The Internet Engineering Task Force (IETF) is holding a hackathon to encourage developers and subject matter experts to discuss, collaborate, and develop utilities, ideas, sample code, and solutions that show practical implementations of IETF standards.
Sign up for the Hackathon
View the list of registered:
Keep up to date by subscribing to the IETF Hackathon email list.
The IETF Hackathon is free to attend and is open to everyone. It is a collaborative event, not a competition. Any competition is friendly and in the spirit of advancing the pace and relevance of new and evolving internet standards.
Subject to Change
Hackathon (all times are GMT+2)
Related activities before and after the Hackathon weekend
NOTE: You will need an IETF Datatracker account to login to the Hackathon Meetecho sessions.
When you register for the IETF Hackathon, you are sent a separate email to create an IETF Datatracker account if you don't already have one.
If you already have an IETF Datatracker account, please ensure that the email address with which you registered is associated with your Datatracker account.
If you received the email but the link to create an account has expired, please see the instructions below:
Access to the IETF network
Requests for networking capabilities beyond wireless access to the IETF network (e.g., wired ports, L2 access, prefix delegation) can be sent to support@ietf.org.
All requests are addressed on a best effort basis. Advance notice is appreciated and improves the odds of your request being fulfilled.
Champions can request a Webex account they can use to schedule meetings for their team. These are similar to the Webex accounts allocated to working group chairs to be used for virtual interim meetings. An account can be requested by a team champion at any time. Accounts will remain active and available for the duration of the IETF meeting. Request your account HERE. In the request form, you can use your project name where it asks for "Working Group Name" ("Hackathon Project Name").
In addition to registering for the Hackathon and subscribing to the Hackathon list. It is recommended to monitor both the Hackathon wiki and the list as the Hackathon approaches, determine which project(s) are of interest to you, and reach out to the champions of those projects to determine how best to be involved and coordinate with the rest of the team working on each project.
Champions are welcome and encouraged to list times and mechanisms for collaborating with their team in the Team Schedule. Participants can use this page to determine how and when to reach other team members.
The Hackathon kickoff and the project results presentations can be joined via Meetecho. The Hackathon Zulip stream may be used for general and project specific communication.
All Hackathon participants are free to work on any code. The rules regarding that code are what each open source project and each participant's organization says they are. The code itself is not an IETF Contribution. However, discussions, presentations, demos, etc., during the Hackathon are IETF Contributions (similar to Contributions made in working group meetings). Thus, the usual IETF policies apply to these Contributions, including copyright, license, and IPR disclosure rules.
Note, all projects are open to everyone. However, some champions have identified their projects as being particularly good for those who are new to the IETF or new to the Hackathon. These projects are marked with a star, i.e. *. If you are championing a project that is great for newcomers, please add a * at the end of your project name.
For inspiration and examples of previous Hackathon projects see the previous Hackathon page.
Champions
Maarten Wullink maarten.wullink@sidn.nl
Pawel Kowalik pawel.kowalik@denic.de
Project Info
The RPP working group is focused on designing a new protocol for registering objects in a shared registry, as a possible alternative for EPP. This will result in a series of specifications known collectively as the RESTful Provisioning Protocol (RPP).
Hackathon Plan
Related documents
Champions
Project Info
Champion
Stuart Cheshire <cheshire@apple.com>
Thread Overview
Thread is a specification for how to carry IPv6 datagrams over a self-configuring mesh of low-power IEEE 802.15.4 wireless links. Stuart Cheshire gave a brief presentation about Thread at the IETF 119 IAB Open meeting in Brisbane. The Thread specification is developed and published by the Thread Group. There are several independent implementations of Thread, the main one being the OpenThread open source project. This Hackathon event is open to all — Thread Group membership is not required, though of course Thread Group members are also welcome to participate.
Participants and Project Info
Champion(s)
John Gray (john.gray@entrust.com)
Daniel Van Geest (Daniel.vangeest@cryptonext-security.com)
Mike Ounsworth (mike.ounsworth@crypticforest.ca)
Jean-Pierre Fiset (jp@crypto4a.com)
Massimiliano Pala (massimiliano.pala@wellsfargo.com)
Draft Specifications
https://datatracker.ietf.org/doc/html/rfc9881
https://datatracker.ietf.org/doc/rfc9935/
https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-sigs/
https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/
https://datatracker.ietf.org/doc/rfc9629/
https://datatracker.ietf.org/doc/rfc9810/
https://www.ietf.org/id/draft-ietf-lamps-certdiscovery/
https://datatracker.ietf.org/doc/rfc9909/
https://datatracker.ietf.org/doc/draft-ietf-lamps-cms-composite-sigs/
Project Info
Test interoperability of Post Quantum algorithms in x.509 structures (Certificates, keys, CMS and other drafts). This project started in November 2022 and continues to evolve. We currently have github automated tooling that automatically tests submitted artifacts allowing implementations to get immediate feedback on their compatibility. This allows us to test interoperability between different algorithm implementations, gain experience using these new algorithms, and provide feedback to the standards groups about practical usage.
A good starting place is our Github repository: https://github.com/IETF-Hackathon/pqc-certificates
For information on OIDs used to create interoperable structures, consult: https://github.com/IETF-Hackathon/pqc-certificates/blob/master/docs/oid_mapping.md
At IETF 126, we plan to add more automation and others are invited to test interoperability. FrodoKEM and Classic McEliece have been standardized at ISO, so participants are welcome to test those algorithms. Some experimentation with Merkle Tree Certificates is also being tested.
Champions
Nigel Davis <ndavis@ciena.com>
Project Info
The IETF IVY WG has been developing models for network inventory. Following on from the successful IVY activity at the IETF 125 hackathon, this hackathon activity will again focus on the modelling of physical inventory. The intention is to have multiple players in both inventory system role and controller role where the inventory system player displays physical inventory detail provided via an IVY conformant interface from various controllers.
Hackathon Objectives and Plan
The aim is to extend the participation, exercise more of the model and, especially, to:
-- Work with the latest ivy YANG and potentially previous versions
-- Demonstrate systems from various vendors can interoperate and convey inventory detail
-- Explore for missing detail and demonstrate interop with additional new properties
-- Compare with other inventory models (especially [TAPI (Linux Foundation)] (https://github.com/Open-Network-Models-and-Interfaces-ONMI/TAPI)) and add further properties as appropriate again demonstrate interop
-- Prepare proposals for updates to IVY model
Hackathon project slides
The slide pack IvyHackathon.pptx, shared with the TAPI team, provides further details.
