No RFCs were announced within the 48h window.
By its name, this PIM working-group draft extends a YANG data model for IGMP/MLD snooping to cover Layer-2 VPN (L2VPN) scenarios. Snooping lets Layer-2 switches learn multicast group membership by inspecting IGMP/MLD messages so multicast is forwarded only to interested ports. The extension probably adds configuration and state nodes needed when snooping operates inside L2VPN services such as EVPN or VPLS. The official abstract page returned 404 on this run, so this summary is approximate and will be grounded from the Abstract on the next run.
This draft introduces new IP Flow Information Export (IPFIX) Information Elements (IEs) to identify information related to Bit Index Explicit Replication (BIER). The new IEs let flow records carry data contained in the BIER header, describing how traffic is being forwarded with BIER. This enables flow monitoring and accounting systems to observe and report on BIER-forwarded multicast traffic using the standard IPFIX framework.
This INTAREA working-group draft specifies PROBE, a network diagnostic tool similar to PING for querying the status of a probed interface. Unlike PING, PROBE does not require bidirectional connectivity between the probing and probed interfaces; instead it requires bidirectional connectivity between the probing interface and a proxy interface. The proxy can reside on the same node as the probed interface, or on a node to which the probed interface is directly connected. The document updates RFC 4884 and obsoletes RFC 8335 (hence the 'bis').
PIM usually builds multicast trees along the shortest path computed by routing protocols. This PIM working-group draft defines PIM message extensions that instead let multicast trees follow a specific topology and a constraint-based path. It leverages Multi-Topology Routing, which enables service differentiation within an IP network, and the IGP Flexible Algorithm (Flex-Algo), which computes constraint-based paths. The result is a way to build multicast trees over specific topologies and constrained paths rather than only the shortest path.
The Verified Infrastructure Response Protocol (VIRP) defines a trust framework for operators -- human or autonomous -- acting on live network infrastructure. As operations shift toward agentic and automated systems, VIRP addresses risks such as fabricated telemetry, unauthorized state changes, and inability to distinguish legitimate operations from compromise. Every observation and authorization decision is routed through a collection-and-verification boundary the requester does not control; observations are authenticated with HMAC-SHA256 (per-session key in session-bound mode). A two-channel design separates read-only Observation from write-intent Intent, with trust tiers (GREEN/YELLOW/RED/BLACK) and human-in-the-loop controls. This revision adds External Authorization Binding, where the write credential never rests on the gate and per-command authorization uses the device's own mechanism (e.g. TACACS+), plus an optional per-entry Ed25519 signature on chain entries.
The Native Post-Quantum Agent Messaging Protocol (N-PAMP) is a binary, multi-channel, wire-level protocol for authenticated communication between autonomous software agents. It sits beneath application-layer agent protocols and provides a fixed-size frame format, a registry of multiplexed channels, and three escalating security profiles (Standard, High, Sovereign). It uses a hybrid key-encapsulation mechanism combining X25519 with ML-KEM, AEAD, and a forward-secure key schedule. N-PAMP runs over QUIC as primary transport and over TCP with TLS 1.3 as fallback, negotiated via the ALPN identifier 'n-pamp/3'. The document describes the wire format, channel architecture, profile negotiation, and cryptographic suites, and reserves code-point ranges for extensions.
The Native Agentic Application Layer Protocol (N-AALP) is an application-layer object protocol for autonomous software agents. Every N-AALP object is a deterministically encoded CBOR structure signed with COSE, carrying under one signature its content identity, originating signer, a closed effect label used as an authorization input, optional approval/audit bindings, and its causal derivation. Objects are transport-independent and can be carried identically over N-PAMP, QUIC, WebSocket, or HTTP. It defines a frozen envelope, a post-quantum signature profile (pure ML-DSA by default, optional Ed25519+ML-DSA composite), self-certifying identity with key rotation, a single-use approval ledger, a hash-chained audit/causal-ordering model, native streaming, and tiered channel surfaces. It is an Independent Submission and does not represent IETF consensus.
This draft argues, with technical evidence, that intra-handshake (a.k.a. early) attestation fails in practice, even without physical access. It references CVE-2026-33697, EUVD-2026-16488, and several GitHub Security Advisories, and notes that because continuous attestation is generally required, intra-handshake attestation adds unnecessary complexity. It cites two CVEs at CVSS 7.5, GHSAs at CVSS 9.1, 7.8, 7.4, and 6.3 published against intra-handshake attestation. Results are backed by ProVerif research artifacts released under Apache-2.0 for reproducibility and review, and have been acknowledged by relevant stakeholders.
