[126attendees] Re: [Din] Re: Invitation for Public Side Meeting on Agentic AI (16-16:45 Uhr [CEST] Tuesday at Park Suite 4 and online) and summary of today's Public Side Meeting

Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Tue, 21 July 2026 08:31 UTC

Return-Path: <muhammad_usama.sardar@tu-dresden.de>
X-Original-To: 126attendees@mail2.ietf.org
Delivered-To: 126attendees@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 91A7211B2543D; Tue, 21 Jul 2026 01:31:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784622677; bh=lOvvmm7qR9R7OL3GJAVlM4Yva97EIBU+y5HSoql9jsI=; h=Date:Subject:From:To:References:In-Reply-To; b=Sb3OayuXGRrNnpwb/9+FanYW87MH4n9twa36O4yPXWpGYT2mCerCc0IWZn3hYOMsM 2F26iDJ8kTsOfkfLlGqlX3ZBZg8IKUwHDtdJ7JnX3j/KaQpFnw68x4OW7/rI08ukDW PjNVSDZN+YK/9sbv/MJMF9SwZrnPdc8sqmY7ghl4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tu-dresden.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W_HGO0nLa6UZ; Tue, 21 Jul 2026 01:31:15 -0700 (PDT)
Received: from mailout3.zih.tu-dresden.de (mailout3.zih.tu-dresden.de [141.30.67.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7FE2011B25427; Tue, 21 Jul 2026 01:31:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:In-Reply-To:References:To:From: Subject:MIME-Version:Date:Message-ID:Sender:Reply-To:Cc: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=LWhA8pdul/uuFAV6WFCGvC4QW0PL883MgZF4ZKTetkk=; b=QRtT6a+EIJJW00aEx1DhMVwZ7J ou99G2XHnZkO9n8MmZMToVfNDJ9+0cpCSttvRvcfiz/pwzYhcqeNCKTnZqSrnihBYEx9YlanNPm1N PAjNqZVwSKp3njlrL2RmYqLeGvD3MlKZh+Muo5NCiKKQ0+BwtrqvqWUZC7lJHQfyR9Cv9thKpZQXI 6VnBHxWVX1tOtfqFN05xqvsCYljW13wC4603+5iVvYuYvMzcMeJiy7Mf2fgv1Wa/Q615rGBWvnZa7 psV4/svyXKTjaq9RvxEWFfqkh3WdlFAka4qVr3auBfEq4kaFp48SAysmpl9TCHGDEV7aQf7NHz4TL chtukghg==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout3.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1wm5sg-00498m-1J; Tue, 21 Jul 2026 10:31:14 +0200
Received: from [31.133.128.222] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Tue, 21 Jul 2026 10:31:11 +0200
Message-ID: <12ecdeff-415b-4b62-8563-2043f5ca2938@tu-dresden.de>
Date: Tue, 21 Jul 2026 10:31:10 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
To: din@irtf.org, 126attendees@ietf.org, "agent2agent@ietf.org" <agent2agent@ietf.org>
References: <ed7fc715-65b3-4df4-adff-5364e2064286@tu-dresden.de> <6b2b3cc0-9743-43dd-966d-14bb09ffe657@tu-dresden.de>
Content-Language: en-US
In-Reply-To: <6b2b3cc0-9743-43dd-966d-14bb09ffe657@tu-dresden.de>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms090305020306050400020909"
X-ClientProxiedBy: MSX-T416.msx.ad.zih.tu-dresden.de (172.26.35.136) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout3.zih.tu-dresden.de
Message-ID-Hash: 4PJ3ICPKTH2KTRKLDQ62QJQNXJC6ZQHX
X-Message-ID-Hash: 4PJ3ICPKTH2KTRKLDQ62QJQNXJC6ZQHX
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [126attendees] Re: [Din] Re: Invitation for Public Side Meeting on Agentic AI (16-16:45 Uhr [CEST] Tuesday at Park Suite 4 and online) and summary of today's Public Side Meeting
List-Id: Mailing list for IETF 126 attendees <126attendees.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/126attendees/hhve44XzibQloJorppdB0Pis1eE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/126attendees>
List-Help: <mailto:126attendees-request@ietf.org?subject=help>
List-Owner: <mailto:126attendees-owner@ietf.org>
List-Post: <mailto:126attendees@ietf.org>
List-Subscribe: <mailto:126attendees-join@ietf.org>
List-Unsubscribe: <mailto:126attendees-leave@ietf.org>

Hi again,

Some folks reached out with the unfortunate overlap with DAWN BoF. 
Please note the time update for public side meeting (we'll start just 
after the DAWN BoF):

     Date: 21st July (Tuesday) [today]

     Time: 16:00 - 16:45 Uhr (CEST)

     Room: Park Suite 4 [Capacity: 15] First-come first-serve; rest are 
welcome to join online: https://ietf.webex.com/meet/sidemeetings1

