Markdown Version | Transcript | Recording 1 | Recording 2 | Session Materials
HACKATHON
Summary
The IETF 126 Hackathon commenced with a kickoff session led by the Hackathon Organizer. The session welcomed participants—including a significant number of first-time attendees—and emphasized the core IETF philosophy of "rough consensus and running code." The organizer detailed intellectual property guidelines, introduced onsite support staff, and announced a schedule adjustment for Sunday. Key guidelines were provided for Sunday's project presentations and Monday's Hack Demo Happy Hour.
Key Discussion Points
- IETF Note Well and Code Licensing:
- The Hackathon Organizer reminded participants that the IETF Note Well applies to all discussions and presentations.
- A distinction was made regarding code written during the event: code contributions are not considered IETF contributions. They remain the intellectual property of the authors and are subject to their own proprietary or open-source licenses.
- Projects and Collaboration:
- Over 40 projects are registered on the active Hackathon Wiki.
- Participants looking to join a project or find specific expertise were encouraged to use the "Lost and Found" section on the Wiki.
- Sunday Schedule Adjustment:
- Due to room availability constraints, the entire Sunday schedule was shifted one hour earlier.
- The room will open at 08:30 (instead of 09:30).
- Lunch will be served at 11:30.
- Closing presentations will begin at 13:00 (instead of 14:00) and conclude by 15:00.
- Closing Presentation Guidelines:
- To accommodate approximately 40 projects within the two-hour window, presentations are strictly limited to 90 seconds. Presenters should focus on high-level contributions, project relevance, and next steps.
- Slides must be uploaded in PDF format to the Data Tracker under the Sunday 13:00 time slot before the 13:00 deadline.
- Presenters must use the exact same filename when uploading slide revisions to prevent duplicate files in Meetecho.
- PowerPoint and HTML templates are available on the IETF Hackathon GitHub repository.
- Data Tracker Draft Integration:
- Draft authors can associate their hackathon work with active drafts using the "additional resources" feature in the Data Tracker. Authors of individual drafts can do this directly, while authors of working group documents must request this through their working group chairs.
- Hack Demo Happy Hour:
- The Hack Demo Happy Hour will take place on Monday at 18:30 in the registration area.
- Participants wishing to secure a table to demo their work must register via the Hackathon Wiki before the 13:00 Sunday deadline.
- Logistics and Support:
- Charles and Barry were introduced as the onsite contacts for network, logistics, and general support.
- The organizer expressed gratitude to ICANN for sponsoring the event.
Decisions and Action Items
- Decision: Sunday's schedule was officially moved forward by one hour, starting at 08:30 with project presentations starting at 13:00.
Next Steps
- Presenters: Upload project presentation slides (in PDF format using a consistent filename) to the Data Tracker before 13:00 on Sunday.
- Demo Participants: Register on the Hackathon Wiki before 13:00 on Sunday to reserve a table for the Monday evening Hack Demo Happy Hour.
Session Date/Time: 19 Jul 2026 11:00
HACKATHON
Summary
The IETF 126 Hackathon session featured rapid-fire technical demonstrations from dozens of development teams working across security, routing, IoT, transport, and network management domains. Due to a tight schedule and a hard stop, presentations were strictly limited to 90 seconds (and later 60 seconds) to ensure all projects could present their running code, testing outcomes, and interoperability results.
Key themes included post-quantum cryptography (PQC) integration across SSH, Kerberos, DNSSEC, and EDHOC; AI agent security, discovery, and verification; RPKI/BGP path verification; and YANG-based network management automation.
Key Discussion Points
Security & Attestation
- AI Agent Mandates and Verifiable Credentials: Anton (TKI Institute Estonia) demonstrated secure invoicing for AI agents using EU digital identity wallets, selective disclosure JWT/JWP verifiable credentials with key binding over OpenID for VCI/VP, and RATS remote attestation procedures appraised by Veraison.
