%% You should probably cite draft-yan-iba-routing-security-requirements-01 instead of this revision. @techreport{yan-iba-routing-security-requirements-00, number = {draft-yan-iba-routing-security-requirements-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-yan-iba-routing-security-requirements/00/}, author = {严豫 and ShengSun and Qiangzhou Gao and Liu Min and Xinyi Zhang}, title = {{Security Requirements for Intent-based Agent Routing}}, pagetotal = 20, year = , month = , day = , abstract = {This document specifies security requirements for intent-based agent routing. It defines a security architecture, phase-specific attack surface analysis, and normative protections for the Registration, Resolution, and Dispatch phases of routing. It also describes a secure operational process and an annotated interaction flow for protecting routing decisions, intent privacy, and capability integrity. Intent-based routing enables autonomous agents to collaborate based on semantic intent rather than static addresses, but this model introduces new security risks beyond those addressed by traditional channel protection and endpoint authentication. Existing mechanisms such as Transport Layer Security (TLS) and Public Key Infrastructure (PKI) verify identity and protect transport, but do not constrain what an agent claims to be capable of, nor do they protect the semantic content of intent queries during routing. This document establishes requirements to mitigate these risks and provides a comprehensive security framework for intent-based agent networks.}, }