Daily digest for Saturday 29 August 2026 · window: the last 48 hours (2026-08-27 to 2026-08-29 UTC)
YANG Library (RFC 8525) specifies the 'ietf-yang-library' module that provides information about the YANG modules, datastores and datastore schemas used by a network management server. This RFC augments that module to provide the augmented-by list, facilitating the process of obtaining all dependencies between YANG modules by querying the server's YANG library. It updates RFC 8525 to also include the augmented-by list.
Specifies procedures for distributing BGP-LS key parameters for inter-domain links between two Autonomous Systems (ASes). It defines a new type within the BGP-LS NLRI for an Inter-AS Link and three new TLVs for the Inter-AS Link descriptor. These extensions let a network controller retrieve topology across inter-AS environments, so operators can collect inter-domain interconnect information and automatically compute the inter-AS topology from data carried by BGP-LS.
Agentic AI systems now call tools, write memory, move money, change infrastructure and trigger physical actions, while most safety layers decide permission upstream and then trust the downstream path. This draft specifies a protected execution-finality architecture, the Decoupled Authorisation System (DAS), built on four mechanisms: two-instance binding that separates collection-time evidence from execution-time validation; mutually load-bearing cross-committed evidence so no single artifact authorises effectuation; scoped non-bearer finality authority where possession alone is insufficient; and independent Finality Sink reconstruction at the effectuation boundary. A Candidate Act stays non-effective until the sink re-derives and verifies the operation, giving fail-closed denial instead of post-event remediation.
Argues the Internet has protocols for moving data, securing channels and delegating identity, but none for the moment a machine-generated instruction becomes a real-world act. It specifies the DAS Candidate-Act Finality architecture: every effect-capable AI output is first converted into a non-effective Candidate Act that stays inert until a Protected Enforcement Domain validates output, provenance, factual support, consequence, jurisdiction, epoch and sink predicates. Only then is a scoped non-bearer capability or Execution Handle released and verified at a Finality Sink, which in advanced forms is cryptographically unable to complete the act without the handle. The document supports graduated and escalated conditional finality and provides JSON Schema for the protected objects.
Describes how to encapsulate the Simple Two-Way Active Measurement Protocol (STAMP, RFC 8762) and its optional extensions (RFC 8972) in MPLS networks. Label Switched Paths (LSPs) and Pseudowires (PWs) carry many services and may use the Control Word (CW); the draft specifies encapsulation of STAMP test packets with or without the CW and/or an IP/UDP header for both LSPs and PWs. It updates RFC 8972 by revising the STAMP Test Session Identifier for LSPs and PWs.
Defines a YANG data model that extends the network topology model of RFC 8345 to map network topologies with inventories. It introduces the 'inventory-topology' network type plus augmentations for physical entity mappings and capabilities, which any overlay network topology can use for service-provisioning validation, network maintenance and capacity planning.
Warns that a compromised enterprise AI server is more than a data-breach risk: it can become a continuously updated reconstruction engine that correlates customer records, engineering defects, financial systems and internal communications into competitive intelligence and then externalises it. The draft describes an architecture that separates computation authority from the ability to externalise results, using decomposed vaults, mandatory output verification and protected release capabilities.
Defines the Sovereign Tensor Container (STC-1.0) and Sovereign Tensor Provenance (STP-1.0) specifications. STC-1.0 establishes a strict 64-byte physical memory alignment standard for binary machine-learning tensor payloads to enable zero-copy Direct Memory Access (DMA). STP-1.0 defines an embedded cryptographic provenance framework using C2PA profiles, X.509 signature chains and SCITT-compatible attestations to secure supply-chain integrity for distributed AI models.
In-situ OAM (IOAM, RFC 9197) collects operational and telemetry information inside packets as they traverse a path, with Option-Types such as Pre-allocated Trace, Proof of Transit, Edge-to-Edge and Incremental Trace, plus the Direct Export (IOAM-DEX) trigger of RFC 9326. MPLS Network Actions (MNA) indicate actions on LSPs, MPLS packets and the node and carry the data those actions need. This draft uses MNA to collect and transport IOAM-Data-Fields and IOAM-DEX operational state and telemetry in MPLS networks.
