Generated 2026-10-01 UTC · Window: last 48 hours (2026-09-29 to 2026-10-01) · Coverage: all groups
No RFCs were announced in the window. The ietf-announce archive shows no "RFC NNNN on ..." announcements after 2026-09-19; there are no items in the 48-hour window.
Discusses the applicability of WIMSE (Workload Identity in Multi-System Environments) to agentic AI, establishing independent identities and credential-management mechanisms for AI agents. It also discusses mechanisms for cryptographically binding an AI agent identity to an accountable user or organization.
Specifies a binding profile for control actions issued to operational-technology (OT) systems by software agents. Each action must carry verifiable statements identifying the agent, the human principal it represents, whether that principal authorized this specific action on this specific asset, whether a named human approved it where risk requires, and an append-only audit record for attribution. The profile composes existing primitives (DNSSEC-rooted agent discovery, scoped revocable grants, named-human authorization receipts, transparency records) into a single Command Authority Envelope (CAE) that enforcement points reject if any required binding is missing or invalid. It maps to IEC 62443 and NERC CIP identification, use-control and audit requirements, and MUST NOT sit in the trip path of a safety function.
Defines a standard mechanism to measure, report, and compare the power usage of different networking devices under different network configurations and conditions.
Describes a generic architecture for intra-domain Source Address Validation (SAV), providing a common framework for developing new intra-domain SAV mechanisms. It describes the conditions under which this architecture can improve SAV accuracy and operational efficiency relative to existing intra-domain SAV mechanisms.
Specifies IntraSAV, a solution for intra-domain source address validation that addresses the problem stated in the savnet intra-domain problem statement (RFC-to-be). It updates BCP 38 (RFC 2827) and BCP 84 (RFC 3704, RFC 8704) with a more comprehensive methodology, accommodating prefixes that are not routed but are used to source traffic originating from an AS.
Presents an operator-perspective framework for building and operating IPv6-only core networks spanning multiple interconnected Autonomous Systems. To carry residual IPv4 traffic, it proposes stateless IPv4/IPv6 address mapping as the basis for IPv4-as-a-Service (IPv4aaS), translating IPv4 packets at the network edge and forwarding them across the IPv6-only core without per-flow state or conversion gateways on the data path. It is a problem statement, guidance and requirements document rather than a protocol spec, covering applicability, trust boundaries, mapping-prefix allocation options, and operational, manageability and security considerations.
Notes that DKIM2 implementations benefit from seeing extra debug information during the early deployment phase. This document is intended to help testers and is explicitly unlikely to be published as an RFC.
The Simple Two-Way Active Measurement Protocol (STAMP) and its optional extensions support Edge-to-Edge active measurements, while In-situ OAM (IOAM) data fields record Hop-by-Hop and E2E telemetry. This document extends STAMP to reflect IPv4/IPv6 headers as well as IPv6 extension headers for Hop-by-Hop and E2E active measurements, for example using the IOAM data fields.
A vCon is the container for information relating to a real-time human conversation, analogous to a vCard for points of contact. Its data may derive from any multimedia session, phone call, video conference, SMS/MMS exchange, webchat or email thread, and may include Call Detail Records, metadata, participant identity (e.g. STIR PASSporT), the conversational media itself (audio, video, text), real-time or post-conversation analysis, and attachments. A standardized container enables many applications and a common method of storage and interchange, and supports identity, privacy and security efforts.
Specifies the verification.* constraint family: a pre-action, fail-closed gate primitive for AI-agent decisions. A verification.* receipt is a JWS-signed artifact carrying a canonical input, a derived binary act/halt output, and a versioned mapping identifier binding them; a relying party recomputes the gate locally and never trusts the issuer's runtime. This revision introduces a four-state vocabulary (verified, contradicted, indeterminate, not_evaluated) plus reason codes separating a state's substance from instrument failure, an admissibility gate, and evidence pinning (an evidence_set block content-addressing sources so a verdict can be recomputed offline). Freshness is anchored to the evidence's own retrieved_at timestamp. The shape aligns with EU AI Act Article 12 record-keeping and a 2026 Zero Trust for AI Agents framework, and is forward-compatible across mapping revisions.
Presents solutions for deploying multicast in SRv6 networks, exploring the use of the native IPv6 multicast data plane for multicast distribution. It discusses distributed control-plane mechanisms including PIM and its integration with IGP Flex-Algo to optimize delivery, and addresses overlay multicast for both Global Table Multicast (GTM) and Multicast VPNs (MVPNs) using IP-in-IPv6 encapsulation without additional shim layers.