TIP MANTRA interest in IETF IVY Hackathon
Please see operator support for this Hackathon at TIP MANTRA interest in IETF IVY Hackathon
Participants
Currently both Ciena and Cisco have committed to engage in the Hackathon activity on site. Other vendors are exploring possible engagement.
Related documents etc.
Network Inventory YANG (Ivy)
A Base YANG Data Model for Network Inventory
network-inventory-yang
TAPI
TLS revocation has never worked reliably at internet scale. OCSP soft-fails, CRLs go unchecked, and the industry's answer has been to shrink certificate lifetimes so a bad certificate expires before it matters. BRAID (draft-davey-tls-braid-00) takes the opposite approach: make freshness owner-controlled and structural, so a certificate stops validating the moment its owner stops authorizing it — no status responder, no revocation list, no 47-day treadmill.
This hackathon project builds the one piece that needs nothing new to run — Phase 0: a monitor that checks the Delegated Credential a TLS endpoint is using against a DNSSEC-signed, owner-published _braid Anchor. No TLS protocol changes, no browser changes, no public-CA or root-program changes. It runs today.
We'll be dogfooding on real infrastructure — live domains, a private CA, and origin-AS space we operate — rather than toy fixtures, so the results reflect what an actual operator would see.
Draft: draft-davey-tls-braid
Code: github.com/braid2026/braid (repo published before the event)
Hackathon goals
_braid TXT-form Anchor listing hashes of the Delegated Credential public keys an owner authorizes.authorized, mismatch, stale, unknown, dnssec-failed.authorized to mismatch within the record's TTL — no OCSP, no CRL, no CA involvement.Optional stretch goal
Expected outputs
_braid TXT Anchor format others can test against.Champions
Aijun Wang (wangaj3@chinatelecom.cn)
Project Info
This project aims to present a demo of the TLS-based service affinity solution. This proposal is designed for environments where operational simplicity and migration speed are paramount. It intentionally omits the path validation steps to minimize the latency of the migration process. Furthermore, it simplifies the trigger mechanism by using a new TLS alert, which is a direct and unambiguous signal.
Related works
Service Affinity Solution based on Transport Layer Security (TLS): https://datatracker.ietf.org/doc/draft-wang-tls-service-affinity/
Champion(s)
Thomas Graf (thomas.graf @ swisscom.com)
Leonardo Rodoni (leonardo.rodoni @ swisscom.com)
Ahmed Elhassany (ahmed.elhassany @ swisscom.com)
Benoit Claise (benoit @ everything-ops.net)
Paolo Lucente (paolo @ pmacct.net)
Vivekananda Boudia (vivekananda.boudia @ insa-lyon.fr)
Maxence Younsi (maxence.younsi @ insa-lyon.fr)
Pierre Francois (pierre.francois @ insa-lyon.fr)
Rob Wilton (rwilton @ cisco.com)
Daniel Voyer (davoyer @ cisco.com)
Deepya Mandadi (dmandadi @ blueplanet.com)
Sivakumar Sundaravadivel (sivakuma @ blueplanet.com)
Jérémie Leska (jeremie.leska @ 6wind.com)
Samuel Gauthier (samuel.gauthier @ 6wind.com)
Irfan Mohammad (irfan @ arrcus.com)
Draft Specifications Message Broker
https://datatracker.ietf.org/doc/html/draft-ietf-nmop-yang-message-broker-integration
https://datatracker.ietf.org/doc/html/draft-ietf-nmop-message-broker-telemetry-message
https://datatracker.ietf.org/doc/html/draft-ietf-netmod-yang-anydata-validation
Draft Specifications YANG-Push
https://datatracker.ietf.org/doc/html/rfc8639
https://datatracker.ietf.org/doc/html/rfc8641
https://datatracker.ietf.org/doc/html/rfc9196
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-notif-envelope
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-yang-notifications-versioning
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-udp-notif
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-distributed-notif
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-yp-transport-capabilities
https://datatracker.ietf.org/doc/html/draft-ietf-netconf-yang-library-augmentedby
Project Info
https://www.network-analytics.org/yp/, validate and verify
5 YANG-Push Publishers
2 YANG-Push Receivers
2 YANG-Push Network Telemetry Message
1 YANG Message Broker Producer and Schema Registry
3 YANG Message Broker Consumers
implementation in the area of YANG data schema validation and obtaining latest YANG-Push subscription state. Subscribe to YANG data on YANG-Publisher, obtain and register all YANG modules necessary to build YANG schema tree, register YANG schemas to Schema Registry and verify YANG notifications against scheme trees and produce and consume from Message Broker.
Champions
Xiang Li (lixiang@nankai.edu.cn)
Lu Sun (sunlu25@mail.nankai.edu.cn)
Yuqi Qiu (qiuyuqi@mail.nankai.edu.cn)
Zuyao Xu (xuzuyao@mail.nankai.edu.cn)
Project Info
The draft <ATP: Agent Transfer Protocol> (https://datatracker.ietf.org/doc/draft-li-atp/) defines the Agent Transfer Protocol (ATP), a server-mediated communication protocol for messaging between autonomous agents across administrative domains. Following the federated, server-mediated model used by SMTP for electronic mail, ATP specifies agent identifier resolution and public-key discovery, a sender authentication mechanism (Agent Transfer Signatures, ATS), recipient-side keying with payload-covering signatures (Agent Transfer Keys, ATK), and a DMARC-style alignment check between ATS and ATK. The error model defines outcomes for cross-domain delivery failures.
This project will produce an interoperability demonstration of ATP, so as to validate the practicality of the protocol architecture and identify potential areas for further standardization.
Related documents
https://datatracker.ietf.org/doc/draft-li-atp/
Champions
Alicja Kario (hkario@redhat.com)
Dmitry Belyavskiy (dbelyavs@redhat.com)
Project Info
We are interested in providing PQ capabilities to the SSH protocol.
We are implementing the draft GSS-API Key Exchange with hybrid ML-KEM (https://datatracker.ietf.org/doc/draft-kario-gss-keyex-pqc/) for OpenSSH (https://github.com/beldmit/openssh-portable/tree/beldmit-f45-103p1-gsshybrids, based on existing patches implementing GSS-API Key Exchange in OpenSSH) and libssh (https://gitlab.com/pzacik/libssh-mirror/-/tree/gssapi-kex-pqc)
We are implementing pure ML-DSA signatures (https://datatracker.ietf.org/doc/draft-sfluhrer-ssh-mldsa/) for OpenSSH and libssh.
