AI智能体已不再只是回答问题。它们会购物、预订行程、注册服务,并越来越多地代表用户采取行动。然而,当智能体访问某个网站或应用时,企业如何知道它代表的是谁,以及它究竟获准做什么?Animoca Brands旗下的数字身份项目Moca Network认为,它给出了部分答案。它与Moca Foundation共同推出了Moca Chain主网,这是一条专为数字身份而建的区块链。
AI agents are no longer just answering questions. They’re shopping, booking trips,g up for services, and increasingly acting on their users’ behalf. However, when an agent shows up at a website or app, how does the business know who it’s working for, and what it’s actually allowed to do? Moca Network, the digital identity project from Animoca Brands, thinks it has part of the answer. Together with the Moca Foundation, it launched the mainnet of Moca Chain, a blockchain built specifically for digital identity.
为个人打造的身份体系 互联网上的大多数身份系统都是为个人而建的。你创建一个账户,提交一些个人信息,然后逐个平台授予权限。你一遍又一遍地进行同样的验证,留下散落在各项服务中的数据副本。智能体让情况变得更糟。同一个智能体可能为了同一个人而穿梭于十多项服务之间,而每一家企业仍需知道其背后是谁,以及它的权限边界在哪里。
Identity built for people Most of the internet’s identity systems were built for people. You create an account, hand over some personal details,, and grant permissions one platform at a time. You repeat the same verification over and over, leaving copies of your data scattered across services. Agents make that worse. A single agent might hop between a dozen services for the same person. Each of those businesses still needs to know who’s behind it and where its authority ends.
假设你让一个购物智能体寻找并预订一张400美元以下的机票。这不应意味着可以任由它使用你的个人数据、已保存的银行卡,或随意购买其他东西。证明智能体的合法性绝非易事。这意味着还必须同时建立一条将用户、智能体及其接触的企业连接起来的信任链。无论智能体走到哪里,这条信任链都必须随之而行。
Say you’ve told a shopping agent to find and book a flight under $400. That shouldn’t give it free rein over your personal data, your saved cards, or the ability to buy whatever else it likes. Proving an agent is legitimate is no easy task. It also means simultaneously building a chain of trust that links the user, the agent, and the businesses it deals with. That chain has to travel with the agent wherever it goes.
为智能体互联网构建身份体系 Moca Chain从设计之初就围绕身份体系展开。它并未将身份功能硬生生附加到一条通用区块链上,而是让各类组织验证用户数据,并在链上签发防篡改凭证。这些组织包括银行和金融平台、电信运营商、零售商及票务服务商。用户自行持有这些凭证,并决定在何处分享。
Building identity for the agentic web Moca Chain is designed around identity from the start. Instead of bolting identity features onto a general-purpose chain, it lets organizations verify a user’s data and issue tamper-proof credentials on-chain. Those organizations include banks and financial platforms, telcos, retailers, and ticketing services. Users hold those credentials themselves and decide where to share them.
当某个应用需要核验信息,例如你是否已通过KYC(了解你的客户)或是否持有某项会员资格时,它获取的是经数字认证的确认凭证,而不是你的文件副本。如果某项凭证被更新或撤销,这一变化会同步反映在整个网络中,因此每个互联应用都能看到最新状态,而你无需重新提交任何材料。
When an app needs to check something, like whether you’ve passed KYC or hold a certain membership, it gets a digitally certified confirmation rather than a copy of your documents. And if a credential is updated or revoked, that change is reflected across the whole network, so every connected app sees it without you having to re-submit anything.
AIR,这一集成层在此次发布的同时,Moca Network正将全部重心放在AIR上。AIR是Moca Network面向身份、支付和会员体系的集成层,构建于Moca Chain之上,并持续增加企业、基础设施和数据合作伙伴。它为企业提供了一个统一的集成点,用于接入用户及其AI智能体。
AIR, the integration layer Alongside the launch, Moca Network is putting its full focus on AIR, its integration layer for identity, payments, and loyalty. AIR is built on Moca Chain and continues to add enterprise, infrastructure, and data partners. It gives businesses a single integration point for onboarding users and their AI agents.
它支持双向运作。企业可以将现有的客户核验流程转化为Moca Chain上的凭证;也可以接受可信合作伙伴签发的凭证,以加快用户注册,并根据经过验证的数据开放相应权限。这样一来,企业既能共享已掌握的客户信息,又无需自行存储那么多个人资料。
It works in both directions. A company can turn the customer checks it already runs into credentials on Moca Chain. Or it can accept credentials issued by trusted partners to speed up sign-ups and unlock access based on verified data. The upshot is that businesses can share what they know about a customer without having to store as much personal information themselves.