By its name this appears to be an individual submission in the 'AER1' series; the official abstract could not be retrieved on this run. Several revisions (-03 through -06) were posted across the window, indicating rapid iteration. The description will be grounded from the official Abstract on the next run.
Addresses auditable payments for AI agents, building upon state-of-the-art HTTP 402, AP2 and credit-card systems. It specifies a cryptographically secured payment-reconciliation protocol using a Trade Manifest (a signed offer before payment), a Policy Decision Point with default deny, a Spend Receipt (a COSE/CWT claim set issued after a gated payment), and rail-extract reconciliation.
RFC 4552 specifies the use of the IPsec Authentication Header (AH) and the Encapsulating Security Payload (ESP) to provide authentication and confidentiality for OSPFv3. This document deprecates the use of AH for OSPFv3 and updates RFC 4552 accordingly. Operators are encouraged to use either ESP with NULL encryption (per RFC 4552) or the OSPFv3 Authentication Trailer (per RFC 7166).
Defines the did:x509 decentralized identifier (DID) method, a flexible issuer-identifier format for messages that transport or refer to X.509 certificates, including COSE messages using RFC 9360. It binds a certificate chain to a compact issuer string by combining the fingerprint of a CA certificate in the chain with predicates on the leaf certificate's subject name, SANs, extended key usage, or Fulcio issuer. The identifier can be conveyed as an issuer value in COSE CWT claims (RFC 9597), in JOSE/JWT messages such as the iss claim (RFC 7519), or via other protocol-specific mechanisms. The method lets existing X.509 and DID-based systems interoperate where a full DID transition is not achievable. It is an Informational Independent Submission describing the method as implemented by Microsoft.
Defines transport profiles for running RADIUS over TLS and DTLS, allowing secure and reliable transport of RADIUS messages. RADIUS/TLS and RADIUS/DTLS are collectively referred to as RadSec. This document obsoletes RFC 6614 and RFC 7360, which specified experimental versions of RADIUS over TLS and DTLS.
Traffic-engineered networks are commonly provisioned for peak demand, leaving resources lightly used and consuming unnecessary power off-peak. This document defines a generic power-management framework for coordinating power-sleep and wakeup transitions between adjacent nodes, defining roles, resource scope, procedures, collision handling, failure behavior and traffic-engineering-preservation requirements, and then specifies an RSVP-TE signaling extension to support it so service can be restored safely.
Specifies how to proxy Ethernet frames in HTTP, similar to IP proxying in HTTP but for Layer 2 instead of Layer 3. It defines a protocol that allows an HTTP client to create a tunnel to exchange Layer 2 Ethernet frames through an HTTP server with an attached physical or virtual Ethernet segment.
Argues, with technical detail from several CVEs and GitHub Security Advisories, that early attestation fails in practice even without physical access to the target machine. Since continuous attestation is generally required, the work contends that early attestation adds unnecessary complexity. Results are backed by formal analysis using ProVerif (Apache-2.0). It catalogs multiple published CVEs/GHSAs across a range of CVSS scores and states that, based on this work, all but two early-attestation implementations have been archived, withdrawn, or moved to post-handshake attestation.
Point-to-multipoint (P2MP) BFD is designed to verify multipoint connectivity. This document specifies the application of P2MP BFD in a BIER (Bit Index Explicit Replication) network.
Builds on the Power Conserving Path Placement Strategy (PCPPS), which concentrates traffic onto a small set of network resources so that other resources become idle and can be powered down until needed, conserving energy. PCPPS uses information distributed by an IGP; this document specifies the IS-IS encoding for that information.
Defines the TLS Trust Anchors extension, a mechanism for a TLS client or server to select a certificate to present based on the peer's trusted certification authorities. It describes certification authorities more succinctly than the TLS Certificate Authorities extension.
By its name this appears to be an individual submission in the 'AER1' series; the official abstract could not be retrieved on this run. Several revisions (-03 through -06) were posted across the window, indicating rapid iteration. The description will be grounded from the official Abstract on the next run.
Defines IANA registries for the YANG Protocol Error List and YANG Protocol Error Identities.
Specifies how the Internet Key Exchange Version 2 (IKEv2) protocol can be used for supplying keys for the PSP Security Protocol (PSP).
