Adaptive Zero-Trust Authentication and Authorization for AI Agent Ecosystems Using SPIFFE/SPIRE

Authors

  • Rohan Malhotra AI Research Scientist, India
  • Meera Iyer Artificial Intelligence Research Analyst, India

DOI:

https://doi.org/10.37547/ijasr-06-09-05

Keywords:

Zero-Trust Security, AI Agents, SPIFFE, SPIRE

Abstract

The emergence of autonomous and semi-autonomous AI agents is transforming distributed computing from conventional service-oriented architectures toward dynamic ecosystems in which software agents can independently invoke models, access data, communicate with other agents, and execute actions on behalf of users or organizations. This evolution creates a security problem that cannot be adequately addressed through static network boundaries or conventional identity mechanisms. Authentication and authorization must instead become continuous, workload-aware, and capable of distinguishing individual agent identities from transient execution contexts. This paper proposes an adaptive zero-trust authentication and authorization framework for AI agent ecosystems based on SPIFFE/SPIRE principles. The proposed approach conceptualizes every AI agent as an independently identifiable workload and combines cryptographically verifiable workload identity with contextual authorization, continuous trust evaluation, least-privilege policies, and adaptive risk decisions. The framework also incorporates computational-efficiency considerations because authentication, policy evaluation, telemetry, and model-mediated security controls can introduce additional processing overhead. The literature indicates that increasingly complex AI workloads require greater attention to computational efficiency, lifecycle management, transparency, and environmental cost (Bartoldson et al., 2023; Menghani, 2021; Schwartz et al., 2020). The study develops a conceptual architecture, identifies its functional components, and evaluates expected security and operational outcomes through analytical scenarios. Findings suggest that SPIFFE/SPIRE-oriented identity can provide a strong foundation for agent authentication, while adaptive authorization is necessary to address dynamic agent behavior, changing context, privilege escalation, and inter-agent delegation. The framework contributes a structured security model for trustworthy agent ecosystems while identifying limitations related to policy complexity, identity lifecycle management, computational overhead, and the absence of standardized behavioral trust metrics.

References

1. D. Amodei and D. Hernandez, “AI and compute,” Accessed: Aug. 3, 2023. [Online]. Available: https://openai.com/blog/ai-and-compute/

2. B. R. Bartoldson, B. Kailkhura, and D. Blalock, “Compute-efficient deep learning: Algorithmic trends and opportunities,” J. Mach. Learn. Res., vol. 24, pp. 1–77, 2023.

3. E. M. Bender, T. Gebru, A. McMillan-Major, and S. Shmitchell, “On the dangers of stochastic parrots: Can language models be too big?,” in Proc. ACM Conf. Fairness, Accountability, Transparency, Virtual Event, 2021, pp. 610–623.

4. A. Canziani, A. Paszke, and E. Culurciello, “An analysis of deep neural network models for practical applications,” 2016, arXiv:1605.07678.

5. J. Dodge, “Measuring the carbon intensity of AI in cloud instances,” in Proc. ACM Conf. Fairness, Accountability, Transparency, Seoul, South Korea, 2022, pp. 1877–1894.

6. J. Dodge, S. Gururangan, D. Card, R. Schwartz, and N. A. Smith, “Show your work: Improved reporting of experimental results,” 2019, arXiv:1909.03004.

7. J. Gitzel, M. Platenius-Mohr, and A. Burger, “Estimating the sustainability of AI models based on theoretical models and experimental data,” 2023, arXiv:202301.0406.v1.

8. U. Gupta, “Chasing carbon: The elusive environmental footprint of computing,” in Proc. IEEE Int. Symp. High- Perform. Comput. Archit., Montreal, QC, Canada, 2023, pp. 854–867.

9. M. Haakman, L. Cruz, H. Huijgens, and A. van Deursen, “AI lifecycle models need to be revised: An exploratory study in fintech,” Empirical Softw. Eng., vol. 26, pp. 1–29, Jul. 2021, doi: 10.1007/s10664-021-09993-1.

10. D. Hershcovich, N. Webersinke, M. Kraus, J. A. Bingler, and M. Leippold, “Towards climate awareness in NLP research,” 2022, arXiv:2205.05071.

11. L. Lannelongue, J. Grealey, and M. Inouye, “Green algorithms: Quantifying the carbon footprint of computation,” Adv. Sci., vol. 8, no. 12, pp. 1–10, 2021.

12. A. Lacoste, A. Luccioni, V. Schmidt, and T. Dandres, “Quantifying the carbon emissions of machine learning,” 2019, arXiv:1910.09700.

13. Z. Li, “Train big, then compress: Rethinking model size for efficient training and inference of transformers,” in Proc. 37th Int. Conf. Mach. Learn., 2020, pp. 5958–5968.

14. G. Menghani, “Efficient deep learning: A survey on making deep learning models smaller, faster, and better,” ACM Comput. Surv., vol. 55, no. 12, pp. 1–37, 2021, doi: 10.1145/3578938.

15. D. Patterson, “The carbon footprint of machine learning training will plateau, then shrink,” Computer, vol. 55, no. 7, pp. 18–28, 2022, doi: 10.1109/MC.2022.3148714.

16. K. Pappu, B. Bhushan and A. Mittal, "SPIFFE-Based Zero-Trust Authentication for AI Agent Ecosystems," 2025 International Conference on Computer and Applications (ICCA), Bahrain, Bahrain, 2025, pp. 1-7, doi: 10.1109/ICCA66035.2025.11431026.

17. R. Schwartz, J. Dodge, N. A. Smith, and O. Etzioni, “Green AI,” Commun. ACM, vol. 63, no. 12, pp. 54–63, Nov. 2020, doi: 10.1145/3381831.

18. E. Strubell, A. Ganesh, and A. McCallum, “Energy and policy considerations for deep learning in NLP,” 2019, arXiv:1906.02243.

19. R. Verdecchia, R. Sallou, and L. Cruz, “A systematic review of Green AI,” Wiley Interdisciplinary Reviews: Data Mining Knowledge Discovery, Wiley Online Library, 2023, Art. no. e1507.

20. R. Verdecchia, L. Cruz, J. Sallou, M. Lin, J. Wickenden, and E. Hotellier, “Data-centric Green AI an exploratory empirical study,” in Proc. Int. Conf. ICT Sustainability, Plovdiv, Bulgaria, 2022, pp. 35–45.

21. J. Xu, W. Zhou, Z. Fu, H. Zhou, and L. Li, “A survey on green deep learning,” 2021, arXiv:2111.05193.

22. D. Rydning, J. Reinsel, and J. Gantz, “The digitization of the world from edge to core,” Framingham: Int. Data Corporation, vol. 16, pp. 1–28, 2018.

Downloads

Published

2026-09-14

How to Cite

Rohan Malhotra, & Meera Iyer. (2026). Adaptive Zero-Trust Authentication and Authorization for AI Agent Ecosystems Using SPIFFE/SPIRE. International Journal of Advance Scientific Research, 6(09), 51-62. https://doi.org/10.37547/ijasr-06-09-05

Similar Articles

31-40 of 291

You may also start an advanced similarity search for this article.