Run date 2026-08-31 (UTC) · Window: Aug 29 - Aug 31, 2026 (last 48 hours)
Proposes a protected rendering execution-finality architecture for age-restricted content (adult, violent, gambling-related, etc.). Upstream age checks, parental controls and content labels decide whether content should be delivered, but they do not guarantee it cannot later be decrypted, composited, rendered, forwarded or mirrored through another path. A proposed rendering is modeled as a Restricted Content Candidate Act held in a Non-Renderable State until a Protected Enforcement Domain validates recipient, content, device, policy, age/eligibility, freshness, revocation and sink predicates. A Protected Rendering Finality Sink then independently verifies scoped, non-bearer authority immediately before content becomes perceptible, controlling content-key release, decryption, decoder enablement, GPU/compositor access or display. It also adds a Temporary Under-18 Handover Mode for lending an adult-configured device to a child. Core principle: permission to deliver content is not permission to render it.
Specifies IPFIX Information Elements that export the context and outcome of Source Address Validation (SAV) enforcement. The SAV-specific IEs capture why packets are identified as spoofed by recording the specific SAV rules that triggered each validation decision. This operational visibility lets network operators observe SAV enforcement behavior and analyze source-address spoofing events detected by SAV.
Proposes a protected rendering execution-finality architecture for age-restricted content (adult, violent, gambling-related, etc.). Upstream age checks, parental controls and content labels decide whether content should be delivered, but they do not guarantee it cannot later be decrypted, composited, rendered, forwarded or mirrored through another path. A proposed rendering is modeled as a Restricted Content Candidate Act held in a Non-Renderable State until a Protected Enforcement Domain validates recipient, content, device, policy, age/eligibility, freshness, revocation and sink predicates. A Protected Rendering Finality Sink then independently verifies scoped, non-bearer authority immediately before content becomes perceptible, controlling content-key release, decryption, decoder enablement, GPU/compositor access or display. It also adds a Temporary Under-18 Handover Mode for lending an adult-configured device to a child. Core principle: permission to deliver content is not permission to render it.
Presents a method for using the Path Computation Element (PCE) for Source Address Validation (SAV) in networks. It extends the PCE Communication Protocol (PCEP) so that PCEP speakers can distribute and synchronize SAV policy between them, mitigating threats from source-address spoofing.
Specifies procedures for distributing BGP-LS key parameters for inter-domain links between two Autonomous Systems (ASes). It defines a new NLRI type for an Inter-AS Link plus three new TLV descriptors, enabling network controllers to collect inter-domain interconnect information and automatically compute the inter-AS network topology using information carried by BGP-LS.
Addresses a SCIM interoperability gap: RFC 7643 requires returning attributes such as Group.members with no bound on how many values they may contain, so a provider holding a group with millions of members has no conformant way to answer a request a client is entitled to make (providers instead truncate, reject, omit or fail). Defines discovery so a client can learn how a provider treats a high-cardinality attribute, a bounded response with a defined continuation (opaque cursor) contract, and rules preventing a partial representation from being mistaken for complete resource state. Adds attributeCount and attributeCursor query parameters and updates RFC 7643 and RFC 7644, without changing behavior for deployments that do not implement it.
Defines an IPFIX Information Element for monitoring the state of RPKI-based BGP Prefix Origin Validation. It lets operators collect and analyze BGP route validation states (valid, invalid, not-found) to help detect potential route hijacks and improve network observability and security.
Introduces IntelliNode, an in-network intelligent scheduling mechanism built on the Computing-Aware Traffic Steering (CATS) framework, targeting distributed heterogeneous GPU/CPU/FPGA clusters used for large-scale AI training and inference. Instead of passive probe-and-controller scheduling, it constructs a data-plane Perception-Inference-Decision-Execution loop using FPGAs alongside programmable switch ASICs: line-rate feature extraction, lightweight prediction of short-term network behavior, and real-time heuristic decisions such as path selection, tensor slicing and compute matching. Defines four core functional layers and the extension signaling that supports an AI-native, scalable distributed computing network.
Defines a Semantic-Driven Shaping Contract so that applications or distributed-training frameworks can pass the minimum necessary semantics about AI training/inference traffic to the underlying network, rather than having it treated as opaque byte streams. In exchange, the network commits to fine-grained, differentiated forwarding and resource allocation for tensor flows based on predefined rules and global real-time state, aiming to improve resource utilization and task completion times in heterogeneous computing networks and integrated training-inference scenarios.