The BGP Monitoring Protocol (BMP) gives full visibility into BGP RIB state, but transient faults, process restarts or buffer overflows can desynchronize the sender's authoritative RIB from the collector's stored view, and existing recovery requires disruptive session teardown or full re-export. This document defines a new BMP Route-Refresh message type that encapsulates standard and Enhanced Route-Refresh semantics within BMP to enable fine-grained, non-disruptive, targeted per-peer or per-AFI/SAFI RIB re-synchronization.
BMP lets routers export BGP RIB data and statistics to collectors, but dynamic changes to a router's monitoring configuration (such as disabling specific Address Families or counters) are not signaled, so collectors cannot distinguish a quiescent BGP state from a disabled feed, leading to staleness and database pollution. This document defines a new BMP Monitoring Options (MO) message that lets a BMP sender explicitly notify collectors of active, disabled, or dynamically altered reporting configurations across RIB types and statistics streams.
Delegation-chain specifications describe the shape of conveyed authority but leave the verifier's half of the exchange underdetermined, so two verifiers can check the same chain, both report success, and enforce different policy. This document states what a verifier must do: the explicit inputs evaluation depends on, how those inputs behave when their sources are stale or unavailable, and four rules that keep evaluation fail-closed. The rules are drawn from the Grant & Autonomy Lifecycle (GAL) and Provenance & Trust Context (PTC) specifications and a public reference implementation.
Defines YANG data models for managing BGP information about the Resource Public Key Infrastructure (RPKI).
Defines conformance classes, validation-result structure, schema requirements, test-vector categories, conformance assertions, reference-validator behavior, implementation disclosure and interoperability-testing guidance for the Judgment Event Protocol (JEP). A companion to JEP-Core 0.7, it does not redefine JEP-Core semantics; its purpose is to make JEP-Core 0.7 implementations testable and interoperable across languages, platforms, trust profiles and deployment environments.
Specifies extensions to the Kerberos PKINIT pre-authentication mechanism to support post-quantum key establishment using the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) algorithms of FIPS 203. The extensions define a new kemInfo arm in PA-PK-AS-REP, a KDC-signed KDCKEMInfo structure, HKDF-based AS reply-key derivation (HKDF-SHA-512 for ML-KEM), and downgrade-prevention rules. The KEM-path framework supports multiple KEM algorithms including ML-KEM, composite ML-KEM, and future KEM standards.
Specifies the compute-location gate: a mechanism by which a client and an identity-inference server negotiate, at the wire layer and before any inference is performed, the location at which an identity inference will compute, as a deterministic function of the provenance class of the input signal.
Specifies a DNS-based mechanism for discovering Model Context Protocol (MCP) servers, organizational identities, and cryptographic identity envelopes. Three TXT records are defined: _mcp.<domain> advertises MCP endpoints, transport bindings, cryptographic identities and capability profiles; _org-alter.<domain> publishes operator identity (legal entity, registry identifiers, operating regions, regulatory frameworks); and _alter.<domain> publishes Ed25519-signed envelopes binding Sovereign-tier handles to public keys, IdentityLog roots and revocation commitments. It complements HTTPS discovery and follows DKIM/SPF/DMARC/MTA-STS precedent, requiring DNSSEC validation for envelope records and DANE TLSA pins when resolution and MCP session establishment occur together, and requests provisional registration of an alter: URI scheme.
Describes a mechanism to allocate network resources to one or a set of Segment Routing Identifiers (SIDs), referred to as resource-aware SIDs. These SIDs retain their original forwarding semantics with additional semantics identifying the set of network resources available for packet processing and forwarding. The mechanism applies to both SR-MPLS and SRv6 data planes.
Defines the Bluetooth Low Energy (BLE) Transport Binding Profile for the Offline Emergency Peer-to-Peer Broadcast Protocol (OEPB). It specifies the advertising mode, fragmentation and reassembly scheme, service and characteristic UUIDs, and channel-access rules required to carry OEPB packets over BLE 4.x and BLE 5.x physical layers.
OEPB enables dissemination of authenticated emergency alerts among unprovisioned devices over short-range peer-to-peer radios when network infrastructure is unavailable. Key features include a compact 256-byte packet format with Ed25519 signatures; transport abstraction over Bluetooth Low Energy, Wi-Fi Direct and LoRa; per-message Trickle dissemination with bounded retransmissions; five-class weighted fair queuing reflecting emergency priorities; and a trust model where relays forward without verifying signatures to preserve reachability for unauthenticated distress messages while receivers authenticate authority alerts.
