Markdown Version | Transcript | Session Recording | Session Materials
DISPATCH
Summary
The DISPATCH working group met at IETF 126. The session was chaired by Jim Fenton, Shuping Peng, and Rifaat Shekh-Yusef. Notes were taken by Laura Scalone and Rich Salz.
This meeting marked the first session of the "new" DISPATCH, which officially merged with SECDISPATCH and integrated the non-transport aspects of the Web and Internet Transport (WIT) area. The chairs welcomed the community to this joint format and reviewed the updated DISPATCH wiki guidelines.
The group reviewed seven proposals to determine their appropriate dispatch path (e.g., direct to an existing WG, forming a new WG, holding a BOF, AD-sponsorship, or taking no action).
Key Discussion Points
1. Caller ID Vouching and Vetting (CIDVV)
- Presenter: Roger Anderson
- Slides: CIDVV Presentation IETF 126
- Discussion:
- The presenter introduced CIDVV, a reachability-based callback protocol designed to mitigate caller ID spoofing in telecom networks without requiring modifications to SIP/SS7 signaling or headers.
- Jonathan Rosenberg and Eric Rescorla expressed severe concerns regarding "ghost ringing" (phantom rings) on the originating side. They noted that the first entity to deploy this would generate disruptive brief rings on legacy callers' phones, making incremental deployment highly destructive and functionally undeployable.
- John Peterson argued that dial-back mechanisms introduce reflection/amplification DDoS vectors (especially in SIP via forking) and suffer from divergence of routing authority in large enterprise setups. He noted that similar dial-back concepts had been proposed and rejected in the past.
2. Email Verification Protocol (EVP)
- Presenter: Dick Hardt
- Slides: Email Verification Protocol (EVP)
- Discussion:
- The presenter described EVP, a protocol to verify email addresses directly on a web page using DNS records and browser-mediated identity cookies, removing the friction of manual one-time passwords (OTPs). The work is split between W3C (browser APIs) and IETF (the protocol).
- Mauro Gennaro, Vittorio Bertola, and John Levine raised concerns that the design is too browser-centric and does not address self-hosted or non-browser email clients (such as native IMAP/JMAP clients), potentially fracturing the email ecosystem.
- Eric Rescorla, Dennis Jackson, and Richard Barnes strongly opposed the presenter's suggestion for AD-sponsorship, stating that the cryptographic, privacy, and architectural designs require deep review and cannot be rushed.
- A side meeting was announced to further discuss this work.
3. A BCP or Applicability Statement for Confidentiality and Authenticity Protection for Internet Email
- Presenter: John Klensin (remote)
- Slides: A BCP or Applicability Statement for Confidentiality and Authenticity Protection for Internet Email
- Discussion:
- The presenter proposed creating a Best Current Practice (BCP) or Applicability Statement to clarify and rationalize the overlapping and sometimes non-interoperable landscape of email confidentiality and authenticity mechanisms (such as STARTTLS, MTA-STS, DMARC, S/MIME, and OpenPGP).
- Ted Hardie and Pete Resnick supported holding a BOF to gauge operator interest and determine if enough contributors would commit to drafting the document.
- Richard Barnes suggested that rather than merely documenting the "sad state of affairs," the work's scope should include actively cleaning up and deprecating redundant or insecure modes.
- John Levine and Vittorio Bertola emphasized that maintaining backward compatibility and ensuring mail delivery are the absolute priorities for operators, making broad operator representation in the room critical for this effort.
4. PARCEP: A Protocol for Parental Controls
- Presenter: Andrew Campling
- Slides: PARCEP: A Protocol for Parental Controls
- Discussion:
- The presenter introduced PARCEP, a protocol aimed at allowing different parental control systems to interoperate and share user-defined settings across multiple devices and networks.
- Ted Hardie argued that the proposed Policy Enforcement Point (PEP) framework falls within policy-based wiretapping/censorship boundaries defined as out-of-scope for the IETF under RFC 2804. He added that the complex architectural and jurisdictional assumptions make it a poor fit for IETF protocol development.
