[dmsc] Re: Comments on draft-dunbar-dmsc-gw-scenarios-gap-analysis-02: evidence for action-level authorization (5.4, 6.9, 7.7)
Iman Schrock <team@emiliaprotocol.ai> Wed, 22 July 2026 19:02 UTC
Return-Path: <team@emiliaprotocol.ai>
X-Original-To: dmsc@mail2.ietf.org
Delivered-To: dmsc@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 446C311CABCAD for <dmsc@mail2.ietf.org>; Wed, 22 Jul 2026 12:02:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784746952; bh=Pi/7flz7f7Q0j+gpn5q+YsRg7AvEldQzQ9Mr+RumN7M=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=tUzg4LKUoHx+Vh+y8gTj/NIGP3pDDbJZgc0H8R3pHEJwlkQKPr/CVNRGI1FEgwZBc REi1pYnqSmABu2HQ1Cj7eoTXzPbwFfHMtf2DodF+omsOjPJWMlLnNmvpqvoEwwA8xd qvFXivxPiqGYWk0dvRUQ/Qu2x0A1T06SnHTObMvc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=emiliaprotocol.ai
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DwqyhXWvz6Vj for <dmsc@mail2.ietf.org>; Wed, 22 Jul 2026 12:02:31 -0700 (PDT)
Received: from mail-oo1-xc2d.google.com (mail-oo1-xc2d.google.com [IPv6:2607:f8b0:4864:20::c2d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A7E1411CAB9A4 for <dmsc@ietf.org>; Wed, 22 Jul 2026 12:00:42 -0700 (PDT)
Received: by mail-oo1-xc2d.google.com with SMTP id 006d021491bc7-6a384e29a20so1368324eaf.1 for <dmsc@ietf.org>; Wed, 22 Jul 2026 12:00:42 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784746835; cv=none; d=google.com; s=arc-20260327; b=jS3gBGSLcR/gqAAgdYY5ryk3dtNSGeBiY4XTVNCI2WFx+qkj9dlVjS4bWj37qsEytv 3NXdb4sJgET7+eRMRFhFTq1HcW/+urAJaoV6bDNGglOjMYFii6xNPSbcH2GSrIN4pTYx eDksOQ3xrYFpCaJzLWQIi5UCizHKofEmECkWPfBkT7/pypxEe4/qZyRifYSnUi+sZRbv aQ1xpQ52SejMhzttLBvfpb2p1SsI3AXMIPoTt1UCNpUzSB/1MEzNur22Q9o+aOt6zeoQ QICE6N94LguEUCbFhJp0hACz9+YeHDgC4yJxADqupbHSavRF5NrRFbQup4HC8sq7aPTf ulow==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=Pi/7flz7f7Q0j+gpn5q+YsRg7AvEldQzQ9Mr+RumN7M=; fh=01P/0g28Iaw+zsfnapvs/yA3BT69o9QkgHq43HZouHc=; b=nZsOr+MMVvMtDn2K5RuhMaY4glnajh2y/x37YdSH/bLwcHSJ73LAPl9HojOon2q4dN A6u+H2OzY2BmHBmkFrRQekVw3a6UAzH5F+7h2LZyD+gTpLOchDkITK890LVHKbUXonEb zA5e7ksHBG+4kXUM767xyxSRaXHx6WM4E9T7OJa1See4VxA4MBe+IPlgKlfhIFlbG+Gk nOlx7e1898CNLvJ/lLXWiYhyO2jCkT2mRQd/dcBVL+jTJ0mPbKX0Bs3pDRk36tZtOqgk ye9ba0eSubqpLz7kxctJUZrj4kMlabvFpPtXd7vvdCTn+qSrRbilSKtHpK0ePJWBu6cg Nipg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=emiliaprotocol.ai; s=google; t=1784746835; x=1785351635; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Pi/7flz7f7Q0j+gpn5q+YsRg7AvEldQzQ9Mr+RumN7M=; b=ZdQoK7FeNws51AwwmuG4jdWMFglydWTyUbZF7u1VTwIdL89ohkRUZRvCUTfpun8+Xj DxUEKwk4P9zsO6fyPpzC2C6f02kHwX4oYcg9PpVyTUzU2bN8wRabszxM2FcK/KeA/BZd lI4oEtDm3QkcLwvTNtbb/7ICoW628auVHbDYQUu8NNCeu7q19yKpMIFr04kplotG7M1E vCGEMfI/An18TICvBM+jdBuHyWlq3pHKH3sJHoYVJUmQ8GanjyqTl57hs62VXGZDt+JV F8OlcLwIC9ZYpQhYdG48xMMBGI4mRs2z/hizHKzhlvqsnURlx3tyaQMJieXoDwtww9ne pnKQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784746835; x=1785351635; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Pi/7flz7f7Q0j+gpn5q+YsRg7AvEldQzQ9Mr+RumN7M=; b=Us3sAxLDP/y5q1qkcBInqpSUQWw4vGicY/2zbL5A8dkQWema/JdDHh1z4c1xklSIun YKeiErwhseGwGVWeHjgWEIOZdce5TsZwj8ABOO7VRqEGb2JqOZvMfyzJAj0DRpl9dPDX XnmBJfHxwZ3tScXXJogoxTQb2yJH9mJ8iTosNdN1IJEvrq9PCo/IBohbjPKjj1uzyC4D dMBDX/U7UimYT+Y7rSh3dPySZKnN4/wdpcPX1XfEJlj07e1aqFFlBirI5x+h/3Wze9on m6p6/QoyS9i1HWPRgUGiRW3Z4L+mkifKVASOfI3R/AXUIyUfXdG4XXj3CBbLMZgTB2TH wJ6A==
X-Gm-Message-State: AOJu0Ywg8hGJF/bBEIs1Vj5yCMaIoQ4G2aqMJeu7/BwNiembgX3WPysv 8OLgugTw1Ku58KO6x45yPC2whNQTCY38w12GETouGud827FxSvcSE9JJECigedkbVOXD9GnA1WN LpW2ldzv+VEiMNuDXT2+CkLHyh4NFfd7QDQg4XJSW+X2dAHfx2UdMM3HJ
X-Gm-Gg: AR+sD117rW2k58uw9/bwzWJdqyfCI4evYARN9PyXLRV0F7tRfsKf75TC967t//xm+w8 kiYZS+pngdUIFZ8QVwFFzLXzU+2tAvXPyM1oN+puK/vTtg0J6o3gXaPfJYBhjwCCzSjSUD2mVmf hsgf1QJRSVL+Osod+xgM1rGd9Fa9FVW9fJGT1Alag2Ru8Y6lCywTvUYBESBv1I16WkfNdT/ei2r glcOY6BTY1SKhQPEeXDMaWNGV9Ghi4mFtljCE5RVNMAn9dHvb3grfmAOGT46O2py/999JUWMhZw zV+AsGl1YEBxapoTN5w4ZKEVDAxVaLm6NfsVLUoHveXXWF4cmAlKZSK7ha054h0r6b1+Dtnl3mH Aget5e4LfFA==
