[OAUTH-WG] Re: [Ztcpp] Re: [saag] ZTNP / ZTIP – attestation-gated authorization & intent-bound delega tion (seeking venue guidance)

Philip Griffiths <[email protected]> Wed, 29 Apr 2026 17:40:48 +0100
Newsgroups gmane.ietf.oauth,gmane.ietf.saag
Message-ID <CAJuQJ1EnoQ8bWB5aZ4-W2aVDiNhNdGDjxgkxRdxAuW4a=krwaw@mail.gmail.com>
--===============9183283707382310560==
Content-Type: multipart/alternative; boundary="0000000000003c78fc06509c035e"

--0000000000003c78fc06509c035e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hey all,

Thanks for sharing @jake, I will quick add too, ZTNP/ZTIP look
complementary to the ZTCPP discussion rather than overlapping entirely (if
my quick reading of the drafts is correct).

I read it that ZTNP/ZTIP focus on how posture, attestation, intent, and
delegation evidence can inform authorization decisions at the
session/application layer.

ZTCPP, is more focused on the control/policy protocol gaps needed to
enforce least-privilege connectivity itself: authenticate-before-connect,
minimizing pre-auth reachability/exposure, and binding policy decisions to
concrete sessions/flows.

So I=E2=80=99d be interested in exploring whether ZTNP/ZTIP could provide i=
nputs or
claims into a ZTCPP-style policy/enforcement model, while ZTCPP addresses
how those decisions are distributed and enforced at the connectivity layer.
Regards
Philip

On Tue, 28 Apr 2026 at 03:08, Aijun Wang <[email protected]> wrote:

> Hi, Jake:
>
>
>
> I think your work is aligned well with the aim of ZTPP(Zero Trust Control
> and Policy Protocol) efforts.
>
> And, we are now updating the charter(
> https://github.com/ietf-ztcpp/Charter/blob/main/Charter.md) for the
> future BoF/Side Meeting in IETF 126.
>
>
>
> If you are interested, please subscribe the mailing list at
> https://mailman3.ietf.org/mailman3/lists/ztcpp.ietf.org/ and contribute
> your thoughts to refine the charter?
>
>
>
> Aijun
>
>
>
> *From:* [email protected] [mailto:[email protected]=
]
> *On Behalf Of *Jake Miller
> *Sent:* Tuesday, April 28, 2026 6:50 AM
> *To:* [email protected]; [email protected]
> *Subject:* [saag] ZTNP / ZTIP =E2=80=93 attestation-gated authorization &
> intent-bound delegation (seeking venue guidance)
>
>
>
> Hello,
>
> I=E2=80=99ve recently submitted two individual Internet-Drafts that explo=
re gaps
> we=E2=80=99re encountering as systems become more agent-driven and involv=
e
> multi-hop delegation:
>
> ZTNP (Zero-Trust Negotiation Protocol)
> https://datatracker.ietf.org/doc/draft-miller-ztnp/
>
> ZTIP (Zero-Trust Intent Protocol)
> https://datatracker.ietf.org/doc/draft-miller-ztip/
>
> At a high level:
>
>    - *ZTNP* looks at how to bind attestation (or posture) to
>    authorization at session establishment, including channel binding and =
local
>    policy evaluation by the relying party.
>    - *ZTIP* explores how to bind authorization to structured user intent
>    across delegation chains, with explicit scope monotonicity and end-to-=
end
>    verifiability.
>
> The drafts explore a potential gap between:
>
>    - attestation (e.g., RATS-style evidence/results), and
>    - authorization mechanisms (OAuth / GNAP)
>
> This is particularly true in scenarios where actions are delegated across
> multiple agents and are susceptible to prompt injection or confused deput=
y
> patterns.
>
> These drafts are intended as early contributions. I=E2=80=99m interested =
in
> critical feedback, especially on:
>
>    - whether the problem framing resonates
>    - how this relates to existing work in OAuth, GNAP, and RATS
>    - and whether there is an appropriate venue (existing WG or otherwise)
>    for further discussion
>
> Thank you for any feedback or direction.
>
> Best regards,
> Jake Miller
> [email protected]
> _______________________________________________
> Ztcpp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