Specifies encapsulations for the Simple Two-Way Active Measurement Protocol (STAMP, RFC 8762) and its optional extensions (RFC 8972) in MPLS networks. It defines encapsulation of STAMP test packets for point-to-point LSPs and point-to-point single-segment pseudowires, with or without an IP/UDP header, so the test packets experience the same forwarding and ECMP behavior as the data traffic being measured. Two new MPLS Generic Associated Channel (G-ACh) types are defined. The document updates RFC 8762 for TTL/HL processing and RFC 8972 for the STAMP Session Identifier for LSPs and PWs.
Specifies a set of practices for using IPv6 to automatically connect stub networks to adjacent infrastructure networks, even when the stub does not otherwise use IPv6. This applies to cases such as constrained (IoT) networks that need functional parity of service discovery and reachability between devices on the stub network and devices on an adjacent infrastructure link, for example a home network.
Specifies AegisFS, a programmable secure file and folder runtime that turns ordinary filesystem objects into policy-driven, state-aware, execution-aware and behavior-aware security objects. It introduces two contributions: the Octal-to-OpCode (OtO) framework, which compiles file operations, state transitions and intent declarations into a 9-bit octal instruction set for hardware-accelerated, microsecond-latency policy enforcement in the runtime kernel; and the Aegis Policy Language (APL), where the policy definition is the executable architecture, so an operation that cannot be expressed in valid APL syntax cannot produce a valid opcode and therefore cannot execute. Submitted for consideration by the SECDISPATCH and RATS working groups.
Specifies a set of practices for using IPv6 to automatically connect stub networks to adjacent infrastructure networks, even when the stub does not otherwise use IPv6. This applies to cases such as constrained (IoT) networks that need functional parity of service discovery and reachability between devices on the stub network and devices on an adjacent infrastructure link, for example a home network.
Observes that limited-domain protocols often rely on edge filtering at every boundary node to keep domain-internal traffic from leaking to the Internet, which creates fail-open designs vulnerable to configuration errors, ACL bypass and hardware table exhaustion. Describes design principles and concrete mechanisms - Layer-2 encapsulation identifiers (dedicated or extended EtherTypes), link-local address scoping, and/or Hop-Limit boundaries - that let limited-domain protocols fail-closed by default. The mechanisms do not apply to all such protocols but can significantly reduce operational and security risk for certain classes.
Defines a YANG data model that can be used to configure and manage IS-IS Segment Routing over the IPv6 data plane (SRv6).
Introduces new IPFIX Information Elements to identify the Segment Routing Path Segment Identifier (PSID) for SR-MPLS and SRv6 path identification.
Describes PSHMP Core, a decentralized data-delivery and proactive self-healing network core for distributed systems operating over existing IP infrastructure. It provides an intelligent network layer above IP so that distributed nodes can perform dynamic multi-hop delivery without changing the underlying Layer-3 routing. The architecture centers on decentralized path selection, continuous node and path assessment, dynamic relay chains, proactive recovery and diversity-aware reconstruction of delivery paths, detecting degradation and rebuilding affected paths before or during service degradation to reduce recovery time and improve resilience. The document is a high-level architectural overview and intentionally omits proprietary algorithms and internal scoring details.
Proposes an authority-centred model of digital sovereignty that separates a globally distributed Compute Plane from an independently governed Authority Plane. Computation may run in another jurisdiction, but a proposed cross-jurisdiction operation is modeled as a Candidate Act held in a Non-Effective State until policy, identity, purpose, destination, jurisdiction, runtime and revocation predicates are validated; a scoped Finality Authority is then independently verified at the effectuation boundary before any external effect occurs. The aim is to retain technical control over sensitive external effects without mandatory data localisation - the computation may occur elsewhere, but a protected external effect cannot occur without the required authority. It explicitly does not standardize national policy, decide which jurisdiction's law prevails, or resolve conflicts of law.
Provides technical details of CVE-2026-33697 and EUVD-2026-16488 as substantial evidence of how intra-handshake attestation fails in practice, even without physical access. It argues that, because continuous attestation is generally required anyway, intra-handshake attestation adds unnecessary complexity. The results are backed by research and reproducible artifacts in the ProVerif formal-analysis tool under an Apache-2.0 license, and have been acknowledged by the relevant stakeholders.