Docker image with a build: https://github.com/beldmit/openssh-ietf126-hackathon
Also Fedora/Red Hat builds of OpenSSH and libssh upstream supports hybrid ML-KEM/NIST variants using OpenSSL as backend, interoperability with Putty is tested and reached.
Champions
Alexander Bokovoy (abokovoy@redhat.com)
Project Info
We are interested in testing new ACME server and client, Akamu, which both support PQ capabilities and Merkle Tree Certificates.
We are implementing new ACME infrastructure for FreeIPA and Dogtag PKI projects, https://codeberg.org/freeipa/akamu. It allows to issue certificates in x.509 and Merkle Tree Certificate formats for both classic and PQ cryptography. Akamu also provides MTC cosigner support.
Champions
Julien Rische (jrische@redhat.com)
Alexander Bokovoy (abokovoy@redhat.com)
Project Info
We are interested in testing implementation interoperability for post-quantum PKINIT support.
We are working on adding PQC PKINIT support to MIT Kerberos, based on https://datatracker.ietf.org/doc/draft-bokovoy-kitten-pkinit-pqc/
Champions
Yong Bok Lee, Meridian Verity Group, [scott@meridianverity.com]
Project Info
This project provides a runnable synthetic reference evaluation for PermitReceipt-based permit-before-commit authorization of AI-agent and workload external effects.
Related Internet-Draft:
https://datatracker.ietf.org/doc/draft-lee-orprg-permit-receipts/
Repository:
https://github.com/meridianverity/permit-receipt
Public evaluation release:
https://github.com/meridianverity/permit-receipt/releases/tag/v2.2.1-public-eval
The evaluation exercises deterministic canonicalization, action-digest binding, policy-epoch checks, scope checks, status and freshness checks, anti-replay handling, and fail-closed denial before a protected external effect is committed.
The project includes a provider-neutral synthetic agentic-commerce profile as one example effect family. It does not process live payments, store payment credentials, call live processors, or provide production payment processing, wallet, issuer, PSP, network-token, or settlement-rail functionality.
Hackathon goals:
Expected outputs:
Coordination:
Champions
Ramon Bister (ramon.bister@ost.ch)
Alexander Clemm (ludwig@clemm.org)
Andrea Mayer (andrea.mayer@uniroma2.it)
Stefano Salsano (stefano.salsano@uniroma2.it)
Project Info
iOAM (in-situ Operations, Administration, Maintenance) has gained popularity as a mechanism to collect telemetry data from a network. However, what is of interest for many use cases is not so much raw telemetry data records from nodes themselves, but aggregates of telemetry data across the nodes of the path traversed by a packet. For example, aggregating packet dwell times can be indicative of end-to-end latency, identifying the interface with the deepest (maximum) queue depth along a path can expose bottlenecks, aggregating environmental indicators can help assess CO2-intensity of paths to optimize pollution-aware routing.
This hackathon project aims to demonstrate and extend a solution that allows to aggregate inband network telemetry data using new proposed extensions to iOAM for some of the mentioned use cases. The starting point is a PoC that implements the IOAM Aggregation Trace Option as well as the IOAM Template Option with an accompanying template used for telemetry aggregation. The PoC is realized using P4 on BMv2 switches on Ubuntu. In addition, the hackathon project also pursues another option to carry aggregation traces using the concept of a Global Opaque Block (GOB) as an extension to the IOAM Pre-allocated Trace Option. This part of the project will leverage a Linux/eBPF-based PoC implementation. GOB and Template will both share the same common structure/identifier space so that the resulting aggregation trace records (e.g. accumulated dwell time / end-to-end latency) are interchangeable regardless of the option with which they were obtained, as we aim to demonstrate using a single Wireshark dissector.
In summary, our goal is to
Depending on interest, there are other possibilities that could also be pursued, such as implementing a companion app to actively probe aggregate telemetry and/or to support an intent assurance use case for intent-based networking.
The following are the primary links related to this Hackathon Project:
Champions
Ian Farrer ian.farrer@telekom.de
Kris Lambrechts kris@intwine.net
Kristian Larsson k@centor.se
Project Info
The newly formed ONSEN WG is chartered with the creation, extension and maintenance of abstracted service and network YANG modules, such as the L3VPN service model. Currently, this model only includes nodes for configuration of service functionality ('config-true'). The ONSEN WG is chartered to extend the abstracted models to include state data to provide real-time visibility of how a provisioned customer service is currently performing based on collected telemetry, or operational state polling.
The goal of the Hackathon is to extend the existing service configuration functionality of the StratoWeave open-source network orchestration platform to:
https://datatracker.ietf.org/doc/draft-wilton-netconf-yang-push-2/
https://datatracker.ietf.org/doc/html/rfc8299
https://github.com/stratoweave
Champions
Karen O'Donoghue (kodonog@pobox.com)
Dieter Sibold (dsibold.ietf@posteo.com)
Project Info
Interoperability testing between different NTPv5 implementations.
Draft Specifications
https://datatracker.ietf.org/doc/draft-ietf-ntp-ntpv5/
Repositories
DNT is a feature-packed, generic software, while XDPPREF focuses on the PREF (and FRER) functionalities only. DNT support wide variety of network headers both for encapsulation and stream identification. XDPPREF only support IPv6 flow-label based stream identification on the edge.
The subject of this project is implementing extended stream identification support for XDPPREF.
In addition to IPv6 flow-label, streams could be identified with other fields of IPv6, or even other network or transport headers.
YANG <--> SID Extension <--> Registry <--> Discovery <--> CORECONFChampions
Tony John (tony.john@ovgu.de)
Adrian Perrig (adrian.perrig@inf.ethz.ch)
Lars-Christian Schulz (lars-christian.schulz@ovgu.de)
Tilmann Zäschke (tilmann.zaeschke@inf.ethz.ch)
Project Info
This project aims to demonstrate interoperability of SCION path-aware routing with all things internet. There are several open-source SCION libraries that facilitate SCION adaptation across various programming languages (Go, Java, C, C++, Rust, Python) and applications. SCION can also interoperate with IPv6 networks via address translation in SCION-IP Translators. All SCION interoperability approaches share a need for robust path selection and packet scheduling as SCION leaves the final routing decision to end host.
We are looking for novel project ideas as well as adaptation of existing open-source project to SCION that tackle the challenges and opportunities of end-host-controlled routing, especially as they highlight SCIONs security features. A good starting point for taking advantage of path-aware routing is path metadata (link speed, latency, geographical location, etc.) provided by SCION's control plane and dataplane telemetry provided through In-band Network Telemetry (ID-INT).
