[saag] [I-D] draft-tonyai-a2a-trust-00: Agent-to-Agent T rust, Identity, and Verifiable Provenance
Anthony Trujillo <[email protected]> Wed, 20 May 2026 15:22:40 -0600
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAL9aEXr4mmQrkAdm5Ny__gOWh0d2Yb+YPAZccXw7SEdFML-=LQ@mail.gmail.com> |
--===============7258654005488945858== Content-Type: multipart/alternative; boundary="000000000000f4b221065246655c" --000000000000f4b221065246655c Content-Type: text/plain; charset="UTF-8" I've submitted an individual Internet-Draft proposing a trust model for agent-to-agent (A2A) interactions in multi-agent AI systems: https://datatracker.ietf.org/doc/draft-tonyai-a2a-trust/ The problem: when Agent A spawns Agent B, and Agent B calls a resource, no current standard defines how the resource verifies that Agent B was legitimately spawned, that its scope hasn't been escalated, or that its origin template is trusted. The draft proposes: - Agent templates as CA-signed identity artifacts (X.509/PKI) - Verifiable spawn chains with cryptographic provenance - Two-lane governance: static cert identity + dual-signature dynamic policy - Fail-closed enforcement at every verification step - Explicit cross-organizational grant authorization The model deliberately reuses existing PKI primitives (X.509, CRL, CSR) and established patterns (OAuth 2.0, On-Behalf-Of, RFC 8693 Token Exchange) rather than introducing new cryptographic mechanisms. This is early-stage work. I'm looking for feedback on whether this is the right framing, what's missing, and whether there's interest in developing it further within the IETF. (.) (.) <> ~~~, TonyT --000000000000f4b221065246655c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div><br clear=3D"all"></div><div><br></div>I've submi= tted an individual Internet-Draft proposing a trust model<br>for agent-to-a= gent (A2A) interactions in multi-agent AI systems:<br><br>=C2=A0 <a href=3D= "https://datatracker.ietf.org/doc/draft-tonyai-a2a-trust/">https://datatrac= ker.ietf.org/doc/draft-tonyai-a2a-trust/</a><br><br>The problem: when Agent= A spawns Agent B, and Agent B calls a resource,<br>no current standard def= ines how the resource verifies that Agent B was<br>legitimately spawned, th= at its scope hasn't been escalated, or that its<br>origin template is t= rusted.<br><br>The draft proposes:<br><br>=C2=A0 - Agent templates as CA-si= gned identity artifacts (X.509/PKI)<br>=C2=A0 - Verifiable spawn chains wit= h cryptographic provenance<br>=C2=A0 - Two-lane governance: static cert ide= ntity + dual-signature dynamic policy<br>=C2=A0 - Fail-closed enforcement a= t every verification step<br>=C2=A0 - Explicit cross-organizational grant a= uthorization<br><br>The model deliberately reuses existing PKI primitives (= X.509, CRL, CSR)<br>and established patterns (OAuth 2.0, On-Behalf-Of, RFC = 8693 Token Exchange)<br>rather than introducing new cryptographic mechanism= s.<br><br>This is early-stage work. I'm looking for feedback on whether= this is<br>the right framing, what's missing, and whether there's = interest in<br>developing it further within the IETF.<br><br><div dir=3D"lt= r" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D= "ltr"><p style=3D"margin:0px;padding:1px 8px;border:0px;font-size:1.4rem;ve= rtical-align:baseline;background-image:initial;background-position:initial;= background-repeat:initial;line-height:1.42857;color:rgba(0,0,0,0.75);font-f= amily:-apple-system,system-ui,BlinkMacSystemFont,"Segoe UI",Robot= o,"Helvetica Neue","Fira Sans",Ubuntu,Oxygen,"Oxyg= en Sans",Cantarell,"Droid Sans","Apple Color Emoji"= ;,"Segoe UI Emoji","Segoe UI Symbol","Lucida Grand= e",Helvetica,Arial,sans-serif">(.) (.)</p><p style=3D"margin:0px;paddi= ng:1px 8px;border:0px;font-size:1.4rem;vertical-align:baseline;background-i= mage:initial;background-position:initial;background-repeat:initial;line-hei= ght:1.42857;color:rgba(0,0,0,0.75);font-family:-apple-system,system-ui,Blin= kMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue","= ;Fira Sans",Ubuntu,Oxygen,"Oxygen Sans",Cantarell,"Droi= d Sans","Apple Color Emoji","Segoe UI Emoji","= ;Segoe UI Symbol","Lucida Grande",Helvetica,Arial,sans-serif= "><></p><p style=3D"margin:0px;padding:1px 8px 8px;border:0px;font-si= ze:1.4rem;vertical-align:baseline;background-image:initial;background-posit= ion:initial;background-repeat:initial;line-height:1.42857;color:rgba(0,0,0,= 0.75);font-family:-apple-system,system-ui,BlinkMacSystemFont,"Segoe UI= ",Roboto,"Helvetica Neue","Fira Sans",Ubuntu,Oxyge= n,"Oxygen Sans",Cantarell,"Droid Sans","Apple Colo= r Emoji","Segoe UI Emoji","Segoe UI Symbol","= Lucida Grande",Helvetica,Arial,sans-serif">~~~,</p><p style=3D"margin:= 0px;padding:1px 8px 8px;border:0px;font-size:1.4rem;vertical-align:baseline= ;background-image:initial;background-position:initial;background-repeat:ini= tial;line-height:1.42857;color:rgba(0,0,0,0.75);font-family:-apple-system,s= ystem-ui,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neu= e","Fira Sans",Ubuntu,Oxygen,"Oxygen Sans",Cantare= ll,"Droid Sans","Apple Color Emoji","Segoe UI Emoj= i","Segoe UI Symbol","Lucida Grande",Helvetica,Ari= al,sans-serif"><span style=3D"font-size:1.4rem">TonyT</span><br></p></div><= /div></div> --000000000000f4b221065246655c-- --===============7258654005488945858== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHNhYWctbGVhdmVAaWV0Zi5vcmcK --===============7258654005488945858==--