一、思维级同意 vs 行为级同意
传统 App 里的“同意”,本质是点击按钮或语音确认,属于行为级同意。而 脑机 Agent 的“同意”可能直接来自脑信号本身——你怎么确认这就是自己的真实意图?
| 维度 |
行为级同意 |
思维级同意 |
| 触发 |
点击/语音确认 |
连续3次同一意图 |
| 误触风险 |
低 |
中 (需去抖) |
| 过期 |
永不过期 |
5分钟自动过期 |
// 同意状态: 四级
#[derive(Debug, Clone, Copy, PartialEq, PartialOrd)]
pub enum ConsentState {
NotGiven, // 未授权
PassiveAware, // 被动知晓 (知道在采集, 但未明确同意)
ActiveConsent, // 主动同意 (连续3次同一意图)
Withdrawn, // 已撤回
}
// 风险等级: 三级
#[derive(Debug, Clone, Copy, PartialEq, PartialOrd)]
pub enum RiskLevel {
Low, // 低: 移动光标/滚动
Medium, // 中: 输入文字/选择
High, // 高: 发送消息/支付/删除
}
// 意图->风险映射
impl RiskAssessor {
pub fn assess(action: &str) -> RiskLevel {
match action {
"move_cursor" | "scroll" | "click" => RiskLevel::Low,
"type_text" | "ui_select" | "voice_output" => RiskLevel::Medium,
"send_message" | "payment" | "delete_file" => RiskLevel::High,
_ => RiskLevel::Medium, // 未知默认中风险
}
}
}
二、ConsentManager
// 同意管理器: 5分钟自动过期
pub struct ConsentManager {
state: RwLock<ConsentState>,
consented_actions: HashMap<String, bool>,
granted_at: Option<u64>,
auto_expire_ms: u64,
confirm_count: HashMap<String, u32>, // 确认计数
required_confirms: u32, // 需要确认次数 (默认3)
}
impl ConsentManager {
pub fn new() -> Self {
Self {
state: RwLock::new(ConsentState::NotGiven),
consented_actions: HashMap::new(),
granted_at: None, auto_expire_ms: 300_000,
confirm_count: HashMap::new(), required_confirms: 3,
}
}
pub fn can_execute(&self, action: &str) -> bool {
let state = *self.state.read();
match state {
ConsentState::ActiveConsent => {
// 检查过期
if let Some(ts) = self.granted_at {
if now_ms() - ts > self.auto_expire_ms { return false; }
}
self.consented_actions.get(action).copied().unwrap_or(false)
}
ConsentState::PassiveAware => {
// 被动知晓: 仅允许低风险
RiskAssessor::assess(action) == RiskLevel::Low
}
_ => false,
}
}
// 累计确认: 连续3次同一意图 -> 主动同意
pub fn record_confirm(&mut self, action: &str) -> bool {
let count = self.confirm_count.entry(action.into()).or_insert(0);
*count += 1;
if *count >= self.required_confirms {
self.grant(action);
*count = 0;
return true; // 已达到主动同意
}
false
}
pub fn grant(&mut self, action: &str) {
*self.state.write() = ConsentState::ActiveConsent;
self.consented_actions.insert(action.into(), true);
self.granted_at = Some(now_ms());
}
pub fn withdraw(&mut self) {
*self.state.write() = ConsentState::Withdrawn;
self.consented_actions.clear();
self.confirm_count.clear();
}
}
三、访问控制策略
// 访问控制策略引擎
pub struct AccessControl {
policy: HashMap<RiskLevel, ConsentState>,
}
impl AccessControl {
pub fn new() -> Self {
let mut policy = HashMap::new();
policy.insert(RiskLevel::Low, ConsentState::PassiveAware);
policy.insert(RiskLevel::Medium, ConsentState::ActiveConsent);
policy.insert(RiskLevel::High, ConsentState::ActiveConsent);
Self { policy }
}
pub fn check(&self, risk: RiskLevel, consent: ConsentState) -> AccessResult {
let required = self.policy.get(&risk).copied()
.unwrap_or(ConsentState::ActiveConsent);
if consent >= required {
AccessResult::Allowed
} else {
AccessResult::Denied { required, current: consent,
message: format!("需要{:?}级别同意", required) }
}
}
}
#[derive(Debug)]
pub enum AccessResult {
Allowed,
Denied { required: ConsentState, current: ConsentState, message: String },
}
四、完整演示
use bci_agent::*;
#[tokio::main]
async fn main() -> anyhow::Result<()> {
let mut consent = ConsentManager::new();
let acl = AccessControl::new();
// 场景1: 低风险 (移动光标) - 被动知晓即可
let risk = RiskAssessor::assess("move_cursor"); // Low
let state = *consent.state.read();
println!("[Low] move_cursor: {:?}", acl.check(risk, state));
// 场景2: 高风险 (发送消息) - 需要主动同意
let risk = RiskAssessor::assess("send_message"); // High
println!("[High] send_message (before): {:?}",
acl.check(risk, *consent.state.read()));
// 连续3次确认 -> 主动同意
for i in 1..=3 {
let granted = consent.record_confirm("send_message");
println!(" confirm {}: granted={}", i, granted);
}
println!("[High] send_message (after): {:?}",
acl.check(risk, *consent.state.read()));
// 5分钟后过期 (模拟)
println!("[Expire] 5min later: can_execute={}",
consent.can_execute("send_message"));
Ok(())
}
五、运行输出
[Low] move_cursor: Allowed
[High] send_message (before): Denied { required: ActiveConsent, ... }
confirm 1: granted=false
confirm 2: granted=false
confirm 3: granted=true
[High] send_message (after): Allowed
[Expire] 5min later: can_execute=false
| 风险 |
操作 |
需同意级别 |
过期 |
| 低 |
移动光标/滚动 |
PassiveAware |
不过期 |
| 中 |
输入文字/选择 |
ActiveConsent |
5分钟 |
| 高 |
发消息/支付/删除 |
ActiveConsent |
5分钟 |
七、总结
- 四级同意:
NotGiven -> PassiveAware -> ActiveConsent -> Withdrawn
- 三级风险:
Low(光标) Medium(文字) High(消息/支付)
- 连续3次同一意图 = 主动同意,5分钟自动过期
- 低风险被动知晓即可,中高风险必须主动同意
- 用户可随时
withdraw 撤回所有同意
下篇拆差分隐私与审计