IETF Internet-Drafts & RFCs — Daily Digest

48-hour window ending 2026-09-06 · generated 2026-09-06 05:21 UTC

62 drafts 0 RFCs 62/62 drafts with official abstract Published: ietf-drafts-ok.pages.dev

Newly published RFCs

Drafts

Saturday, September 05, 2026

draft-templeman-scitt-framing-space-00 Individual new -00 abstract

Reports a measurement on COSE_Sign1 signed statements. Re-emitting one 165-octet object under six independent CBOR encoding freedoms yields 64 distinct byte sequences that all carry an identical Sig_structure and therefore the same valid signature. Yet all 64 produce different data-hash values (identifiers computed over the wire octets), with no collisions, so an identifier bound to the framing diverges from a signature that is not. A stock CBOR decoder rejected none of them and silently repaired 31 into canonical form on read. The draft specifies nothing: it publishes the measurement, the reproduction recipe, and prior work already addressing the problem.

draft-zhang-dawn-agent-discovery-framework-00 Individual new -00 abstract

An Informational framework for the IETF DAWN effort on discovering agents, workloads and named entities across organizational boundaries. It defines a two-layer federated reference architecture: a Local Discovery Plane that performs zero-configuration agent advertisement and collection inside each site without mandating a link-local protocol, and a Federation Plane that links site gateways to exchange lightweight Federation Metadata Records — a concrete binding of DAWN Minimum Discoverable Information — across domains, with full Capability Cards fetched on demand over authenticated unicast. It emphasizes data sovereignty through an Export Policy Engine and separates metadata indexes from capability documents. It defines no normative wire formats and composes, rather than competes with, existing DAWN proposals.

draft-hebbar-zeropath-vpn-protocol-01 Individual rev -01 abstract

Specifies the ZeroPath VPN protocol suite of three coordinated sub-protocols. HBSPV (Hop-Bound Secure Packet Validation) is a three-domain packet-framing model that confines payload decryption to the authorized egress node while letting intermediate hops validate forwarding context without accessing payload. SGCP (State Graph Cryptographic Protocol) is a three-message attested handshake enforcing mutual authentication and device-posture verification before any session is established. SCSWP provides continuous session state with tamper-evident hash-chain continuity, epoch-bound forward secrecy and four-dimensional trust scoring across the session lifetime. A full opcode architecture governs all control- and data-plane message types. A pure-Python reference implementation is cited.

draft-hebbar-zeropath-vpn-protocol-00 Individual new -00 abstract

Specifies the ZeroPath VPN protocol suite of three coordinated sub-protocols. HBSPV (Hop-Bound Secure Packet Validation) is a three-domain packet-framing model that confines payload decryption to the authorized egress node while letting intermediate hops validate forwarding context without accessing payload. SGCP (State Graph Cryptographic Protocol) is a three-message attested handshake enforcing mutual authentication and device-posture verification before any session is established. SCSWP provides continuous session state with tamper-evident hash-chain continuity, epoch-bound forward secrecy and four-dimensional trust scoring across the session lifetime. A full opcode architecture governs all control- and data-plane message types. A pure-Python reference implementation is cited.

draft-cel-nfsv4-rpc-tls-othername-04 Individual rev -04 abstract

Extends RPC-with-TLS so that a client's X.509 certificate can carry instructions telling the RPC server to execute all of that client's RPC transactions under a single user identity. This targets NFSv4 and related RPC deployments where a client should be mapped to one server-side identity rather than per-request credentials.

Friday, September 04, 2026

draft-sato-soos-aep-03 Individual rev -03 abstract

Defines the Agent Execution Protocol (AEP), the normative five-step SENSE / REASON / PLAN / ACT / OBSERVE loop by which a governed AI agent interfaces with a Governing Enforcement Component (GEC) at every iteration. It specifies the Context Package delivered at SENSE, the GEC Query Interface exercised at PLAN, the Transition Request submitted at ACT, and the atomic GEC response at OBSERVE, plus Standard and Goal-Execution-Engine conformance modes. REASON is deliberately left GEC-unspecified: the LLM is opaque to the protocol. Revision -03 adds a DAM lineage and data-residency validation step before the Event Stream write, integrating with the wider SOOS governance suite.

draft-sato-soos-rgp-01 Individual rev -01 abstract

Specifies the Resource Governance Protocol (RGP): a two-stage discovery and declaration protocol by which physical resources, digital services and AI model instances declare their capability class, trust level, operational constraints and availability to a governed AI agent operating under a Mandate JWT. Stage 1 delivers a capability fingerprint via a well-known URI; Stage 2 delivers a full governance envelope for mandate-scope validation. It defines eight capability classes, four trust levels, a session-scoped Resource Map Sovereign Object and a three-condition autonomous fallback test, and adds an AI Model Capability Declaration and a Physical Resource Profile bound to digital-twin standards. Part of the SOOS governance family.