MASQUE (Multiplexed Application Substrate over QUIC Encryption) is a set of protocols and HTTP extensions that allow proxying all kinds of Internet traffic over HTTP. This document describes the architectural principles behind MASQUE and the properties it can provide.
Building on RFC 2501's definition of a MANET as an autonomous system of mobile nodes that may operate in isolation or interface with a fixed network such as the public Internet, this document presents a MANET Internetworking problem statement and gap analysis.
Notes that systems anchoring records to a SCITT Transparency Service keep re-deriving the same construction: a canonical form of structured content, a content-addressed identifier from that form, a receipt in the unprotected header of a Signed Statement, and a typed reference letting one record cite another by digest across profiles. It defines that construction as a reusable Canonical Payload Binding profile, so each payload class declares its canonicalization algorithm and exclusion set once and inherits statement-to-receipt binding and typed digest reference semantics. It complements the COSE Hash Envelope of RFC 9995, with an IANA registry of immutable canonicalization algorithms.
Describes an approach for storing a fingerprint-based identifier for an OpenPGP key packet on a hardware security device whose identifier field is size-constrained.
Chips Message Robust Authentication (Chimera) lets a GNSS constellation such as GPS provide receivers with authentication of pseudorange measurements on one or more open PNT signals. This specification defines a Fast Channel Chimera Marker Key Package, an efficient structure for encoding one or more Fast Channel Chimera marker keys and associated metadata with a digital signature over all security-relevant parameters, using CBOR Object Signing and Encryption (COSE) as the message structure. It also describes a streaming network protocol for distributing these key packages over the Internet.
Specifies AegisFS, a programmable secure file and folder runtime that turns ordinary filesystem objects into policy-driven, state-, execution- and behaviour-aware security objects. It introduces two contributions: the Octal-to-OpCode (OtO) framework, which compiles file operations, state transitions and intent declarations into a 9-bit octal instruction set for microsecond-latency policy enforcement in the runtime kernel; and the Aegis Policy Language (APL), where the policy definition is the executable architecture, so an operation that cannot be expressed in valid APL syntax cannot produce a valid opcode and cannot execute. Submitted for consideration by the SECDISPATCH and RATS groups.
Defines new DHCPv4 and DHCPv6 options to explicitly signal available upstream and downstream data rates. In many broadband access networks CPE and intermediate nodes lack visibility into the subscriber's provisioned service tier; by communicating these capacities natively via DHCP, clients, relay agents and snooping switches can dynamically configure local traffic shaping and queuing. The explicit signalling reduces reliance on indiscriminate dropping and policing at the service edge and enables Active Queue Management and the L4S (Low Latency, Low Loss, Scalable Throughput) architecture.
Several link-layer standards mandate in-order delivery of layer-2 frames, apparently believing higher layers require it, and implement a resequencing operation that can add delay and degrade performance. Modern TCP and QUIC implementations tolerate out-of-order delivery far better. This draft provides new information for layer-2 technology standards on the actual need to assure in-order delivery to support IETF protocols.
Describes the changes between Unicode 12.0.0 and Unicode 18.0.0 in the context of IDNA2008. Additions and changes in the Unicode Standard affect the values produced by the IDNA2008 algorithm; the review assigns the derived property value 'UNDER REVIEW' to certain code points as backward-compatibility exceptions and supplies the tables IANA needs to make its database consistent with Unicode 18.0.0. The abstract stresses the work is based on pre-release data (Unicode 18.0.0 is unreleased), so its figures are provisional; all values are computed directly from the listed Unicode Character Database files via RFC 5892 Section 3.
Defines the Cedulon Protocol, an audit layer for agent-to-agent commerce. Payment rails such as HTTP 402 flows (x402) and mandate protocols (AP2) move value but do not by themselves produce a fail-closed policy check and a signed spend receipt that a verifier can reconcile against a rail extract. Cedulon specifies a signed Trade Manifest, a default-deny Policy Decision Point, a COSE/CWT Spend Receipt after a gated payment, epoch checkpoints and rail-extract reconciliation showing no settlement lacks a receipt and no receipt is absent from the extract. This revision profiles the checkpoint as a Signed Statement, extends the verification algorithm, brings equivocation within reach, and adds a Dispute Evidence Bundle and optional SCITT anchoring. It sits above x402 and AP2, not against them.
