[OAUTH-WG] Re: [Ztcpp] Re: [saag] ZTNP / ZTIP – attestation-gated authorization & intent-bound delega tion (seeking venue guidance)
Philip Griffiths <[email protected]> Wed, 29 Apr 2026 17:40:48 +0100
| Newsgroups | gmane.ietf.oauth,gmane.ietf.saag |
|---|---|
| Message-ID | <CAJuQJ1EnoQ8bWB5aZ4-W2aVDiNhNdGDjxgkxRdxAuW4a=krwaw@mail.gmail.com> |
--===============9183283707382310560== Content-Type: multipart/alternative; boundary="0000000000003c78fc06509c035e" --0000000000003c78fc06509c035e Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hey all, Thanks for sharing @jake, I will quick add too, ZTNP/ZTIP look complementary to the ZTCPP discussion rather than overlapping entirely (if my quick reading of the drafts is correct). I read it that ZTNP/ZTIP focus on how posture, attestation, intent, and delegation evidence can inform authorization decisions at the session/application layer. ZTCPP, is more focused on the control/policy protocol gaps needed to enforce least-privilege connectivity itself: authenticate-before-connect, minimizing pre-auth reachability/exposure, and binding policy decisions to concrete sessions/flows. So I=E2=80=99d be interested in exploring whether ZTNP/ZTIP could provide i= nputs or claims into a ZTCPP-style policy/enforcement model, while ZTCPP addresses how those decisions are distributed and enforced at the connectivity layer. Regards Philip On Tue, 28 Apr 2026 at 03:08, Aijun Wang <[email protected]> wrote: > Hi, Jake: > > > > I think your work is aligned well with the aim of ZTPP(Zero Trust Control > and Policy Protocol) efforts. > > And, we are now updating the charter( > https://github.com/ietf-ztcpp/Charter/blob/main/Charter.md) for the > future BoF/Side Meeting in IETF 126. > > > > If you are interested, please subscribe the mailing list at > https://mailman3.ietf.org/mailman3/lists/ztcpp.ietf.org/ and contribute > your thoughts to refine the charter? > > > > Aijun > > > > *From:* [email protected] [mailto:[email protected]= ] > *On Behalf Of *Jake Miller > *Sent:* Tuesday, April 28, 2026 6:50 AM > *To:* [email protected]; [email protected] > *Subject:* [saag] ZTNP / ZTIP =E2=80=93 attestation-gated authorization & > intent-bound delegation (seeking venue guidance) > > > > Hello, > > I=E2=80=99ve recently submitted two individual Internet-Drafts that explo= re gaps > we=E2=80=99re encountering as systems become more agent-driven and involv= e > multi-hop delegation: > > ZTNP (Zero-Trust Negotiation Protocol) > https://datatracker.ietf.org/doc/draft-miller-ztnp/ > > ZTIP (Zero-Trust Intent Protocol) > https://datatracker.ietf.org/doc/draft-miller-ztip/ > > At a high level: > > - *ZTNP* looks at how to bind attestation (or posture) to > authorization at session establishment, including channel binding and = local > policy evaluation by the relying party. > - *ZTIP* explores how to bind authorization to structured user intent > across delegation chains, with explicit scope monotonicity and end-to-= end > verifiability. > > The drafts explore a potential gap between: > > - attestation (e.g., RATS-style evidence/results), and > - authorization mechanisms (OAuth / GNAP) > > This is particularly true in scenarios where actions are delegated across > multiple agents and are susceptible to prompt injection or confused deput= y > patterns. > > These drafts are intended as early contributions. I=E2=80=99m interested = in > critical feedback, especially on: > > - whether the problem framing resonates > - how this relates to existing work in OAuth, GNAP, and RATS > - and whether there is an appropriate venue (existing WG or otherwise) > for further discussion > > Thank you for any feedback or direction. > > Best regards, > Jake Miller > [email protected] > _______________________________________________ > Ztcpp mailing list -- [email protected] > To unsubscribe send an email to [email protected] > --0000000000003c78fc06509c035e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hey all,</div><div><br></div><div>Thanks for sharing= =C2=A0@jake,=C2=A0I will quick add too,<span>=C2=A0ZTNP/ZTIP look complemen= tary to the ZTCPP discussion rather than overlapping entirely (if my quick = reading of the drafts is correct).