Best,

-Usama


On 20.07.26 23:14, Muhammad Usama Sardar wrote:
>
> Hi folks,
>
> *TL;DR*: First an invitation for a public side meeting on Agentic AI 
> Research Group and then a summary of action points from today's side 
> meeting. If you are interested, just show up (first-come, 
> first-serve). If you are not interested, please keep ignoring it until 
> some AI agent steals your bank balance. 😉
>
> *Info*:
>
>     Date: 21st July (Tuesday)
>
>     Time: 15:00 - 16:00 Uhr (CEST)
>
>     Room: Park Suite 4 [Capacity: 15] First-come first-serve; rest are 
> welcome to join online: https://ietf.webex.com/meet/sidemeetings1
>
> *Relevant for*: RATS, SEAT, WIMSE, DINRG, UFMRG, and agent2agent
>
> *# Description*
>
> Agentic AI is moving fast, but without thorough security 
> considerations. We would like to discuss different topics to scope the 
> proposal of a research group on agentic AI-related topics. 
> Participants are encouraged to share their thoughts as short 
> presentations.
>
> # *Tentative agenda*
>
> (35 min) Muhammad Usama Sardar, "Technical Background and Research 
> Gaps for Agentic AI Research Group" Please see [0-4].
>
> (5 min) Alexander Pelov, "Bounded vs. dynamic capabilities: a taxonomy 
> the security work will need." Please see 
> draft-pelov-bounded-agent-capabilities [5].
>
> To be confirmed (20 min) Arnaud Taddei, Related work/Update on ITU-T 
> SG17 work. Please see [6].
>
>
> ==========
>
> *# Summary of today's side meeting
> *
>
> Thanks to all attendees for sharing the insights. As always, I 
> collected great ideas from the discussions. Here is my summary of the 
> concrete action points to address the points raised by attendees in 
> meeting:
>
>  1. Explicitly mention collaboration with CCC and ITU-T in the charter
>  2. Research question: Confidential Computing may be used by the
>     adversary to secretly offer bad services. How can we prevent such
>     abuse cases?
>  3. Explicitly mention RISC-V CoVE
>  4. Use case analysis
>  5. Levels of security: Sec. 6.2 of [2] provides a good starting point
>     of 3 levels of security that can serve as a starting point.
>
> A question was asked where to focus this discussion. In the IRTFOpen 
> meeting, I will put up the request to the IRTF chair.
>
> Best regards,
>
> -Usama
>
>
>
> On 20.07.26 07:24, Muhammad Usama Sardar wrote:
>>
>> Hi all,
>>
>> *TL;DR*: There will be a public side meeting on Confidential 
>> Computing for Agentic AI. See my HotRFC slides [0] and 4-minutes 
>> pitch [1] and if you are interested, just show up (first-come, 
>> first-serve).
>>
>> *Info*:
>>
>>     Date: 20th July (Monday) [today]
>>
>>     Time: 11:00 - 12:00 Uhr (CEST)
>>
>>     Room: Park Suite 4 [Capacity: 15] First-come first-serve; rest 
>> are welcome to join online: https://ietf.webex.com/meet/sidemeetings1
>>
>> *Relevant for*: RATS, SEAT, WIMSE, DINRG, UFMRG, and agent2agent
>>
>> *# General Overview
>> *
>>
>> Thanks to all who contributed their insights in the last 4 years side 
>> meetings which resulted in the formation of the SEAT WG. This is 
>> another effort which builds on top of SEAT.
>>
>> We will explore whether this work can fit the scope of DINRG. If not 
>> (and if there is sufficient interest), we can aim to form a RG in 
>> IRTF on confidential computing.
>>
>> If you are interested in the topic but time does not work for you, 
>> please drop me an email with a couple of possible options for meeting 
>> times during the week convenient to you and I will be very happy to 
>> meet you.
>>
>> *# Description*
>>
>> Recent research on confidential computing has shown its core trust 
>> mechanism (namely attestation protocol) to be broken without the need 
>> of physical access to the desired server, leading to high-severity 
>> vulnerabilities like Intra-handshake.fail [2,3] (CVE-2026-33697 [4]) 
>> of CVSS 7.5, which indicates that further research is required on 
>> this topic before forming a WG dedicated to confidential computing. 
>> We will discuss potential topics of research and scope for the 
>> proposed RG. Based on discussions so far, folks have proposed 
>> focusing on agentic AI.
>>
>> Best regards,
>>
>> -Usama
>>
>> [0] 
>> https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00
>>
>> [1] https://youtu.be/FDHWRijxKso?t=3285
>>
>> [2] 
>> https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS
>>
>> [3] https://github.com/muhammad-usama-sardar/intra-handshake.fail
>>
>> [4] https://www.cve.org/CVERecord?id=CVE-2026-33697
>>
> [5] 
> https://datatracker.ietf.org/doc/draft-pelov-bounded-agent-capabilities/
>
> [6] 
> https://mailarchive.ietf.org/arch/msg/agent2agent/w4FCe0Yurm_VsdiGOLeo_3UDKPY/
>
>
> _______________________________________________
> Din mailing list --din@irtf.org
> To unsubscribe send an email todin-leave@irtf.org