Hackathon Goals
The aim is to demo and extend existing open-source SCION projects and to spark ideas for new use cases of SCION. We put special focus on how projects deal with the wealth of inter-domain paths that SCION exposes.
For example:
-- Demo path selection and in-band telemetry in SCION
-- Offer participants a chance to connect to SCION from their laptops
-- Improve path selection in existing libraries and applications
-- Create new SCION demo applications, e.g.,
-- Create a SCION enabled : curl" CLI tool by adapting Java CURL (https://github.com/rockswang/java-curl) to work with the SCION JPAN library (https://github.com/scionproto-contrib/jpan)
-- Create a demo application that combines SCION with segment routing
Draft Specification SCION
https://datatracker.ietf.org/doc/draft-dekater-scion-controlplane/
https://datatracker.ietf.org/doc/draft-dekater-scion-dataplane/
https://datatracker.ietf.org/doc/draft-dekater-scion-pki/
Related documentaion etc.
-- List of various SCION libraries and projects: https://github.com/scionproto/awesome-scion
-- SCION documentation: https://docs.scion.org/en/latest/index.html
Champions
Roland Bless (roland.bless@kit.edu)
Julius Rüberg (julius.rueberg@student.kit.edu)
Project Info
KIRA is a scalable zero-touch routing architecture that provides IPv6 connectivity without any configuration for hundreds of thousands of nodes. It is ID-based and also works well in fixed networks, data center networks, mobile ad-hoc networks, and LEO satellite networks. The prototypical implementation is written in Rust.
More info at https://s.kit.edu/KIRA
Draft Specifications
Internet Draft: https://datatracker.ietf.org/doc/draft-bless-rtgwg-kira/
Side Meeting
Thursday, July 23, 2026, 19:00-20:00 ( Europe/Vienna ) · Park Suite 4
Hackathon Plan (Potential Working Items)
Technologies
Remote Participation
we will use Gather
Source Code Repository
Champions
Potential collaboration with project AEP × Veraison: Anton Sokolov
Drafts vulnerable to CVE-2026-33697
- Early attestation
- FACTS
- Attestation in (D)TLS
Project Motivation
- https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056
- https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw
- https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/
- https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols
- https://www.securitylab.ru/news/574545.php
- Russian https://www.securitylab.ru/news/574545.php
- German https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/
- https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/
- Chinese https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html
- https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing
- Japanese https://blackhatnews.tokyo/archives/119915
- https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi
- https://post.smzdm.com/p/a82ol990/
- Russian https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls
- Chinese https://blog.csdn.net/weixin_42376192/category_13096766.html
- https://daily.dev/posts/bad-epoll-hits-99-reliability-sharepoint-rce-under-active-exploitation-zgp0yt8lh
- https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/
- https://osintsights.com/confidential-computing-flaws-expose-trust-risks
- https://www.boerse-express.com/news/articles/digitale-souveraenitaet-vergabebeschleunigungsgesetz-staerkt-europaeische-cloud-ab-juli-924836
- Turkish: https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/
- https://akber.com/sovereignty-in-the-cloud-is-an-illusion/
- https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls
- German https://www.ad-hoc-news.de/wissenschaft/digitale-souveraenitaet-bundesregierung-beschliesst-34-punkte-paket/69692503
Implementations vulnerable to CVE-2026-33697
- Meta’s Private Processing for WhatsApp
- Cocos AI
- Confidential Computing Consortium (CCC) Attestation SIG's adopted project
Project Background
Code under Apache-2.0 License: https://github.com/CCC-Attestation/formal-spec-KBS
Paper: https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS
Project Info
Hackathon plan
Background on Attestation
Background on Diversion Attacks
Background on Relay Attacks (CVE-2026-33697)
Champions
Anton Sokolov (Tyche Institute, Tallinn) anton.sokolov@tyche.institute
Project Info
This project carries an application-layer Action Evidence Package (AEP) — a signed, append-only record of what an (AI) agent did, who authorised it, and the outcome — end-to-end through a conformant Project Veraison RATS Verifier, and closes a freshness gap found in Veraison's reference tpm-enacttrust scheme. The pattern treats the AEP as application-layer Evidence (RATS, RFC 9334) and output-binds it to a hardware-rooted TPM quote: the AEP outcome digest rides inside the signed quote, so the agent — which is both witness and suspect over its own log — cannot swap the outcome without breaking the signature.
What runs today (emulated swtpm)
A real Project Veraison verifier appraises a Tyche AEP-bound swtpm quote (CoRIM provisioning → challenge-response → signed EAR), returning affirming for good evidence and contraindicated for an outcome-swap or signature tamper. This validates the composition/conveyance mechanics against an emulated software TPM — an interoperability result, not a hardware guarantee and not a Veraison endorsement. It also surfaced that the reference tpm-enacttrust scheme checks the signature and PCR digest but not challenge-nonce freshness, so a replayed quote still appraises affirming (filed as veraison/services#427).
New since listing — a MachineMandate in the real EU wallet. We issued a MachineMandate (a machine-readable delegation: principal, allowed action, spend limit, action hash) as an SD-JWT VC into the actual EU reference wallet over OpenID4VCI, and present it over OpenID4VP to the EC reference verifier (trusted-list-backed). A payment agent runs it live: a €250 invoice is accepted; a €5,000 payment is denied for exceeding the delegated limit; a prompt-injected "wire it elsewhere" is denied because that tool and payee were never in the mandate. On a real phone, on a single tap, the wallet presents the mandate and the verifier accepts it. (Software TPM in the PoC.)
Composition — the four-box chain. PermitReceipt (Y. B. Lee) authorises before commit → the MachineMandate is the authority the action is checked against → the SCITT Agent Action Capsule (S. Mih, draft-mih-scitt-agent-action-capsule) records what happened → AEP/RATS attests the platform. The AAC × AEP cross-verification is closed both ways — one capsule_id, one response_digest, two independent trust roots.
Hackathon goals
/dev/tpmrm0), live beside the Veraison maintainers, to retire the "emulated-only" caveat.affirming → contraindicated flip on a replayed quote.Standards context (Internet-Drafts unless marked RFC)
Repositories & artifacts
Related Hackathon projects (collaboration welcome)
Coordination
Onsite in Vienna — champion attends in person (first IETF / first Hackathon). Remote collaborators from RATS / TPM / Veraison very welcome; sync slot to be listed on the Team Schedule.