</span></div><div><span><br></span></div>= <div><span>I read it that=C2=A0</span><span>ZTNP/ZTIP</span><span> focus on= how posture, attestation, intent, and delegation evidence can inform autho= rization decisions at the session/application layer.=C2=A0</span></div><div= ><span><br></span></div><div><span>ZTCPP, is more focused on the control/po= licy protocol gaps needed to enforce least-privilege connectivity itself: a= uthenticate-before-connect, minimizing pre-auth reachability/exposure, and = binding policy decisions to concrete sessions/flows.</span></div><div><p><s= pan>So I=E2=80=99d be interested in exploring whether ZTNP/ZTIP could provi= de inputs or claims into a ZTCPP-style policy/enforcement model, while ZTCP= P addresses how those decisions are distributed and enforced at the connect= ivity layer.</span></p>Regards</div><div>Philip</div></div><br><div class= =3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr= ">On Tue, 28 Apr 2026 at 03:08, Aijun Wang <<a href=3D"mailto:wangaijun@= tsinghua.org.cn">[email protected]</a>> wrote:<br></div><blockqu= ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px= solid rgb(204,204,204);padding-left:1ex"><div class=3D"msg8503291009778098= 83"><div lang=3D"ZH-CN"><div class=3D"m_850329100977809883WordSection1"><p = class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7= =BA=BF;color:rgb(31,73,125)">Hi, Jake:<u></u><u></u></span></p><p class=3D"= MsoNormal"><span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;col= or:rgb(31,73,125)"><u></u>=C2=A0<u></u></span></p><p class=3D"MsoNormal"><s= pan lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,= 125)">I think your work is aligned well with the aim of ZTPP(Zero Trust Con= trol and Policy Protocol) efforts.<u></u><u></u></span></p><p class=3D"MsoN= ormal"><span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:r= gb(31,73,125)">And, we are now updating the charter(<a href=3D"https://gith= ub.com/ietf-ztcpp/Charter/blob/main/Charter.md" target=3D"_blank">https://g= ithub.com/ietf-ztcpp/Charter/blob/main/Charter.md</a>) for the future BoF/S= ide Meeting in IETF 126.<u></u><u></u></span></p><p class=3D"MsoNormal"><sp= an lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,1= 25)"><u></u>=C2=A0<u></u></span></p><p class=3D"MsoNormal"><span lang=3D"EN= -US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,125)">If you a= re interested, please subscribe the mailing list at <a href=3D"https://mail= man3.ietf.org/mailman3/lists/ztcpp.ietf.org/" target=3D"_blank">https://mai= lman3.ietf.org/mailman3/lists/ztcpp.ietf.org/</a> and contribute your thoug= hts to refine the charter?<u></u><u></u></span></p><p class=3D"MsoNormal"><= span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73= ,125)"><u></u>=C2=A0<u></u></span></p><p class=3D"MsoNormal"><span lang=3D"= EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,125)">Aijun<= u></u><u></u></span></p><p class=3D"MsoNormal"><span lang=3D"EN-US" style= =3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,125)"><u></u>=C2=A0<u></= u></span></p><p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-s= ize:11pt;font-family:"Calibri",sans-serif">From:</span></b><span = lang=3D"EN-US" style=3D"font-size:11pt;font-family:"Calibri",sans= -serif"> <a href=3D"mailto:[email protected]" target=3D"_blank">= [email protected]</a> [mailto:<a href=3D"mailto:forwardingalgori= [email protected]" target=3D"_blank">[email protected]</a>] <b>On Beh= alf Of </b>Jake Miller<br><b>Sent:</b> Tuesday, April 