X-Received: by 2002:a05:6820:f07:b0:6a3:7701:660c with SMTP id 006d021491bc7-6a5367fb608mr11931102eaf.20.1784746834866; Wed, 22 Jul 2026 12:00:34 -0700 (PDT)
MIME-Version: 1.0
References: <CAOfgHgp_0yK632F9Qgm9eqwz4HQvy3MND-4Vrp_Xyd1N7jQKzw@mail.gmail.com> <CO6PR13MB53558919A94FF5E02B56E18C85C72@CO6PR13MB5355.namprd13.prod.outlook.com>
In-Reply-To: <CO6PR13MB53558919A94FF5E02B56E18C85C72@CO6PR13MB5355.namprd13.prod.outlook.com>
From: Iman Schrock <team@emiliaprotocol.ai>
Date: Wed, 22 Jul 2026 12:00:24 -0700
X-Gm-Features: AUfX_mzfV187kaemYpP_3_Q_XBZmLKVUd_CMOVnk68pQ9E0hCxPeFusT3pU9s2I
Message-ID: <CAOfgHgo=uEYttR6uZscH+uxSm9GOav7AKGAcn_93fCP38Zu12g@mail.gmail.com>
To: linda.dunbar@futurewei.com
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: HBMUZEXBYYDTORUWKOFXFEDCQX36OT6V
X-Message-ID-Hash: HBMUZEXBYYDTORUWKOFXFEDCQX36OT6V
X-MailFrom: team@emiliaprotocol.ai
X-Mailman-Rule-Hits: member-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address
CC: dmsc@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [dmsc] Re: Comments on draft-dunbar-dmsc-gw-scenarios-gap-analysis-02: evidence for action-level authorization (5.4, 6.9, 7.7)
List-Id: Dynamic Multi-agent Secured Collaboration <dmsc.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmsc/7ZMlrXEIgrDndJXDprm9wtEv7Uw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmsc>
List-Help: <mailto:dmsc-request@ietf.org?subject=help>
List-Owner: <mailto:dmsc-owner@ietf.org>
List-Post: <mailto:dmsc@ietf.org>
List-Subscribe: <mailto:dmsc-join@ietf.org>
List-Unsubscribe: <mailto:dmsc-leave@ietf.org>
Dear Linda, A quick update, and thank you again for the way you handled the DMSC comments. The boundary you described in your proposed text for Sections 6.9 and 6.7 is now reflected in a public EMILIA artifact, the Action Evidence Boundary (AEB): https://datatracker.ietf.org/doc/draft-schrock-action-evidence-boundary/ Your text identifies the requirement: a receiving gateway may need independently verifiable approval evidence bound to the specific action, evaluated under the receiving gateway's own trust anchors, and recorded separately from its local allow-or-deny decision. AEB provides a concrete profile and implementation of that boundary. It separates deriving and matching the exact material action with CAID, verifying the supplied evidence, determining whether it satisfies the relying party's requirement, making the gateway's local decision, consuming the authorization, and recording the eventual outcome. That separation is useful whether DMSC keeps the requirement mechanism-neutral or decides that a concrete reference, worked example, or interoperability profile would help. EMILIA is available for any of those roles. The artifact can travel between gateways while each gateway retains its own trust configuration and enforcement decision. If useful, I can contribute whichever form best fits the authors' direction: 1. concise text or an informative reference for Sections 6.7 and 6.9; 2. a runnable two-gateway example in which both gateways verify the same action-bound evidence independently; or 3. a short mapping showing how CAID and AEB satisfy the requirements without changing DMSC's gateway transport model. I would value your view on which of those would be most useful. If you think the work merits a stronger role in DMSC's next steps, I would also be glad to work with you and the other authors on the appropriate path. Thank you again for the detailed response and for incorporating the earlier suggestions. Best, Iman
- [dmsc] Comments on draft-dunbar-dmsc-gw-scenarios… Iman Schrock
- [dmsc] Re: Comments on draft-dunbar-dmsc-gw-scena… Linda Dunbar
- [dmsc] Re: Comments on draft-dunbar-dmsc-gw-scena… Iman Schrock
- [dmsc] Re: Comments on draft-dunbar-dmsc-gw-scena… Iman Schrock