I-D Action: draft-schrock-ae-challenge-07.txt

[email protected] Mon, 10 Aug 2026 22:02:02 -0700
Newsgroups gmane.ietf.announce
Message-ID <178642452236.494386.10635303825105577709@dt-datatracker-559c48c7fb-9llwz>
Internet-Draft draft-schrock-ae-challenge-07.txt is now available.

   Title:   An Authorization Evidence Challenge for High-Risk Agent Actions
   Author:  Iman Schrock
   Name:    draft-schrock-ae-challenge-07.txt
   Pages:   36
   Dates:   2026-08-10

Abstract:

   When a relying party refuses a consequential agent action because
   authorization evidence is missing, stale, or unverifiable, the agent
   needs a machine-readable description of what remains necessary.  This
   document defines a transport-neutral Authorization Evidence Challenge
   data model bound to the relying party's exact action.  The challenge
   identifies outstanding evidence requirements, freshness and status
   constraints, acceptable presentation profiles, and retry state.  It
   authorizes nothing, transfers no admission ownership, and provides no
   promise that a later request will execute.

   The document also defines an HTTP challenge-response carrier using
   403 Forbidden and RFC 9457 Problem Details, and describes an
   informative gateway-handoff illustration for DMSC-style federation.
   The gateway illustration communicates evidence requirements; it does
   not solve conserved admission or double-admission across
   independently operated gateways.

   A challenge can synchronize corrected retries and amplify load.  The
   core therefore defines optional retry timing with per-challenge
   jitter, and the HTTP carrier maps its lower bound to Retry-After.
   Retry timing controls presentation attempts only; it does not
   authorize the action or make an uncertain action safe to repeat.

   Single-use processing also places state on the refusal path.  The
   core therefore requires bounded outstanding and replay state, fail-
   closed behavior when state cannot be claimed, and retention of live
   replay records until they are no longer security-relevant.  Nonce
   claim and refusal-path capacity reservation are one atomic owner-side
   transition before native evidence verification, and a binding
   capacity refusal reveals no remaining evidence requirements.  In a
   sharded replay domain, only the authoritative owner can classify a
   nonce as already claimed; inability to reach that owner is
   unavailability, not replay.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-schrock-ae-challenge/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-schrock-ae-challenge-07.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-schrock-ae-challenge-07

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]