28, 2026 6:50 AM<br><= b>To:</b> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]= g</a>; <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>= <br><b>Subject:</b> [saag] ZTNP / ZTIP =E2=80=93 attestation-gated authoriz= ation & intent-bound delegation (seeking venue guidance)<u></u><u></u><= /span></p><p class=3D"MsoNormal"><span lang=3D"EN-US"><u></u>=C2=A0<u></u><= /span></p><div><div><p><span lang=3D"EN-US">Hello,<u></u><u></u></span></p>= <p><span lang=3D"EN-US">I=E2=80=99ve recently submitted two individual Inte= rnet-Drafts that explore gaps we=E2=80=99re encountering as systems become = more agent-driven and involve multi-hop delegation:<u></u><u></u></span></p= ><p><span lang=3D"EN-US">ZTNP (Zero-Trust Negotiation Protocol)<br><a href= =3D"https://datatracker.ietf.org/doc/draft-miller-ztnp/" target=3D"_blank">= https://datatracker.ietf.org/doc/draft-miller-ztnp/</a><u></u><u></u></span= ></p><p><span lang=3D"EN-US">ZTIP (Zero-Trust Intent Protocol)<br><a href= =3D"https://datatracker.ietf.org/doc/draft-miller-ztip/" target=3D"_blank">= https://datatracker.ietf.org/doc/draft-miller-ztip/</a><u></u><u></u></span= ></p><p><span lang=3D"EN-US">At a high level:<u></u><u></u></span></p><ul t= ype=3D"disc"><li class=3D"MsoNormal"><strong><span lang=3D"EN-US" style=3D"= font-family:=E5=AE=8B=E4=BD=93">ZTNP</span></strong><span lang=3D"EN-US"> l= ooks at how to bind attestation (or posture) to authorization at session es= tablishment, including channel binding and local policy evaluation by the r= elying party. <u></u><u></u></span></li><li class=3D"MsoNormal"><strong><sp= an lang=3D"EN-US" style=3D"font-family:=E5=AE=8B=E4=BD=93">ZTIP</span></str= ong><span lang=3D"EN-US"> explores how to bind authorization to structured = user intent across delegation chains, with explicit scope monotonicity and = end-to-end verifiability. <u></u><u></u></span></li></ul><p><span lang=3D"E= N-US">The drafts explore a potential gap between:<u></u><u></u></span></p><= ul type=3D"disc"><li class=3D"MsoNormal"><span lang=3D"EN-US">attestation (= e.g., RATS-style evidence/results), and <u></u><u></u></span></li><li class= =3D"MsoNormal"><span lang=3D"EN-US">authorization mechanisms (OAuth / GNAP)= <u></u><u></u></span></li></ul><p><span lang=3D"EN-US">This is particularly= true in scenarios where actions are delegated across multiple agents and a= re susceptible to prompt injection or confused deputy patterns.<u></u><u></= u></span></p><p><span lang=3D"EN-US">These drafts are intended as early con= tributions. I=E2=80=99m interested in critical feedback, especially on:<u><= /u><u></u></span></p><ul type=3D"disc"><li class=3D"MsoNormal"><span lang= =3D"EN-US">whether the problem framing resonates <u></u><u></u></span></li>= <li class=3D"MsoNormal"><span lang=3D"EN-US">how this relates to existing w= ork in OAuth, GNAP, and RATS <u></u><u></u></span></li><li class=3D"MsoNorm= al"><span lang=3D"EN-US">and whether there is an appropriate venue (existin= g WG or otherwise) for further discussion <u></u><u></u></span></li></ul><p= ><span lang=3D"EN-US">Thank you for any feedback or direction.<u></u><u></u= ></span></p><p><span lang=3D"EN-US">Best regards,<br>Jake Miller<br><a href= =3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><u></u><u></u>= </span></p></div></div></div></div>________________________________________= _______<br> Ztcpp mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">z= [email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar= get=3D"_blank">[email protected]</a><br> </div></blockquote></div> --0000000000003c78fc06509c035e-- --===============9183283707382310560== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KT0F1dGggbWFp bGluZyBsaXN0IC0tIG9hdXRoQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gb2F1dGgtbGVhdmVAaWV0Zi5vcmcK --===============9183283707382310560==--