Specifies the External Verifier Contract (EVC), a small, testable, proof-system-agnostic boundary between a host (a program about to take a privileged action for an agent) and an external verifier subprocess that returns an allow/deny verdict on an opaque proof bundle. The contract governs only the transport and verdict envelope: how the host passes one JSON request over stdin, how the verifier answers with exactly one JSON verdict on stdout, and how the host handles exit codes, timeouts and malformed output under a fail-closed rule. It is deliberately not a governance framework, delegation model or policy language, but the narrow decision boundary those larger systems need at the point of enforcement.
Specifies BGP Failure Propagation (BGP-FP), an infrastructure and protocol that improves inter-domain routing convergence by accelerating the removal of stale (invalid) routes.
Specifies a trust-enforcement architecture for autonomous AI agents in container orchestration environments such as Kubernetes. It defines a sidecar injection pattern using mutating admission webhooks, graduated trust enforcement (L0-L4) on every outbound call, credential isolation via secret managers, bilateral revocation across clusters and tamper-evident evidence generation. It works alongside SPIFFE/SPIRE, extends X.509v3 with agent-specific extensions under a registered IANA PEN, and provides compliance evidence for EU AI Act Article 12, FDA 21 CFR Part 11, IEC 62443 and NERC CIP. Three default-deny gates (LLM, Database, API) classify each call, record it in a hash-chained ECDSA-signed ledger, and permit or refuse it.
Provides technical details of CVE-2026-33697 (CVSS 7.5) and EUVD-2026-16488, demonstrating how intra-handshake attestation fails in practice, even without physical access. It argues that because continuous attestation is generally required, intra-handshake attestation adds unnecessary complexity. The results are backed by research and artifacts using the ProVerif formal-analysis tool, released under Apache-2.0 for reproducibility and acknowledged by the relevant stakeholders.
Describes the Stateless IP/ICMP Translation Algorithm (SIIT), which translates between IPv4 and IPv6 packet headers, including ICMP headers. This document obsoletes RFC 7915.
Network operators running overlay networks need visibility into underlay hops during traceroute from overlay endpoints. This draft defines an ICMP extension object, the Underlay Information Object (UIO), that lets underlay head-end nodes encapsulate underlay error information within ICMP error messages, giving overlay operators visibility into underlay paths for troubleshooting.
Defines a YANG data model for the management of Computing-Aware Traffic Steering (CATS) systems.
Defines an extension to the RESTCONF protocol to support Trace Context propagation as defined by the W3C.
Defines how to propagate trace context information across the Network Configuration Protocol (NETCONF) to enable distributed tracing scenarios; it is an adaptation of the HTTP-based W3C specification.
Observes that autonomous AI agents increasingly perform actions once limited to authenticated human users - initiating financial transactions, querying regulated data, invoking tools and coordinating with other agents - while Internet protocols built for human-operated clients lack primitives to say which agent acted, whether it was authorised, and whether the resulting evidence is independently verifiable. This informational document defines a framework for agent identity and trust enforcement, enumerates gaps between current standards and autonomous-agent needs, and introduces a five-layer model (identity, authorization, attestation, evidence, trust) to separate concerns now conflated. It defines no wire protocol but references drafts that instantiate individual mechanisms.
Specifies a protocol for trust scoring, identity verification and spend-limit enforcement for autonomous AI agents that initiate financial transactions. As agents gain the ability to pay via protocols such as the Machine Payments Protocol (MPP), a standard mechanism is needed to verify identity, assess trustworthiness and enforce financial limits from behavioural history. It defines a five-dimension trust scoring model, per-agent ECDSA P-256 identity, challenge-response verification, trust-derived spend-limit tiers, anomaly detection and a public trust-query API. It complements draft-sharif-mcps-secure-mcp, which provides message-level security for the Model Context Protocol.
Defines protocol-mapping extensions for the Semantic Definition Format (SDF), enabling mapping of protocol-agnostic SDF affordances to protocol-specific operations.
Defines a cryptographic attestation framework for the full AI model lifecycle - from training-data provenance through weight signing, quantization verification, deployment attestation and per-inference output signing - creating an unbroken chain of evidence binding each inference output to the model version, training data and deployment configuration that produced it. It uses ECDSA P-256 signatures, SHA-256, Merkle trees for corpus attestation and JWKS for key discovery, and addresses threats including model distillation, quantization poisoning, training-data manipulation, silent degradation and output tampering. It complements the ATTP, MCPS and Agent Audit Trail drafts.