--0000000000003c78fc06509c035e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hey all,</div><div><br></div><div>Thanks for sharing=
=C2=A0@jake,=C2=A0I will quick add too,<span>=C2=A0ZTNP/ZTIP look complemen=
tary to the ZTCPP discussion rather than overlapping entirely (if my quick =
reading of the drafts is correct).</span></div><div><span><br></span></div>=
<div><span>I read it that=C2=A0</span><span>ZTNP/ZTIP</span><span> focus on=
 how posture, attestation, intent, and delegation evidence can inform autho=
rization decisions at the session/application layer.=C2=A0</span></div><div=
><span><br></span></div><div><span>ZTCPP, is more focused on the control/po=
licy protocol gaps needed to enforce least-privilege connectivity itself: a=
uthenticate-before-connect, minimizing pre-auth reachability/exposure, and =
binding policy decisions to concrete sessions/flows.</span></div><div><p><s=
pan>So I=E2=80=99d be interested in exploring whether ZTNP/ZTIP could provi=
de inputs or claims into a ZTCPP-style policy/enforcement model, while ZTCP=
P addresses how those decisions are distributed and enforced at the connect=
ivity layer.</span></p>Regards</div><div>Philip</div></div><br><div class=
=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr=
">On Tue, 28 Apr 2026 at 03:08, Aijun Wang &lt;<a href=3D"mailto:wangaijun@=
tsinghua.org.cn">[email protected]</a>&gt; wrote:<br></div><blockqu=
ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px=
 solid rgb(204,204,204);padding-left:1ex"><div class=3D"msg8503291009778098=
83"><div lang=3D"ZH-CN"><div class=3D"m_850329100977809883WordSection1"><p =
class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=
=BA=BF;color:rgb(31,73,125)">Hi, Jake:<u></u><u></u></span></p><p class=3D"=
MsoNormal"><span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;col=
or:rgb(31,73,125)"><u></u>=C2=A0<u></u></span></p><p class=3D"MsoNormal"><s=
pan lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,=
125)">I think your work is aligned well with the aim of ZTPP(Zero Trust Con=
trol and Policy Protocol) efforts.<u></u><u></u></span></p><p class=3D"MsoN=
ormal"><span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:r=
gb(31,73,125)">And, we are now updating the charter(<a href=3D"https://gith=
ub.com/ietf-ztcpp/Charter/blob/main/Charter.md" target=3D"_blank">https://g=
ithub.com/ietf-ztcpp/Charter/blob/main/Charter.md</a>) for the future BoF/S=
ide Meeting in IETF 126.<u></u><u></u></span></p><p class=3D"MsoNormal"><sp=
an lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,1=
25)"><u></u>=C2=A0<u></u></span></p><p class=3D"MsoNormal"><span lang=3D"EN=
-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,125)">If you a=
re interested, please subscribe the mailing list at <a href=3D"https://mail=
man3.ietf.org/mailman3/lists/ztcpp.ietf.org/" target=3D"_blank">https://mai=
lman3.ietf.org/mailman3/lists/ztcpp.ietf.org/</a> and contribute your thoug=
hts to refine the charter?<u></u><u></u></span></p><p class=3D"MsoNormal"><=
span lang=3D"EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73=
,125)"><u></u>=C2=A0<u></u></span></p><p class=3D"MsoNormal"><span lang=3D"=
EN-US" style=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,125)">Aijun<=
u></u><u></u></span></p><p class=3D"MsoNormal"><span lang=3D"EN-US" style=
=3D"font-family:=E7=AD=89=E7=BA=BF;color:rgb(31,73,125)"><u></u>=C2=A0<u></=
u></span></p><p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-s=
ize:11pt;font-family:&quot;Calibri&quot;,sans-serif">From:</span></b><span =
lang=3D"EN-US" style=3D"font-size:11pt;font-family:&quot;Calibri&quot;,sans=
-serif"> <a href=3D"mailto:[email protected]" target=3D"_blank">=
[email protected]</a> [mailto:<a href=3D"mailto:forwardingalgori=
[email protected]" target=3D"_blank">[email protected]</a>] <b>On Beh=
alf Of </b>Jake Miller<br><b>Sent:</b> Tuesday, April 28, 2026 6:50 AM<br><=
