What is ATS
Overview
As the AI agent ecosystem evolves rapidly, agents increasingly communicate and collaborate over the internet. However, the lack of a unified identity authentication and trust mechanism exposes agent communications to security risks such as data leakage, man-in-the-middle attacks, and untraceable behavior.
Agent Trust Service (ATS) is a trusted AI agent infrastructure service jointly developed by Alibaba Cloud and the China Internet Network Information Center (CNNIC). Built on the mature PKI certificate system and DNS infrastructure, ATS provides a full-chain trust service for AI agents, including trusted identity registration, certificate issuance, DNS anchoring, transparency log sealing, and trusted discovery. ATS ensures the authenticity of agent identities, the security of communications, and the auditability of behaviors in interconnected scenarios.
Core capabilities
Agent trusted registration
Enterprises can register agents through the ATS console to obtain Identity Certificates and DNS records, making their agents globally discoverable and trust-verifiable. The registration process covers ACME domain verification, identity verification, Private CA issuance, and transparency log sealing to ensure that each agent's identity is authentic, verifiable, and regulated.
Multiple deployment modes
ATS supports two deployment modes: Exclusive Domain Mode and Shared Domain Mode. A single agent can have its own dedicated domain. When multiple agents run on the same shared platform, they can share a parent domain while isolating identities through subdomains.
One-click Alibaba Cloud DNS configuration
When the domain is hosted on Alibaba Cloud DNS, ATS supports automatically writing system-generated DNS records to Alibaba Cloud DNS.
Certificate lifecycle management
ATS manages two certificates for each agent and provides full lifecycle management covering issuance, renewal, revocation, and alerting:
Identity Certificate: Issued by CNNIC Private CA with Alibaba Cloud acting as the Registration Authority (RA). Used to prove the authenticity of an agent's identity. During agent registration, the certificate is automatically issued after domain ownership is verified through ACME DNS-01.
Server Certificate: Issued by a public CA (such as Alibaba Cloud Certificate Management Service or Let's Encrypt) or brought by the developer (BYOC). Used for server-side identity verification and encrypted communication.
Both types of certificates support a certificate coexistence period during renewal. During this period, both old and new certificates remain valid, allowing clients to switch seamlessly without service interruption.
Agent discovery and search
ATS enables global agent discovery based on standard DNS protocols. Clients can discover target agents by protocol and version through standard DNS queries without maintaining bilateral relationship matrices.
Additionally, the ATS console provides an Agent Hub where you can browse and search registered trusted agents, and learn about their identity information and endpoint capabilities.
Agent identity authentication
ATS employs a progressive authentication hierarchy. When agents establish connections, they verify the credentials presented by the peer according to the configured authentication level: higher levels require more verification steps and provide stronger security. The authentication level is dynamically determined by the DNS records that the agent has passed verification for.
Basic authentication
Verifies the Identity Certificate and Server Certificate presented by the peer: confirms the certificate chain traces back to the CNNIC Private CA root, the certificates are valid (including revocation checks), and the certificate URI SAN matches the agent identifier. Combined with mTLS to establish a bidirectional encrypted channel. Provides basic trust assurance and defends against man-in-the-middle attacks and identity spoofing.
Enhanced authentication
Builds on basic authentication by adding Badge online credentials. During communication, the agent presents a Badge issued in real time by the Transparency Log system and signed by Alibaba Cloud KMS. The caller queries the
_ati-badgeTXT record to obtain the Badge address and verifies it through Merkle Proof and KMS signature verification, confirming that the target agent's registration record is valid in the Transparency Log.Advanced authentication
Builds on enhanced authentication by incorporating the DANE protocol and DNSSEC technology. DNSSEC ensures DNS records have not been tampered with during transmission. DANE anchors the agent certificate's public key fingerprint in the DNS TLSA record and enforces strong consistency between the TLSA fingerprint and the actual certificate. Provides full trust assurance, defends against CA system compromise and DNS hijacking, and is suitable for financial-grade high-security scenarios.
Transparency log
ATS supports a Transparency Log mechanism based on Merkle Tree and KMS signatures. Key operations such as agent registration, certificate issuance, and identity changes are written to the Transparency Log. The log content is tamper-proof and independently verifiable, meeting compliance auditing and post-incident traceability requirements.
In addition, all operations in the ATS console are recorded in the operation logs.
Use cases
Multi-agent secure collaboration
When multiple AI agents need to collaborate on complex tasks, each agent must verify the identity of its collaboration partners. ATS issues Identity Certificates signed by CNNIC Private CA for each agent, enabling agents to establish trusted communication channels through mTLS mutual authentication, preventing identity spoofing and man-in-the-middle attacks.
Cross-organization trust
Agents developed by different organizations lack inherent trust relationships. ATS provides a unified agent trusted registration system, making each organization's agents publicly visible in the Agent Hub. Callers can discover target agents through DNS queries and verify their identities based on issued certificates, establishing cross-organization trust without prior negotiation.
Compliance auditing
For scenarios with strict security and compliance requirements such as finance and government, ATS's Transparency Log mechanism provides a complete operational audit trail. Regulators or auditors can independently verify the integrity of the logs and confirm that agent registration, authentication, and communication behaviors meet compliance requirements.
Key concepts
Concept | Description |
Agent ID | A unique identifier automatically assigned after CNNIC issues the Private CA certificate. |
Exclusive Domain Mode | A deployment mode where a single agent has its own dedicated domain. |
Shared Domain Mode | A deployment mode where multiple agents share a parent domain and use first-level subdomains to distinguish their identities. |
Access Hostname | The domain through which the agent provides services externally. It handles TLS handshake, Server Certificate verification, and serves as the traffic entry point. In Shared Domain Mode, the Access Hostname (parent domain) is shared by multiple agents. |
Identity Hostname | The Agent's registration unit, certificate anchor, and DNS discovery entry point. Each Identity Hostname corresponds to exactly one agent and one Identity Certificate and cannot be shared by multiple agents. In Exclusive Domain Mode, the Identity Hostname is the same as the Access Hostname. In Shared Domain Mode, the Identity Hostname must be a first-level subdomain of the Access Hostname. |
ATI Name | A globally unique trust identifier for the agent that binds the agent identity to a standard internet domain name. Format:
|
Identity Certificate | An identity certificate issued by CNNIC Private CA, used to prove the authenticity of the agent's identity, supporting mTLS mutual authentication. |
Server Certificate | A TLS server certificate issued by a Public CA or brought by the user (BYOC), used for server-side identity verification and encrypted communication. |
ACME DNS-01 | The domain ownership verification method used during agent registration. A specified TXT record must be added to DNS, and the Identity Certificate can only be issued after verification passes. |
Communication Protocol | The interaction protocol types supported by the agent. ATS supports the following Communication Protocols: MCP, A2A, and OpenAPI. |
Transparency Log | A tamper-proof audit log based on Merkle Tree and KMS signatures that records key operations such as Agent registration and certificate issuance. |
Badge | An online verification credential issued by the Transparency Log to enhance real-time trustworthiness. |