draft-sato-soos-aop-02 Individual rev -02 abstract

Defines the Agent Orchestration Protocol (AOP), governing how an orchestrating agent decomposes a mission into a sub-goal directed acyclic graph, delegates sub-goals via kernel-mediated Assignment Primitives, and maintains a Mission Plan and Mission Status Sovereign Object across the lifecycle. It specifies the Expected Outcome Declaration as the pre-commitment structure, a DAG with sequential/parallel/conditional dependency types, and a governed handoff requiring an endorsed EOD and a Sub-Agent Composition Record. It integrates with the Intent Declaration Primitive, the Agent Execution Protocol, the Governance Audit Record and the Human Escalation Mechanism. Revision -02 fixes ordering and reference defects and clarifies ownership of the plan objects.

draft-sato-soos-aop-01 Individual rev -01 abstract

Defines the Agent Orchestration Protocol (AOP), governing how an orchestrating agent decomposes a mission into a sub-goal directed acyclic graph, delegates sub-goals via kernel-mediated Assignment Primitives, and maintains a Mission Plan and Mission Status Sovereign Object across the lifecycle. It specifies the Expected Outcome Declaration as the pre-commitment structure, a DAG with sequential/parallel/conditional dependency types, and a governed handoff requiring an endorsed EOD and a Sub-Agent Composition Record. It integrates with the Intent Declaration Primitive, the Agent Execution Protocol, the Governance Audit Record and the Human Escalation Mechanism. Revision -02 fixes ordering and reference defects and clarifies ownership of the plan objects.

draft-sato-soos-mad-04 Individual rev -04 abstract

Defines the Multi-Agent Delegation (MAD) protocol, which establishes accountability when governed agents spawn and delegate to sub-agents. Its single recoverable property is that the accountability chain is always reconstructable from the GEC-signed audit record alone; cascade revocation means one decision stops the whole delegation tree. Revision -03 adds the Sub-Agent Composition Record for kernel-governed spawning, a hub-only communication topology, XPID cross-cluster integration, and full specifications of the R-1 through R-7 revocation trigger classes. Revision -04 adds an eighth class, R-8 (Compromise), to align with the Mandate Lifecycle Events profile's compromise value. Part of the SOOS suite.

draft-kavian-offering-discovery-protocol-01 Individual rev -01 abstract

Defines the Offering Discovery Protocol (ODP), which lets an automated agent inspect a service, discover its Collections and Offerings, interpret service-defined structured attributes and follow links to subsequent operations. ODP is designed to scale from a handful of offerings to large marketplaces without imposing a universal product taxonomy. The document sets out the protocol's scope, terminology, roles, discovery architecture, extensibility model, composition boundaries and conformance model.

draft-kavian-aep-platform-hosted-identity-01 Individual rev -01 abstract

Defines interoperable hosted-identity behavior for Agent Enrollment Protocol (AEP) Platforms. It lets a Platform provision service-scoped agent did:web identities, publish the corresponding DID documents, custody signing keys, and produce AEP client-assertion JWTs through delegated signing operations. This gives platforms a standard way to host and operate agent identities on behalf of the agents they serve.

draft-kavian-aep-oauth-session-credential-04 Individual rev -04 abstract

Defines the OAuth Bearer session-credential grant type for the Agent Enrollment Protocol (AEP). The grant lets an AEP Service issue an OAuth-style Bearer access token through the AEP Grant command while preserving baseline AEP client-assertion authentication as the root of trust. It suits deployments that want an agent to receive a familiar OAuth Bearer token after enrolling, without abandoning AEP's assertion-based authentication.

draft-kavian-aep-basic-session-credential-04 Individual rev -04 abstract

Defines the Basic session-credential grant type for the Agent Enrollment Protocol (AEP). The grant lets an AEP Service issue an HTTP Basic credential through the AEP Grant command, targeting deployments that already integrate with HTTP Basic authentication middleware. It lets those existing systems adopt agent enrollment while continuing to consume Basic credentials.