Specifies how an AI-agent runtime, bound at instantiation to a principal identity handle, resolves at session initialization a target organizational identity substrate and retrieves a typed policy stack (a handbook artefact, an SOP registry pointer, an enforcement-gate specification, and an audit-signal ingestion endpoint). The policy stack is applied as runtime constraints on subsequent tool invocations, with audit signals emitted back to the substrate, so policy provision occurs in the same act as principal identification rather than via a side-channel. A principal bound to multiple substrates operates under a deterministic composition of policy stacks, with residual conflicts routed to the Identity Accord ceremony. Informational; relies on draft-morrison-mcp-dns-discovery and draft-morrison-identity-pronouns.
Defines an identity-pronoun grammar as a reference axis orthogonal to the ~handle identity-tier taxonomy. A pronoun is a session-scoped reference that resolves client-side to a concrete handle using local session state before any cryptographic, DNS or federation operation. The entity-class taxonomy (Sovereign, Bot, Instrument) is unchanged; Absolute vs Pronoun is introduced as an orthogonal axis. A pronoun MUST NOT appear in a capability token, DNS record, Accord signature, or inter-organizational payload. The reference implementation defines one Wave-1 pronoun, ~org, resolving to the organization bound to the caller's current session, with a relative-path pronoun grammar sketched as future work.
Specifies the briefing-and-binding envelope: a delivery contract for how an AI agent surfaces a consequential decision to the human principal it acts for, and how the principal commits, declines, amends or rejects it. The envelope carries eight named slots (synopsis, findings, recommendations, an offer of detail, a question stem, options each with its own reasoning, a single recommended option, and a pair of escape hatches) and is emitted as a structured field of an MCP tool result. Its central element is a dual-veto handshake: one escape hatch revises the answer space while accepting the question, the other rejects the question itself and reopens deliberation. A JCS-canonicalized SHA-256 content digest lets a resolution name the exact envelope it resolves. Informational.
Part of the individual 'Helm Protocol' series (by its name, 'tttps' suggests a transport or trust-transfer mechanism); the official abstract was unavailable on this run. Details will be grounded from the official Abstract on the next run.
Defines dialogue.txt, a small text file a person or organization publishes at a well-known location on its own domain. It is the publisher's own standing, talk-only consent to be contacted by any reader, including software systems, with no prior relationship. A first message only proposes a conversation; the publisher's reply creates the channel. The file grants talk and nothing else (no action, advertising, access, or representation), and the publisher may name the topics it can be asked about.
Describes EAP using Privacy Pass token (EAP-PPT) Version 1. The protocol specifies use of the Privacy Pass token for client authentication within EAP (RFC 3748). Privacy Pass is a privacy-preserving authentication mechanism used for authorization (RFC 9576). EAP-PPT must be performed only within a tunnel-based EAP method.
Adds Private Use ranges to IANA registries that pertain to the Lightweight Authenticated Key Exchange (LAKE) protocol.
Fine-grain Optical Transport Network (fgOTN) is a data-plane technology (ITU-T G.709/Y.1331 (2020) Amd. 3) that complements existing OTN with bandwidth-efficient support for sub-1 Gbit/s services. This document defines YANG data models to describe the topology and tunnel information of an fgOTN network.
Defines a set of IPFIX Information Elements for monitoring Explicit Congestion Notification (ECN), specifically in the context of the Low Latency, Low Loss, and Scalable Throughput (L4S) service. They allow operators to observe ECN codepoint usage within L4S deployments and evaluate the corresponding traffic performance.
Defines the knowledge-linkset well-known URI, at which a web origin publishes one link set describing the knowledge artefacts it makes available (graph serializations, a JSON-LD context, an agent-facing text file, a chunk export, a change ledger, and related resources). Each artefact link may carry a SHA-256 digest (HTTP digest-field syntax) so a client can verify the retrieved artefact, and a profile URI identifies the conventions followed. It defines no new media type or link relation type, pointing at the resource with the existing describedby relation, and requests one well-known URI registration.
