Sunday, March 15, 2025
Starting Time: An hour after the Welcome Reception starts (18:00)
Room: Grand Ballroom 3
Organizers: Bron Gondwana, Heather Flanagan, Liz Flynn
Email: hotrfc@ietf.org
SESSION AGENDA
Presenter, Affiliation: Jinyang Li, Yiyang Shao, Huawei
Abstract: Existing agent protocols like MCP suffer from stateless, plain-text
exchanges and reactive OAuth flows, causing token overhead and broken workflows on
constrained terminals. We propose two IETF drafts: structured semantic context management
(draft-chang-agent-context-interaction-01) and OAuth scope aggregation
(draft-jia-oauth-scope-aggregation-00), to enable efficient, seamless multi-agent collaboration.
Looking for:
Related I-Ds:
https://datatracker.ietf.org/doc/draft-chang-agent-context-interaction
https://datatracker.ietf.org/doc/draft-jia-oauth-scope-aggregation/
The current A2A and MCP protocols could be further enhanced due to
some scenario requirements. For the first draft, we have also posted a
hackathon project,
https://wiki.ietf.org/en/meeting/125/hackathon#optimizing-agent-context-interaction.
You are welcome to join us to explore further.
Coordinates: Jinyang Li, lijinyang9@huawei.com
Presenter, Affiliation: Mingzhe Xing, Beijing Zhongguancun Laboratory, in person
Abstract: The heterogeneity of network data (e.g., PCAPs, textual reports,
images, and KPI time series) presents a significant challenge to
unified analysis. To address this, we propose a framework that
utilizes large language models to automatically extract entities and
relations, constructing a unified knowledge graph. To enable reasoning
over the structured knowledge within the graph, we introduce an
agentic approach for searching and reasoning on graph data. This
mechanism can benefit various downstream networking tasks. We evaluate
our framework in a network security use case, with experimental
results confirming its practical effectiveness.
Looking for: We are looking for collaborators to engage in ongoing discussions and
code implementation.
Relevant drafts:
A Framework for LLM Agent-Assisted Network Management with
Human-in-the-Loop
(https://datatracker.ietf.org/doc/draft-cui-nmrg-llm-nm/)
A Gateway for Network Knowledge Graph Management
(https://github.com/nniujl/draft-nmop-cui-nkg-gateway.md)
Presenter, Affiliation: Kefei Liu, China Mobile Research Institute, in person
Abstract: Many per-packet load balancing schemes have been proposed
to mitigate network load imbalances. However, due to the randomness of
packet paths, loss location is challenging in per-packet load balancing
networks. An efficient solution is to leverage the alternate packet
marking technique. This draft analyzes the usage and requirements of
alternate packet marking for packet loss detection and location in
per-packet load balancing networks. Catch me after the meeting.
Relevant drafts:
https://datatracker.ietf.org/doc/draft-liu-opsawg-alt-mark-per-packet/
Coordinates: Kefei Liu, liukefei@chinamobile.com
Presenter, Affiliation: Zian Wang, Beijing University of Posts and Telecommunications, in person
Abstract: Traditional stateless, endpoint-centric gateways cannot
address the core interoperability challenges of heterogeneous
multi-agent systems, including intent-driven task dispatch, multi-step
workflow context retention, and cross-domain/protocol collaboration.
This draft defines the Agent-GW architectural framework, with two core
native primitives: Semantic Routing (intent/capability-based dispatch
replacing static address routing) and policy-governed Working Memory for
shared multi-turn context. It also specifies automated protocol
adaptation, oracle-free agent compliance evaluation, and KDN-based
collaborative inference acceleration, filling the standardization gap
for agent-oriented internet infrastructure.
