[dmsc] Re: [DMSC] Architecture document proposals - on the post-onboarding security plane
Guigui Wang <wangguigui@correctover.com> Thu, 03 September 2026 14:14 UTC
Return-Path: <wangguigui@correctover.com>
X-Original-To: dmsc@mail2.ietf.org
Delivered-To: dmsc@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C3806134CD5F9 for <dmsc@mail2.ietf.org>; Thu, 3 Sep 2026 07:14:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788444885; bh=YMWHqB4uJkaP6PJpZCe4JLx3QYl9i/xoUWnp6nt/WLg=; h=From:To:Subject:Date; b=pUvzRA3IxDxqGgWn97bHkeQ/tpqrWxxUcrggT1C3fwpgin1LmcXurh3d+4e2SLu2I kfp768CBtPLNzMit2xbX2CFLMXeF3GbdYv9My45msw0c3FFBk0hc4LxtVhIgPYLxWu VPppMiVZPmHwb+KdQPExS13Zom8ZI1MhOIrLNP7A=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: 1.237
X-Spam-Level: *
X-Spam-Status: No, score=1.237 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_SBL_CSS=3.335, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=correctover.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 850RHerwkyh7 for <dmsc@mail2.ietf.org>; Thu, 3 Sep 2026 07:14:44 -0700 (PDT)
Received: from mail-m15568.qiye.163.com (mail-m15568.qiye.163.com [101.71.155.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EC15C134CD5F6 for <dmsc@ietf.org>; Thu, 3 Sep 2026 07:14:43 -0700 (PDT)
Received: from [127.0.0.1] (unknown [115.190.137.13]) by smtp.qiye.163.com (Hmail) with ESMTP id 4c6dabd8f for <dmsc@ietf.org>; Thu, 3 Sep 2026 22:14:40 +0800 (GMT+08:00)
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
From: Guigui Wang <wangguigui@correctover.com>
To: dmsc@ietf.org
Date: Thu, 03 Sep 2026 22:14:40 +0800
Message-ID: <178844488000.4.18004983997219782681@correctover.com>
X-HM-Tid: 0aa0679f2db403cfkunmba58367938457
X-HM-MType: 4
X-HM-Spam-Status: e1kfGhgUHx5ZQUpXWQgPGg8OCBgUHx5ZQUlOS1dZFg8aDwILHllBWSg2Ly tZV1koWUFDSUNOSEhLS043V1kYFggdWUFKV1ktWUFJV1kPCRoVCBIfWUFZQh9JSFZCSxodH01NHU NMGh5WHQkeHlUCFhMWGhIXJBQOD1lXWRgSC1lBWUpKTlVKQktVSkhMVUpIWVdZFhoPEhUdFFlBWU 9LSFVKS0hKSE1KVUpLS1VKQktLWQY+
DKIM-Signature: a=rsa-sha256; b=PvW/ka68y5J83AYjZM4vDKJfR8ws6GBaSkLBEeZyrcdAcLMrgGd/vbBO2cKylqQgF34wQY8jg7wbDIckHJm9RFCD2JXB6YYGx4RCo+GIX97wrse7oJOKj02hY6Nf1VL37t/e5boNKEYlfmtUL18OAWD8h7pgTSmwaI7y2pOVYGSv+9E6+I7iSVxXW3PVbqwO65b7Ujl+QBeYU4iesnsP+VPImKQh36b9x+UUlSW4Fj7KisentIK5WdWioCCKN2tLxji0MpcCGct6LGh/wbjIthvXp+gsxeHXB/vM+8KN5U1/tmErKqV3sC+D2ujz16so5ambTsmYrfv/9PGj6bJ5Cg==; c=relaxed/relaxed; s=default; d=correctover.com; v=1; bh=YMWHqB4uJkaP6PJpZCe4JLx3QYl9i/xoUWnp6nt/WLg=; h=date:mime-version:subject:message-id:from;
Message-ID-Hash: REXHBST7DSJZRVSMD6I2O2UHOGD2LB4N
X-Message-ID-Hash: REXHBST7DSJZRVSMD6I2O2UHOGD2LB4N
X-MailFrom: wangguigui@correctover.com
X-Mailman-Rule-Hits: member-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [dmsc] Re: [DMSC] Architecture document proposals - on the post-onboarding security plane
List-Id: Dynamic Multi-agent Secured Collaboration <dmsc.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmsc/PLM_AtLVHppG1yHRlXTCodWkBjo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmsc>
List-Help: <mailto:dmsc-request@ietf.org?subject=help>
List-Owner: <mailto:dmsc-owner@ietf.org>
List-Post: <mailto:dmsc@ietf.org>
List-Subscribe: <mailto:dmsc-join@ietf.org>
List-Unsubscribe: <mailto:dmsc-leave@ietf.org>
Hi Aijun, and all, Thank you for collecting the architecture proposals. I have read all three from a security perspective and would like to offer one observation for the architecture discussion. All three proposals define strong mechanisms at the trust-establishment boundary: the MACP architecture centralizes agent identity and credential issuance in the AMC with the AAAP for authentication and authorization; ACPs covers trusted registration and authentication; and AIN treats intent-route integrity at the forwarding layer. What appears to be unaddressed across all three is the security plane after onboarding - verification of what an authenticated, authorized agent actually does once it is operating through the gateway: the tool calls and MCP invocations it makes, the data it exfiltrates, and whether its per-interaction behavior stays within the policy scope it was admitted with. Section 4.3 of draft-li-dmsc-macp explicitly lists agent internal verification capabilities and notes they are not standardized as architectural components, which I think is precisely the gap. Authentication establishes that an agent is legitimate; it does not constrain the actions a legitimate agent takes. Credentialed agents can still invoke injected tools, be steered into unintended tool calls through their tool surface, or trigger higher-cost actions than the interaction intended - and the gateway is the natural observation point because it already mediates every cross-domain interaction. A suggestion for the architecture document: consider distinguishing two security sub-layers at the AI Agent Gateway - (1) admission control (identity, credentials, capability authorization), which all three drafts cover; and (2) interaction verification at the mediation layer (tool/invocation conformance to declared capabilities and policy), which none currently cover. This would not require a new entity: it fits naturally into the gateway-side mediation functions of draft-li-dmsc-macp and into the operational-visibility deliverables in the charter, and it degrades gracefully where gateways do not implement it. I am happy to write this up as a short contribution describing the conformance checks such a mediation layer could perform, if the group considers the distinction useful. Best regards, Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Iman Schrock
- [dmsc] Re: [DMSC] Architecture document proposals… David R. Oran
- [dmsc] Re: Architecture document proposals - on t… Sumit Ahuja
- [dmsc] Re: [DMSC] Architecture document proposals… Iman Schrock
- [dmsc] Re: [DMSC] Architecture document proposals… Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Iman Schrock
- [dmsc] Re: [DMSC] Architecture document proposals… Xueting Li
- [dmsc] Re: [DMSC] Architecture document proposals… Sumit Ahuja
- [dmsc] Re: [DMSC] Architecture document proposals… Iman Schrock
- [dmsc] Re: [DMSC] Architecture document proposals… Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Iman Schrock
- [dmsc] Re: [DMSC] Architecture document proposals… Xueting Li
- [dmsc] Re: [DMSC] Architecture document proposals… Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Iman Schrock
- [dmsc] Re: [DMSC] Architecture document proposals… Guigui Wang
- [dmsc] Re: [DMSC] Architecture document proposals… Xueting Li