Champions
Jiang Yuning (jiangyuning2@h-partners.com)
Song Yurong (songyurong1@huawei.com)
Foo Chuan Ann (foo.chuan.ann1@h-partners.com)
Tu Yaowei (tuyaowei@h-partners.com)
Project Info
In recent years, AI agents have witnessed remarkable progress and are increasingly recognized as a pivotal force in various fields. However, as these agents interact with one another, external tools, and data sources, the security of their communication channels has become a critical concern. Ensuring secure and trusted interactions is no longer optional but essential for maintaining system integrity and data confidentiality.
We are continuously working to implement and test Agent Protocol Security in IETF#123 and #125. Now we are expanding the scope from the security for agent protocol to the broader agent communication layer. In this Hackathon, we are planning to test security tools and agent skills focused on three key areas: intent source validation, agent and tool identity, and heterogeneous credentials verification.
Agent Protocol Background
https://modelcontextprotocol.io/
https://www.a2aprotocol.org/
Related Drafts
https://www.ietf.org/archive/id/draft-jiang-intent-security-03.html
https://www.ietf.org/archive/id/draft-jiang-wimse-heterogeneous-credential-00.html
https://www.ietf.org/archive/id/draft-song-oauth-ai-agent-collaborate-authz-01.html
https://www.ietf.org/archive/id/draft-jiang-oauth-intent-admission-00.html
Repositories
https://agent-security-labs.github.io/agentic-security-hackathon-plan/agentic-security-hackathon-plan.html
Champions
Jiang Yuning (jiangyuning2@h-partners.com)
Song Yurong (songyurong1@huawei.com)
Foo Chuan Ann (foo.chuan.ann1@h-partners.com)
Tu Yaowei (tuyaowei@h-partners.com)
Project Info
Workload and agentic systems may receive multiple credentials in one request, such as workload identity credentials, OAuth access tokens, JWTs, X.509 certificates, verifiable credentials, API keys, and opaque tokens. These credentials can use different formats, issuers, and verifiers, while the receiver still needs to make one handling decision for the request.
This project will test a heterogeneous credential verification pipeline for workload and agent communication. The prototype receives a mixed credential set, identifies each credential type, routes credentials to the appropriate verifier, normalizes verification results, and applies a decision policy.
Hackathon Plan
We plan to test the following items:
Related Drafts
https://datatracker.ietf.org/doc/draft-jiang-wimse-heterogeneous-credential/01/
Repositories
https://github.com/agent-security-labs/wimse-heterogeneous-credential-draft
Champions
Jia Zhang (zhangj@zgclab.edu.cn)
Mingwei Xu (xmw@cernet.edu.cn)
Nan Geng (gengnan@huawei.com)
Chongfeng Xie (xiechf@chinatelecom.cn)
Yangyang Wang (wangyy@cernet.edu.cn)
Project Info
This project explores priority-safe use of local or supplemental routing-security data together with signed RPKI data. Operators may use ROAs, SLURM entries, IRR-derived inputs, local exceptions, customer records, or other local data in validation and filtering workflows, but these inputs may have different authority or assurance levels. We will prototype practical deployment models, especially multi-cache / multi-table validation using existing RTR/cache/router mechanisms, so that signed RPKI semantics are preserved while operators can apply local actions such as reject, deprefer, warn, monitor, or exception handling.
Hackathon Plan
We will build a Proof of Concept (PoC) to demonstrate the multi-priority RPKI Route Origin Validation (ROV) framework. Our development will focus on two core tasks:
Related Drafts
https://datatracker.ietf.org/doc/draft-zhang-sidrops-prioritized-route-validation/
Jia Zhang (zhangj@mail.zgclab.edu.cn)
Yangyang Wang (wangyy@cernet.edu.cn)
Maria Matejka (maria.matejka@nic.cz)
Mingwei Xu (xmw@cernet.edu.cn)
Kotikalapudi Sriram (ksriram@nist.gov)
Nan Geng (gengnan@huawei.com)
This project explores practical deployment of ASPA-based AS_PATH verification at eBGP egress. ASPA verification is primarily defined for validating received BGP routes, but operators may also benefit from checking routes before they are exported to external neighbors. Egress-side verification can help detect export-policy mistakes, AS_PATH manipulation errors, AS migration or renumbering issues, missing provider ASPA records, and partial deployment gaps inside an AS.
The project will prototype how egress ASPA verification can be implemented in routers, route servers, or detached monitoring systems. The work will focus on how an egress verifier determines the relevant AS_PATH, local AS, neighbor AS, BGP Role or local relationship, OTC or equivalent leak-prevention signal, and export-policy context before deciding whether a route should be propagated, warned, monitored, or blocked.
The goal is to preserve the semantics of the base ASPA verification procedures while exploring operational models for export-side assurance and route-leak prevention.
We will build a Proof of Concept (PoC) to demonstrate ASPA-based AS_PATH verification at eBGP egress. Our development will focus on three core tasks:
Basic Egress ASPA Verification
Implement a prototype that performs ASPA-based AS_PATH verification on routes before they are exported to eBGP neighbors. The prototype will construct the AS_PATH as it would be seen at egress, apply the appropriate ASPA upstream or downstream verification procedure according to the neighbor relationship, and identify routes that would become ASPA Invalid after export.
Neighbor-AS and Export-Context Handling
Explore how the verifier obtains and uses egress-specific context, including the egress ASBR, local AS, neighbor AS, BGP Role or locally configured relationship, OTC or equivalent intra-AS leak-prevention signal, and export-policy information. The prototype may also evaluate Neighbor-AS-Augmented Verification as an optional mode for operational assurance or deployment-specific checking.
Deployment and Policy Modes
Demonstrate different deployment modes, including inline egress enforcement, alert-only operation, detached/offline verification, and centralized or Route Reflector assisted monitoring. The prototype will map verification outcomes to local actions such as SHOULD NOT propagate, warning, logging, monitoring, or local policy-driven handling.
https://datatracker.ietf.org/doc/draft-zhang-sidrops-aspa-egress/
Champions
Lun Li (lilun20@huawei.com)
Yaowei Tu (architect117@u.nus.edu)
Project Info
The academic community has been proposing new privacy technologies, but in existing networks, more pseudonymization is used to protect identifiers. Can these new privacy technologies enhance processing privacy?In this project, we try to let the network perform computing directly on ciphertext through privacy computing. The potential solution is to use homomorphic encryption. AI inference and neural networks are the types of computation we are primarily coped with. The main goal is as follows:
Hackathon Plan
Test the performance of homomorphic encryption in AI inference
Finish a MCP tool using FHE to complete ciphertext AI inference
Try your own cats( or dogs if you like) in the LLM to perform the ciphertext AI inference in the MCP tool.
