Security design for NLIP: a universal protocol for AI-enabled systems

Sanjay Aiyagari, Elisa Bertino, Jan Bieniek, Yan-Ming Chiou, Raj Dodhiawala, Sean Hughes, Sugih Jamin, Ashish Kundu, Jon Lenchner, Matthew Louis Mauriello, Abhay Ratnaparakhi, Mohamed Rahouti, Tom Sheffler, Chien-Chung Shen, Dinesh Chandra Verma, Jinjun Xiong, Luyi Xing, Wenpeng Yen, Hasan Zengin · 2025

NLIP or Natural Language Interaction Protocol is being defined by a group of researchers that enables a universal, standards-based application-level protocol to work across AI Enabled Services. NLIP leverages the capabilities of large language models to transform unstructured natural language to a structured representation at the endpoints, replacing multiple individual application protocols with a single one. The design of such a protocol must necessarily include security considerations, paying significant attention to protocol integrity, privacy, data governance and cybersecurity defenses. In this paper we discuss the approaches we have introduced to maintain these security elements of the protocol. The security of the protocol requires not only taking into consideration the needs of communication flow on the wire, but also to handle the security requirements of the endpoints. This requires appropriate support for functions like authentication and authorization, where some of these services can be provided by a third-party service provider. Furthermore, many existing security protocols and paradigms are already supported by existing software services which NLIP may utilize which we need to be able to leverage them at server endpoints. An application-level protocol needs to leverage existing services while still ensuring adequate security at the application level. We discuss the challenges in designing security for an application-level protocol like NLIP and discuss how we have addressed these problems to ensure a secure implementation of NLIP.

Read the paper · More papers on PaperTik