Defines Forwarding Commitment BGP (FC-BGP), an extension to BGP that secures the path of Autonomous Systems through which a BGP UPDATE passes. A Forwarding Commitment (FC) is a cryptographically signed segment certifying an AS's routing intent on its directly connected hops. Based on FC, FC-BGP builds a secure inter-domain system that can simultaneously authenticate the AS_PATH attribute and alleviate route leaks. The extension is backward compatible, so a supporting router can interoperate with a non-supporting one.
Specifies an extension to the EAP-AKA' protocol introducing a Bitmap-based Selective Acknowledgment (SACK) mechanism to the AT_FRAGMENT attribute. This enables window-based transmission and precise recovery of lost fragments, optimizing fragment delivery during post-quantum identity concealment and authentication exchanges.
Specifies an extension to the EAP-AKA' protocol introducing a Bitmap-based Selective Acknowledgment (SACK) mechanism to the AT_FRAGMENT attribute. This enables window-based transmission and precise recovery of lost fragments, optimizing fragment delivery during post-quantum identity concealment and authentication exchanges.
By its name this relates to Computing-Aware Traffic Steering (CATS) and the mapping of agent selection; the official abstract was unavailable on this run. It probably defines how agent/service-instance selection maps onto CATS metrics or paths. To be grounded on the next run.
Computing-Aware Traffic Steering (CATS) optimizes steering of traffic to a service instance by considering the dynamic state of computing and network resources. To enable such decisions, CATS components exchange metrics describing resource conditions affecting service-instance selection. This document focuses on compute and communication metrics for CATS and defines a hierarchical abstraction of them to improve interoperability, scalability and operational simplicity. It does not standardize raw (Level 0) metrics; instead it specifies higher-level representations derived from raw measurements via aggregation and normalization.
The BGP Flowspec mechanism (BGP-FS) propagates both traffic Flow Specifications and Traffic Filtering Actions using BGP NLRI and Extended Community encodings. This document specifies a new BGP-FS component type to support community-level filtering: the match field is the community of the destination IP address encoded in the Flowspec NLRI. The function is applied within a single administrative domain.
Defines two YANG data models to support scheduled network diagnosis using OAM tests. The oam-unitary-test and oam-sequence-test modules manage the lifecycle of network-diagnosis procedures, intended for use by external management and orchestration systems (including SDN controllers and network orchestrators) rather than by individual network nodes.
OAuth 2.0 access tokens are typically scoped to a session rather than a transaction and carry no transaction context. This document defines Transactional Access Tokens: a JWT access-token profile carrying a transaction identifier and authorization-server-asserted transaction context, with a very short lifetime and audienced to a single resource server. They align with the claims and semantics of OAuth Transaction Tokens so transaction context can flow from the AS to a resource server and onward. A primary use case is task-scoped authorization of AI agents, where the AS makes a fresh policy decision per transaction.
Provides guidelines and best practices for writing security considerations in RATS technical specifications, targeting the needs of implementers, researchers and protocol designers. It addresses 'bottom turtle' trust-anchoring issues and currently presents an outline of general security guidelines and templates for RATS that will receive more detailed coverage in future versions.
By its name this appears to be an individual submission in the 'AER1' series; the official abstract could not be retrieved on this run. Several revisions (-03 through -06) were posted across the window, indicating rapid iteration. The description will be grounded from the official Abstract on the next run.
The Virtualized Conversations (vCon) specification defines a standardized object format for multimedia conversations, recently expanded to capture sessions with AI agents including tool calls, reasoning steps and model configuration, which broadens the requirements for redaction of sensitive information. This document outlines use cases and requirements for redaction in vCons. It is intended for discussion purposes, and the author notes the whole document was written by a human rather than an LLM.
The Agent Action Decision Protocol (AADP) decides, per action, whether an agent's concrete request may proceed now, assuming the decision is consumed by an enforcement point on the same secured channel. This document specifies AADP's action-bound permit: a permit signed by the decision point and bound to one recipient, one presenter key, one HTTP request and one decided action instance, and short-lived. It composes with mandate formats such as the Agent Authorization Envelope, carrying a decision the recipient cannot recompute because it depends on issuer-held state (cumulative budgets, live reservations, approval lifecycle, escalation). It adds scoped issuer trust, a declared currentness mode, a mandate reference, a verification order with registered refusal reasons, and a signed confirmation, defining no new signature, token or policy format.