AIR还将这一能力延伸至AI智能体,允许用户设置智能体的权限和授权规则。在向智能体提供访问权限、定价、服务或优惠之前,企业可以同时核验智能体及其人类所有者的身份,还可以确认该智能体获准执行的操作范围。在实际应用中,智能体可以证明自己有权进行某类购买,而用户不必一次又一次地披露授权背后的个人详细信息。
AIR also extends this to AI agents by letting users set an agent’s permissions and authorization rules. Before offering an agent access, pricing, services, or deals, a business can verify both the agent and its human owner. It can also confirm the scope of what the agent has been cleared to do. In practice, an agent could prove it’s authorized to make a certain kind of purchase without the user having to expose the personal details behind that authorization again and again.
这一点至关重要,因为智能体商业的未来不会仅仅取决于AI能否完成任务。企业还必须充分信任智能体,才会让它执行相关任务。
That matters, because the future of agentic commerce won’t hinge only on whether AI can do the task. Businesses also have to trust the agent enough to let it.
从人类身份到委托身份:所有这些变化都重新定义了数字身份的职责。对个人而言,身份核验通常是为了回答:“你是否就是自称的那个人?年龄是否达标?是否已完成规定的验证?”智能体又带来了另一个问题——委托。一个智能体即使完全真实可信,也不一定获准执行某项特定操作。因此,身份不仅必须表明智能体背后是谁,还必须说明此人批准了哪些事项。
From human identity to delegated identity All of this changes what digital identity has to do. For people, identity checks have mostly answered “Are you who you say you are? Are you old enough? Have you passed the required verification?”Agents then add another question, which is delegation. An agent can be perfectly genuine and still not have permission to do a particular thing. So identity has to convey not just who’s behind the agent but what that person has signed off on.
Moca Network首席执行官肯尼斯·谢克表示,虽然AI智能体需要可扩展的数据共享来代表人们采取行动,但“委托和权限方面的信任框架仍然缺失”,而平台为了实现智能体自动化,往往会牺牲用户隐私。AIR的解决方案是采用范围明确、由用户自行定义的权限,而不是允许智能体无限制访问用户的全部数据或账户。
Moca Network CEO Kenneth Shek says that while AI agents need scalable data sharing to act for people, “the trust framework for delegation and authority is lacking,” and that platforms have often traded away user privacy to make agent automation work. AIR’s answer is scoped, user-defined permissions instead of blanket access to someone’s data or accounts.
这可以让授权更加细化。你可以允许智能体预订酒店,但仅限于既定预算;只能使用某些特定服务;或者只能调用特定的经验证属性,而无需披露底层数据。当智能体不再需要这些权限时,你还可以将其收回。
That could make authorization much more fine-grained. You might let an agent book hotels but only within a set budget, deal only with certain services, or use specific verified attributes without revealing the data underneath. And when you no longer need it to have those permissions, you can take them back.
身份即基础设施:Moca宣布主网启动,合作伙伴已覆盖消费平台、金融科技、忠诚度计划及智能体商务等领域,包括SK Planet、Biletinial、Oyunfor、Open Campus、OneFootball、Automobili Lamborghini、Inveo Kripto、Plume和Nansen。
Identity as infrastructure Moca launches mainnet with partners already on board across consumer platforms, fintech, loyalty programs, and agentic commerce. They include SK Planet, Biletinial, Oyunfor, Open Campus, OneFootball, Automobili Lamborghini, Inveo Kripto, Plume, and Nansen.
Animoca Brands联合创始人兼执行主席叶钊说,现有模式不仅浪费用户时间,还把用户锁定在他们已经完成身份验证的平台上。这让竞争性的商户和服务商更难争取到这些用户。
Yat Siu, co-founder and executive chairman of Animoca Brands, argues the current model doesn’t just waste users’ time. It also keeps them locked into platforms where they’re already verified. That makes it harder for competing merchants and providers to win them over.
如果智能体成为人们与在线服务交互的主要方式,身份识别与授权就需要像互联网的核心基础设施一样:能够在不同应用之间移植,可由不同组织验证,能够保护隐私,并且易于更新或撤销。数十年来,人们一直在构建各种方法,以证明访问账户的是真人。而现在需要的是一种方法,以证明某个软件正在代表正确的人、拥有正确的权限,并在正确的时刻采取行动。仅仅让智能体具备能力还不够,要让互联网的其余部分信任它们,还需要新的创新。
If agents become the main way people interact with online services, identity and authorization will need to work like core internet infrastructure: portable across apps, checkable by different organizations, protective of privacy, and easy to update or revoke. Decades have been spent building ways to prove that a human can access an account. What’s needed now is a way to prove that a piece of software is acting for the right person, with the right permissions, at the right moment. Beyond just making agents capable, getting the rest of the internet to trust them requires new innovation.
投稿文章。本文并非由 TNW 新闻编辑部制作,不代表 TNW 的编辑立场。
Contributed article. Not produced by the TNW newsroom and does not reflect the editorial stance of TNW.