- Composite Attestation in Veraison: A presenter demonstrated composite attestation inside the Veraison open-source project, focusing on collecting component evidence tokens and generating composite evidence using Concise Message Wrappers (CMW, RFC 9339) and the composite attester draft.
- Attested TLS Vulnerability: A presenter shared a newly discovered Man-in-the-Middle (MITM) vulnerability (CVE score 7.5) affecting three Attested TLS drafts, illustrating that intra-handshake options are vulnerable and unsuitable for standardization.
- Network Infrastructure Hiding Protocol (NIHP): Greg proposed NIHP, an authenticate-before-connect protocol designed to make network services invisible to AI-driven discovery and scanning tools until clients are cryptographically authenticated.
- Lightweight Cryptographic Suites for COSE: Mitro Ochkas presented implementations of the lightweight ASCON AEAD algorithms (with 32-bit, 64-bit, and 128-bit tags) in COSE libraries, enabling highly optimized encryption for extremely constrained IoT environments.
- Acme RATS: A presenter showcased Acme RATS, an extension of the ACME protocol to support attestation verification, successfully demonstrating an end-to-end implementation for EAP-TLS client enrollment.
- Post-Quantum SSH and Kerberos: Speaker 23 presented interop testing for hybrid ML-KEM in GSS-API key exchanges and pure ML-DSA keys in SSH, identifying a lack of specification for private key formats. Another team presented an implementation of ML-KEM and ML-DSA within Kerberos PKINIT.
Routing, BGP, & RPKI
- RPKI Publication Point Incremental Validation: Ying Soo demonstrated an incremental validation procedure for RPKI caches using Publication Point (PP) cache states to reduce validation overhead, achieving a 99% hit rate and reducing validation times by 49% to 90%.
- BGP Prioritized Resource Data & Export Verification: Jia presented two prototypes built on OpenBGPD:
- RPKI-based validation utilizing prioritized resource data to resolve validation conflicts.
- Outbound AS-path verification based on ASPA (draft-ietf-sidrops-aspa-verification), demonstrating basic egress verification without session resets.
- Kira Zero-Touch Routing Protocol: Roland Bless tested Kira, a resilient zero-touch control plane routing protocol, scaling topologies over a physical testbed of eight Raspberry Pis.
- SCION Native Connectivity: Speaker 49 demonstrated native SCION (Secure Internet Architecture) connections tunneled from the meeting venue to a SCION node in Vienna.
- IPv6 Multicast to Ethernet Mapping: Ekwee implemented a 31-line Linux kernel patch demonstrating a new
6mandraft mapping of IPv6 multicast addresses to Ethernet. - SRv6 SFC & Redundancy: Speaker 46 presented an SRv6 Service Function Chaining management and control architecture using BGP Flowspec. Ferenc Fejes implemented an SRv6 redundancy segment routing engine in XDP using eBPF to interpret CBPF filtering rules.
IoT & Constrained Environments
- MUD Extensions and Clarifications: Elliot presented MUD extensions and clarifications, detailing IP address usage in Manufacturer Usage Description (RFC 8520) files, multicast routing rules, and drag-and-drop PCAP-to-MUD file generation in MUD Maker.
- TEEP Agent on Heterogeneous TEEs: A presenter demonstrated TEEP (Trusted Execution Environment Provisioning) agents running inside WebAssembly (Wasm) runtimes on Intel SGX and OP-TEE.
- COPIP in Physical IoT: A presenter demonstrated the first physical IoT deployment of the Constrained Object-Identifiers Registry Protocol (COPIP) on Nordic Semiconductor hardware, complete with a Wireshark dissector.
- Embedded CoAP & EDHOC: Christian Amsüss integrated the Lakers EDHOC library with hardware cryptographic accelerators in RiotOS. Speaker 53 successfully tested the Lakers EDHOC Rust library on physical robots. Nikolay advanced the RiotOS CoAP server implementation, including group communication and OSCORE integration.
AI, Verification, & Agentic Architectures
- AI Agent Discovery & Semantic Routing: Yihan presented an intent-based agent discovery and semantic routing framework at the application layer.
