My understanding is that the integrity of the contents is assured due to the identifier being a hash of the content. From there I don't think it's really needed for a whole protocol to verify the author. Couldn't something as simple as a gpg signature be sufficient? If they signed the hash and gave it to you then it would be good
I suppose I could copy and paste an inline signature from the ipfs content into some other software. Standard support in the protocol for this would be very helpful though.
(‘hecturchi’s response hints at how IPFS achieves this, I think.)