By its name, this individual '-00' draft concerns an agentic market -- likely a framework or protocol for autonomous software agents to participate in a marketplace, discovering, negotiating, or transacting on behalf of principals. It probably fits the current wave of agent-authorization and agent-commerce work at the IETF. The official abstract page returned 404 on this run, so this summary is approximate; no mechanisms, message formats, or claims are asserted here. It will be grounded from the Abstract on the next run.
This draft defines a second population on the Cedulon reconciler (see draft-dogru-cedulon). Where the Cedulon core reconciles signed Spend Receipts against a payment rail, this Decision Profile reconciles Decision Records -- signed by the party that decided whether an agent may act -- against an Effect Extract, an authenticated list of effects that actually occurred on a channel. An 'allow' must match exactly one effect whose content hash the record named; a 'refusal' must match none. It defines the Decision Record claim set, the Effect Extract shape, the departures from the spend rules, finding codes, and a media type. This revision clarifies that the binding compares content and reference rather than clock order, corrects the boundary to two adjacent documents, and records an independent second reader of a frozen fixture.
By its name, this individual draft ('rlt-genesis') appears to describe the genesis or bootstrap of an 'RLT' construct -- possibly a ledger, trust, or transport mechanism -- but the official abstract page returned 404 on this run, so its scope cannot be confirmed. No algorithms, formats, or claims are asserted here. This summary is approximate and will be grounded from the Abstract on the next run.
This document defines the Cedulon Protocol, an audit layer for agent-to-agent commerce. Payment rails such as HTTP 402 flows (x402) and mandate protocols (AP2) already move value and can refuse a spend, but do not give a party that is neither payer nor rail operator a retrievable record of that decision plus a signed spend receipt that reconciles against an authenticated rail extract. Cedulon specifies a Trade Manifest (a signed pre-payment offer), a Policy Decision Point with default-deny, a Spend Receipt (a COSE/CWT claim set), epoch checkpoints, and rail-extract reconciliation showing no settlement lacks a receipt and no settled receipt is missing. That result is unconditional only when the verifier pins the rail key out of band. Checkpoints are profiled as SCITT Signed Statements. Cedulon complements, not competes with, x402 or AP2.
This RATS-related draft addresses protection of Sensitive Model Information (SMI) in frontier and proprietary AI deployments -- probability data, embeddings, cached states, hidden representations, and diagnostics that are richer than ordinary final-answer text. Repeated unauthorized or excessive release of such information can make model reconstruction, imitation, extraction, or distillation more efficient. Authentication establishes who is requesting; confidential computing and attestation establish the environment; but neither alone decides whether a particular release, to a particular destination, under the current extraction state and security epoch remains authorized. The draft describes an execution-finality architecture: sensitive data may be computed as a non-effective Candidate Release, with external release only after protected validation, extraction-state checks, bounded-authority reservation, and verification at a controlled Finality Sink.
Consequential agent actions can produce heterogeneous identity, delegation, policy, permit, approval, transparency, capability, and execution artifacts, each verifying under its own spec while referring to a different action or failing a relying party's freshness/binding requirements. This draft defines the Authorization Evidence Chain (EP-AEC): a transport-agnostic composition object and a fail-closed evaluation algorithm that preserves native verification, establishes exact material-action matching, and evaluates a relying-party-pinned evidence requirement. AEC yields SATISFIED or UNSATISFIED plus a replayable evaluation record. SATISFIED means only that presented evidence filled the named requirement at the stated time -- not a universal authorization decision nor proof of execution. The executor makes the separate AUTHORIZED decision and controls consumption and effects.
This draft describes an evidence architecture for consequential agent actions that cross operator and administrative boundaries, where the party deciding whether to rely on an action record may not have participated and may trust neither operator. It separates transport and workload identity, delegation and policy, material action identity, authorization evidence, evidence satisfaction, local authorization, durable consumption/reservation, effect invocation, outcome evidence, revocation, and preservation. The architecture composes the Canonical Action Identifier (CAID), Authorization Evidence Chain (AEC), and Action Evidence Boundary (AEB), with optional staged-approval and consequence-control profiles. It explicitly does not define a universal token, policy language, execution engine, settlement network, or consensus system: a valid signature, a current credential, a satisfied evidence requirement, and an observed effect remain different facts.
