Markdown Version | Transcript | Session Recording | Session Materials
SCITT
Summary
The Supply Chain Integrity, Transparency, and Trust (SCITT) Working Group met at IETF 126 in Vienna to discuss the completion of its core specifications, potential extensions, new use cases arising from the recent Hackathon, and the future strategic direction of the working group.
Key outcomes included progress on core drafts and upcoming errata, a call for adoption of the Merkle Mountain Range (MMR) Verifiable Data Structure (VDS) profile, proposals for multi-signature joint statements, and a significant debate on whether SCITT should expand into application-level payload interoperability.
The presentation materials are available in the IETF 126 Supply Chain Integrity Transparency and Trust Vienna slide deck.
Key Discussion Points
1. WG Status and Core Specifications Update
Presented by Henk Birkholz
- Core Specifications Status: RFC 9493 / RFC 9943 (Architecture) and RFC 9492 / RFC 9942 (Proofs) have been progressed.
- EDN Errata: Henk Birkholz identified two issues with the Extended Diagnostic Notation (EDN) examples in the Architecture specification (unquoted strings and malformed nulls copied from the CTD head). An errata will be filed within the next 14 days to resolve this.
- API and Service Finding: The API and service-finding draft is currently in the RFC Production Center (RPC) queue. It addressed IESG feedback, notably returning to
20xstatus codes for operations in progress.
2. CCF Profile & Joint Statements Extension
Presented by Amaury Chamayou
- CCF Profile: Amaury Chamayou presented the confidential consortium framework (CCF) VDS profile, currently under IESG review. CCF requires a distinct VDS profile over RFC 9162 to accommodate its internal transaction hash (for ledger governance and hardware attestation) and internal commitments (to prevent front-running receipts before consensus).
- Joint Statements Extension: Amaury Chamayou and Yogesh proposed an extension to support signing artifacts by multiple parties using
COSE_Signinstead of the single-signerCOSE_Sign1. The proposed draft is draft-chamayou-scitt-cose-sign. - Discussion: A representative from Telefonica queried if COSE countersignatures should be used for multi-signing. Amaury Chamayou clarified that
COSE_Signis more appropriate because all parties directly sign the target payload itself, rather than signing each other's signatures sequentially. - Review Volunteers: David Rogers and Carsten Bormann volunteered to review the draft.
3. MMR Profile Call for Adoption
Presented by Jon Geater
- Merkle Mountain Range (MMR) VDS Profile: Jon Geater presented a call to rehome and adopt the MMR VDS profile (draft-ietf-scitt-bwt-bkey / MMR profile) into the SCITT WG.
- Benefits of MMR: MMR grows linearly, supports fast append operations, and allows conflict-free concurrent writes without locking in distributed systems. It is lightweight, cheap to implement, and supports both consistency and inclusion proofs.
- Status & Next Steps: The draft is currently at version -03 and is functionally complete with multiple independent implementations. The primary open task is introducing cryptographic agility beyond a single hashing algorithm.
- Review Volunteers: Carsten Bormann, Henk Birkholz, Alistair Woodman, Jon Geater, and Amaury Chamayou agreed to review the draft.
4. Hackathon Report & New Incoming Use Cases
Presented by Steven, Anton, Evangelos, and Gregor
- Hackathon Results: Steven reported that seven independent parties with four codebases achieved pairwise agreement by digest during the Hackathon. He proposed standardizing a canonical, payload-opaque signed statement (derived from the agent action capsule concept) using COSE and RFC 9942 receipts to keep semantics separate from core protocols.
- Verified Platform Evidence: Anton presented on separating record validity (SCITT history proof) from platform validity (RATS attestation). He highlighted that a digest serves as a join key but does not inherit trust, and asked if SCITT should own the registration policies for interoperable evidence schemes.
- AI Model Bill of Materials (AIM BOM): Evangelos presented the CoVolution EU project, which utilizes CycloneDX documents to capture AI model metadata (data provenance, ethics, vulnerability assessments). He proposed using SCITT to sign and store these AIM BOMs to provide transparent, verifiable credentials.
- Software Supply Chain Communication: Gregor discussed regulatory compliance (CRA, EO 14028, etc.) and proposed using "standards badges" on repositories along with SCITT to establish verifiable, compliance-critical communications between open-source projects, users, and market surveillance authorities.
5. Future of the Working Group
Led by Jon Geater
- The working group debated three paths forward:
- Stop/Declare Done: Wind down the group as the core protocols are complete.
- Recharter: Expand the scope to officially cover hardware, AI, physical handling, etc.
- Establish Conventions: Keep the current charter but define payload conventions/registries to make application-level integrations visible.
- Discussion:
- Orie Steele expressed concern that SCITT has introduced too much optionality, trapping interoperability within individual profiles instead of enabling a unified ecosystem. He questioned what interoperability SCITT actually achieves if it remains entirely payload-agnostic.
- Carsten Bormann noted that maintenance work (such as the EDN errata and adding
COSE_Sign) still requires the WG. He argued that media types already function as a registry for payload formats, so a new registry is unnecessary. - Henk Birkholz argued that SCITT has built a versatile "sidecar" but has not yet solved the charter's core objective of supporting software consumers. He proposed rechartering to address practical integration with existing SBOM formats (e.g., CycloneDX).
- David Rogers and Nicole Bates cautioned against tracking and defining various SBOM/AI BOM file formats within SCITT, as it would create excessive overhead and slow down progress.
Decisions and Action Items
Session Polls
- Poll 1: Does this work?
- Yes: 0, No: 0, No Opinion: 0 (Total: 2)
- Poll 2: Do you agree to review the MMR draft?
- Yes: 4, No: 0, No Opinion: 3 (Total: 34)
- Poll 3: Do we believe this work on application-level interop belongs in the SCITT WG?
- Yes: 11, No: 6, No Opinion: 5 (Total: 36)
Action Items
- Core Specs: Henk Birkholz to submit the EDN-related errata for RFC 9493 / RFC 9943 within 14 days.
- Multi-Signature Extension: Amaury Chamayou and Steven to post their proposed drafts to the SCITT mailing list for feedback.
- MMR Draft Adoption: Chairs to initiate an official call for adoption on the mailing list for the MMR VDS profile draft.
- Reviewers: Reviewers who volunteered during the session (Carsten Bormann, Henk Birkholz, Alistair Woodman, Jon Geater, Amaury Chamayou, and David Rogers) are expected to provide feedback on their respective drafts once the calls are posted.
Next Steps
- Mailing List Calls: The chairs will issue list-based confirmation calls for the review of the MMR draft and the multi-signature joint extension draft.
- Interoperability & Payload Scope: Based on the majority "Yes" vote regarding whether application-level interoperability belongs in the SCITT WG, the chairs and ADs will discuss how to structure this work (either through rechartering or by utilizing existing registries/conventions) ahead of IETF 127.