I-D Action: draft-ztop-secdispatch-protocol-00.txt
[email protected] Thu, 23 Jul 2026 19:01:17 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178485847777.707355.8663695316738831701@dt-datatracker-d4d6ff9d9-fsx7d> |
Internet-Draft draft-ztop-secdispatch-protocol-00.txt is now available. Title: Zero Trust Transfer Orchestration Protocol (ZTOP) Author: Sripad Karthik Name: draft-ztop-secdispatch-protocol-00.txt Pages: 16 Dates: 2026-07-23 Abstract: This document defines the Zero Trust Transfer Orchestration Protocol (ZTOP), a novel Application Layer (OSI Layer 7) protocol for orchestrating cryptographically authenticated, continuously attested peer-to-peer file transfer in Zero Trust Architectures (ZTA). ZTOP operates within a TLS 1.3 transport tunnel and introduces: a hardware-derived cryptographic Peer Identity using HKDF-SHA512 and Ed25519; a 5-layer X.509 certificate chain with custom OID-encoded Zero Trust metadata; a continuous 16-field Heartbeat attestation protocol; a 100-point Adaptive Tamper Resistance Score; a dual-signed 19-field Metadata Exchange Protocol preceding any payload; a 380-byte Cryptographic Execution Manifest (CEM) permanently bound to every transferred file; SHA-256 binary Merkle-tree chunk integrity with immediate per-chunk proof validation; protocol-native static pre-execution behavioral analysis; and a 7-Level non-repudiation Signature Chain. A transfer is considered complete only when all seven cryptographic signatures are present and verified. A Python reference implementation is available at: https://github.com/sripad2020/ztop-research/ The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ztop-secdispatch-protocol/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-ztop-secdispatch-protocol-00 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]