Agents sometimes need bounded authority to perform more than one consequential action without a fresh human approval each time. A signed token alone cannot enforce a shared budget across replicas, survive retries safely, or distinguish an operation that never crossed an effect boundary from one whose outcome is unknown. This draft defines a bounded capability receipt and a durable reserve-admit-reconcile protocol. The receipt binds an issuance authorization, a closed action scope, a budget with explicit units, a holder proof, an expiry, and any parent capability. The state protocol atomically refuses overspend and replay, fences concurrent owners, and charges an indeterminate operation when an external effect may have occurred. Delegation transfers rather than copies authority, with narrowing-only delegation, revocation inheritance, and an optional admission-control epoch.
This draft defines a multi-party approval predicate over action-bound human signoffs: valid signatures, admitted roles, distinct approvers and keys, a threshold, and an optional ordered trail. The relying party pins the governing policy and approver directory independently. Passing the predicate is approval evidence -- not a complete authorization decision, proof of execution, or proof of unused authority. This revision repairs the strong ordered profile: a successor signs a digest of the completed predecessor signoff (including its signature) rather than a precomputable context, establishing causal dependence under the cryptographic assumptions, though not trusted wall-clock time or human comprehension. Reference verifiers in JavaScript, Python, and Go share a corpus, which is a same-team consistency check rather than independent interop evidence.
This draft presents an optional new type of link-state database synchronization packet, the Aggregated SNP Hash (ASH). When feasible, it compresses traditional Sequence Number PDU (SNP) exchanges into a dynamic Merkle tree-like structure, speeding synchronization of large databases and adjacencies while reducing the load from regular CSNP exchanges during normal operation. Like CSNPs and PSNPs, ASH packets come in two flavors: Complete ASH (CASH) and Partial ASH (PASH). The work targets link-state routing (LSR) protocols.
This RATS-related draft targets protection of Sensitive Model Information (SMI) in frontier and proprietary AI deployments, where richer-than-usual artifacts (probability information, embeddings, cached intermediate state, hidden representations, activations, diagnostics, metadata) can accelerate model reconstruction, imitation, extraction, or distillation if released without control. It notes that authentication answers who is requesting and attestation answers the environment, but neither decides whether a specific release to a specific destination under the current extraction state and epoch stays authorized. It describes an execution-finality architecture: information may be computed as a non-effective Candidate Release, with external release only after protected validation, rollback-resistant extraction-state checks, atomic bounded-authority reservation, and verification at a controlled Finality Sink. RATS can complement it by attesting the release-control mechanism.
Autonomous AI agents now operate at production scale across financial, commercial, and infrastructure domains, executing transactions and invoking APIs without direct human oversight at each step. Existing mechanisms (OAuth 2.0, API keys, ACLs) were designed for human-initiated requests and do not capture machine-evaluable authorization semantics: what the agent is mandated to do, what constraints bound it, and for how long. This draft specifies the Agent Authorization Envelope (AAE), a structured authorization container with three mandatory blocks -- MANDATE, CONSTRAINTS, and VALIDITY -- forming a machine-evaluable, cryptographically verifiable assertion. AAE is protocol-agnostic, binding to W3C DIDs for agent identity and W3C Verifiable Credentials for issuance and signature, and is independent of any AI framework, transport, or blockchain.
This NMOP working-group draft defines a structured, iterative lifecycle for network anomaly detection systems to enable human-in-the-loop refinements. Its key contributions are three lifecycle stages, a state machine for anomaly annotations, and YANG data models for standardized labeling and exchange. Together these let operators and tools capture, refine, and share anomaly labels in a consistent, machine-readable way as detection systems learn and improve over time.
This draft specifies an architectural framework and metadata profile to mitigate 'enterprise-future reconstruction' risks in multi-system AI workloads, where traditional access controls fail because an AI environment can correlate independently authorized, disjointed data fragments to infer unrecorded strategic intent. It introduces two mechanisms: Technical Non-Joinability, enforced by a session-bound Reconstruction Authorization Object (RAO) that limits relational data binding; and Technical Non-Completability, enforced by an Output Release Boundary requiring verifiable validation evidence before an AI token or tool invocation can achieve external effect. It defines token schemas, cryptographic bindings, and boundary validation sequences to isolate context-reconstruction domains without modifying underlying enterprise datastores.
This draft profiles a verifiable-telemetry ledger. Its interoperability boundary begins with exact canonical record byte strings that an upstream system has already produced. The profile fixes their admission into serial-numbered segments, deterministic commitment-tree calculation, an authoritative segment artifact encoded in CBOR, a producer manifest, three disclosure classes, and binding of the artifact digest through a required external timestamp channel. Segment closure uses a deployment-configured elapsed-time interval rather than calendar dates. The profile enables independent recomputation and audit of disclosed evidence from the admitted bytes onward; transport framing, decryption, anti-replay, payload interpretation, source-to-record mapping, device onboarding, end-to-end sensor security, and safety decisions are out of scope.