Related Drafts
https://datatracker.ietf.org/doc/draft-li-pearg-ciphertext-inference-tool-mcp/
Champions
Qin Wu (bill.wu@huawei.com)
Qiufang Ma (maqiufang1@huawei.com)
Luis M. Contreras (luismiguel.contrerasmurillo@telefonica.com)
Wei Song (songwei80@huawei.com)
Junjie Luo (luojunjie6@huawei.com)
Mingyuan Chen (chenmingyuan3@huawei.com)
Yanping Cao (caoyanping@huawei.com)
Project info
Our aim is to develop an AI agent observability framework for network diagnosis AI agent to capture its internal reasoning process (Chain-of-Thought), decision-making logic, workflow execution, and operational metrics. This framework could serve as the foundational prerequisite for enabling advanced capabilities, such as agent control and run-time intervention, and AI agent benchmarking.
Related Drafts
https://datatracker.ietf.org/doc/draft-wnd-opsawg-icon-ps/
https://datatracker.ietf.org/doc/draft-mcw-opsawg-icon-requirements/
https://datatracker.ietf.org/doc/draft-contreras-bmwg-ai-agent-benchmarking/
Champions
Meiling Chen (chenmeiling@chinamobile.com)
Yu Han(hanyu@chinamobile.com)
Project Info
This project provides a security evaluation benchmark for AI agents, evaluating dimensions like algorithms, data, execution, third-party components, and evolution. Key metrics include adversarial, privacy, and jailbreak defenses, as well as plugin, skill and autonomous iteration security. Using static and dynamic testing, the framework assesses agents before, during, and after deployment. By scoring these metrics, it quantitatively evaluates the security posture, enabling direct capability comparisons and security grading across agents. The main goal is as follows:
Hackathon Plan
Carry out the evaluation demonstration of two ai agents based on the evaluation benchmark.
Related Drafts
Champions
Project Info
DNS for AI Discovery (DNS-AID) explores how AI agents and agentic workloads
can publish and discover connectivity and capability metadata using existing
DNS mechanisms, including SVCB, DNS-SD-style names, DNSSEC, and optional
DANE/TLSA.
Hackathon Plan
The scneario is based on a threat-intelligence federation use case. An AI SOC analyst
assistant needs an ip-reputation capability that was not pre-wired into
the assistant. The assistant uses DNS-AID to discover how to find and invoke
the published capability. DNS-AID publication provides discovery and
invocation metadata; the actual IP reputation verdict is produced only after
the discovered MCP tool is invoked.
Related Documents
Champions
Esko Dijk (esko.dijk@iotconsultancy.nl)
Project Info
cBRSKI is an onboarding protocol for IoT devices to automatically and securely onboard a new network domain. It uses EST-coaps for enrollment into the domain. This project will work on cBRSKI implementation for 6LoWPAN mesh nodes (specifically, implementing Thread) and the required back-end infrastructure. We'll also attempt some interop testing if sufficient implementations are available for that.
More Info
See the hackathon Thread project page, item 'cBRSKI' for more info.
Champions
Mingzhe Xing (xingmz@zgclab.edu.cn)
Linzhe Li (lilz@zgclab.edu.cn)
Yujia Gao (gaoyj@zgclab.edu.cn)
Project Info
Agent-assisted network operations increasingly depend on timely and trustworthy operational state. However, sending raw telemetry, flow records, device counters, or configuration data to every agent or analysis component can be expensive, slow, and difficult to share across administrative boundaries. Raw state may also contain sensitive customer, topology, or traffic details that should not be disclosed when an aggregate answer is sufficient.
This Hackathon project explores a minimal implementation of compact network state exchange based on Sketch data structures. The initial demo focuses on DDoS evidence exchange: two simulated domains convert IPFIX-like flow records into Count-Min Sketch state artifacts, exchange and merge those artifacts, and provide an agent-facing heavy-hitter report. The report includes query scope, provenance, freshness, bounded-error metadata, privacy caveats, audit identifiers, and a clear statement that the artifact is evidence only and does not authorize automatic mitigation.
Related Drafts
https://xmzzyo.github.io/nmop-agent-sketch-com/draft-cui-nmop-agent-sketch-com.html
https://datatracker.ietf.org/doc/draft-cui-nmop-agent-sketch-com
Champions
Mohit P. Tahiliani (tahiliani@nitk.edu.in)
Abhyuday K. Hegde (akh.241cs201@nitk.edu.in)
Vishal Kamath (vishalkamath.221cs261@nitk.edu.in) [Remote]
Project Info
Objective 1: Performance Evaluation of FQ-CoDel and FQ-PIE in Mobile Hot Spot (MHS)
Objective 2: Testing the integration of picoquic with ns-3
Objective 3: Developing a NeST based Congestion Control Evaluation Suite compliant with RFC 9743
Objective 4: Develop an example to demonstrate the implementation of rate-limited sender in ns-3
Related Documents
Related Repositories
Champions
Peter Liu (liuchunchi@huawei.com)
Project Info
This document (ACME-RATS) describes an approach where an ACME Server can challenge an ACME Client to provide Evidence, Endorsements, or Attestation Result according to the Remote ATtestation procedureS (RATS) framework in any format supported by the Conceptual Message Wrapper (CMW).
Related documents
draft-ietf-acme-rats-01
Champions
Benfeng Chen
benfeng@gmail.com
(Additional contributors and collaborators are welcome during the hackathon.)
Project Info
OpenNHP is an open-source implementation of the Network-infrastructure Hiding Protocol (NHP), an emerging Zero Trust protocol that provides authenticate-before-connect semantics through cryptographic authentication and network resource hiding.
Unlike traditional security approaches that protect visible services, NHP aims to prevent reconnaissance, DDoS attacks, and pre-authentication exploits by making protected network resources invisible to unauthorized entities. NHP extends concepts from Software-Defined Perimeter (SDP) and Single Packet Authorization (SPA) using modern cryptographic techniques including mutual authentication, continuous verification, and resource obfuscation.
For the IETF 126 Hackathon, we invite participants to actively evaluate, test, and attempt to bypass the security properties of OpenNHP.
Challenge objectives include:
Success criteria:
We believe that open adversarial testing, public peer review, and running code are essential for building trustworthy Internet security protocols.