Defines a method for content versioning in CCNx, enabling content published under the same name to be differentiated using version numbers. Updates RFC 8569 and RFC 8609.
Describes connection contamination, a class of security exposure in HTTP/3. HTTP/3 clients commonly reuse (coalesce) an existing QUIC connection for a second origin when the TLS certificate is valid for both, even though the two origins may route to different backends. When a routing layer - reverse proxy, load balancer or CDN edge - selects the backend using a signal established at connection setup rather than re-validated per request, a coalesced connection can reach an unintended backend, potentially enabling cross-tenant data leakage, authentication bypass and response-queue interference analogous to HTTP request smuggling. The document defines the mechanism, characterizes the attacker model, distinguishes it from related QUIC exposures, and gives normative operational guidance for HTTP/3-terminating infrastructure.
Documents a robots.txt extension, Archive-Embargo, that lets sites hosting time-sensitive information request that archiving crawlers delay publication of the information. It updates RFC 9309 to add two directives supporting embargoes.
Defines the Cedulon Protocol, an audit layer for agent-to-agent commerce that sits above payment rails such as HTTP 402 flows (x402) and mandate protocols (AP2), which move value but do not by themselves produce a fail-closed policy check and a signed spend receipt reconcilable against a rail extract. Cedulon specifies a signed Trade Manifest (offer before payment), a default-deny Policy Decision Point, a COSE/CWT Spend Receipt after a gated payment, epoch checkpoints and rail-extract reconciliation showing that no settlement lacks a receipt and no settled receipt is absent from the extract. This revision defines the encodings earlier revisions called canonical and states the exact input to every hash-valued field, so an independent verifier can be built from the text alone. Cedulon is not a competitor to x402 or AP2; it sits above them.
Defines an OAuth profile for AI agents that invoke protected APIs on behalf of human users: identifying an agent client instance, obtaining an authenticated user's consent, issuing resource-bound and sender-constrained access tokens, attenuating authority through OAuth Token Exchange, and rotating refresh tokens safely. The profile reuses existing OAuth and JOSE mechanisms wherever possible and defines no new JWT claims or OAuth endpoints. Operational facilities such as policy engines, audit stores, budgets, event streams and credential vaults are outside the interoperable core; the Grantex reference implementation is incomplete and not required for conformance.
Proposes an authority-centred model of digital sovereignty that separates a globally distributed Compute Plane from an independently governed Authority Plane. Computation may run in another jurisdiction, but a proposed cross-jurisdiction operation is modeled as a Candidate Act held in a Non-Effective State until policy, identity, purpose, destination, jurisdiction, runtime and revocation predicates are validated; a scoped Finality Authority is then independently verified at the effectuation boundary before any external effect occurs. The aim is to retain technical control over sensitive external effects without mandatory data localisation - the computation may occur elsewhere, but a protected external effect cannot occur without the required authority. It explicitly does not standardize national policy, decide which jurisdiction's law prevails, or resolve conflicts of law.
Defines the AI Agent Identity Certificate (AIC) extension for X.509 v3 certificates, binding an AI agent's cryptographic identity to a natural person (principal) to provide cryptographic evidence supporting attribution of AI-autonomous actions. It deliberately separates cryptographic delegation from authorization semantics: AIC defines the agent-to-principal binding while capability and policy semantics are defined externally. The extension carries agent identity fields, a principal identifier, a container-based capability declaration, authorization-boundary constraints and delegation evidence with replay protection, complemented by a PrincipalAuthorization extension. The document specifies the ASN.1 module, OID registration (IANA PEN 66257), delegation model and extensibility framework.
Introduces operational semantics for CATS (Computing-Aware Traffic Steering) metrics - Freshness, Operational acceptability and Assurance exposure - describing whether a metric remains temporally aligned with the underlying condition, remains suitable for use in steering, and whether degraded consumption is externally visible to management or OAM functions. It explains how these semantics apply across centralized, distributed and hybrid deployments, giving a consistent basis for interpreting metric usability in CATS without introducing a new metric level or prescribing a single derivation method.