b>To:</b> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]=
g</a>; <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>=
<br><b>Subject:</b> [saag] ZTNP / ZTIP =E2=80=93 attestation-gated authoriz=
ation &amp; intent-bound delegation (seeking venue guidance)<u></u><u></u><=
/span></p><p class=3D"MsoNormal"><span lang=3D"EN-US"><u></u>=C2=A0<u></u><=
/span></p><div><div><p><span lang=3D"EN-US">Hello,<u></u><u></u></span></p>=
<p><span lang=3D"EN-US">I=E2=80=99ve recently submitted two individual Inte=
rnet-Drafts that explore gaps we=E2=80=99re encountering as systems become =
more agent-driven and involve multi-hop delegation:<u></u><u></u></span></p=
><p><span lang=3D"EN-US">ZTNP (Zero-Trust Negotiation Protocol)<br><a href=
=3D"https://datatracker.ietf.org/doc/draft-miller-ztnp/" target=3D"_blank">=
https://datatracker.ietf.org/doc/draft-miller-ztnp/</a><u></u><u></u></span=
></p><p><span lang=3D"EN-US">ZTIP (Zero-Trust Intent Protocol)<br><a href=
=3D"https://datatracker.ietf.org/doc/draft-miller-ztip/" target=3D"_blank">=
https://datatracker.ietf.org/doc/draft-miller-ztip/</a><u></u><u></u></span=
></p><p><span lang=3D"EN-US">At a high level:<u></u><u></u></span></p><ul t=
ype=3D"disc"><li class=3D"MsoNormal"><strong><span lang=3D"EN-US" style=3D"=
font-family:=E5=AE=8B=E4=BD=93">ZTNP</span></strong><span lang=3D"EN-US"> l=
ooks at how to bind attestation (or posture) to authorization at session es=
tablishment, including channel binding and local policy evaluation by the r=
elying party. <u></u><u></u></span></li><li class=3D"MsoNormal"><strong><sp=
an lang=3D"EN-US" style=3D"font-family:=E5=AE=8B=E4=BD=93">ZTIP</span></str=
ong><span lang=3D"EN-US"> explores how to bind authorization to structured =
user intent across delegation chains, with explicit scope monotonicity and =
end-to-end verifiability. <u></u><u></u></span></li></ul><p><span lang=3D"E=
N-US">The drafts explore a potential gap between:<u></u><u></u></span></p><=
ul type=3D"disc"><li class=3D"MsoNormal"><span lang=3D"EN-US">attestation (=
e.g., RATS-style evidence/results), and <u></u><u></u></span></li><li class=
=3D"MsoNormal"><span lang=3D"EN-US">authorization mechanisms (OAuth / GNAP)=
<u></u><u></u></span></li></ul><p><span lang=3D"EN-US">This is particularly=
 true in scenarios where actions are delegated across multiple agents and a=
re susceptible to prompt injection or confused deputy patterns.<u></u><u></=
u></span></p><p><span lang=3D"EN-US">These drafts are intended as early con=
tributions. I=E2=80=99m interested in critical feedback, especially on:<u><=
/u><u></u></span></p><ul type=3D"disc"><li class=3D"MsoNormal"><span lang=
=3D"EN-US">whether the problem framing resonates <u></u><u></u></span></li>=
<li class=3D"MsoNormal"><span lang=3D"EN-US">how this relates to existing w=
ork in OAuth, GNAP, and RATS <u></u><u></u></span></li><li class=3D"MsoNorm=
al"><span lang=3D"EN-US">and whether there is an appropriate venue (existin=
g WG or otherwise) for further discussion <u></u><u></u></span></li></ul><p=
><span lang=3D"EN-US">Thank you for any feedback or direction.<u></u><u></u=
></span></p><p><span lang=3D"EN-US">Best regards,<br>Jake Miller<br><a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><u></u><u></u>=
</span></p></div></div></div></div>________________________________________=
_______<br>
Ztcpp mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">z=
[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar=
get=3D"_blank">[email protected]</a><br>
</div></blockquote></div>

--0000000000003c78fc06509c035e--


--===============9183283707382310560==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KT0F1dGggbWFp
bGluZyBsaXN0IC0tIG9hdXRoQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gb2F1dGgtbGVhdmVAaWV0Zi5vcmcK

--===============9183283707382310560==--