- Heterogeneous Credential Verification: A presenter showcased a framework to detect and verify multiple concurrent credentials (VCs, X.509, JSON) within a single request, mapping agentic security to the OWASP Agentic Top 10.
- AI-Assisted Protocol Testing: Yunsoo described a testing framework using AI representing message formats and state machines to generate and run test cases from RFCs.
- Sketch-Based Network State Compression: Yincheng presented a sketch-based algorithm to compress and exchange network states for AI agents, achieving high compression ratios.
- Agent Action Capsules: Steven Mi presented content-addressable records of agent actions anchored in SCITT (draft-ietf-scitt-architecture).
Network Management, Telemetry, & DNS
- YANG-Push to Message Broker Integration: Speaker 68 presented Validate YANG-Push to Message Broker End-To-End Data Processing Chain, demonstrating YANG-Push publishers sending DTLS/CBOR notifications to message brokers and schema registries across various network OS implementations.
- YANG-Push UDP Notif in L3VPN: A presenter demonstrated YANG-Push UDP notifications integrated into a Layer 3 VPN service model with a Cisco NCS 5500 and the StrataWeave orchestrator.
- YANG-based Network Management Agent (NMA): Xin developed a RESTCONF-based text/UI user interface (A2U) for network management agents supporting intent submission and task monitoring.
- DRIP End-To-End Implementation with DNS: Speaker 41 presented DRIP End-To-End Implementation with DNS, demonstrating RFC 9374 and RFC 9486 compliant drone broadcast identification, HDA endorsement, and DNSSEC validations using Android and Nordic hardware.
- NTP, NTPv5, and Roughtime: A presenter performed interoperability testing for NTP pools, NTPv5, and Roughtime, discovering bugs in IPv4-mapped IPv6 address handling and version negotiation.
- DNS Table / DELEG implementation: Ekwee summarized DNS table achievements including DELEG draft implementation, zone signaling additions, and serial zone versioning in DNS servers.
- vCon Core Specification: Dan Petrie presented vCon, discussing updates to the vCon core spec, addressing CDDL grammar corrections, and resolving ambiguities.
Transport & Security Protocols
- Service Affinity based on TLS: Ajuan discussed maintaining service affinity in anycast environments by notifying the client of a designated IP address during the TLS handshake.
- ILNP end-to-end Addressing: Salim evaluated the Identifier-Locator Network Protocol (ILNP) in FreeBSD, modifying libc to support locator (L64) and node identifier (NID) DNS records.
- Multicast QUIC Extension: Speaker 29 tested a multicast QUIC extension for unreliable video streaming over the hotel Wi-Fi network.
- L4S Interoperability: Greg White presented the ninth iteration of L4S interoperability testing, examining SCReAM congestion control in libwebRTC and Apple responsiveness under L4S.
Decisions and Action Items
- MUD Specifications: Elliot identified a bug in the specification that will be corrected via updates discussed with Michael Richardson.
- Attested TLS Vulnerability: The identified vulnerabilities (CVE score 7.5) will be formally reported back to the active working groups to deprecate intra-handshake options.
- SSH Private Key Format: Speaker 23 flagged that the private key format for pure ML-DSA keys is currently unspecified; this is slated for discussion during the SSH WG session.
- IVY Interoperability: Nigel Lewis noted discrepancies and missing elements in the IVY interface compared to TAPI; these gaps will be fed back directly to the IVY working group.
Next Steps
- Hackdemo Happy Hour: Presenters are encouraged to register their projects to provide deeper technical demonstrations during the Hackdemo session on Monday.
- Working Group Presentations: Several teams (including those representing ASPA, 6man, ACME, and NTP) will present their hackathon results and code insights during their respective WG sessions throughout the week.
- Thursday Side Meetings: Side meetings are scheduled to discuss Kira, XMPP 2.0, and Post-Quantum Cryptography implementations.
Related Documents
draft-ietf-scitt-architecture, draft-ietf-sidrops-aspa-verification