Defines the API-key session-credential grant type for the Agent Enrollment Protocol (AEP). The grant lets an AEP Service issue an opaque API key through the AEP Grant command for deployments that already operate header-based API-key authentication. It gives such systems a standard way to hand a freshly enrolled agent an API key it can present on later requests.

draft-kavian-agent-enrollment-protocol-04 Individual rev -04 abstract

Defines the Agent Enrollment Protocol (AEP), an HTTP-based mechanism by which autonomous agents discover a service's enrollment requirements, enroll an agent identity, obtain optional session credentials, revoke them, and query enrollment status. AEP builds on Decentralized Identifiers, client-assertion JWTs and HTTP Problem Details to provide a narrow, machine-first enrollment and authentication substrate for agent-to-service interactions. It is the base specification that the AEP grant-type and hosted-identity drafts extend.

draft-dogru-cedulon-decision-profile-01 Individual rev -01 abstract

Extends the Cedulon reconciliation core — which matches signed Spend Receipts against an authenticated payment-rail extract — to a second population beyond money. A Decision Record, signed by the party that decided whether an agent may act, is reconciled against an Effect Extract, an authenticated list of effects that actually occurred on a channel: an allow must match exactly one effect whose content hash the record named, and a refusal must match none. It defines the Decision Record claim set, the Effect Extract shape, the departures from the spend rules, the finding codes and a media type. Revision -01 binds the allowed effect's class into the signed record and narrows the decider's claimed control.

draft-chung-ccwg-search-10 Individual rev -10 abstract

Proposes SEARCH (Slow start Exit At Right CHokepoint), an algorithm to improve TCP slow-start behavior. Default Linux slow start (Cubic with HyStart) can exit prematurely over wireless links and under-use capacity, while disabling HyStart makes TCP exit too late and induce loss. SEARCH has the sender estimate the congestion point from acknowledged deliveries — comparing delivered to sent bytes, smoothed for latency variation and normalized for capacity — and exit slow start when delivered bytes fall below expectation. The authors implemented it in Linux, FreeBSD and QUIC and evaluated it over WiFi, 4G/LTE, and LEO and GEO satellite links, showing reliable exit after the congestion point but before loss.

draft-bormann-cbor-configuration-00 Individual new -00 abstract

Discusses configuration of CBOR processors and, using that discussion as a basis, provides Working Group Last Call feedback on draft-ietf-cbor-serialization-08. It is a short contribution aimed at informing the CBOR serialization work rather than defining a new protocol.

draft-laxsharma-pact-01 Individual rev -01 abstract

Specifies PACT, which adds liability as a required, co-signed member of an agent contract and propagates it through a subcontract tree — filling a gap where existing agent identity, delegation, audit and payment specs make no party financially answerable for an undelivered result. PACT defines the Verifiable Task Contract (a signed JSON object binding parties, scope, price, verification profile and liability allocation), a Delivery object the contract is judged against, an escrowed settlement whose release depends on a stated assurance level rather than elapsed time, and a subcontract tree where a parent's Work Attestation commits to its children by Merkle root and liability cascades upward. It composes existing identity, authorization, audit and payment work rather than redefining them.

draft-clifford-testimony-record-00 Individual new -00 abstract

Specifies a format for recording what automated systems believed: their evidence, contradictions, attempted actions and authorizations. It aims to let specific properties be verified mechanically rather than by assertion, and defines four conformance levels. The format differs from ordinary logging by documenting claimed knowledge and disagreements rather than just the actions a program took, giving auditors a structured record of an automated system's reasoning state.

draft-admnr-lsr-igp-measurement-group-03 Individual rev -03 abstract

Defines an IS-IS capability sub-TLV for advertising measurement-group membership for Active Measurement Protocols such as TWAMP and STAMP. It lets IGP routers discover other routers participating in different measurement groups, enabling automatic discovery of measurement endpoints throughout an IS-IS routing domain. Membership is identified by a Group ID, and the same interface address (IPv4 or IPv6) may participate in multiple measurement groups.

draft-ietf-nmop-simap-concept-13 WG NMOP rev -13 abstract

Defines the concept of Service & Infrastructure Maps (SIMAP), formerly known as the Digital Map, and identifies a set of SIMAP requirements and use cases. SIMAP makes explicit the ties between service and infrastructure layers, clarifies expected outcomes for operations and automation, and removes the ambiguity associated with the term 'digital'. The document is intended as a reference for assessing whether various topology modules meet SIMAP requirements.

draft-stone-adrp-01 Individual rev -01 abstract

Defines the Agent Dispute Resolution Protocol (ADRP), a wire protocol and state machine for resolving disputes arising from cryptographically attested agent-to-agent transactions; it is the companion to ATXN, which defines what such a transaction is. ADRP rejects the assumption that a valid proof bundle equals contractual satisfaction, splitting disputes into a cryptographic class (resolvable by code from the proof bundle and mandate chain) and a semantic class (resolvable only against pre-committed machine-readable acceptance criteria, escalating to arbitration when absent). It introduces an Arbitration Mandate recording the principal's pre-committed dispute policy, and a counter-attestation override in which a signed RulingBundle supersedes a proof bundle by precedence rather than mutation, preserving both in the hash chain.