Links:
Website: https://opennhp.org/
Source Code: https://github.com/OpenNHP/opennhp
Live Demo: https://opennhp.org/demo/
Internet-Draft: https://datatracker.ietf.org/doc/html/draft-opennhp-ztcpp-nhp
Champion: Naoto Miyachi
Internet-Draft:
https://datatracker.ietf.org/doc/draft-miyachi-ltv-jws/
Source code:
https://github.com/miyachi/draft-miyachi-ltv-jws/tree/main/implementation
LTV-JWS is an extension of JSON Web Signature (JWS) for lightweight
long-term validation. It defines signature levels including SIG-B and
SIG-T, RFC 3161 timestamps, validation information, archive timestamps,
and external references.
An experimental Java reference verifier is available in the repository.
It currently supports JWS signature verification, SIG-B and SIG-T,
RFC 3161 timestamp verification, certificate-path validation using local
trust anchors, CRL-based certificate-status checking, and verification of
referenced JWS files.
refs integrity verification and referenced JWS processing.-offline verification behavior.Java, JOSE/JWS, PKI, X.509 certificates, RFC 3161 timestamps, CRLs,
JSON processing, and interoperability testing.
This is an experimental reference implementation intended for
interoperability discussion and demonstration. It is not production
software.
The verifier currently supports CRL retrieval for online certificate-status
checking. OCSP is not currently supported.
This is the champion's first IETF Hackathon.
Newcomers and experienced participants alike are welcome.
Please contact Naoto Miyachi after the Hackathon team-formation session.
The meeting location will be announced on this page at the event.
Participants are welcome to join at any time during the Hackathon.
Contact:
Participants are encouraged to clone the repository and run the included
examples before joining, but this is not required.
Champions
Joe Harvey (jsharvey@verisign.com)
Swapneel Sheth (ssheth@verisign.com)
Andrew Kaizer (akaizer@verisign.com)
Draft Specifications
[1] https://datatracker.ietf.org/doc/draft-harvey-cfrg-mtl-mode/
[2] https://datatracker.ietf.org/doc/draft-harvey-cfrg-mtl-mode-considerations/
[3] https://datatracker.ietf.org/doc/draft-fregly-dnsop-slh-dsa-mtl-dnssec/
Project Info
This hackathon topic continues our evaluation of post-quantum cryptography (PQC) DNSSEC with MTL Mode by focusing on the benefits of MTL Mode beyond support for smaller signatures over the wire. MTL Mode can help with things like signing and verification performance, in particular for slower PQC signature algorithms, and reducing cache sizes in resolvers.
Related Groups
• PQ DNSSEC Research Side Meetings
• DNS Operations (DNSOP) Working Group
• Crypto Forum Research Group (CFRG)
• Post-Quantum Use in Protocols (PQUIP)
unicoap in RIOT OSunicoap is the unified and modular CoAP stack in RIOT OS, the friendly operating system for the IoT
Champions
Paul Wouters
Steffen Klassert
Project Info
Continued interop of IKEv2 drafts such as draft-ietf-ipsecme-ikev2-mlkem, draft-ietf-ipsecme-child-pfs-info, draft-ietf-ipsecme-ikev2-sa-ts-payloads-opt and IPsec performance testing for per-CPU Child SA's (RFC 9611), IPTFS (RFC 9347) and maybe some EESP draft-ietf-ipsecme-eesp hacking.
Champions
William Takeshi Pereira (william.a.pereira@inria.fr)
Project Info
Lakers is a Rust implementation of EDHOC (Ephemeral Diffie-Hellman Over COSE). This project aims to extend Lakers with support for the PSK (Pre-Shared Key) authentication method, enabling EDHOC to be used in scenarios where devices share a pre-established secret rather than relying on public-key credentials, which is particularly useful for constrained devices with limited resources for asymmetric cryptography.
In addition, this project will integrate embedded-cal into Lakers, providing a common cryptographic accelerator abstraction layer (CAL) interface for embedded targets. This will allow Lakers to more easily leverage hardware-accelerated cryptographic operations across different embedded platforms, improving performance and portability in constrained device deployments.
Related documents
EDHOC: RFC9528
Lakers: https://github.com/lake-rs/lakers
embedded-cal: https://github.com/lake-rs/embedded-cal/
Champions
Lucia Cabanillas, lucia.cabanillasrodriguez@telefonica.com
Diego López, diego.r.lopez@telefonica.com
Ana Méndez, ana.mendezperez@telefonica.com
Pedro Martínez-Julia, pedromj@gmail.com
Project Info
This project demonstrates a framework for sharing and managing authorization policies using a YANG-based model.
Authorization policies are expressed using declarative Policy-as-Code languages (e.g., Rego) and encapsulated in a YANG artifact that includes metadata such as owner, author, origin, area, and language.
The prototype implements a policy lifecycle workflow in which a Policy Administration Point (PAP) validates a policy artifact and routes it, based on its area, to the corresponding Policy Decision Point (PDP).
The demonstration shows how a YANG-based policy artifact can be created, validated, distributed, and enforced across two independent domains, with support for updates, deletion, and rollback to previous versions.
Related Drafts
https://datatracker.ietf.org/doc/draft-cabanillas-nmop-authz-policy-sharing-model/03/
Related Repositories
https://github.com/LuciaCabanillasRodriguez/authz-policy-sharing-model
Champions
Tobias Fiebig (tobias@internet.wien)
Project Info
The idea for this group is doing a 'polishing run' on two currently active drafts dealing with BGP security and global routing operations terminology currently in use. Both need ample polishing to 'get there', but still should be polishable in the time a hackathon allows.
Related Drafts
https://datatracker.ietf.org/doc/draft-ietf-grow-routing-ops-sec-inform/
https://datatracker.ietf.org/doc/draft-ietf-grow-routing-ops-terms/
Champions
Henry Yu (hyu2010b@gmail.com)
Project Info
This project demonstrates how incidents [1] and issues [2] can be identified and reported in optical networks using agentic AI and knowledge graphs.
-- AI agents are used to identify, locate, analyze, and report issues and incidents. Throughout this process, the agents employ cognitive reasoning to correlate information and infer root causes.
-- Knowledge graphs are constructed from multiple network data sources, including TE topology, services, inventory, and alarms. They provide a unified ontology to assist the reasoning performed by the Agents.
-- The issues and incidents are reported using their YANG models.
