accumulation. We present the ZTAG architecture, its integration with SASE policy enforcement points at the network edge, and a formal security analysis demonstrating resistance to the principal threat classes identified by NIST SP 800-207. An empirical evaluation on a production-representative service mesh of 18 microservices shows that ZTAG adds a median overhead of 4.2 ms per inter-service request, well within acceptable latency budgets for synchronous API calls, while reducing the mean time to contain a lateral movement incident from 47 minutes to under 6 minutes in tabletop exercises.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.