- Stephen Farrell, Paul Wouters, and Phillip Hallam-Baker expressed concerns that the design could facilitate upstream network-level censorship and is socially problematic.
- Arnaud Taddei (ITU-T SG17 Chair) noted that ITU-T has a mandate for child online protection but cannot develop protocols due to anti-duplication agreements, leaving a gap for the protocol work.
- Peter Koch recommended that the IAB and liaison managers coordinate with the ITU-T before the IETF makes any formal decisions.
5. Taxonomy for Agentic AI Use Cases
- Presenter: Jordi Rajyal
- Slides: Taxonomy for Agentic AI Use Cases
- Discussion:
- The presenter proposed a multi-dimensional taxonomy to classify and structure Agentic AI use cases brought to the IETF, helping working groups and DISPATCH route future work.
- Rich Salz questioned the utility of a taxonomy validated against only a single draft.
- Eric Rescorla suggested removing the taxonomy framework entirely, which he termed a "straightjacket," while retaining the useful technical characterizations as an individual draft.
- Muhammad Usama Sardar and Wes Hardaker commented that it is premature to dispatch this taxonomy. They advised holding off until after the current meeting's AI-related BOFs (such as DAWN) determine the active directions of Agentic AI work.
6. Ciphertext Inference in MCP (Model Context Protocol)
- Presenter: Lun Li
- Slides: slides-126-dispatch-ciphertext-inference-mcp
- Discussion:
- The presenter proposed extending the Model Context Protocol (MCP) schema to negotiate parameters for Fully Homomorphic Encryption (FHE), enabling privacy-preserving ciphertext inference on remote AI servers.
- Eliot Lear and Eric Rescorla noted that standardizing FHE-based inference in the IETF is highly premature due to performance costs and a lack of broader academic review.
- Aaron Parecki and Eric Rescorla suggested that micro-extensions to the MCP should be directed to the MCP Foundation (under the Linux Foundation) rather than the IETF.
- Stephen Farrell suggested that research on this topic could continue within the IRTF Privacy Enhancements and Assessments Research Group (PEARG).
7. Authorization Evidence for High-Risk Actions
- Presenter: Mohammed Khalil (remote)
- Slides: Authorization Evidence for High-Risk Actions
- Discussion:
- The presenter outlined the need for a standardized contract to compose and evaluate multi-layer signed authorization artifacts for high-risk Agentic AI actions.
- Eric Rescorla and Leslie Daigle (co-chair of the Agent Proto BOF) agreed that while the topic is interesting, the Agent Proto BOF agenda is already full. They recommended that the authors monitor the progression of the Agent Proto BOF to see if a relevant working group is eventually chartered.
Decisions and Action Items
- Caller ID Vouching and Vetting (CIDVV):
- Decision: No action. The IETF will not take on this work due to fundamental deployment and security issues (e.g., ghost ringing and reflection risks).
- Email Verification Protocol (EVP):
- Decision: Directed to a side meeting. AD-sponsorship was rejected. The recommended path is to hold a BOF or form a focused Working Group if the side meeting demonstrates sufficient interest.
- Email Security BCP/Applicability Statement:
- Decision: Directed to a mailing list first. If the mailing list gathers enough energy and active participation from mail operators and vendors, a future BOF can be requested.
- PARCEP (Parental Controls):
- Decision: No action. The work is considered out of scope for the IETF. The authors may continue discussions offline and coordinate through appropriate liaison channels with the ITU-T.
- Taxonomy for Agentic AI Use Cases:
- Decision: No action. The draft should remain an individual submission and be socialized within the relevant AI BOFs (e.g., DAWN).
- Ciphertext Inference in MCP:
- Decision: No action. Authors are encouraged to bring this work to the MCP Foundation or continue research in the IRTF PEARG.
- Authorization Evidence for High-Risk Actions:
- Decision: No action. The authors should wait to see the outcome and potential chartering of the Agent Proto BOF.