oneM2M TR-0081Release Notes diff from v0.2.0 to v0.1.0
  • ETSI title

  • 1 Scope
  • 2 References
    • 2.1 Normative references
    • 2.2 Informative references
  • 3 Definition of terms, symbols and abbreviations
    • 3.1 Terms
    • 3.2 Symbols
    • 3.3 Abbreviations
  • 4 Conventions
  • 5 Overview
    • 5.1 Agentic AI
    • 5.2 Architecture Overview
    • 5.3 Transport Protocol and Message Format
    • 5.4 Lifecycle
      • 5.4.1 Illustrative simple API wrapper scenario
  • 6 Architecture model of MCP to oneM2M interworking
    • 6.0 Overview
    • 6.1 Design Considerations
      • 6.1.1 Layered Tool Pattern
      • 6.1.2 Agent Skills
    • 6.2 Interworking Scenarios
      • 6.2.1 Agentic IPE Generation Framework
        • 6.2.1.1 Introduction
        • 6.2.1.2 Framework Overview
        • 6.2.1.3 Scenario Discussion
  • 7 Security aspects of MCP interworking
    • 7.1 Overview
    • 7.2 Security architecture
      • 7.2.1 Security architecture overview
      • 7.2.2 MCP Host and AI Agent
      • 7.2.3 PAT Issuer (OAuth Authorization Server)
      • 7.2.4 MCP Interworking Proxy Entity (MCP-IPE)
      • 7.2.5 oneM2M CSE
    • 7.3 Security procedure for MCP Interworking
      • 7.3.1 Security procedure overview
        • 7.3.1.1 oneM2M-side trust establishment prerequisite
        • 7.3.1.2 (Optional) DAS authorization data availability prerequisite
      • 7.3.2 Authorization and Token Issuance phase
        • 7.3.2.1 Protected resource discovery procedure
        • 7.3.2.2 PAT Issuer discovery and client registration procedure
        • 7.3.2.3 Dedicated supporting AE assignment / registration and actual AE-ID acquisition procedure
        • 7.3.2.4 Authorization code with PKCE and PAT issuance procedure
        • 7.3.2.5 MCP-IPE verification material preparation procedure
      • 7.3.3 Protected operation phase
        • 7.3.3.1 Protected operation overview
        • 7.3.3.2 Common protected request pre-processing procedure
          • 7.3.3.2.1 Token extraction and request validation procedure
          • 7.3.3.2.2 PAT cryptographic and claim validation procedure
          • 7.3.3.2.3 Token acceptance state handling procedure
          • 7.3.3.2.4 Token-level deny-by-default admission and capability gating procedure
          • 7.3.3.2.5 Abuse mitigation and audit procedure
        • 7.3.3.3 Capability exposure and accessible privileges listing procedure
        • 7.3.3.4 Protected tool invocation request procedure
        • 7.3.3.5 Tool execution and oneM2M mediation procedure
        • 7.3.3.6 CSE authorization and execution procedure
        • 7.3.3.7 Response normalization and minimal exposure procedure
        • 7.3.3.8 Token acceptance update handling procedure
        • 7.3.3.9 Operational scenarios procedure
          • 7.3.3.9.1 Sensing scenario (Retrieve state)
          • 7.3.3.9.2 Actuation scenario (Update desired state)
          • 7.3.3.9.3 Multi-step mapping scenario (Retrieve-then-conditionally-update)
      • 7.3.4 Token Reissuance phase
        • 7.3.4.1 Reissuance trigger and client guidance procedure
        • 7.3.4.2 New PAT issuance procedure
        • 7.3.4.3 Revocation and reissuance change notification procedure
      • 7.3.5 AE de-registration and cleanup phase
        • 7.3.5.1 Dedicated supporting AE de-registration and cleanup procedure
  • Annex A: Title of annex
  • Annex B: Title of annex
    • B.1 First clause of the annex
      • B.1.1 First subdivided clause of the annex
  • Annex: Bibliography
  • History
Copyright © 2024 oneM2M Partnership Project