Specifies the Verifiable AI Provenance (VAP) Framework for cryptographically verifiable decision audit trails in high-risk AI systems, plus the Legal AI Profile (LAP) for legal/LegalTech systems. VAP defines common infrastructure: hash-chain integrity, digital signatures, Bronze/Silver/Gold conformance levels, external anchoring via RFC 3161 timestamping and compatible transparency services (including IETF SCITT), a Completeness Invariant guaranteeing no selective logging, a standardized Evidence Pack format, and privacy-preserving verification. LAP extends VAP for the judicial domain with attorney-oversight verification, three-pipeline completeness invariants, tiered retention with legal-hold protocols, graduated override enforcement, and privacy fields preserving attorney-client privilege while enabling third-party auditability.
A Transparency Service (RFC 9943) registers Signed Statements about Artifacts and returns Receipts (RFC 9942) proving append-only registration, but today's statements describe how an artifact was built, tested or released, not what happens after it is sealed, moved, lost and re-created. This document defines a Continuity Receipt: the Receipt obtained when a recovery event is registered as a Signed Statement. It specifies the Subject and required claims of a recovery Statement, how RFC 9334 Attestation Results are carried or referenced, and how a sequence of such Statements under one Subject forms a verifiable continuity chain across a stateful asset's lifetime. It defines a payload and claim set only, and records rather than conceals divergence from its reference implementation.
By its name this specifies ICANN registry interfaces (a registry-operations/provisioning document); the official abstract was unavailable on this run. Its high revision number (-27) indicates a long-running individual specification. To be grounded on the next run.
Formalizes and consolidates the definition of the Concise Diagnostic Notation (CDN) of CBOR, addressing implementer experience. Replacing CDN's previous informal descriptions, it updates RFC 8949 (obsoleting its Section 8) and RFC 8610 (obsoleting its Appendix G). It also specifies registry-based extension points and uses them to support text representations such as epoch-based dates/times and IP addresses and prefixes.
Updates the AUTH48 or equivalent process by introducing deterministic state-integrity constraints within the IETF Datatracker architecture. It establishes automated validation milestones and explicit access controls to prevent late technical modifications after Working Group Last Call, thereby safeguarding rough consensus. The constraints and milestones apply programmatically across the core processing streams, and the document updates RFC 6359 and RFC 7841.
Lists many of the considerations the DNS community needs to balance when deciding which post-quantum algorithms to standardize for DNSSEC. The draft states explicitly that it is not meant to become an RFC.
Segment Routing can steer packets via source routing over MPLS (SR-MPLS) and IPv6 (SRv6) data planes. This document describes procedures for performance measurement in SR-MPLS networks using STAMP (RFC 8762) with its optional extensions (RFC 8972) and the SR-specific extensions (RFC 9503). The procedures measure SR-MPLS paths (Segment Lists of SR-MPLS Policies, SR-MPLS IGP best paths, and IGP Flex-Algo paths) as well as Layer-3 and Layer-2 services carried over those paths.
Segment Routing can steer packets via source routing over MPLS (SR-MPLS) and IPv6 (SRv6) data planes. This document describes procedures for performance measurement in SRv6 networks using STAMP (RFC 8762) with its optional extensions (RFC 8972) and the SR-specific extensions (RFC 9503). The procedures measure links and SRv6 paths (Segment Lists of SRv6 Policies, SRv6 IGP best paths, and IGP Flex-Algo paths) as well as Layer-3 and Layer-2 services carried over those paths.
The SCHC framework defines an abstract view of its rules, formalized through a YANG data model; in its original description rules are static and shared by two endpoints. This document defines an augmentation to the existing data model to restrict changes to rules and therefore the impact of possible attacks.
Describes an extension to the Extensible Provisioning Protocol (STD 69) that allows clients to provision DELEG records for domain names.
Argues, with technical detail from several CVEs and GitHub Security Advisories, that early attestation fails in practice even without physical access to the target machine. Since continuous attestation is generally required, the work contends that early attestation adds unnecessary complexity. Results are backed by formal analysis using ProVerif (Apache-2.0). It catalogs multiple published CVEs/GHSAs across a range of CVSS scores and states that, based on this work, all but two early-attestation implementations have been archived, withdrawn, or moved to post-handshake attestation.