Looking for:
Relevant drafts: https://www.ietf.org/archive/id/draft-agent-gw-01.html
Coordinates:
Zian Wang, zianwang@bupt.edu.cn
Presenter, Affiliation: Nick Sullivan, Cryptography Consulting LLC, presenting remotely
Abstract: SAFE is an encrypted container format for large files with
multi-recipient keying, multi-factor unlock, and random-access
authenticated encryption (raAE). The LOCK abstraction composes HPKE,
password-based, WebAuthn-PRF, and Privacy Pass credential types, with
algorithm agility and a natural path to PQ hybrid schemes. The data
section defines three wire formats: armored, binary/linear, and
binary/aligned. All support O(1) random access reads and writes; the
aligned format additionally supports in-place block rewrites with a
minimal editing profile. raAE is under ongoing formal analysis.
Looking for: design feedback, collaborators on the formal analysis, and implementers.
Relevant drafts:
draft-sullivan-safe-00: https://datatracker.ietf.org/doc/draft-sullivan-safe/
Formal analysis preprint: https://eprint.iacr.org/2025/2275
Coordinates:
Author email: draft-sullivan-safe@ietf.org
Web: thesafe.dev
Presenter, Affiliation: Yihan Chao, Beijing Zhongguancun Laboratory, presenting in person
Abstract: This draft proposes an HTTP-based protocol for discovering
and invoking AI agents across the Internet. It defines standardized
metadata and invocation interfaces to support interoperable, secure, and
efficient agent-to-agent communication. I welcome interested
participants to continue the discussion via the mailing list or by
contacting me after the meeting.
Looking for: I hope to connect with IETF/IRTF participants
interested in agent communication protocols, discovery services, and
related standardization efforts, especially potential collaborators or
implementers who would like to explore this framework further.
Relevant drafts: https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/
Coordinates:
Interested participants can reach me via email (chaoyh@zgclab.edu.cn or chao_yihan@outlook.com ) for further discussion. I also welcome follow-up via relevant IETF mailing lists or side meetings after the presentation.
Presenter, Affiliation: Yuanyuan Zhou, University College London (UCL), in person
Abstract: We study the long-term persistence of attacker
infrastructure using longitudinal honeypot observations enriched with
DNS threat intelligence. By tracking active attacking IPs over time, we
examine how long attacker infrastructure remains active and how
representative attack behaviours observed in honeypots align with DNS
infrastructure intelligence. We are interested in discussion on
measuring persistent attacker infrastructure and its operational
implications.
Looking for: Feedback and discussion with researchers and operators working on DNS abuse, Internet measurement, and attacker infrastructure tracking.
Coordinates: Yuanyuan Zhou, yuanyuan.zhou.23@ucl.ac.uk
Presenter, Affiliation: Henk Birkholz (in person)
Abstract: Homogenization of Inputs, Outputs, as well as Chain of Though in a
comprehensive record format in support of auditability and accountability
Looking for: a home and more implementors
Relevant drafts: https://datatracker.ietf.org/doc/draft-birkholz-verifiable-agent-conversations/
Coordinates: Henk Birkholz, henk.birkholz@ietf.contact, the draft & authors, the AI Security side meeting on Monday
Presenter, Affiliation: Carlos Kamienski, Federal University of ABC (UFABC) - Brazil, in person
Abstract: For decades, the end-to-end argument has been the "North
Star" of Internet architecture, keeping the network core simple and
innovation at the edges. But now, the rise of the IoT Computing
Continuum is blurring the very definition of an "endpoint." Are we
witnessing a sophisticated evolution, or are we repeating the mistakes
of the middlebox era by embedding application semantics into the network
fabric? This talk challenges the community to decide whether the
end-to-end principle remains a viable design constraint or has the
"Continuum" rendered it obsolete.
Looking for: collaborators and ideas
Relevant resources:
- Saltzer, J. H., Reed, D. P., & Clark, D. D. (1984). End-to-end arguments in system design. ACM Transactions on Computer Systems (TOCS), 2(4), 277-288.
- Kamienski, C., Zyrianoff, I., Bittencourt, L. F., & Di Felice, M. (2024, April). Iotinuum: The IoT computing continuum. In 2024 20th International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT) (pp. 732-739). IEEE.
Coordinates: Carlos Kamienski, carlos.kamienski@ufabc.edu.br
Presenter, Affiliation: Daniel Huang, ZTE Corporation, in person
Abstract: Use cases as well as practices of high performance
transmission of large volume data over shared and public network, the
related hachathon results will also be demonstrated.
