[saag] Draft Charter for ZTCPP(Zero Trust Control and Policy Protocols

Aijun Wang <[email protected]> Tue, 13 Jan 2026 21:57:14 +0800
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>

Hi, All:

Based on the past discussions, we determined to limit the scope of “zero trust” to “zero trust control and policy protocol”, which is above the TLS transport layer, accomplishes the aim of “zero trust”, and is also the necessary standards that are needed for the interoperable operation among the zero trust solutions from different vendors.

We would like to seek more feedbacks(suggested expressions) on the following charters.

We are also preparing the BoF application in theses days for ZTCPP.

If you have also interests in this topic, and would like to make some presentations on the BoF meeting, please let me know.

Aijun Wang
China Telecom

==================================
# Zero Trust  Control and Policy Protocols WG Charter(ZTCPP)
 
Working Group Name:
## Zero Trust Control and Policy Protocols (ztcpp)
 
## Area:
Security (SEC)
 
## Chair(s):
To be determined
 
## Problem Statement:
Existing Internet protocols rely on a default-trust model, where IP addresses and ports are accessible without prior authorization, and security measures are applied only after a connection attempt. This model is increasingly inadequate in today’s threat landscape, especially with AI-driven, automated scanning and exploitation, where mere network visibility heightens risk.
 
Zero Trust Control and Policy Protocols working group aims to eliminate implicit trust by enforcing continuous authentication,
authorization, and policy evaluation. Existing Zero Trust deployments rely heavily on proprietary,
non-interoperable mechanisms. There is a need for open, interoperable protocol specifications to
address these gaps, particularly for authenticated-before-connect access, control-plane signaling, and enforcement within network infrastructure.
 
## Objectives:
The ZTCPP Working Group will define interoperable protocols and frameworks that support:
- Authenticated-before-connect access to protected resources
- Dynamic trust and context signaling
- Zero Trust control-plane communication
- Application of Zero Trust principles within network infrastructure
 
## Scope of Work:
The WG will produce specifications and guidance for Zero Trust protocol interoperability,
including authenticated-before-connect mechanisms, in-network policy enforcement considerations and control-plane requirements. 
The WG will reuse existing IETF protocols where possible and define new mechanisms only when gaps are identified.
 
## Out of Scope:
- Redefinition of Zero Trust principles or architectures
- Vendor-specific or proprietary mechanisms
- Endpoint security technologies unrelated to protocol interoperability
 
## Deliverables:
- Zero Trust Problem Statements and Gap Analysis(Informational)
- Network-infrastructure aligned Zero Trust considerations (Informational/BCP)
- Zero Trust protocol interoperability framework (Informational)
- Authenticated-before-connect mechanisms (Standards Track)
- Control-plane protocol requirements (Informational)
 
## Milestones:
- Adopt Problem Statements and Gap Analysis/Network-infrastructure aligned Zero Trust considerations drafts.(6 months)
- Adopt framework and requirements drafts(12 months)
- Adopt authenticated-before-connect draft(18 months)
- Publish above WG documents as RFCs(24 months)
- Publish deployment and interoperability guidance(24 months)
- Re-Charter or Close the WG
 
## Coordination:
The WG will coordinate with SAAG, ACE, RATS, OAuth, and Other relevant WGs.
=====================================

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]