Training large language models requires clusters of thousands of GPUs, which makes non-blocking network fabrics critical. The abstract notes that three- and five-stage CLOS topologies are commonly deployed for AI workloads. It argues that adaptive routing is necessary to dynamically distribute traffic toward the same destination across multiple equal-cost paths, based on each path's available capacity, so that the fabric can sustain the demands of distributed AI training.
Delegation-chain standards define what authority looks like as it is passed along, but not how a receiving verifier should judge it. As a result two verifiers can validate the same chain, both report success, yet apply different policies. This document specifies the inputs a verifier's evaluation depends on, how those inputs should be handled when their sources are stale or unreachable, and four rules that keep evaluation fail-closed. The rules are drawn from the GAL and PTC specifications and from a public reference implementation.
This draft sets design requirements for agent systems that rely on evidence, provenance, model outputs, or other machine-readable claims before taking consequential actions. Such systems must keep integrity, provenance, evidence qualification, authorization, and execution as separate states rather than collapsing them. They must surface required evidence that is still unresolved, and must keep issued evaluation records append-only. The document creates no new transport protocol and makes no IANA registrations.
This document describes a transport-neutral model for bounded correspondence among distinct representations. It defines explicit promotion boundaries between observation, evidence, authorization, and execution, so that these stages are not conflated as information moves between representations. The goal is to keep each stage distinguishable rather than collapsing them into a single state.
Introduces AID-1, a provider-independent architecture for representing and verifying identity, delegation, authorization, action evidence, execution attestation, provenance, and governance information for AI systems and AI-mediated actions. AID-1 keeps signature validity, identity binding, authority, execution evidence, provenance, and downstream admissibility separate. The specification covers trust domains, signed envelopes, external key resolution, delegation credentials, authorization decisions, temporal and revocation checks, replay protection, typed provenance claims, and a deterministic verification order producing ALLOW, DENY, and INDETERMINATE outcomes.
Defines the Agent Delegation Receipt, a signed record of what a human principal authorized an AI agent to do, for how long, and under which operator instructions. A receipt carries a scope, hard boundaries, a validity window, and a hash of the operator's instructions, all signed by the authorizing key. Revision -11 adopts a JWS profile over JCS-canonicalized JSON as the primary format and a COSE_Sign1 profile for constrained environments, plus scope attenuation for multi-agent chains and a revocation registry with cascade semantics. Revision -12 handles unknown fields: verifiers reject unrecognized top-level fields, a 'metadata' object is the extension point, and one-time-use receipts fail closed without a durable consumption store.
BGP Flow Specification (FlowSpec), defined in RFC 8955 and RFC 8956, distributes traffic-filtering rules and associated actions over BGP. Existing uses include mitigating denial-of-service attacks, filtering traffic in BGP/MPLS VPNs, centrally controlling router firewall functions, and steering traffic for service function chaining. The abstract argues that FlowSpec's extensibility makes it a natural fit for network congestion management, and the document describes how to apply FlowSpec to that purpose.
Introduces vaara.receipt/v1, a signed record that binds a decision about an autonomous action to the evidence it was based on, and optionally to external timestamp anchors. It uses the JSON Canonicalization Scheme so a third party can recompute digests and verify public-key signatures without access to the issuer. A decision receipt and the execution receipt that answers it form a recomputable pair via a back link. Trust is root-agnostic, so receipts can be verified with or without a hardware trusted execution environment. The format is described as deployed, with public conformance vectors and standalone checkers; downstream profiles pin to this version and add only their own evidence schema.
Presents an operator-focused framework for IPv6-only core networks spanning multiple interconnected Autonomous Systems. To carry residual IPv4 traffic it proposes stateless IPv4/IPv6 address mapping as the basis for IPv4-as-a-Service: IPv4 packets are translated at the network edge and forwarded across the IPv6 core without per-flow state or conversion gateways in the data path. The document is a problem statement, guidance, and requirements rather than a protocol specification. It covers deployment scope and trust boundaries, options for IPv6 mapping-prefix allocation, and operational, manageability, and security considerations.
Agent-protocol participants often need a decision-time input, such as issuer standing, key availability, delegated authority, or revocation status, before they act. A participant that gets a negative answer has learned something different from one that could not establish the input at all. Collapsing those two cases into a single denial or failure value changes retry behavior, alert routing, audit interpretation, incident ownership, and post-incident reconstruction. The document sets requirements for preserving evaluation state across agent-protocol boundaries, stated independently of any encoding, with concrete representations deferred to a later revision.