Looking for:
Relevant drafts:
https://datatracker.ietf.org/doc/draft-kcrh-hpwan-state-of-art/
https://datatracker.ietf.org/doc/draft-xhy-hpwan-framework/
https://datatracker.ietf.org/doc/draft-xiong-hpwan-signaling-solution/
https://datatracker.ietf.org/doc/draft-yx-hpwan-uc-requirements-public-operator/
https://datatracker.ietf.org/doc/draft-zhao-hpwan-scenarios-deployment/
Coordinates: mailing list: hp-wan@ietf.org
Presenter, Affiliation: Mahdi Baghbani, Giuseppe LoPresti, and Micke Nordin, presenting in person
Abstract: Open Cloud Mesh (OCM) is a server-to-server protocol for
federated file sharing across administrative domains, recently adopted
by an IETF Working Group. This talk gives a brief overview of the
protocol and summarises the changes introduced in versions 1.2.x and
1.3.0 of the specification. Highlights include: formalization of the
Directory Service and Invite format, updates to the token exchange and
HTTP Message Signatures as well as a new SSH share access method, and a
cleaner accessType model. We also outline open work items including
ResourceDiscovery, RequestShare, and IANA registration of
/.well-known/ocm.
Looking for: Reviewers of the IETF draft, implementers, and anyone interested in federated cloud storage and cross-platform file sharing.
Coordinates:
Micke Nordin, kano@sunet.se
Mailing list: https://mailman3.ietf.org/mailman3/lists/ocm.ietf.org/
IETF Datatracker: https://datatracker.ietf.org/doc/draft-ietf-ocm-open-cloud-mesh/
Presenter, Affiliation: Yujia Gao, Zhongguancun Laboratory (In person)
Abstract: Existing BGP FlowSpec is widely used in operator networks
for traffic mitigation. However, operators often have limited visibility
into whether deployed rules are actually executed as intended, and
incorrect configurations may remain unnoticed for a long time. To
address this, we propose a feedback optimization framework for BGP
FlowSpec, including a new feedback action, a rule execution state
machine, and telemetry protocols. This framework enables devices to
automatically collect execution status and report it back to the
controller, helping operators verify network behavior and enabling
closed-loop, agent-assisted automated tuning.
Looking for: potential collaborators and suitable deployment scenarios.
Relevant drafts: https://datatracker.ietf.org/doc/draft-cui-idr-flowspec-feedback-binding/
Coordinates: Yujia Gao, gaoyj@zgclab.edu.cn
Presenter, Affiliation: Christian Giese, onsite
Abstract: Access line identification and characterization attributes
are defined in various sources, Broadband Forum Technical Reports, RFCs,
and even expired drafts, and are used far beyond their standards
definition. I am looking forward to properly document the status quo to
prevent future number conflicts and help vendors and operators to
navigate through the chaos.
Looking for: collaborators and feedback.
Relevant drafts:
Coordinates: christian@rtbrick.com
Presenter, Affiliation: Muhammad Usama Sardar, TU Dresden and GA4GH, presenting remotely
Abstract: Using formal analysis [0], we found that intra-handshake
attestation is vulnerable to diversion attacks [1]. These attacks were
later practically shown in TEE.fail, wiretap.fail and battering RAM.
Further formal analysis showed that intra-handshake attestation is also
vulnerable to relay attacks [2]. Cocos AI using intra-handshake
attestation have acknowledged [3] the attacks.
To avoid these attacks, we present a new proposal
(draft-fossati-seat-expat) for post-handshake attestation based on
RFC9261.
