To obtain access to full text of journal and articles you must register!
- Article name
- Methodology for protecting AI system authorization tokens when using MCP servers
- Authors
- Gezhin S. A., , gezhinsergey@mail.ru, Moscow Polytechnic University, Moscow, Russia
Pikov V. A., , pikov@yandex.ru, Moscow Aviation Institute (National Research University), Moscow, Russia
- Keywords
- Model Context Protocol / MCP / authorization tokens / AI agents / Prompt Injection / transit encapsulation / intent verification / information security
- Year
- 2026 Issue 3 Pages 31 - 35
- Code EDN
- IXCSIE
- Code DOI
- 10.52190/2073-2600_2026_3_31
- Abstract
- The rapid proliferation of AI agents interacting with corporate services via the Model Context Protocol (MCP) gives rise to a qualitatively new class of information security threats. The non-deterministic nature of language models renders traditional transport-layer protection insufficient for ensuring the confidentiality of authorization tokens. This article presents a three-component methodology of transit encapsulation and intent verification implementing the defence-in-depth principle. The methodology comprises an algorithm for transit encapsulation of secrets using surrogate identifier substitution, an algorithm for two-way semantic inspection of input data, and an algorithm for detailed auditing and verification of the AI agent's intent. Experimental verification on a Linux-based testbed demonstrated an increase in the security coefficient from 15 % to 97 %, with a false-positive rate of 3 % and an overhead of 26.5 ms under the test dataset. The results indicate the applicability of the methodology in the design of secure enterprise AI systems.
- Text
- BUY for read the full text of article
- Buy
- 800.00 rub