Notes that many in-progress YANG modules define counters, gauges and other measured values that are compared, summed or averaged by a remote collector, yet YANG (RFC 7950) has no first-class, machine-checkable way to state the domain within which two occurrences of such a value are comparable, so this is currently decided inconsistently in prose. Defines a YANG extension statement, csc:comparability-scope, a four-value scope lattice and a compatibility rule that lets a schema-aware tool statically detect an illegal aggregation across incomparable scopes rather than discovering it at a collector.
Revisits EVPN Designated Forwarder election. RFC 8584 chose Highest Random Weight (HRW) and named but explicitly declined to evaluate the Consistent Hashing family. Because per-multicast-flow DF election introduces a per-(ES,VLAN,S,G) scope transition - a key-space-resizing event of the kind Consistent Hashing was designed to bound churn for - this draft supplies the applicability analysis RFC 8584 declined to make: it defines a DF-churn metric, states HRW's and Consistent Hashing's known theoretical guarantees, and sets out an evaluation methodology using bounded-load Consistent Hashing as the comparison point, given that multicast group popularity is highly non-uniform in deployed networks.
Observes that YANG-Push version 2 assigns each publisher a monotonically increasing sequence number so a receiver can detect loss and reordering, but leaves unspecified what happens when the counter wraps and how a receiver aggregating records from multiple publishers can compare sequence numbers that were never defined to be comparable across publishers. Both problems are largely settled in the distributed-systems literature on logical and hybrid logical clocks. The draft evaluates three causal-ordering primitives against YANG-Push's constraints and proposes adopting a Hybrid Logical Clock so wraparound and cross-publisher comparison are removed by construction rather than patched with a wider counter.
Addresses a crash-recovery gap in EVPN MAC Mobility. Gateways maintain two independent MAC Mobility sequence counters per host (intra-DC and inter-DC) so a local move need not be reconciled against the interconnect state, but no text covers a gateway that fails after locally resetting its intra-DC counter to zero and before propagating that fact. The draft shows this is a special case of a Last-Writer-Wins Register, a member of the Conflict-Free Replicated Data Type (CRDT) family with proven convergence properties, and proposes modeling the per-gateway mobility sequence state that way so a mid-reset crash is recovered as a consequence of the data type's algebra rather than a new, separately specified procedure.
Specifies the Proof of Sovereign Integrity (PSI) Protocol, version 1.2, enabling organizations to prove compliance with AI regulations (including the EU AI Act 2024/1689, NIST AI RMF, UK AI Safety Institute guidelines and equivalent frameworks) without disclosing proprietary model architectures, training data or inference logic. PSI combines SHA-256 hash-chained audit trails, Ed25519 signatures, Merkle inclusion proofs, Groth16-compatible zero-knowledge commitments over BN128 fields, and a 3-node Multi-Party Computation consensus mechanism with 2/3 threshold verification. This revision documents a deployed public reference implementation and adds optional post-quantum signature profiles and Bitcoin timestamp anchoring.
Defines a transport-independent Contestability Binding for authorized agent actions. The binding commits an authorization to a versioned Contestation Parameters Object identifying the forum, submission mechanism, standing policy, procedure, time bounds, declared effect policy and selection evidence. A forum can acknowledge one exact authorization or publish a reusable acceptance manifest, and a deterministic verifier validates the binding, classifies evidence claiming pre-execution verification by the executor, and reports forum-selection provenance as unilateral, multiparty, externally selected or indeterminate. The mechanism makes contestation parameters identifiable and verifiable while resisting post-action substitution; it does not determine standing, prove forum independence, resolve a dispute or establish legal enforceability.
Specifies a compact HTTP API for administering an OpenID Federation node - the management plane operators and control-plane software use to configure what the public federation protocol publishes (Entity Configurations, Subordinate Statements, Trust Marks and Federation Entity Keys defined by OpenID Federation 1.1). It does not replace the public protocol. The design is document-oriented: operators read and write the same JSON objects OpenID Federation already defines, across five resources covering node identity, Federation Entity Keys, the node's Entity Configuration, Immediate Subordinates and Trust Mark issuance.