Looking for:
Relevant drafts:
Wiki page: https://github.com/EuroProofNet/ProgramVerification/wiki/AttestedTLS
Technical concepts: https://www.researchgate.net/publication/396199290_Perspicuity_of_Attestation_Mechanisms_in_Confidential_Computing_Technical_Concepts
Validation of TLS 1.3 Key Schedule: https://www.researchgate.net/publication/396245726_Perspicuity_of_Attestation_Mechanisms_in_Confidential_Computing_Validation_of_TLS_13_Key_Schedule
General Approach: https://www.researchgate.net/publication/396593308_Perspicuity_of_Attestation_Mechanisms_in_Confidential_Computing_General_Approach
Pre-handshake attestation: https://www.researchgate.net/publication/385384309_Towards_Validation_of_TLS_13_Formal_Model_and_Vulnerabilities_in_Intel's_RA-TLS_Protocol
Intra-handshake attestation: https://www.usenix.org/conference/atc25/presentation/weinhold
Attestation in Arm CCA and Intel TDX: https://www.researchgate.net/publication/375592777_Formal_Specification_and_Verification_of_Architecturally-defined_Attestation_Mechanisms_in_Arm_CCA_and_Intel_TDX
Repo for attested TLS: https://github.com/CCC-Attestation/formal-spec-id-crisis
Repo for attestation: https://github.com/CCC-Attestation/formal-spec-TEE
Intra-handshake attestation: https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/ and https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/
Post-handshake attestation: https://datatracker.ietf.org/doc/draft-fossati-seat-expat/
Intra vs. post: https://datatracker.ietf.org/doc/draft-usama-seat-intra-vs-post/
https://datatracker.ietf.org/doc/draft-rats-sardar-sec-cons/
Some recent slides and videos at https://github.com/CCC-Attestation/formal-spec-id-crisis
Slides from side-meeting at IETF 120: https://www.researchgate.net/publication/382489639_Presentation_Interactive_Tutorial_Attested_TLS_and_Formalization
Slides from side-meetings at IETF 121: https://www.researchgate.net/publication/385587687_Presentation_Interactive_Tutorial_Attested_TLS_and_Formalization
Slides from side-meetings at IETF 122: https://www.researchgate.net/publication/390121641_Presentation_Attested_TLS_Fundamentals
Coordinates: Muhammad Usama Sardar, muhammad_usama.sardar@tu-dresden.de
Side meeting
Confidential AI, Monday, 18:30 - 20:00, Jiangsu
[0] https://github.com/CCC-Attestation/formal-spec-id-crisis
[2] https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/
[3] https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/
Presenter, Affiliation: in person with Yaroslav Rosomakho, Zscaler and/or Brian Campbell, Ping Identity
Abstract: AI agents are moving fast. While inventing brand-new
"agent identity" protocols from scratch is tempting, we already have
proven foundations that scale: workload identity (WIMSE/SPIFFE) and
delegated authorization (OAuth 2.0 and friends).
The AI Agent Authentication and Authorization draft maps common agent
interaction patterns onto established standards. The goal is to reduce
fragmentation, improve interoperability, and focus new standardization
only where real gaps exist.
Looking for: raise awareness going into the 125 week and encourage engagement around prospective cross-area IETF work
Relevant drafts: https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/
Coordinates: the draft, the draft authors (especially Yaroslav), dispatch on Monday, and several of the side meetings this week
Presenter, Affiliation: Yuning Jiang, Singapore Huawei Research Centre, in person
Abstract: Remote Attestation (RATS) is currently trapped in silos.
While it works well within a single trust domain, the model breaks down
when we move to cross-domain, heterogeneous environments. Today, every
Verifier must manually integrate with every Endorser and Reference Value
provider. This is a point-to-point approach that simply doesn't scale.
This talk explores a shift toward Distributed Remote Attestation. We
propose moving away from fragmented, private integrations toward a model
where attestation artifacts, like endorsements and reference values, are
reusable and discoverable across trust boundaries. By introducing a
shared publication channel with built-in provenance and access control,
we can bridge the transparency gap between domains. I’ll discuss how a
distributed architecture can transform attestation from a series of
isolated handshakes into a scalable, many-to-many infrastructure.
Looking for: collaborators and ideas
Coordinates: Yuning Jiang, jiangyuning2@h-partners.com
• Internet-Draft: https://datatracker.ietf.org/doc/draft-wang-rats-distributed-remote-attestation/
• Github: https://github.com/DistributedRemoteAttestaion/Distributed-remote-attestation