Specifies ATTP (Agent Trust Transport Protocol), a synchronous request-response protocol between autonomous AI agents and web API servers, operating over HTTP and adding mandatory cryptographic identity verification, per-message signing, trust-gated access control and tamper-evident audit trails to every interaction. It defines five request headers and three response headers carrying a JWT-based Agent Passport, ECDSA P-256 signatures, nonces and timestamps, all verified by server middleware before application code runs. ATTP has no insecure mode - every request and response body must be signed and recorded in a hash-chained trail - defines the attp:// URL scheme, and is the synchronous counterpart to the asynchronous Agent Transport Protocol (ATP).
Specifies how the Agent Trust Transport Protocol (ATTP) applies to Industrial Control Systems, SCADA environments and IoT deployments. It addresses per-message authentication gaps in legacy industrial protocols such as Modbus/TCP, OPC UA, MQTT and CoAP through mandatory ECDSA signing, cryptographic agent identity passports and trust-gated access control. It includes a gateway architecture that protects legacy devices without firmware modification, maps ATTP trust levels to IEC 62443 Security Levels, and defines real-time revocation suitable for safety-critical environments.
Defines a profile of OpenID Connect Core 1.0 that enables Identity Providers to issue identity tokens for autonomous software agents. It introduces standard claims representing agent identity, ownership, trust posture, authorised capabilities and compliance-screening status within OpenID Connect ID Tokens. The profile operates within existing OpenID Connect infrastructure without core-protocol changes and defines how Relying Parties validate agent tokens and enforce graduated access controls based on trust levels and sanctions-screening results.
Notes that traditional X.509-based PKI was designed for human-operated clients and long-lived servers and lacks primitives for graduated trust scoring, capability constraints, delegation chains, model provenance and the ephemeral lifecycles of AI agents. It defines Agent PKI (APKI), a certificate-based identity and trust system that extends X.509v3 with five agent-specific extensions, defines the agent:// URI scheme, specifies Agent Transparency Logs modelled on Certificate Transparency (RFC 9162) and provides cross-organizational trust federation. APKI is compatible with existing PKI, SPIFFE workload identity and IETF WIMSE specifications.
Specifies the Agent Transport Protocol (ATP), an asynchronous store-and-forward messaging protocol for autonomous AI agents that lets agents transmit themselves - state, context, capabilities and cryptographic identity - between runtimes across network boundaries. It draws on the SMTP (RFC 5321) operational model but is purpose-built for agent-to-agent communication where the agent is the payload. ATP provides store-and-forward delivery, per-hop cryptographic identity verification, ingress trust scoring and policy enforcement, runtime capability negotiation and tamper-evident end-to-end envelopes. It is transport-agnostic (TCP, TLS, QUIC) and interoperates with A2A, MCP and FIPA ACL.
Specifies Agent Event Behaviour Analysis (AEBA), a framework for collecting, signing, exchanging and analysing behavioural events from autonomous AI agents - the agent-domain equivalent of User and Entity Behaviour Analytics (UEBA) in enterprise SOCs. It defines a canonical event schema, signature binding to agent identity, baseline and peer-group exchange protocols, deviation signalling, detection-rule structure, revocation mechanisms and interoperability bindings for existing SIEM formats (syslog, CEF, LEEF). It composes with cryptographic primitives for agent identity, payment and transport, supporting cross-framework deployments where agents from different runtimes share a common observability surface.
This document is a formal administrative notice that the individual Internet-Draft draft-hawkins-scitt-attested-agent-payment has been discontinued and will not be progressed as an individual submission.
Argues that online child-safety controls (age flags, parental settings, content labels, server-side classification, age assurance, filters) act before the final rendering boundary, and an upstream decision does not guarantee that content cannot later be decrypted, decoded, composited, rendered or forwarded through another path. It defines a protected rendering execution-finality architecture for adult, explicit, violent, gambling-related or otherwise age-restricted content: a proposed rendering becomes a Restricted Content Candidate Act that stays non-renderable until a Protected Enforcement Domain validates recipient, content, device, policy, eligibility, freshness and revocation predicates. A Rendering Finality Sink then verifies scoped authority just before content becomes perceptible - controlling key release, decryption, decoder, GPU/compositor or display - so bytes may be delivered yet remain non-renderable. Its principle: permission to deliver is not permission to render.