draft-stone-atxn-01 Individual rev -01 abstract

Defines a canonical, machine-checkable primitive for an agent-to-agent (A2A) transaction: the bundle of cryptographically signed elements that constitute a recorded value exchange between two software agents acting for identified principals. It sets out conformance tiers determining which elements are required, rail-specific Profiles mapping the bundle onto existing payment infrastructure, and a two-tier validity model distinguishing externally adjudicable transactions from operationally valid uncontested exchanges. ATXN is presented as the foundational primitive for escrow, dispute resolution, audit and liability allocation in agentic commerce, designed to yield evidence mappable to existing contract and agency frameworks. It maps directly to AP2, Stripe ACP, Visa TAP, Mastercard Agent Pay and x402 as Profiles.

draft-stone-aref-00 Individual new -00 abstract

Specifies the Agent Referral and Escrow Framework (AREF) for cryptographically attributed agent-to-agent referrals, escrow-bound commission commitments and dual-rail settlement in multi-agent environments. It addresses the absence of any standard way to record how one agent introduced another to a platform, bind that introduction to a financial commitment, and settle the commission across heterogeneous payment rails. AREF defines a portable Ed25519-signed attribution proof for referral chains of arbitrary depth, a SwarmSync-Referrer HTTP header binding a referrer to an escrow at hold time, a commission vesting model tied to escrow finality, a unified settlement-finality signal over both Stripe Connect and the X402 cryptographic channel, and a swarm_meta embedding by which referral codes propagate without human involvement.

draft-stone-atep-02 Individual rev -02 abstract

Specifies the Agent Trust & Execution Passport (ATEP), an open standard for representing an AI agent's verifiable track record of work across marketplaces and platforms. ATEP defines a portable, machine-readable credential encoding an agent's execution history, success rate, capability domains, trust tier and earned badges, computed entirely from append-only execution logs so it cannot be manually inflated. It is positioned as the trust layer for agent-to-agent commerce, giving agents that move between marketplaces a universal format for answering whether another agent should be hired.

draft-stone-vcap-02 Individual rev -02 abstract

Specifies Verified Commerce for Agent Protocols (VCAP), an open standard for settling financial transactions between autonomous AI agents using cryptographically verifiable proof of work delivery. VCAP defines the message formats, state machines, cryptographic bindings and callback contracts an agent marketplace needs to hold funds in escrow, automatically verify deliverables via independent verification engines, and release or refund payments based on machine-verifiable evidence. It is designed as a settlement layer complementing agent-to-agent communication protocols such as Google A2A: where those define how agents discover and talk to each other, VCAP defines how agents pay each other with proof that work was done.

draft-stone-swarmscore-v2-canary-01 Individual rev -01 abstract

Extends the SwarmScore V1 two-pillar reputation protocol with a third dimension, Safety, measured through controlled canary prompt testing. It specifies five formally analyzed design decisions for the canary subsystem: mandatory testing thresholds, hybrid response classification (pattern matching plus an opaque LLM ensemble), dedicated test-session placement, prompt-library composition and rotation, and session isolation to reduce buyer-harm risk. V2 Canary is backwards compatible with V1 — all V1 scores are unchanged — and yields a five-pillar formula scoring Technical Execution (300), Commercial Reliability (300), Operational Depth (150), Safety (100) and Identity Verification (150).

draft-stone-swarmscore-v1-01 Individual rev -01 abstract

Specifies SwarmScore V1, a transparent, community-governed open standard for agent reputation scoring in open marketplaces. It provides a two-dimensional score measuring technical execution (via Conduit browser verification) and commercial reliability (via the AP2 payment protocol), with volume-scaled metrics rewarding consistent high-volume performance and cryptographically signed certificates enabling decentralized trust. The document defines the complete V1 standard: formula, trust tiers, escrow integration, wire format, governance model, legal framework, implementation guidance, a V2 roadmap, competitive analysis and known limitations, including a plan to move canary-prompt curation to a multi-stakeholder community registry.

draft-stone-vcap-ap2-binding-01 Individual rev -01 abstract

Defines a binding between Verified Commerce for Agent Protocols (VCAP) and the Agent Payments Protocol (AP2). AP2 supplies agent-commerce authorization evidence through IntentMandate, CartMandate and PaymentMandate artifacts, while VCAP supplies delivery verification, settlement evidence, escrow directives, timeout handling and dispute handoff. This revision deliberately does not model AP2 as an escrow or settlement state machine; treating AP2 as an authorization and security layer used within a surrounding commerce protocol, it references AP2 mandates by cryptographic digest or opaque identifier and leaves payment capture, refund and settlement to the commerce protocol and payment rail.