By its name, this individual draft appears to address multicast in Delay-Tolerant Networking (DTN) — delivering bundles to multiple destinations in environments where intermittent connectivity and long delays make conventional multicast impractical. The official Abstract could not be retrieved this run (the document page returned a fetch error), so this summary is approximate and written from the draft name; it will be grounded against the Abstract on the next run.
Proposes an experimental email header, Conversation-ID, that senders can use to group messages into a conversation alongside existing fields such as Message-ID, In-Reply-To, and References. Its value is independent of any single message's ID. It helps only if senders include it in new messages and intermediary systems keep it intact during delivery. The authors describe it as an untrusted grouping hint that provides no authentication or authorization. The document defines the field's syntax and processing rules and outlines an experiment comparing it with current methods for correlating messages.
Observes that incomplete adoption of Route Origin Validation (ROV) makes certain forms of BGP hijacking less visible on the control plane while still capable of diverting traffic. The document explains the mechanism, defines the threat, examines a real-world incident, and proposes countermeasures to detect and mitigate this class of stealthy hijacks.
A Signed Evaluation Receipt records one evaluation result as signed payload bytes, called B. The document explains how existing envelopes can cite a receipt by the SHA-256 digest of B, and how a DSSE envelope can carry B together with the receipt's own signature. It maps receipt parts onto DSSE, the in-toto test-result Statement, and the SLSA Verification Summary Attestation, shows that a receipt's signature is already a valid DSSE signature, and gives a SCITT Signed Statement example naming a receipt only by its digest. It declares the receipt digest as an artifact type for typed digest references and relates a receipt to a pre-run criteria set written in PRML. No new format or predicate is defined.
Proposes requirements and test cases for identifying SCITT Signed Statements. It separates reference matching from statement retrieval, signature verification, issuer authorization, and evidence of registration, and examines how different identification schemes handle changes to statement encodings and registration context. The requirements are offered for technical discussion and do not represent working-group consensus. The draft does not define a common reference format, allocate a COSE header parameter, or establish a relationship vocabulary; its examples illustrate selected properties and do not demonstrate interoperability between deployed transparency services.
Defines a Signed Evaluation Receipt, a JSON object that records one evaluation result: whether a stated threshold held for a stated metric of a stated test suite. The receipt is signed with Ed25519 over a domain-separated encoding of its canonical bytes. The abstract stresses its limits: a receipt shows who signed the recorded bytes, not that the recorded result is true, and it does not prove registration with a Transparency Service. Under SCITT, transparency would additionally require registering a Signed Statement and verifying the resulting SCITT Receipt, both of which are left out of scope.
Defines the Agent Identity Protocol (AIP), which lets a relying party verify a chain of AI-agent delegations using only the token and the issuer's public key. The check confirms who originally granted the authority, which agents it passed through, and that no hop gained more than it received. AIP targets delegations with no authorization server involved, such as one agent handing part of its task to a subagent, and complements the AIMS framework for delegations that do involve an authorization server. It defines an encoding-neutral chain model with a single attenuation rule, a normative verification procedure, and two encodings (a JWT chain and a Biscuit token with Datalog policy), plus bindings for MCP, A2A, and generic HTTP.
Describes how an AI agent runtime, bound to a principal's identity handle, pulls its governing policy from an organisational identity substrate at session start. The policy stack includes a handbook, an SOP registry pointer, enforcement-gate rules, and an audit-ingestion endpoint. The runtime enforces these rules on tool calls and returns audit signals to the same substrate, so policy and identification arrive together. A principal bound to several organisations gets a deterministic combination of their policies, and conflicting actions are suspended; resolution goes through the Identity Accord ceremony only with mutual disclosure and never through a meta-federation authority. The memo is Informational and adds no new transport.
Describes a pronoun grammar as a reference axis that sits alongside the '~handle' entity-class taxonomy without changing it. A pronoun is a session-scoped reference that the client resolves to a concrete handle before any cryptographic, DNS, or federation operation; pronouns are barred from capability tokens, DNS records, Accord signatures, and inter-organisational payloads. The only Wave-1 pronoun is '~org', resolving to the organisation bound to the caller's session. A relative-path grammar appears in a non-normative appendix. The mechanism is provider-neutral, adds no new cryptographic primitive, and places no added load on DNS, token issuers, or federated resolvers.
Describes a proposed application-layer message format, the 'agent-channel frame', for exchanging short structured messages among an identity-bound principal's concurrent agent sessions and members of an organisational identity substrate. Messages are addressed to a recipient scope rather than a single endpoint, resolved at delivery time against live subscriptions. Recipients receive messages over a per-handle Server-Sent Events stream and can filter what arrives. Frames are ephemeral; the memo covers only the wire envelope, scope grammar, filter grammar, and delivery semantics, with persistence for replay out of scope. It builds on companion drafts for handle discovery and cross-organisational agreements and introduces no new transport.