Specifies RCOAP, a compact, zero-round-trip, link-layer-agnostic object-security mechanism for highly constrained devices that transmit infrequently. RCOAP is a targeted delta over OSCORE: instead of a single long-lived Sender Key, it derives a fresh symmetric key for every message via a one-way hash ratchet, bounding the impact of physical device capture to future messages only, at the cost of a modest per-message size increase and the loss of future secrecy. It is scoped to the niche between OSCORE and EDHOC - devices for which even EDHOC's one-time handshake is disproportionate - and requests feedback from the LAKE and CoRE working groups on whether the gap is real and worth standardizing.
Describes a Capability-Validated Inbound Descriptor (CVID) and a query-scoped communication model so that knowing a routable identifier (phone number, SIP URI, messaging handle, relay address, etc.) does not by itself create a usable reachability path. A communication request is represented as a Candidate Act that remains non-effective until current authorization is established for the requested communication effect, bound to sender/recipient scope, purpose, channel, time, quota, freshness, revocation, jurisdiction and device or agent identity. Two profiles are distinguished: a blocked-path profile where routing proceeds to an enforcement point that rejects unauthorized requests, and a stronger absent-path profile where the handle alone does not resolve to an effective path. The model targets IMT-2030/6G machine-speed traffic, with potential (not guaranteed) signaling and energy savings.
Notes that ordinary TCP segments can carry up to only 40 octets of options, which becomes insufficient when, for example, a 36-byte TCP Authentication Option (TCP-AO) leaves no room for other required options. Describes an experiment introducing upgraded sessions (SES-U) and upgraded segments (SEG-U), where each SEG-U can accommodate up to 1,016 octets of individual options.
Expands RFC 5926's list of cryptographic algorithms for TCP-AO by adding two Message Authentication Code algorithms, HMAC-SHA256 and KMAC256, each with a corresponding Key Derivation Function. These MACs are 256-bit (32-byte); when encoded in TCP-AO they consume 36 of the 40 bytes available for TCP options.
Expands RFC 5926's list of cryptographic algorithms for TCP-AO by adding two Message Authentication Code algorithms, HMAC-SHA256-128 and KMAC256-128, each with a corresponding Key Derivation Function. These MACs are 128-bit (16-byte); when encoded in TCP-AO they consume 20 of the 40 bytes available for TCP options.
Defines the Behavioral State Protocol (BEST), a discovery-first, behaviour-oriented interaction surface for domain services: the commands a service accepts, the events it publishes, and optionally the queries it answers and the multi-step recipes (workflows) it publishes. Services self-describe through a manifest at the well-known URI /.well-known/best, and messages use a conformant profile of the CloudEvents 1.0 envelope described by JSON Schema. BEST specifies only the interaction surface - never a service's internal architecture, storage or execution model - so independent implementations across any runtime, language or transport can interoperate without bespoke integration.
Provides technical details of CVE-2026-33697 and EUVD-2026-16488 as substantial evidence of how intra-handshake attestation fails in practice, even without physical access. It argues that, because continuous attestation is generally required anyway, intra-handshake attestation adds unnecessary complexity. The results are backed by research and reproducible artifacts in the ProVerif formal-analysis tool under an Apache-2.0 license, and have been acknowledged by the relevant stakeholders.
Specifies General-Purpose Compression via Mathematical Functions (GCMF), a lossless compression format that represents sequences of data using mathematical functions and associated parameters, attempting a compact mathematical representation rather than storing every value explicitly. Defines the GCMF data format, function types, encoding rules, decoding procedure and interoperability requirements.
Observes that Route Origin Authorization (ROA) and Autonomous System Provider Authorization (ASPA) mitigate origin hijacks, path hijacks and route leaks in general scenarios, but large ISPs managing multiple ASes remain vulnerable to carefully crafted routes that bypass ROA and ASPA validation, causing traffic hijacking within or between large ISPs. Defines a region-based authorization and verification framework for multi-AS ISPs to prevent intra-ISP and inter-ISP traffic hijacking.
Describes a Capability-Validated Inbound Descriptor (CVID) and a query-scoped communication model so that knowing a routable identifier (phone number, SIP URI, messaging handle, relay address, etc.) does not by itself create a usable reachability path. A communication request is represented as a Candidate Act that remains non-effective until current authorization is established for the requested communication effect, bound to sender/recipient scope, purpose, channel, time, quota, freshness, revocation, jurisdiction and device or agent identity. Two profiles are distinguished: a blocked-path profile where routing proceeds to an enforcement point that rejects unauthorized requests, and a stronger absent-path profile where the handle alone does not resolve to an effective path. The model targets IMT-2030/6G machine-speed traffic, with potential (not guaranteed) signaling and energy savings.
