[Din] Public Side Meeting on Confidential Computing for Agentic AI (11-12 Uhr [CEST] Monday at Park Suite 4 and online)

Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Mon, 20 July 2026 05:25 UTC

Return-Path: <muhammad_usama.sardar@tu-dresden.de>
X-Original-To: din@mail2.ietf.org
Delivered-To: din@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1FEEC119FC3C5 for <din@mail2.ietf.org>; Sun, 19 Jul 2026 22:25:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784525116; bh=4W2L40gNNJy/cOwf3jkncuMZ0FXDk3/Uy6czoilvsr4=; h=Date:From:Subject:To; b=Fair1WnN5nGqckDHoSB50zuYMWn5vKF/H+AFCLCyqaPTEC/3GTxPHOVyLBnB5aWDP YW8P8dil8b+cATG7Bcil0jifpUTSD2PaQEDcfmroN0SgSUGm5y8dyM06WZhbipsEeL KCC0YTuoKG7IohejguFIknLsL3hGDuZiyYfHCKnQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tu-dresden.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yt4CI7TQ4XGX for <din@mail2.ietf.org>; Sun, 19 Jul 2026 22:25:15 -0700 (PDT)
Received: from mailout4.zih.tu-dresden.de (mailout4.zih.tu-dresden.de [141.30.67.75]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 154C1119FC3AF for <din@irtf.org>; Sun, 19 Jul 2026 22:25:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:To:Subject:From:MIME-Version:Date :Message-ID:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=BnRSYdQ+3fwqdYWFNx0be50PtN09UEQjWw8udc6JdfE=; b=CjdMeEcpG5qSokhMq3Jx4BoIVj 1K7rzgbDHPgkUaICofl8FQs1Ys1NYtGjYkNGtMvnPm6XT38rvQOeS8Do6DX0eZR8n5wOyUh+9JOHu DXr4dxk3xv1o7s0hpNXF/qEoJ+O2wqT4gqxcd02JYzxiFYYSb2y63ugCUo27g/SSzMrMDbtNs2vr5 +P+m3sZZduPqDhjxLeLp+SAoe3DqSKixy6XpjBzmwa1iWCIr1293RftvE1mfchYr+KjL8QOwao5Rv kR9yMsOYoeJ1eac4MQqXErCxPg2wUVYVYmwDyA6eIP6zErXX13YUwURSKBdFmQK8exfXLp9ctffE+ Nj0K+WGg==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout4.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1wlgV7-001kYw-2h; Mon, 20 Jul 2026 07:25:14 +0200
Received: from [192.168.0.75] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Mon, 20 Jul 2026 07:25:03 +0200
Message-ID: <ed7fc715-65b3-4df4-adff-5364e2064286@tu-dresden.de>
Date: Mon, 20 Jul 2026 07:24:57 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
To: din@irtf.org, 126attendees@ietf.org, "agent2agent@ietf.org" <agent2agent@ietf.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms040706030507090609020009"
X-ClientProxiedBy: MSX-L415.msx.ad.zih.tu-dresden.de (172.26.34.135) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout4.zih.tu-dresden.de
Message-ID-Hash: GPQTF2GJSDBEUO2B2TKWYUIUCWRLID6O
X-Message-ID-Hash: GPQTF2GJSDBEUO2B2TKWYUIUCWRLID6O
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-din.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Din] Public Side Meeting on Confidential Computing for Agentic AI (11-12 Uhr [CEST] Monday at Park Suite 4 and online)
List-Id: "Discussion of distributed Internet Infrastructure approaches, aspects such as Service Federation, and underlying technologies" <din.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/din>
List-Help: <mailto:din-request@irtf.org?subject=help>
List-Owner: <mailto:din-owner@irtf.org>
List-Post: <mailto:din@irtf.org>
List-Subscribe: <mailto:din-join@irtf.org>
List-Unsubscribe: <mailto:din-leave@irtf.org>

Hi all,

*TL;DR*: There will be a public side meeting on Confidential Computing 
for Agentic AI. See my HotRFC slides [0] and 4-minutes pitch [1] and if 
you are interested, just show up (first-come, first-serve).

*Info*:

     Date: 20th July (Monday) [today]

     Time: 11:00 - 12:00 Uhr (CEST)

     Room: Park Suite 4 [Capacity: 15] First-come first-serve; rest are 
welcome to join online: https://ietf.webex.com/meet/sidemeetings1

*Relevant for*: RATS, SEAT, WIMSE, DINRG, UFMRG, and agent2agent

*# General Overview
*

Thanks to all who contributed their insights in the last 4 years side 
meetings which resulted in the formation of the SEAT WG. This is another 
effort which builds on top of SEAT.

We will explore whether this work can fit the scope of DINRG. If not 
(and if there is sufficient interest), we can aim to form a RG in IRTF 
on confidential computing.

If you are interested in the topic but time does not work for you, 
please drop me an email with a couple of possible options for meeting 
times during the week convenient to you and I will be very happy to meet 
you.

*# Description*

Recent research on confidential computing has shown its core trust 
mechanism (namely attestation protocol) to be broken without the need of 
physical access to the desired server, leading to high-severity 
vulnerabilities like Intra-handshake.fail [2,3] (CVE-2026-33697 [4]) of 
CVSS 7.5, which indicates that further research is required on this 
topic before forming a WG dedicated to confidential computing. We will 
discuss potential topics of research and scope for the proposed RG. 
Based on discussions so far, folks have proposed focusing on agentic AI.

Best regards,

-Usama

[0] 
https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00

[1] https://youtu.be/FDHWRijxKso?t=3285

[2] 
https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS

[3] https://github.com/muhammad-usama-sardar/intra-handshake.fail

[4] https://www.cve.org/CVERecord?id=CVE-2026-33697