Links
[1] https://datatracker.ietf.org/doc/draft-ietf-nmop-network-incident-yang/
[2] https://datatracker.ietf.org/doc/draft-yu-ccamp-sla-assurance-optical-yang/
Champions
Yingying Su (suyy@mail.zgclab.edu.cn)
Lancheng Qin (qinlc@mail.zgclab.edu.cn)
Project Info
This project demonstrates a publication-point-based incremental validation procedure for RPKI Relying Parties (RPs). The goal is to reduce repeated validation work after repository synchronization while preserving the same validated output as full top-down validation.
The RP project supports:
-- building a publication point cache after initial top-down validation;
-- full validation when a CA publication point is new or when its effective resource context changes;
-- publication-point-level reuse when the CA_ID, ca_effective_resources, manifest, and CRL are unchanged;
-- object-level reuse when the manifest changes but the CA_ID and ca_effective_resources remain unchanged, with re-checks for validation time and CRL status before reuse;
-- collecting metrics such as running time, PP cache hit/miss rate, PP-level reuse rate, object-level reuse rate, and validation output statistics.
Hackathon Plan
-- Run our RP, Routinator, rpki-client, and FORT in an initial repository synchronization followed by full validation.
-- Run the same implementations after incremental repository synchronization followed by full RPKI object validation.
-- Run our RP after incremental repository synchronization with publication-point-based incremental validation enabled.
-- Compare running time, cache hits/misses, PP-level and object-level reuse behavior, and validated output, and show the results in the monitoring dashboard.
Related Documents
-- https://datatracker.ietf.org/doc/draft-su-sidrops-rpki-rp-incremental-validation/
Champions
Sandoche BALAKRICHENAN (sandoche.balakrichenan@afnic.fr)
Nathan LE SAUSSE (nathan.le_sausse@telecom-sudparis.eu)
Lourenço Alves Pereira Jr (ljr@ita.br)
Flavio Souza (flavioluiz.ssouza@gmail.com)
Project Info
This project aims to demonstrate an end-to-end implementation of the DRIP (Drone Remote ID Protocol) architecture, with a particular focus on the DNS and DNSSEC components specified in RFC 9886.
Current implementation includes:
A proof of concept implementing the DNS resolution architecture described in Figure 3 of RFC 9886, enabling DRIP identifiers to be resolved through the DNS.
A DRIP cryptographic implementation integrated with a Remote ID implementation running on ESP32 hardware.
A DNSSEC-enabled DRIP namespace, providing a complete chain of trust from the DRIP apex through delegated registry zones to registrant records.
Goals for the IETF Hackathon
Two drafts already explore how to extend QUIC with multicast support:
draft-jholland-quic-multicast
draft-navarre-quic-flexicast
Though they offer benefits, the two approaches already embed numerous features that go beyond the basic framework to efficiently deliver the same data to multiple recipients.
In this hackathon, the objective is to implement a minimal, interop-ready multicast extension in QUIC as a proof of concept.
Champions
Paul Howard (paul.howard@arm.com)
Project Info
CoSERV has introduced a new query mechanism based on RIM identifiers instead of environments.
This project is to implement the new query style and to show a simple end-to-end demonstration of it interoperating between the Rust and Go implementations.
Rust support for CoSERV is here.
Go support for CoSERV is here.
Champions
Ben Curtis (ietf@nowsci.com)
Project Info
MyTerms establishes a technical framework for Verifiable Contractual Agreements (VCAs) between individuals and entities, allowing individuals to proffer their privacy and data usage requirements in a format that can be read, acknowledged, and agreed to by both humans and machines.
Hackathon Plan
Related documents
Links
[1] https://datatracker.ietf.org/doc/draft-ietf-emu-teapv2/)
[2] https://datatracker.ietf.org/doc/draft-lear-iotops-mudextras/
Champion
Ike Kunze (ike.kunze@cujo.com)
Project Info
Quality of Outcome (QoO) is an IPPM framework for assessing network quality in the context of application requirements. The QoO draft is currently in the RFC Editor Queue. This project aims to help grow the QoO ecosystem through practical experimentation, tooling, implementation experience, and discussion around application profiles and measurements. A pre-built Docker-based testbed provides network emulation, active and passive measurements, live QoO score calculation, and Grafana dashboards. Participants can bring applications to test or use provided examples. The focus is not on validating QoO itself, but on exploring questions such as:
Hackathon Activities
QoO under Network Impairments: latency, jitter, and (burst) packet loss
Comparing Network Quality Metrics: QoO, responsiveness, and underlying network measurements
Comparing Measurement Approaches: active measurements (e.g., ping, TWAMP) and passive measurements (e.g., based on TCP or QUIC semantics)
Exploring QoO Profiles: application-specific versus category-based profiles
Expected Outcomes
Related Documents
Champions
Jaehoon Paul Jeong (pauljeong@skku.edu)
Project Info
The goal of the Interface to In-Network Computing Functions (I2ICF) is to demonstrate the feasibility of an I2ICF framework that translates natural language intent into real-time tracing and detection actions for moving objects. The framework provides a structured architecture and a collection of interfaces that enable cloud-based users to control and monitor mobile systems, such as robotic AI agents and other moving devices. In this work, a robot car fuses real-time camera and LiDAR data to detect and track a target object. An AI-based intent inference server converts natural language commands into structured tracing and detection workflows.
Specifications
[draft-jeong-nmrg-i2icf-problem-statement-00]
[draft-jeong-nmrg-i2icf-framework-00]
[draft-an-nmrg-i2icf-cits-02]
Champions
Linzhe Li (lilz@zgclab.edu.cn)
Yujia Gao (gaoyj@zgclab.edu.cn)
Project Info
This project demonstrates how CoAP Task Resources can be used to deploy DDoS defense policies as observable asynchronous tasks.
In the demo, a control center acts as a CoAP Task Client and a DDoS cleaning device acts as a CoAP Task Server. The control center creates a task for sequential policy deployment, including cleaning policy, ACL, BGP FlowSpec, BGP diversion, and mitigation verification. The cleaning device reports task state, progress, diagnostics, and per-step results through /tasks/{id}.
Don’t see anything that interests you? Feel free to add a project to the list, sign up as its champion, and show up to work on it. Note: you must login to the wiki to add content. If you add a new project, we suggest you send an email to (hackathon@ietf.org) to let others know. You may generate interest in your project and find other people who want to contribute to it. TEMPLATE: Copy/paste and update the following template to add your project to the list:
### Your Project
- **Champions**
name and email
- **Project Info**
project description
To edit the wiki, log in using your IETF Datatracker login credentials. If you don't yet have an IETF Datatracker account, you may get one by going here and requesting a new account.