Provides a roadmap to a large subset of the roughly 250 CBOR tag definitions added to the IANA registry since RFC 7049 (now superseded by RFC 8949). Where applicable it points to the IETF standards or standards-development document that specifies each tag; where none exists, it collects specification information from the sources of the registrations. After further development the document is intended to serve as a reference for the IANA registrations of the collected CBOR tags.
Observes that Route Origin Authorization (ROA) and Autonomous System Provider Authorization (ASPA) mitigate origin hijacks, path hijacks and route leaks in general scenarios, but large ISPs managing multiple ASes remain vulnerable to carefully crafted routes that bypass ROA and ASPA validation, causing traffic hijacking within or between large ISPs. Defines a region-based authorization and verification framework for multi-AS ISPs to prevent intra-ISP and inter-ISP traffic hijacking.
Describes the changes between Unicode 12.0.0 and Unicode 18.0.0 in the context of IDNA2008, where Unicode additions and changes affect the values produced by the IDNA2008 algorithm. It assigns the derived property value UNDER REVIEW to certain code points as backward-compatibility exceptions and provides the tables IANA needs to make its database consistent with Unicode 18.0.0. All values are computed directly from the Unicode Character Database files via the RFC 5892 Section 3 algorithm. This version is based on pre-release data - Unicode 18.0.0 has not been released - so every figure concerning it is provisional and must be regenerated against the released files.
Notes that ASPA validates the AS_PATH of BGP routes using a single global Customer-to-Provider relationship model, but two ASes may hold different business relationships across different regions or interconnection points (for example, Customer-to-Provider in one region but Peer-to-Peer in another). Such regionalized or hybrid AS-relationships can produce incorrect ASPA validation results, such as a false Valid attestation for a route propagated over a P2P link. The draft analyzes the vulnerabilities and proposes mechanisms to incorporate regional granularity into ASPA objects and verification procedures.
Describes a method for an SRv6 endpoint (for example a host or a customer provider edge) to advertise its SRv6 Locator to a neighboring SRv6-aware router using extensions to the IPv6 Neighbor Discovery (ND) protocol. Through the resulting locator routes, other SRv6 nodes can steer traffic to that endpoint without running a full routing protocol stack on simple endpoints, facilitating SRv6 deployment in controlled, trusted domains such as data centers and managed access networks.
Extends the IOAM Trace Option to incorporate the Alternate-Marking method. In-situ OAM (IOAM) records and collects operational and telemetry information by pushing IOAM data fields into in-flight data packets, while the Alternate-Marking method measures performance metrics on live traffic such as packet loss, delay and jitter. The draft combines the two to augment IOAM in performance measurement.
Specifies General-Purpose Compression via Mathematical Functions (GCMF), a lossless compression format that represents sequences of data using mathematical functions and associated parameters, attempting a compact mathematical representation rather than storing every value explicitly. Defines the GCMF data format, function types, encoding rules, decoding procedure and interoperability requirements.
Extends the IOAM Direct Export (DEX) Option-Type to integrate the Alternate-Marking method. Passport-based IOAM pushes telemetry generated at each node into data packets, while postcard-based IOAM (DEX) exports that data directly without pushing it into in-flight packets; Alternate-Marking measures packet loss, delay and jitter on live traffic. The draft incorporates Alternate-Marking into DEX to augment IOAM in performance measurement.
Specifies SAIP (Signed Agent Identity Protocol), a lightweight, opt-in mechanism for verifiable client identity at the application layer, addressing the weakness of User-Agent strings and IP-based attribution against spoofing, shared infrastructure (NAT) and the rapid growth of automated agents including AI crawlers, IoT devices and enterprise automation. SAIP implements the principles of the Verifiable Identity Claims and Delegation Model (VICDM) and provides cryptographic identity at three granularities - vendor, agent type and individual instance. It is protocol-agnostic (HTTP, SMTP and other header-based protocols) and introduces DNS-based Attestation Discovery as a lightweight alternative to registry-based key lookup.