draft-stone-aivs-01 Individual rev -01 abstract

Defines the Agentic Integrity Verification Standard (AIVS), a portable, self-verifiable archive format for cryptographic proof of AI agent sessions. An AIVS bundle is a gzip-compressed tar archive containing a SHA-256 hash-chained audit log, an Ed25519 signature over the chain, a machine-readable manifest and an embedded verification script needing only the Python 3 standard library. It also defines AIVS-Micro, a roughly 200-byte six-field attestation for continuous monitoring, embedded widgets and API responses. AIVS lets any party verify offline that every action is accounted for and unmodified, that nothing was inserted, deleted or reordered, and that the session came from a specific cryptographic identity.

draft-tonyai-a2a-trust-03 Individual rev -03 abstract

Defines a trust model for agent-to-agent (A2A) interactions in multi-agent AI systems. It specifies how agents obtain verifiable identities via CA-signed templates, how spawn chains are cryptographically established and validated, how dynamic policies are governed under a dual-signature model, and how cross-organizational agent interactions are explicitly authorized. The model reuses existing PKI primitives (X.509, CRL, CSR) and established identity patterns (OAuth 2.0, On-Behalf-Of) to address agent provenance. It deliberately excludes agent-to-resource access control, human-in-the-loop orchestration and agent behavior, leaving those to the resource-enforcement and orchestration layers.

draft-abak-agent-control-delivery-evidence-01 Individual rev -01 abstract

Defines format-independent evidence requirements for showing whether agent control instructions — stop, suspend, revoke, constrain, cancel or override — actually reached and were applied at their enforcement points. A record that a control was decided or dispatched does not prove every intended target received or applied it, and the absence of an acknowledgement does not by itself prove non-delivery. The draft separates issuer-side emission, required-target resolution, receiver-side observation, enforcement outcome and observation of the control effect, treats each instruction-target obligation as the unit of reconciliation, and defines bounded negative observations, total reconciliation, population conservation and semantic-preservation requirements. It defines no receipt format, wire protocol, authorization system or audit regime.

draft-mott-cose-sqisign-08 Individual rev -08 abstract

Specifies the algorithm encodings and representations for the SQIsign digital signature scheme within the COSE and JOSE frameworks. SQIsign is an isogeny-based post-quantum signature scheme with unusually compact signatures and public keys among NIST PQC candidates, still under third-round evaluation, so the underlying primitive may change. The document notes that SQIsign does not expose the auxiliary torsion-point information exploited in the SIDH/SIKE attacks, so the Castryck–Decru techniques do not directly apply, while acknowledging ongoing isogeny cryptanalysis. By establishing stable COSE and JOSE identifiers it targets interoperability for bandwidth-constrained and legacy-compatible hardware such as FIDO2 CTAP2 devices.

Describes an attestation-bound execution-finality architecture for workloads — notably AI agents — that emit consequential operations such as API calls, storage mutations, configuration changes or financial instructions. It observes that an acceptable Attestation Result gives a Relying Party trust information but is not, without an application-defined authorization step, a decision on each operation the attested workload later emits. In the architecture a consequential operation first exists as a Candidate Act in a non-effective state; before it gains external effect its parameters are cryptographically bound to validation context (Attestation Results, workload identity, execution context, policy, authorization scope, freshness). A designated Finality Sink verifies the binding at the effectuation boundary, separating environment appraisal from authorization of a concrete act. It complements RATS, EAT, TEEs and existing authorization mechanisms.

draft-reilly-government-integrity-02 Individual rev -02 abstract

Defines the Reilly Government Integrity Protocol (RGIP), a standards-aligned pipeline for producing permanent, independently verifiable public records by combining multi-algorithm content hashing, public timestamp anchoring, archival deposit under a persistent identifier, decentralized storage and web archiving. Revision -02 corrects defects from -01 that would have prevented independent verification or overstated guarantees: it replaces the SHA3-512-only cross-chain hash with an entangled link-and-braid construction, defines a canonical domain-separated encoding for hashed inputs, separates the signed Evidence Receipt Core from the mutable anchor envelope, adds chain-checkpoint anchoring, salted field commitments, explicit anchor states, a revocation registry and hash-migration records, prohibits automated repair of integrity violations, and narrows the -01 post-quantum claims.

draft-albanna-regext-rdap-deleg-05 Individual rev -05 abstract

Describes an extension to the Registration Data Access Protocol (RDAP) that includes DNS DELEG values in responses to RDAP domain-object queries. It lets RDAP clients receive DELEG information alongside the usual domain registration data returned for a domain query.