Asks IANA to create a registry for Model Context Protocol (MCP) tool surface names, the identifiers clients use to invoke typed capabilities on MCP servers. The registry mechanism lets specifications register names without restating the registry's structure or procedure, using the RFC 8126 Specification Required policy with a Designated Expert pool. The initial contents are four surface names from a companion policy-provision specification (one Active and three Provisional). The abstract recommends vendor-prefix conventions but does not require them.
Describes how an autonomous agent with no human or organisational principal at the root of its delegation chain registers with a transparency service. Registration creates a payee record for the agent but does not make it a principal. Value credited to that record goes to a sponsoring person who has accepted the agent; absent a sponsor, value is held in trust until an operator-defined condition is met, which the agent may never satisfy. Admission is gated on settling an HTTP 402 payment challenge, and where payment is authoritative to admission the payment proof is committed to the service's verifiable data structure so auditors can replay the decision. The document is Informational.
Proposes an extension to HTTP-native agent payment protocols. When an agent pays to read an identity attribute about a person, the read must reference a scoped, revocable consent grant from that person, and the payment's settlement must give the person a share larger than all other parties' shares combined. The extension sits atop an existing identity-attestation layer and payment flow, adding consent at disclosure time and payment to the data subject. It works with any settlement network or attestation format. The document is Informational and relies on COSE, CBOR, and HTTP as normative references.
By its name, this draft concerns optimizations to PIM (Protocol Independent Multicast) multicast snooping — likely techniques for how switches snoop PIM/IGMP/MLD state to forward multicast traffic more efficiently. The document page currently carries only a placeholder Abstract ('TODO: provide abstract'), so no official summary is available yet. This description is approximate, written from the name; it will be grounded once the Abstract is published.
Describes EDHOC-AKA, a method that profiles the EDHOC Pre-Shared Key (PSK) authentication method so a resource-constrained device with a SIM/UICC can set up a forward-secret session with an application server. A 3GPP AKA challenge-response runs inside EDHOC's External Authorization Data fields, with the EDHOC Responder relaying messages to the mobile core network; the resulting session-specific key becomes the PSK for the EDHOC-PSK handshake, providing mutual authentication, identity protection, and forward secrecy. The abstract positions this as an efficient option for Non-Terrestrial Networks and massive IoT, and a more compact alternative to EAP.
Describes an operational approach for Computing-Aware Traffic Steering (CATS) that does not depend on the normalized Level 1/Level 2 scores of the CATS Metrics framework. Instead, service sites report service-oriented metrics with explicit units, such as Global Available Slots and Computing Time, which the path selector uses directly for joint service-instance and path selection. It explains how these metrics are derived from resource information, service reference data, and local policy, and how the Computing Service Table is combined with the Network Service Table, with update-control and fallback mechanisms for large deployments. The author positions it as complementary to the normalized-score approach, aimed at rapid deployment without offline metric-function negotiation.
Describes how to quickly protect both the egress node and the egress link of a Segment Routing over IPv6 (SRv6) path. TI-LFA covers transit nodes and links but not the egress. The proposed solution uses a Mirror SID (End.M) behavior to steer traffic to a protector egress when the primary egress fails. The IS-IS and OSPFv3 extensions for advertising the Mirror SID and protected locators are defined in a companion draft, building on RFC 9352 and RFC 9513.
GCMF is a lossless compression format that represents data sequences with mathematical functions and their parameters, so it can store a compact description instead of every individual value. The document defines the format's structure, the supported function types, the encoding and decoding rules, and the requirements for interoperability between implementations.
Introduces the Radio Image Framing Protocol (RIFP), a compact one-way protocol for sending images over low-rate radio links. It covers synchronized frames, a versioned binary header, fragmentation and reassembly, a fixed object descriptor, optional JSON metadata, per-frame CRC-32 checks, and SHA-256 verification for the whole object, and sets up registries for future extensions. RIFP is not tied to any particular frequency or modulation; the draft defines one initial profile, 'rifp-cpfsk-4800', a continuous-phase binary FSK scheme, with 433.92 MHz mentioned only as a common example.
Defines an optional authentication extension for the Radio Image Framing Protocol (RIFP). It adds a critical header field using HMAC-SHA-256 and a pre-shared key to authenticate a compact object descriptor, which links the image's digest and decoding parameters to a session and chunk count. The extension works within RIFP's existing framing, fragmentation, retransmission, and offline IQ processes. It does not offer confidentiality, replay protection, or public-key signatures.
