[saag] [I-D] draft-tonyai-a2a-trust-00: Agent-to-Agent T rust, Identity, and Verifiable Provenance

Anthony Trujillo <[email protected]> Wed, 20 May 2026 15:22:40 -0600
Newsgroups gmane.ietf.saag
Message-ID <CAL9aEXr4mmQrkAdm5Ny__gOWh0d2Yb+YPAZccXw7SEdFML-=LQ@mail.gmail.com>
--===============7258654005488945858==
Content-Type: multipart/alternative; boundary="000000000000f4b221065246655c"

--000000000000f4b221065246655c
Content-Type: text/plain; charset="UTF-8"

I've submitted an individual Internet-Draft proposing a trust model
for agent-to-agent (A2A) interactions in multi-agent AI systems:

  https://datatracker.ietf.org/doc/draft-tonyai-a2a-trust/

The problem: when Agent A spawns Agent B, and Agent B calls a resource,
no current standard defines how the resource verifies that Agent B was
legitimately spawned, that its scope hasn't been escalated, or that its
origin template is trusted.

The draft proposes:

  - Agent templates as CA-signed identity artifacts (X.509/PKI)
  - Verifiable spawn chains with cryptographic provenance
  - Two-lane governance: static cert identity + dual-signature dynamic
policy
  - Fail-closed enforcement at every verification step
  - Explicit cross-organizational grant authorization

The model deliberately reuses existing PKI primitives (X.509, CRL, CSR)
and established patterns (OAuth 2.0, On-Behalf-Of, RFC 8693 Token Exchange)
rather than introducing new cryptographic mechanisms.

This is early-stage work. I'm looking for feedback on whether this is
the right framing, what's missing, and whether there's interest in
developing it further within the IETF.

(.) (.)

<>

~~~,

TonyT

--000000000000f4b221065246655c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><br clear=3D"all"></div><div><br></div>I&#39;ve submi=
tted an individual Internet-Draft proposing a trust model<br>for agent-to-a=
gent (A2A) interactions in multi-agent AI systems:<br><br>=C2=A0 <a href=3D=
"https://datatracker.ietf.org/doc/draft-tonyai-a2a-trust/">https://datatrac=
ker.ietf.org/doc/draft-tonyai-a2a-trust/</a><br><br>The problem: when Agent=
 A spawns Agent B, and Agent B calls a resource,<br>no current standard def=
ines how the resource verifies that Agent B was<br>legitimately spawned, th=
at its scope hasn&#39;t been escalated, or that its<br>origin template is t=
rusted.<br><br>The draft proposes:<br><br>=C2=A0 - Agent templates as CA-si=
gned identity artifacts (X.509/PKI)<br>=C2=A0 - Verifiable spawn chains wit=
h cryptographic provenance<br>=C2=A0 - Two-lane governance: static cert ide=
ntity + dual-signature dynamic policy<br>=C2=A0 - Fail-closed enforcement a=
t every verification step<br>=C2=A0 - Explicit cross-organizational grant a=
uthorization<br><br>The model deliberately reuses existing PKI primitives (=
X.509, CRL, CSR)<br>and established patterns (OAuth 2.0, On-Behalf-Of, RFC =
8693 Token Exchange)<br>rather than introducing new cryptographic mechanism=
s.<br><br>This is early-stage work. I&#39;m looking for feedback on whether=
 this is<br>the right framing, what&#39;s missing, and whether there&#39;s =
interest in<br>developing it further within the IETF.<br><br><div dir=3D"lt=
r" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D=
"ltr"><p style=3D"margin:0px;padding:1px 8px;border:0px;font-size:1.4rem;ve=
rtical-align:baseline;background-image:initial;background-position:initial;=
background-repeat:initial;line-height:1.42857;color:rgba(0,0,0,0.75);font-f=
amily:-apple-system,system-ui,BlinkMacSystemFont,&quot;Segoe UI&quot;,Robot=
o,&quot;Helvetica Neue&quot;,&quot;Fira Sans&quot;,Ubuntu,Oxygen,&quot;Oxyg=
en Sans&quot;,Cantarell,&quot;Droid Sans&quot;,&quot;Apple Color Emoji&quot=
;,&quot;Segoe UI Emoji&quot;,&quot;Segoe UI Symbol&quot;,&quot;Lucida Grand=
e&quot;,Helvetica,Arial,sans-serif">(.) (.)</p><p style=3D"margin:0px;paddi=
ng:1px 8px;border:0px;font-size:1.4rem;vertical-align:baseline;background-i=
mage:initial;background-position:initial;background-repeat:initial;line-hei=
ght:1.42857;color:rgba(0,0,0,0.75);font-family:-apple-system,system-ui,Blin=
kMacSystemFont,&quot;Segoe UI&quot;,Roboto,&quot;Helvetica Neue&quot;,&quot=
;Fira Sans&quot;,Ubuntu,Oxygen,&quot;Oxygen Sans&quot;,Cantarell,&quot;Droi=
d Sans&quot;,&quot;Apple Color Emoji&quot;,&quot;Segoe UI Emoji&quot;,&quot=
;Segoe UI Symbol&quot;,&quot;Lucida Grande&quot;,Helvetica,Arial,sans-serif=
">&lt;&gt;</p><p style=3D"margin:0px;padding:1px 8px 8px;border:0px;font-si=
ze:1.4rem;vertical-align:baseline;background-image:initial;background-posit=
ion:initial;background-repeat:initial;line-height:1.42857;color:rgba(0,0,0,=
0.75);font-family:-apple-system,system-ui,BlinkMacSystemFont,&quot;Segoe UI=
&quot;,Roboto,&quot;Helvetica Neue&quot;,&quot;Fira Sans&quot;,Ubuntu,Oxyge=
n,&quot;Oxygen Sans&quot;,Cantarell,&quot;Droid Sans&quot;,&quot;Apple Colo=
r Emoji&quot;,&quot;Segoe UI Emoji&quot;,&quot;Segoe UI Symbol&quot;,&quot;=
Lucida Grande&quot;,Helvetica,Arial,sans-serif">~~~,</p><p style=3D"margin:=
0px;padding:1px 8px 8px;border:0px;font-size:1.4rem;vertical-align:baseline=
;background-image:initial;background-position:initial;background-repeat:ini=
tial;line-height:1.42857;color:rgba(0,0,0,0.75);font-family:-apple-system,s=
ystem-ui,BlinkMacSystemFont,&quot;Segoe UI&quot;,Roboto,&quot;Helvetica Neu=
e&quot;,&quot;Fira Sans&quot;,Ubuntu,Oxygen,&quot;Oxygen Sans&quot;,Cantare=
ll,&quot;Droid Sans&quot;,&quot;Apple Color Emoji&quot;,&quot;Segoe UI Emoj=
i&quot;,&quot;Segoe UI Symbol&quot;,&quot;Lucida Grande&quot;,Helvetica,Ari=
al,sans-serif"><span style=3D"font-size:1.4rem">TonyT</span><br></p></div><=
/div></div>

--000000000000f4b221065246655c--


--===============7258654005488945858==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls
aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHNhYWctbGVhdmVAaWV0Zi5vcmcK

--===============7258654005488945858==--