Describes the Prove-Transform-Verify (PTV) protocol for hardware-anchored attestation of AI-agent identity. PTV enables an agent to prove, at exercise time, that it is bound to an enrolled attestation key and an authorized configuration, without exposing model weights or inference inputs. It is a thin request/response profile over the RATS architecture (RFC 9334) and the Entity Attestation Token (RFC 9711), does not replace workload identifiers such as SPIFFE or WIMSE, and does not attest behavioral continuity (treated as a separate requirement class). This Experimental revision defines a CBOR/CDDL message set, four message types, a COSE-based message-protection rule, an informative EAT claim mapping, and a threat model separating identity-binding integrity from behavioral continuity.
A SCHC (Static Context Header Compression) working-group document; by its name it likely defines 'SCHClet', a compact or lightweight profile/subset of SCHC. The official abstract was unavailable on this run and will be grounded next time.
In networks where Layer 2 interface bundles (such as a Link Aggregation Group per IEEE 802.1AX) are deployed, a controller may need the connectivity relationships between bundle members for traffic engineering, for example when performing topology management and bidirectional path computation. This document describes how OSPF and IS-IS advertise the remote interface identifiers for L2 bundle members, and also specifies the corresponding BGP Link State (BGP-LS) extension.
Delegation-chain specifications describe the shape of conveyed authority but leave the verifier's half of the exchange underdetermined, so two verifiers can check the same chain, both report success, and enforce different policy. This document states what a verifier must do: the explicit inputs evaluation depends on, how those inputs behave when their sources are stale or unavailable, and four rules that keep evaluation fail-closed. The rules are drawn from the Grant & Autonomy Lifecycle (GAL) and Provenance & Trust Context (PTC) specifications and a public reference implementation.
Part of the individual 'Helm Protocol' series; by its name it concerns a 'confidence' signal or metric (probably for agent decisions). The official abstract was unavailable on this run and will be grounded next time.
Part of the individual 'Helm Protocol' series; by its name it targets deep-space or delay/disruption-tolerant scenarios. The official abstract was unavailable on this run and will be grounded next time.
By its name this appears to be an individual submission in the 'AER1' series; the official abstract could not be retrieved on this run. Several revisions (-03 through -06) were posted across the window, indicating rapid iteration. The description will be grounded from the official Abstract on the next run.
Specifies the conventions for using Composite FrodoKEM algorithms with the Cryptographic Message Syntax (CMS). Composite FrodoKEM combines FrodoKEM with traditional algorithms (RSA-OAEP, ECDH, X25519, X448) to provide hybrid post-quantum key encapsulation.
Part of the rfc8881bis respecification effort for NFSv4.1, this document describes the structure and function of NFSv4 Access Control Lists within NFSv4.0 and NFSv4.1, using an ACL structure derived from Windows ACLs (support for draft-POSIX ACLs remains an option for later minor versions). It covers the role of these ACLs in the NFSv4 security architecture, focusing on flexible file-access authorization beyond the POSIX-derived attributes while also covering other potential ACL-based security functionality. Because previous specifications did not satisfactorily describe NFSv4 ACL authorization semantics, it takes a different approach while maintaining compatibility, and when published it will supersede existing ACL descriptions, updating RFC 7530 and RFC 8881.
Provides the External Data Representation (XDR) description for NFSv4 minor version 1, including protocol extensions made as part of the respecification effort for NFS Minor Version 1. It obsoletes and replaces RFC 5662.
Provides guidance for application developers and SaaS providers on how to approach IPv6 testing in Dual-stack (IPv4+IPv6) and IPv6-only scenarios, including IPv6-only-strict scenarios without any connectivity to IPv4 endpoints. It discusses common misconceptions about how much operating systems and libraries can abstract IPv6 issues away, and explains common regressions to avoid when deploying IPv6 support.
Describes a new mechanism and DNS resource record (RR) type to carry information about energy-related characteristics for end-to-end internet access. The EE (Energy Efficiency) record lets the network provide different levels of energy-saving service; by giving more energy information to the client before it attempts a connection, the records offer potential benefits for using energy as a service criterion.
Defines RVP, a protocol for asking a bounded verification question, carrying it through one of several verification mechanisms, and producing evidence bound to the exact question. RVP separates five often-collapsed concerns: consumer policy deciding whether evidence is needed, the frozen evidence requirement, the question's lifecycle, the carrier obtaining a response, and later consumption of the evidence. It does not grant authority, establish admission, or replace account authentication and session policy. It supports local biometric checks, signed companion-device responses, WebAuthn, authenticated-session evidence, recovery standing and future carriers, and is transport-independent, able to operate locally without a central identity provider.