Describes an attestation-bound execution-finality architecture for workloads — notably AI agents — that emit consequential operations such as API calls, storage mutations, configuration changes or financial instructions. It observes that an acceptable Attestation Result gives a Relying Party trust information but is not, without an application-defined authorization step, a decision on each operation the attested workload later emits. In the architecture a consequential operation first exists as a Candidate Act in a non-effective state; before it gains external effect its parameters are cryptographically bound to validation context (Attestation Results, workload identity, execution context, policy, authorization scope, freshness). A designated Finality Sink verifies the binding at the effectuation boundary, separating environment appraisal from authorization of a concrete act. It complements RATS, EAT, TEEs and existing authorization mechanisms.

draft-dogru-cedulon-decision-profile-00 Individual new -00 abstract

Extends the Cedulon reconciliation core — which matches signed Spend Receipts against an authenticated payment-rail extract — to a second population beyond money. A Decision Record, signed by the party that decided whether an agent may act, is reconciled against an Effect Extract, an authenticated list of effects that actually occurred on a channel: an allow must match exactly one effect whose content hash the record named, and a refusal must match none. It defines the Decision Record claim set, the Effect Extract shape, the departures from the spend rules, the finding codes and a media type. Revision -01 binds the allowed effect's class into the signed record and narrows the decider's claimed control.

draft-cao-opsawg-ipfix-sav-04 Individual rev -04 abstract

Specifies IP Flow Information Export (IPFIX) Information Elements that export the context and outcome of Source Address Validation (SAV) enforcement. The SAV-specific elements give detailed insight into why packets are identified as spoofed by capturing the specific SAV rules that triggered each validation decision. This operational visibility lets network operators observe SAV enforcement behavior and analyze the source-address spoofing events SAV detects.

draft-rfcxml-pqc-key-fragmentation-00 Individual new -00 abstract

Analyzes the security and operational implications of fragmenting cryptographic keying material across low-power and constrained links. As post-quantum and other modern algorithms bring larger key sizes, key-establishment messages may exceed link-layer frame sizes and be segmented by adaptation-layer fragmentation such as 6LoWPAN or SCHC. The document identifies common fragmentation patterns and examines risks including fragment loss, reordering, duplication and partial exposure, and discusses fragment-level integrity, replay resistance and correct binding of fragments to cryptographic session state. It defines no new cryptographic algorithms or fragmentation mechanisms.

draft-sirkkavaara-vaara-receipt-10 Individual rev -10 abstract

Specifies vaara.receipt/v1, a signed and independently recomputable record that binds a decision about an autonomous action to the evidence it was made on, and optionally to external timestamp anchors. It is canonicalized with the JSON Canonicalization Scheme so any third party can recompute its digests and verify its signature without the issuer, and a decision plus its execution receipt form one recomputable pair via the envelope's back link. Trust is root-agnostic — verifiable with or without a hardware TEE and re-expressible as an IETF RATS Entity Attestation Result — and downstream specifications add only their own evidence schema through profiles. The format is deployed with public conformance vectors and standalone checkers.

draft-sirkkavaara-vaara-receipt-09 Individual rev -09 abstract

Specifies vaara.receipt/v1, a signed and independently recomputable record that binds a decision about an autonomous action to the evidence it was made on, and optionally to external timestamp anchors. It is canonicalized with the JSON Canonicalization Scheme so any third party can recompute its digests and verify its signature without the issuer, and a decision plus its execution receipt form one recomputable pair via the envelope's back link. Trust is root-agnostic — verifiable with or without a hardware TEE and re-expressible as an IETF RATS Entity Attestation Result — and downstream specifications add only their own evidence schema through profiles. The format is deployed with public conformance vectors and standalone checkers.

Describes a recurring interoperability problem in exported network telemetry: many values are encoded without an explicit definition of the scope in which they are unique, meaningful and comparable, so the wire representation is standardized while the semantic context stays implicit. A receiver may then treat two numerically identical values as equivalent when they came from different semantic domains, leading to incorrect aggregation, incorrect cross-instance comparison and erroneous conclusions about routing, forwarding or network health. The draft argues that exported telemetry identifiers and statistics MUST explicitly define both the scope of uniqueness and the conditions for cross-context comparison, applying to any telemetry mechanism — not just BMP — where a value can arise in multiple semantic domains.

