Window: last 48 hours (Aug 30 - Sep 1, 2026 UTC) · generated 2026-09-01
Post-Quantum/Traditional Hybrid Key Exchange with the Module-Lattice-Based Key-Encapsulation Mechanism for Use in SSH
This document defines Post-Quantum/Traditional (PQ/T) Hybrid key exchange methods that combine the quantum-resistant Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) with traditional Elliptic-Curve Diffie-Hellman (ECDH) key exchange. By deriving the shared secret from both a post-quantum KEM and a classical ECDH exchange, the hybrid approach stays secure as long as at least one of the two component algorithms remains unbroken, easing the transition to post-quantum cryptography. The methods are specified for use in the SSH Transport Layer Protocol. This summary is grounded in the document's official Abstract.
By its name, this individual submission appears to address "child-safe rendering finality" — probably guarantees or mechanisms ensuring that content presented to child users settles into a safe, final rendered state and cannot be silently altered afterwards. It likely connects to the IETF/IAB conversation on age-based restrictions and online safety that has been active recently. The exact scope, terminology, and any protocol elements are not confirmed here because the official Abstract could not be read on this run; this summary is approximate and will be grounded next time.
The name points to an IPFIX (IP Flow Information Export) extension related to SAV (Source Address Validation), in the operations and management (opsawg) context. It probably defines new IPFIX Information Elements so that routers can export source-address-validation events or state — for example, packets dropped or permitted by SAV — for monitoring and troubleshooting. Details of the specific elements and encodings are not confirmed on this run; the description is approximate and based on the document name.
By its name, this individual submission appears to address "child-safe rendering finality" — probably guarantees or mechanisms ensuring that content presented to child users settles into a safe, final rendered state and cannot be silently altered afterwards. It likely connects to the IETF/IAB conversation on age-based restrictions and online safety that has been active recently. The exact scope, terminology, and any protocol elements are not confirmed here because the official Abstract could not be read on this run; this summary is approximate and will be grounded next time.
By its name this is a PCEP (Path Computation Element Communication Protocol) extension concerning Source Address Validation. It likely specifies new PCEP objects or TLVs to convey SAV-related information between a PCE and PCC, so that computed paths can account for or install source-address validation state. The precise mechanism is unconfirmed here; this is an approximate, name-based summary pending grounding against the official Abstract.
An IDR working-group document extending BGP-LS (BGP Link-State) to distribute inter-AS (inter-domain) topology information. It probably defines additional BGP-LS NLRI or attributes that let a controller assemble a topology view spanning multiple autonomous systems. The high revision number (-40) indicates a long-running, mature specification. Exact attribute definitions are not confirmed on this run; the summary is approximate and derived from the name.
The name indicates a SCIM (System for Cross-domain Identity Management) extension that adds cursor-based pagination for attribute or resource queries, as an alternative to the index/count pagination SCIM defines today. Cursor pagination is typically more stable and efficient over large, changing result sets. The specific query parameters and response semantics are unconfirmed here; this is an approximate, name-based description.
By its name this individual draft ties IPFIX export to a BGP "point of view" (pov) in the SIDR Operations (sidrops) context, which deals with RPKI and route-origin/route validation. It probably describes exporting flow telemetry annotated with BGP/RPKI validation state so operators can observe how routing security decisions map to real traffic. The details are not confirmed on this run; the summary is approximate.
This submission sits in the CATS (Computing-Aware Traffic Steering) problem space. Its name suggests "intelligent-node" network scheduling — probably a scheme for scheduling traffic and compute across capable nodes based on their computing and network state. The concrete scheduling algorithm and any signaling are unconfirmed here; this description is approximate and based on the document name.
Another CATS-related individual draft; the name points to an "AI semantic contract" — likely a way to express semantic agreements or service contracts for AI-aware compute/traffic-steering services, so that clients and the network share a common understanding of what an AI service offers. The precise model is not confirmed on this run; the summary is approximate.
An MPLS working-group document applying STAMP (Simple Two-Way Active Measurement Protocol) to pseudowires (PW). It probably specifies how to run STAMP test packets over a pseudowire to measure delay and loss for emulated services carried across an MPLS network. Exact encapsulation and procedures are unconfirmed here; this is an approximate, name-based summary.
A SNAC working-group document titled "Automatically Connecting Stub Networks to Unmanaged Infrastructure." It describes how a stub-network router can automatically attach a small stub network to adjacent, unmanaged infrastructure without manual configuration — covering prefix delegation, routing, and service discovery in that setting. The title is known from the announcement; the finer technical detail here is approximate because the official Abstract was not read on this run.
This individual draft appears in the security dispatch (secdispatch) / RATS (Remote ATtestation procedureS) area. The name suggests a remote-attestation mechanism for an "aegis" security framework or filesystem, brought to secdispatch for triage toward an appropriate venue. The specific attestation flow and evidence formats are unconfirmed here; the summary is approximate and name-based.
A SNAC working-group document titled "Automatically Connecting Stub Networks to Unmanaged Infrastructure." It describes how a stub-network router can automatically attach a small stub network to adjacent, unmanaged infrastructure without manual configuration — covering prefix delegation, routing, and service discovery in that setting. The title is known from the announcement; the finer technical detail here is approximate because the official Abstract was not read on this run.