This draft proposes an extension to the Registration Data Access Protocol (RDAP) to represent and exchange structured reliability assessment metadata for registrars and domain names. It defines a structured assessment envelope through which an RDAP server can expose assessment results -- produced by a registry, registrar, or third-party assessor -- in a common, machine-readable format within RDAP responses. The extension standardizes how results are transported and referenced, not how they are computed; scoring methodologies, thresholds, criteria, and governance are left to the operational and policy layer. It does, however, require any publishable scheme to provide safeguards for notification, remediation, and contestation, since publishing an evaluative judgement about an identified party without such safeguards is not a safe practice.
Large-scale data transfers may be hindered by bandwidth limitations and network instability, which can make network-based transfer inefficient. This '-00' draft defines the Data Truck Transport Protocol (DTTP), an alternative data-transfer method for such situations. DTTP uses physical transportation to carry Storage Media containing the Payload: a physical vehicle serves as the Transmission Medium, moving the Storage Media between the Sender and the Receiver. In effect it formalizes 'sneakernet' as a transport, trading latency for very high effective bandwidth when the network path is inadequate.
This draft specifies use of the Bundle Transfer Protocol - Unidirectional (BTPU) as a Convergence Layer directly over Ethernet, and requests allocation of an EtherType and a multicast MAC address for that purpose. This gives Delay-Tolerant Networking (DTN) an alternative to IP-based convergence layers for environments where Ethernet forwarding is operationally feasible but IP routing is unavailable or operationally undesirable, letting bundles be carried natively over Ethernet segments.
QUIC defines a RESET_STREAM frame to abort sending on a stream; when a sender resets a stream it also stops retransmitting lost STREAM frames, so the receiver has no guarantee that data sent on that stream is delivered. This QUIC working-group draft defines a new frame, RESET_STREAM_AT, that allows resetting a stream while guaranteeing delivery of stream data up to a certain byte offset. This lets applications abort a stream cleanly yet still ensure a defined prefix of the data is reliably delivered.
This CCWG working-group draft specifies how transport protocols should increase their congestion window when the sender is rate-limited -- for example because the sending application is not supplying data, or because of receiver flow control. Growing the congestion window while rate-limited can overestimate available capacity, so the document defines the correct behavior and updates RFCs 4341, 5681, 9002, 9260, and 9438 accordingly.
This BESS working-group draft specifies proactive, in-band Network Layer OAM mechanisms (per RFC 9062) to detect loss-of-continuity faults affecting both unicast and multi-destination paths -- the latter used by Broadcast, Unknown-unicast, and Multicast (BUM) traffic -- in an Ethernet VPN (EVPN, RFC 7432bis) network. The mechanisms rely on the widely adopted Bidirectional Forwarding Detection (BFD, RFC 5880) protocol to provide fast fault detection across EVPN forwarding paths.
This NETCONF working-group draft describes extensions to YANG notifications subscription that allow metrics to be published directly from processors on line cards to target receivers, while the subscription itself is still maintained at the route processor in a distributed forwarding system of a network node. This offloads high-volume telemetry publication from the central route processor, improving scale and efficiency for streaming telemetry on distributed platforms.
Independently written systems that anchor records to a SCITT Transparency Service repeatedly need the same construction: a canonical form of structured content, a content-addressed identifier derived from it, binding to a SCITT Signed Statement and Receipt, and references citing external artifacts by digest. This draft defines that as the Canonical Payload Binding (CPB). A payload profile declares its canonicalization algorithm and exclusion set to obtain a reproducible derived identifier. A CPB Signed Statement carries either the complete content (per RFC 9943) or a digest of content held elsewhere via the COSE Hash Envelope (RFC 9995). CPB also defines an abstract typed digest reference model and an optional 'cpb-refs' header encoding, with an IANA registry governing CPB canonicalization algorithms.
This draft describes an evidence-record format for long-term, verifiable preservation of digitally-signed data across the migration to post-quantum cryptography. It builds on the Evidence Record Syntax (ERS) of RFC 4998 and adds an explicit algorithm-agility extension: a record is a chain of signed attestations where each link re-witnesses the data under a fresh signature primitive and commits to the prior link, so authenticity survives the cryptographic break of any single primitive. It specifies canonical hashing for reproducible verification, authenticated temporal binding (an append-only transparency log a la RFC 6962 whose signed inclusion receipt is 'not-after' evidence), and the verification procedure. A per-link beacon anchor records 'not-before' evidence, authenticated against the beacon's hash chain from wire version 3.