draft-ietf-mpls-stamp-pw-18 WG MPLS rev -18 abstract

Specifies encapsulations for the Simple Two-Way Active Measurement Protocol (STAMP, RFC 8762) and its optional extensions (RFC 8972) in MPLS networks. It defines how to carry STAMP test packets for point-to-point LSPs and single-segment pseudowires, with or without an IP/UDP header, so the test packets experience the same forwarding and ECMP behavior as the measured data traffic, and it defines two new MPLS Generic Associated Channel types. The document updates RFC 8762 and RFC 8972 to let STAMP operate without an IP/UDP header over MPLS, adjusting handling of the session identifier, TTL/Hop Limit and TLV extensions, and states requirements for IPv6 STAMP using UDP zero-checksum, deviating from RFC 6936.

draft-ietf-ippm-alt-mark-deployment-08 WG IPPM rev -08 abstract

Provides a framework for deploying the Alternate Marking performance-measurement methodology, together with considerations and practical guidance for its deployment. It is aimed at operators applying alternate marking in real networks rather than at redefining the underlying measurement technique.

draft-sato-soos-sov-03 Individual rev -03 abstract

Defines the Sovereign Object (SO): a causally ordered, policy-governed, typed, living document that evolves through a predefined finite state space under Governing Enforcement Component (GEC) authority, serving as the unit of governance in the SOOS protocol family — the thing agents operate on, the GEC governs and human principals reason about. It specifies the SO's five-layer structure (Identity, State, Event Stream, Typed Graph, Attachment Index), its Zone A / Zone B boundary model, its five-phase lifecycle, its SO Type system, its Cedar policy context model and the Mandate-JWT binding. Revision -03 removes the Mission Plan and Mission Status subtypes (now owned by AOP) and reorders Cedar evaluation to verify the Mandate JWT first.

draft-sato-soos-kia-06 Individual rev -06 abstract

Specifies the Kernel Identity and Attestation (KIA) protocol, the Layer 0 signing and attestation component of the SOOS governance architecture. KIA defines the cryptographic identity of the GEC, the trust chain anchoring kernel authority from hardware root through an operator root keypair to every signed Event Log entry, the GEC Manifest schema for runtime-state attestation, and Revocation Registry maintenance. Later revisions add FROST threshold signing for high-availability deployments, the Cross-Principal Identifier (XPID) for cross-instance federation audit correlation, and several security considerations covering FROST nonce reuse, XPID revocation gaps, identity takeover and attestation channel binding; revision -06 completes a WIMSE security-review pass, restoring manifest fields and updating the FROST reference to RFC 9591.

draft-xiao-fann-fast-cnp-with-proxy-03 Individual rev -03 abstract

Describes the necessity and feasibility of introducing a proxy network node between a congested node and the traffic sender to translate congestion notifications. The congested node sends its congestion notification to the proxy in a format defined in this document; the proxy then translates it into a format the traffic sender understands and forwards the translated notification to the sender. This allows congestion signaling to interoperate across nodes that use different notification formats.

draft-lz-fann-bandwidth-notification-00 Individual new -00 abstract

Proposes a data-plane-based method for rapidly advertising end-to-end path bandwidth information using a bitmap encoding. The mechanism is aimed at enabling fast load-balancing adjustments in AI/ML data-center fabrics, where quick reaction to available path bandwidth matters for performance.

draft-ietf-v6ops-rfc6146-bis-16 WG V6OPS rev -16 abstract

Specifies stateful NAT64 translation, which lets IPv6-only clients reach IPv4 servers over unicast UDP, TCP or ICMP by sharing one or more public IPv4 addresses assigned to the translator among several IPv6-only clients. It also supports IPv4-initiated communication to a subset of IPv6 hosts through configured bindings in the translator. When used together with DNS64, no changes are required in either the IPv6 client or the IPv4 server. This document obsoletes RFC 6146.

draft-sato-soos-mjwt-05 Individual rev -05 abstract

Defines the Mandate JWT (MJWT), a WIMSE workload-credential profile that binds an AI agent's authority to a specific Sovereign Object instance under a named human principal, with a cryptographically enforced delegation ceiling and an eight-dimensional Narrowing Property that prevents any sub-agent from exceeding the root human principal's authority. Revisions add a consent-scope dimension and claim, a purpose-code registry and fail-closed consent enforcement (-02); tighten parent-mandate re-verification and tie the Revocation Registry to KIA (-04); and add a max_delegation_depth dimension bounding an unbounded-delegation DoS vector plus a MUST-level consent-staleness defense (-05). It is the authorization primitive referenced across the SOOS governance drafts.