Defines a conceptual framework for handling identity assertions in application-layer protocols, in which identity on the Internet is optional but any asserted identity MUST be verifiable. It also defines a delegation mechanism allowing entities to authorize third-party infrastructure to act on their behalf in a verifiable and transparent manner, while fully preserving anonymous and pseudonymous interaction. The document defines principles that protocol specifications should follow rather than a protocol itself; a concrete implementation of these principles is SAIP.
The official Abstract could not be retrieved on this run (the fast-source page was unavailable). By its name (vdac) and the author's related work - SAIP (Signed Agent Identity Protocol) and VICDM (Verifiable Identity Claims and Delegation Model) - this draft probably defines a verifiable delegated-authorization or delegated-access credential mechanism within that agent-identity family. This description is approximate and will be grounded in the official Abstract on the next run.
Specifies SAIP (Signed Agent Identity Protocol), a lightweight, opt-in mechanism for verifiable client identity at the application layer, addressing the weakness of User-Agent strings and IP-based attribution against spoofing, shared infrastructure (NAT) and the rapid growth of automated agents including AI crawlers, IoT devices and enterprise automation. SAIP implements the principles of the Verifiable Identity Claims and Delegation Model (VICDM) and provides cryptographic identity at three granularities - vendor, agent type and individual instance. It is protocol-agnostic (HTTP, SMTP and other header-based protocols) and introduces DNS-based Attestation Discovery as a lightweight alternative to registry-based key lookup.
Uses the Apple-Siri interoperability debate under the EU Digital Markets Act to frame a question: how can third-party AI assistants gain meaningful access to device functions without forcing the platform to surrender privacy, security or control over consequential actions. Proposes an execution-finality architecture in which an assistant may request an action, but the request itself has no power to make it effective: each consequential operation stays in a Non-Effective State until protected infrastructure validates the requester, resource, destination, user intent, freshness, revocation state and policy, after which narrowly scoped, non-bearer execution authority is created and independently verified at a Finality Sink, with any mismatch, replay, substitution, expiry or revocation causing fail-closed denial. The principle: interoperability should grant participation, not uncontrolled execution authority.
Defines a SCITT statement profile - the Agent Action Capsule - for recording what an AI agent did. A Capsule is a digest-committed record of one agent action carrying its verdict-level disposition (executed, blocked, denied, errored, timed out), the deterministic constraints that were evaluated, the effect that was committed together with a confirmed-effect binding that distinguishes a dispatched attempt from an observed result, and an honest human-in-the-loop flag. Capsules are identified independently of signing, may be authenticated by one or more COSE_Sign1 Producer Envelopes, and can be made transparent by registration in a SCITT Transparency Service. A Capsule is recorded on every verdict, including refusals - a blocked or denied Capsule is auditor-grade evidence that a gate worked.
Defines a SCITT statement profile - the Agent Action Capsule - for recording what an AI agent did. A Capsule is a digest-committed record of one agent action carrying its verdict-level disposition (executed, blocked, denied, errored, timed out), the deterministic constraints that were evaluated, the effect that was committed together with a confirmed-effect binding that distinguishes a dispatched attempt from an observed result, and an honest human-in-the-loop flag. Capsules are identified independently of signing, may be authenticated by one or more COSE_Sign1 Producer Envelopes, and can be made transparent by registration in a SCITT Transparency Service. A Capsule is recorded on every verdict, including refusals - a blocked or denied Capsule is auditor-grade evidence that a gate worked.
Defines a way to derive unlinkable P-256 credential keys from one protected parent key while retaining the parent's key-protection properties, so a wallet need not generate and store many keys to obtain per-credential unlinkability. It is specified as an extension to OpenID for Verifiable Credential Issuance (OpenID4VCI), allowing the Issuer to derive each child public key while only the wallet can use the corresponding child private key.
Describes architectural requirements for supporting AI agents on the Internet as they evolve from interactive assistants into networked software workloads that discover services, invoke tools, delegate authority, transact, communicate with other agents and act asynchronously on behalf of humans and organizations. The requirements span naming and discovery, HTTP, authentication, authorization and delegation, TLS and workload identity, transport and connection continuity, asynchronous messaging, capability and intent-based resolution, payments, provenance, auditability, revocation, security and privacy. The document favors profiling and extending existing Internet protocols over defining a monolithic new agent protocol and identifies the need for IETF-wide architectural coordination.