Lineage: A UMA2.0 Protocol Extension for Multi-Hop LLM Agent Delegation

Ştefania Ştefănescu, Iulian Aciobăniţei · IEEE Access · 2026

Autonomous Large Language Model (LLM) agents in enterprise and compliance-sensitive systems delegate authority to sub-agents to decompose complex tasks. OAuth 2.0 and User-Managed Access (UMA) 2.0 support delegated authorization between a single requesting party and a resource server, but they lack primitives for the multi-hop authority propagation typical of agent chains. This produces ad hoc permission models and audit gaps incompatible with regulations such as the EU Digital Operational Resilience Act (DORA). This paper presents Lineage, an authorization architecture that extends UMA 2.0 with a cryptographically verifiable delegation-chain primitive: every protected request carries a signed record of its full delegation ancestry, validated at the resource server without an additional authorization-server round-trip. Scope monotonicity and bounded delegation depth are enforced by construction, and every authorization decision is recorded in a tamper-detecting audit log. These properties directly implement the technical controls that DORA Article 9 mandates: least-privilege access (Art. 9(4)(c)), data integrity and authenticity (Art. 9(2)), and continuous ICT monitoring (Art. 9(1)). Full DORA compliance requires broader institutional governance beyond any software protocol; Lineage addresses the protocol-layer subset. We validated the design end-to-end on a reference implementation running live LLM agents under DORA-representative scenarios. One test involved an active prompt-injection attempt; the protocol layer blocked it independently of model behavior, which is precisely the property a deployment operator needs to rely on. Per-request overhead remained negligible relative to the UMA baseline. Lineage maintains full OAuth 2.0 and UMA 2.0 conformance. It extends an existing resource server with two chain-signing endpoints and a signing secret, requiring no changes to the authorization server or the UMA token flow.

Read the paper · More papers on PaperTik