draft-ietf-cats-metric-definition-11 WG CATS rev -11 abstract

Focuses on the compute and communication metrics used by Computing-Aware Traffic Steering (CATS), a traffic-engineering approach that steers traffic to a service instance by considering the dynamic state of computing and network resources. CATS components exchange metrics describing resource conditions that affect instance selection, and this document defines a hierarchical abstraction of those metrics to improve interoperability, scalability and operational simplicity. Rather than standardizing raw infrastructure (Level 0) metrics, it specifies higher-level representations derived from raw measurements through aggregation and normalization functions.

draft-gq-savnet-sav-terms-02 Individual rev -02 abstract

Provides an overview of terms and abbreviations related to Source Address Validation (SAV), aiming to establish a common and consistent set of terminology for use across SAV-related discussions and documents. The document explicitly states that it is not intended to be an authoritative source of correct terminology, but a shared reference vocabulary for the SAVNET work.

draft-grimminck-safe-ioc-sharing-13 Individual rev -13 abstract

Codifies a consistent, reversible convention used in the threat-intelligence community for sharing potentially malicious indicators of compromise such as URLs, IP addresses, email addresses and domain names. It describes an obfuscation format that reduces the risk of accidental execution or activation when IOCs are displayed or transmitted: the transformation renders an indicator syntactically invalid as a URI while keeping it human-readable, and the original value can be recovered deterministically. Safe-IOC strings are a textual rendering convention, not URIs, and are not meant for generic URI parsers. The conventions aim to improve interoperability among tools and feeds that exchange threat-intelligence data.

draft-farley-acta-signed-receipts-03 Individual rev -03 abstract

Defines a portable, cryptographically signed receipt format for recording machine-to-machine access-control decisions. Each receipt captures the identity of the decision maker, the tool or resource being accessed, the policy-evaluation result and a timestamp, all signed with Ed25519 and serialized using deterministic JSON canonicalization. It targets environments where AI agents invoke tools on behalf of human operators, particularly the Model Context Protocol ecosystem. Receipts are independently verifiable without contacting the issuer, enabling offline audit, regulatory compliance and cross-organizational trust federation.

draft-mott-cose-sqisign-07 Individual rev -07 abstract

Specifies the algorithm encodings and representations for the SQIsign digital signature scheme within the COSE and JOSE frameworks. SQIsign is an isogeny-based post-quantum signature scheme with unusually compact signatures and public keys among NIST PQC candidates, still under third-round evaluation, so the underlying primitive may change. The document notes that SQIsign does not expose the auxiliary torsion-point information exploited in the SIDH/SIKE attacks, so the Castryck–Decru techniques do not directly apply, while acknowledging ongoing isogeny cryptanalysis. By establishing stable COSE and JOSE identifiers it targets interoperability for bandwidth-constrained and legacy-compatible hardware such as FIDO2 CTAP2 devices.

draft-ietf-pim-gaap-23 WG PIM rev -23 abstract

Describes GAAP (pronounced 'gap'), a lightweight decentralized multicast group-address allocation protocol. GAAP requires no centralized service or coordination for the allocation protocol itself, though it depends on ASM-capable multicast routing already being provisioned, and deployments using encryption or administrative scoping may need extra configuration. The protocol runs among group participants that need a unique group address to send and receive multicast packets, and is tailored for both IPv4 and IPv6 networks. Rather than extending an existing protocol it offers a simple, lightweight alternative, and it is Experimental, with rationale and completion criteria stated for the experiment.

Specifies procedures for distributing BGP-Link State (BGP-LS) key parameters for inter-domain links between two Autonomous Systems. It defines a new BGP-LS NLRI type for an Inter-AS Link, together with three new TLV descriptors for that link. These extensions let network operators collect inter-domain interconnect information and automatically compute the inter-AS topology from the information carried by BGP-LS.

draft-ietf-pce-sr-p2mp-policy-20 WG PCE rev -20 abstract

Specifies PCEP extensions for Segment Routing Point-to-Multipoint (P2MP) Policies, a set of policies enabling an architecture for P2MP service delivery. The extensions let a stateful Path Computation Element compute and initiate P2MP paths for SR-MPLS from a Root to a set of Leaf nodes, extending the stateful PCE model to point-to-multipoint segment-routed trees.

draft-goncharov-rfcregsimples-00 Individual new -00 abstract

Registers a range of sixteen CBOR simple values (0 to 15) that different specifications can share for CBOR transformations such as compression or templating in a non-conflicting way. Reserving this smallest, single-byte simple-value range lets current and future specifications reuse it while defining their own ways to use the values for their own goals. The document updates RFC 8949 (CBOR, STD 94), whose design goals include very small code and message size and extensibility without version negotiation.