An Internet Area (intarea) draft, by Warren Kumari and others, on "safe limited domains." It probably builds on the limited-domains concept (RFC 8799), discussing how to define and operate such domains safely so that domain-specific protocol behavior does not leak or cause harm outside the domain boundary. The concrete guidance is unconfirmed on this run; this description is approximate.
An LSR working-group YANG data model for IS-IS with SRv6 (Segment Routing over IPv6). It likely augments the IS-IS YANG model with configuration and operational state for SRv6 locators, end-behaviors, and related parameters, enabling standardized management of SRv6-enabled IS-IS. Exact model contents are not confirmed here; this is an approximate, name-based summary.
An OPSAWG working-group document defining IPFIX Information Elements to export path segment identifiers — for example Segment Routing path segments — so that exported flow records carry the path a flow traversed. This supports fine-grained path visibility and SR performance monitoring. The precise element definitions are unconfirmed on this run; the summary is approximate.
A new individual submission naming a "PSHMP" core specification. The acronym is not expanded in the announcement, so the purpose cannot be stated with confidence; by its name it probably defines the core of a new protocol "PSHMP." This is a cautious, name-only note — no algorithms or fields are asserted — and it will be grounded against the official Abstract on a future run.
By its name, this individual draft discusses "digital sovereignty finality" — probably a conceptual or architectural treatment of digital-sovereignty requirements and the notion of finality (irreversible, authoritative outcomes) in that setting. Whether it proposes protocol mechanics or is purely a framing document is unconfirmed here; this summary is approximate and based on the name.
The name suggests a document about handshake failure handling ("intra handshake fail"). It probably describes how a protocol should detect, signal, or recover from failures that occur within a handshake exchange. The relatively high revision (-17) suggests sustained iteration. The specific protocol and procedures are not confirmed on this run; this is a cautious, approximate, name-based note.
An IRTF ICNRG (Information-Centric Networking Research Group) draft on CCNx versioning. It likely defines a versioning convention for named content in CCNx/Content-Centric Networking — how different versions of a named object are named, discovered, and retrieved. As an IRTF research-group document it is experimental in nature. Exact naming rules are unconfirmed here; the summary is approximate.
An HTTP (httpbis) individual draft on "connection contamination." It probably describes a class of problems where an HTTP connection becomes contaminated — for example through incorrect connection reuse or coalescing across origins — and proposes detection or mitigation. The precise threat model and remedies are unconfirmed on this run; this description is approximate and name-based.
A new individual draft by Mark Nottingham whose name points to an "archive embargo" mechanism — probably a way to signal that archived or cached web content should not be released or surfaced until an embargo period ends. The exact signaling (headers, fields, or policy) is not confirmed here; this is an approximate, name-based summary pending the official Abstract.
An individual draft named "cedulon." The term is not explained in the announcement, so its purpose cannot be stated confidently; it is probably a named protocol or system defined by the authors. This is a deliberately cautious, name-only note — no specifics are asserted — and it will be grounded against the official Abstract on a later run.
An OAuth-area individual draft on "agent grants." It probably defines an OAuth 2.0 grant type or flow that lets autonomous agents obtain authorization to act on behalf of a user or service, an area of growing interest as AI agents call protected APIs. The exact grant semantics and security considerations are unconfirmed on this run; this summary is approximate and based on the name.
By its name, this individual draft discusses "digital sovereignty finality" — probably a conceptual or architectural treatment of digital-sovereignty requirements and the notion of finality (irreversible, authoritative outcomes) in that setting. Whether it proposes protocol mechanics or is purely a framing document is unconfirmed here; this summary is approximate and based on the name.
By its name this individual draft concerns "AIC identity certificates" — probably a certificate profile or issuance scheme for identifying AI components or agents. It likely aims to bind an identity to an AI entity so its actions can be authenticated. The precise certificate format and trust model are not confirmed here; this is an approximate, name-based description.
A CATS-related individual draft defining the semantics of metrics used in Computing-Aware Traffic Steering. It probably specifies how compute- and network-related metrics are defined, interpreted, and compared so that steering decisions are consistent across implementations. The concrete metric set is unconfirmed on this run; the summary is approximate and based on the document name.
A new NETMOD-area individual draft adding a "comparability scope" extension. It probably extends YANG or NETMOD tooling to express the scope within which values or nodes may be meaningfully compared. The exact YANG statements or semantics are not confirmed on this run; this is an approximate, name-based note that will be grounded later.
A new BESS-area individual draft analyzing designated-forwarder (DF) hashing in EVPN. It probably examines how EVPN's DF election hashing behaves — for example fairness or distribution across Ethernet segments — and may propose improvements. Being an analysis document, it likely focuses on evaluation rather than new protocol machinery. The specifics are unconfirmed here; this summary is approximate.
A new NETCONF-area individual draft on causal ordering for YANG-Push. It probably describes how to preserve or convey causal ordering among YANG-Push notifications so that subscribers can reconstruct the order in which datastore changes actually occurred. The exact mechanism is not confirmed on this run; this is an approximate, name-based description.
A new BESS-area individual draft applying CRDTs (Conflict-free Replicated Data Types) to EVPN mobility. It probably proposes using CRDT techniques to resolve MAC/host mobility conflicts in EVPN without tight coordination, improving convergence when a host moves between PEs. The concrete design is unconfirmed here; this summary is approximate and based on the name.