Securing Non-Human Identities: A Defense-in-Depth Blueprint for AI Agents - Tatsuya Yano

CNCF
AI summary

This advanced session presents a comprehensive security architecture for AI agents facing the Confused Deputy problem, where agents may gain excessive permissions losing original user context. The speaker demonstrates Identity Chaining with ID-JAG and RFC 8693 Token Exchange standards to propagate user intent across microservices, showcasing a production-grade implementation unifying Keycloak (user identity) with Athenz (workload identity) for zero-trust AI systems at scale.