<p>Recent cybersecurity incidents in Korea have heightened public concern regarding digital trust, access governance, and accountability within large scale platform infrastructures [<CitationRef CitationID="CR8">8</CitationRef>, <CitationRef CitationID="CR31">31</CitationRef>, <CitationRef CitationID="CR52">52</CitationRef>]. This paper utilizes these incidents as contextual examples of access governance and platform accountability issues, rather than as direct evidence of failures in agentic commerce. It posits that the proliferation of agentic commerce where AI agents are capable of initiating purchases, processing payments, and executing contractual actions on behalf of users may exacerbate the existing trust deficit. This is due to the potential disconnection between a user’s original intent and the final transaction outcome [<CitationRef CitationID="CR1">1</CitationRef>, <CitationRef CitationID="CR42">42</CitationRef>, <CitationRef CitationID="CR46">46</CitationRef>]. To address this issue, the paper proposes a Public Key Infrastructure (PKI)-based delegation architecture. This architecture treats the delegation moment as a legally significant electronic declaration of intent, captured through a user’s digital signature and encoded as a time-bounded, scope-limited delegation certificate, which must be presented and verified at the time of execution. The proposed design prioritizes non-repudiation, least-privilege authority, revocation, verifiable provenance, and auditable dispute resolution [<CitationRef CitationID="CR4">4</CitationRef>, <CitationRef CitationID="CR7">7</CitationRef>, <CitationRef CitationID="CR28">28</CitationRef>, <CitationRef CitationID="CR53">53</CitationRef>]. The paper concludes by explaining why South Korea is a plausible candidate for early adoption under specific institutional and governance conditions: its historical experience with certificate-based authentication provides relevant institutional capacity, while its previous certificate regime highlights the necessity for any renewed public trust infrastructure to be modular, privacy-preserving, risk-based, and contestable [<CitationRef CitationID="CR3">3</CitationRef>, <CitationRef CitationID="CR36">36</CitationRef>, <CitationRef CitationID="CR37">37</CitationRef>].</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Delegating trust in agentic commerce: a PKI-based governance architecture for South Korea

  • Dong Soon Kang,
  • Young Hee Ko

摘要

Recent cybersecurity incidents in Korea have heightened public concern regarding digital trust, access governance, and accountability within large scale platform infrastructures [8, 31, 52]. This paper utilizes these incidents as contextual examples of access governance and platform accountability issues, rather than as direct evidence of failures in agentic commerce. It posits that the proliferation of agentic commerce where AI agents are capable of initiating purchases, processing payments, and executing contractual actions on behalf of users may exacerbate the existing trust deficit. This is due to the potential disconnection between a user’s original intent and the final transaction outcome [1, 42, 46]. To address this issue, the paper proposes a Public Key Infrastructure (PKI)-based delegation architecture. This architecture treats the delegation moment as a legally significant electronic declaration of intent, captured through a user’s digital signature and encoded as a time-bounded, scope-limited delegation certificate, which must be presented and verified at the time of execution. The proposed design prioritizes non-repudiation, least-privilege authority, revocation, verifiable provenance, and auditable dispute resolution [4, 7, 28, 53]. The paper concludes by explaining why South Korea is a plausible candidate for early adoption under specific institutional and governance conditions: its historical experience with certificate-based authentication provides relevant institutional capacity, while its previous certificate regime highlights the necessity for any renewed public trust infrastructure to be modular, privacy-preserving, risk-based, and contestable [3, 36, 37].