I-D Action: draft-bu-agentproto-security-principal-binding-05.txt
[email protected] Sun, 09 Aug 2026 07:01:05 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178628406502.280234.8850524648666840264@dt-datatracker-559c48c7fb-llb9x> |
Internet-Draft draft-bu-agentproto-security-principal-binding-05.txt is now available. Title: Security Principal and Verifier Binding for Agent Communication Protocols Author: Songbo Bu Name: draft-bu-agentproto-security-principal-binding-05.txt Pages: 62 Dates: 2026-08-09 Abstract: Agent communication protocols often carry claims about user authority, agent instance identity, tool or external-resource identity, delegation state, session continuity, and action evidence. These claims have different verifiers, freshness requirements, failure modes, and security consequences. If they are collapsed into a single token, identity label, session identifier, or audit record, protocol text can accidentally imply more authority or accountability than the receiver can actually verify. This document defines a verifier-facing model for separating those claims. It provides a reusable matrix format that protocol authors can use to state, for each security-relevant claim, which field carries it, which party verifies it, what binding or freshness rule applies, what failure behavior is required when the claim is absent, stale, inconsistent, or not verifiable, and what constrained result an application may consume after successful verification. It also separates specification status, implementation status, and evidence type so that reviewers can distinguish current protocol text, implementation evidence, inherited mechanisms, and architectural assumptions. The document is protocol-neutral. It is intended to help compare candidate agent communication drafts and to provide security-considerations and requirements text for agent session and delegation binding. The document also defines row-outcome semantics and dependency- closure rules for composed mappings. These rules prevent a composite result from becoming stronger than its verified inputs, distinguish failed checks, unsupported verifier capabilities, checks skipped after a failed prerequisite, and unavailable or ambiguous inputs, propagate transitive dependency failures, and make cyclic, stale, downgraded, or revision-incoherent dependencies visible to reviewers. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-bu-agentproto-security-principal-binding/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-bu-agentproto-security-principal-binding-05.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-bu-agentproto-security-principal-binding-05 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]