By its name this specifies an audit-trail mechanism for software agents; the official abstract was unavailable on this run. It likely defines a record/log format for agent actions. To be grounded on the next run.
Defines a base YANG data model for reporting network inventory. The scope of this base model is application- and technology-agnostic, and it can be augmented with application- and technology-specific details.
Computing-Aware Traffic Steering (CATS) optimizes steering of traffic to a service instance by considering the dynamic state of computing and network resources. To enable such decisions, CATS components exchange metrics describing resource conditions affecting service-instance selection. This document focuses on compute and communication metrics for CATS and defines a hierarchical abstraction of them to improve interoperability, scalability and operational simplicity. It does not standardize raw (Level 0) metrics; instead it specifies higher-level representations derived from raw measurements via aggregation and normalization.
Describes the necessity and feasibility of introducing a proxy network node for a congested node to notify the traffic sender of congestion. The proxy translates the congestion notification: the congested node sends a notification to the proxy in a format defined in this document, and the proxy translates it to a format known by the traffic sender and resends it to the sender.
Describes an RDMA over Converged Ethernet v2 (RoCEv2) congestion-control mechanism known as Fast Congestion Notification Packet (Fast CNP). By extending the RoCEv2 CNP, Fast CNP can be sent by the switch directly to the sender, advising it to reduce the rate at which it sends the flow of RoCEv2 data traffic.
The Entropy Label (EL) can be used in the SR-MPLS data plane to improve load balancing, and multiple Entropy Label Indicator (ELI)/EL pairs may be inserted in the SR-MPLS label stack per RFC 8662. This document defines PCEP extensions to configure where in the label stack the ELI/EL pairs should be inserted in an SR-MPLS network (the Entropy Label Positions, ELP).
Software agents increasingly act on behalf of people and organizations across administrative and security boundaries, but existing discovery mechanisms do not provide a common way to resolve who operates an agent, its bounded authority, whether that authority is current, or what evidence supports a reliance decision. This document defines the Agent Registry Protocol (ARPA), an HTTP/JSON protocol for publishing and resolving information about agents, their deployments, typed relationships, bounded delegated authority, lifecycle status and evidence. ARPA separates identification, authentication, authorization, assurance and lifecycle state, and is designed for deterministic fail-safe behavior when material authority information is revoked, suspended, expired, stale, conflicting, unavailable or unverifiable.
A delegation record kept as evidence must stay verifiable long after its signing key retires, so it needs anchoring in trusted time, renewed before the protecting algorithms weaken. An RFC 3161 timestamp is itself a signature, so an adversary with a cryptanalytically relevant quantum computer could mint one bearing any date; anchoring must therefore become post-quantum anchoring by a stated transition date and be applied early. This document states requirements that software and AI-agent identity mechanisms should satisfy to remain sound across the transition and identifies four not yet imposed on delegation credentials: signing algorithms must be visible to verifiers and retained with evidence; trust anchors must migrate before credentials; every retained record must be post-quantum anchored and renewed from a stated date; and credentials kept as evidence must be signed post-quantum from that date. It notes delegation chains propagate the weakest algorithm and routinely cross organizational boundaries.
Specifies procedures for distributing BGP-Link State (BGP-LS) key parameters for inter-domain links between two Autonomous Systems. It defines a new BGP-LS NLRI type for an Inter-AS Link plus three new TLV descriptors. These extensions let operators collect inter-domain interconnect information and automatically compute the inter-AS topology using information provided by BGP-LS.
Specifies procedures for distributing BGP-Link State (BGP-LS) key parameters for inter-domain links between two Autonomous Systems. It defines a new BGP-LS NLRI type for an Inter-AS Link plus three new TLV descriptors. These extensions let operators collect inter-domain interconnect information and automatically compute the inter-AS topology using information provided by BGP-LS.
Introduces new IPFIX Information Elements to identify the Segment Routing (SR) Path Segment Identifier (PSID) for SR-MPLS and SRv6 path identification.
Realizing network slices may require a Service Provider to partition a physical network into multiple logical networks of varying sizes, structures and functions, each dedicated to specific services or customers, while ensuring slice elasticity in resource allocation. This document describes a scalable solution to realize network slicing in IP/MPLS networks, supporting multiple services over a single physical network by requiring compliant domains and nodes to provide forwarding treatment (scheduling, drop policy, resource usage) based on slice identifiers.