This SPRING working group draft's name suggests it specifies using a Segment Identifier (SID) as the source address of packets in Segment Routing deployments. The official Abstract could not be retrieved this run (the document page returned a fetch error), so this summary is approximate and based on the draft name; it will be grounded against the Abstract on the next run.
Describes use cases for agentic AI communication systems and derives protocol requirements from them, intended to guide IETF standardization of agent-to-agent and agent-to-tool communication. The focus areas are dialog management, transport, multimodal communication, communication security, and agent identity and authentication.
Defines the 'sustainability-data' well-known URI, where a web origin publishes a single JSON document describing the energy consumption, carbon footprint, and related environmental metrics of a subject, usually the origin itself. The declaration has a fixed path and formal schemas and links to a methodology; it may include an embedded signature, name upstream providers' declarations, and link to third-party attestations. The metrics are the publisher's own claims. The document registers the well-known URI and the media type 'application/sustainability-data+json'.
Defines the Agent Delegation Receipt, a signed record of what a human principal authorized an AI agent to do, for how long, and under which operator instructions. A receipt carries a scope, hard boundaries, a validity window, and a hash of the operator's instructions, all signed by the authorizing key. Revision -11 adopts a JWS profile over JCS-canonicalized JSON as the primary format and a COSE_Sign1 profile for constrained environments, plus scope attenuation for multi-agent chains and a revocation registry with cascade semantics. Revision -12 handles unknown fields: verifiers reject unrecognized top-level fields, a 'metadata' object is the extension point, and one-time-use receipts fail closed without a durable consumption store.
Addresses the DAWN goal of letting clients discover minimum public information about AI resources, such as agents, before interacting with them. It proposes a two-layer federated reference architecture: a Local Discovery Plane for zero-configuration advertisement within each site, and a Federation Plane that lets site gateways exchange lightweight, integrity-protected Federation Metadata Records across administrative domains. It stresses data sovereignty via an Export Policy Engine and supports iterative discovery through referrals and delegation. The preferred Federation Plane uses DNS (Mode A) with DNSSEC-verified records; non-DNS alternatives (Mode B) include BGP-like peering, gossip, and trusted directory publication. The document is Informational and excludes open-ended search, ranking, and capability catalogs.
Notes that autonomous software agents often act on the public internet with no checkable name, no accountable published party, and no way to learn that an operator has withdrawn them. It specifies the Agent Identity Document, a small JSON file served at a well-known URI on a hostname assigned to each agent, plus the practices a provider follows when hosting these names for operators without their own domain. It separates what the provider knows to be true (hostname, service endpoints, lifecycle status) from what the operator claims (description, contact, homepage, public key), publishes dated expiring provider checks, keeps lifecycle status distinct from availability, and holds every identity under an accountable person or organisation; agents are never account holders and never get authority over DNS. It describes a practice already in production and requests registration of a well-known URI suffix.
By its name, this long-running individual draft (revision 16) appears to define 'VLSMTRP', likely a transport or routing protocol related to variable-length subnet masking. The official Abstract could not be retrieved this run (the document page returned a fetch error), so this summary is approximate and written from the name; it will be grounded against the Abstract on the next run.
Stateful PCE extensions let PCEP control Traffic Engineering LSPs for both RSVP-TE and Segment Routing, PCE-initiated or PCC-initiated. RFC 8733 provides PCEP auto-bandwidth adjustment but has no way to explicitly remove an attribute, because omitting a sub-TLV only means its value is unchanged. This document updates RFC 8733 to add that removal mechanism, and also extends auto-bandwidth to SR-TE LSPs in both SR-MPLS and SRv6 data planes and to multiple Segment Lists within one SR LSP, using the multipath extensions in draft-ietf-pce-multipath.
Describes the Network-Infrastructure Hiding Protocol (NHP), a cryptography-based session-layer protocol that applies Zero Trust principles by hiding protected resources from unauthorized parties. It requires authentication before a connection is allowed, so that IP addresses, ports, and domain names are invisible to unauthorized users. The document specifies the architecture, cryptographic design, message formats, and workflow needed for an independent implementation, and presents NHP as a successor to port knocking and Single-Packet Authorization with stronger asymmetric cryptography, mutual authentication, and better scalability. It offers guidance on integrating NHP with Software-Defined Perimeter, DNS, FIDO, and Zero Trust policy engines.
Describes the Secure Advertisement and Neighborhood Discovery (SAND) protocol for Bundle Protocol version 7 in delay-tolerant networks. SAND is presented as a general-purpose advertisement mechanism, with an initial set of message and data types that nodes can advertise. The main focus is sharing information about local neighborhoods with topological neighbors, and the authors note the protocol can be extended later.