Agent-authorization mandate formats authorise autonomous agents to act for human principals through signed constraint instances bound into delegated mandates, but their existing constraint families describe the transaction itself, not the environment in which it executes (whether a venue is open, a funding source is funded, or other external conditions hold at execution). This draft specifies the environment.* constraint family for mandate vocabularies, defined against a host-binding profile that the Verifiable Intent (VI) format satisfies. It defines the membership criterion, the family-wide vocabulary, composition and register discipline, security considerations and IANA registry mechanics; it defines no individual constraint type, referencing two examples (market_state, wallet_state) informatively.
Observes that LLM inference is normally run by one provider even when execution is distributed, and describes a different model where independently operated, mutually untrusted participants contribute compute, memory, model storage and network capacity to one inference service without any single entity admitting participants, selecting every path, holding the whole model or settling all contributions. It defines the Open, Decentralized and Scalable Inference (ODSI) architecture: roles, trust boundaries, named objects, protocol-independent interfaces, execution workflow, verification choices, timing model and security/privacy requirements for a multi-operator inference overlay. Related to CATS but not an extension of its single-provider model; this Informational document defines no wire format, consensus, payment system or new CATS metric.
Specifies host behaviour enabling IPv4 communication for dual-stack hosts on IPv6-only segments, without subnets, ARP, tunneling or translation. Hosts that receive 192.0.0.11/32 as their IPv4 default gateway resolve the next-hop link-layer address from the IPv6 neighbor cache rather than via ARP, and IPv4 packets are forwarded natively end-to-end. It is incrementally deployable alongside unmodified hosts with no DHCPv4 changes, and requests allocation of 192.0.0.11/32 in the IANA IPv4 Special-Purpose Address Registry.
Describes best current practices for operating an RFC 8181 RPKI publication engine and its associated publicly accessible rsync (RFC 5781) and RPKI Repository Delta Protocol (RRDP, RFC 8182) repositories.
AI agents increasingly delegate tasks to other agents, and each delegation should convey only a bounded subset of the delegator's authority that any enforcement point can verify offline. OAuth 2.0 Token Exchange (RFC 8693) models two-party delegation and records prior actors in a nested 'act' claim, but that claim is informational and cannot enforce attenuation across chains of depth two or more. This draft defines the Agent Delegation Chain: a profile of OAuth 2.0 JWT access tokens (RFC 9068) that carries authority as Rich Authorization Requests (RFC 9396), links each delegation to its parent by a cryptographic byte-commitment, and specifies a deterministic offline verification algorithm enforcing monotonic attenuation, bounded depth and monotonic expiry, reusing existing JOSE, proof-of-possession and status-list machinery with no new cryptography.
Many network applications, from AI/ML training and inference to cloud services, need combinations of high bandwidth, low delay, low jitter and minimal packet loss, requiring networks to adapt rapidly to faults, degradation and congestion. Existing routing and traffic-management mechanisms are often limited in responsiveness, coverage and operational complexity, especially in large-scale, high-bandwidth environments such as data centres and DCI. This document presents a gap analysis and the need for fast network notification, and identifies the set of problems a fast network notification solution must address.
Defines a methodology for benchmarking Segment Routing (SR) performance for both Segment Routing over IPv6 (SRv6) and MPLS (SR-MPLS).
The WIMSE architecture defines authentication and authorization for software workloads across runtime environments, from basic deployments to complex multi-service, multi-cloud, multi-tenant systems. This draft specifies the Workload Proof Token (WPT), a mechanism for a workload to prove possession of the private key associated with a Workload Identity Token (WIT). The WPT is a signed JWT that binds the workload's authentication to a specific HTTP request, giving application-layer proof of possession for workload-to-workload communication. It works alongside the WIT credential format in draft-ietf-wimse-workload-creds and can be combined with other WIMSE protocols in multi-hop call chains.
Defines a new BGP Capability that enables an IPv6 BGP speaker to use its global unicast IPv6 address as its BGP Identifier. This simplifies configuration in IPv6-only networks by leveraging the inherent uniqueness of IPv6 addresses, while remaining fully backward-compatible with existing BGP implementations.