Summary
- The IAB plans an invitation-only workshop in Prague on 11–12 October to document deployment experience, obstacles and open questions in post-quantum authentication.
- Its call for papers draws a clear authority boundary: the workshop is not meant to compare, recommend or converge on an approach, select algorithms, standardize them, or direct IETF and IRTF groups.
- The evidence sample will nevertheless be curated through paper weighting, invitations, attendance decisions and confidentiality choices. Those are legitimate workshop tools, but they must remain visible in the report.
- An evidence-to-claim ledger can distinguish participant experience, organizers' synthesis, IAB advice and any later IETF work without exposing protected operational detail.
A workshop built around a negative power
The most important sentence in the Internet Architecture Board's new call for papers is a list of things the meeting is not empowered to do.
The IAB plans to bring implementers, operators and protocol designers to Prague on 11 and 12 October 2026 to examine why post-quantum authentication is moving more slowly than post-quantum key establishment. The stated goal is to document deployment experience, challenges and unanswered questions. The workshop is not intended to compare, recommend or converge on a particular approach. It will not select or standardize algorithms.
That negative mandate is a governance asset. Post-quantum authentication touches certificates, identity tokens, hardware security modules, trusted platform modules, secure elements, and software and firmware signing. A meeting that collects constraints across those systems may be useful before any standards body decides what work belongs where. It becomes less useful if acceptance into the room is later treated as a technical endorsement, or if the report's synthesis is read as consensus.
The call establishes another boundary. A report is expected on the IAB Stream, but the workshop is not intended to direct IETF working groups or IRTF research groups. Organizers may identify a venue for follow-up. That makes the workshop an input to possible work, not the work's decision procedure.
At the 31 August cutoff, the evidence pipeline has barely opened. Position papers are due 4 September. Invitations are being sent on a rolling basis, with outcomes promised by 14 September. There is no final attendee list, agenda, note set, report or IAB advice to assess. The current news is the design of the process.
The evidence sample will be selected
Attendance is invitation-only and planned as an in-person event. Remote participation may be allowed at the Program Committee's discretion. Applicants are encouraged to submit one- or two-page position papers grounded in real deployment experience. A statement of interest is also allowed, but papers are said to carry more weight in shaping the agenda.
Submission does not buy a speaking slot. Papers are inputs to agenda construction, not promised talks, and not every submission will be presented. The Program Committee may also invite key participants without requiring a paper. Relevant papers from people who do not attend are welcome and may be published.
None of that proves improper selection. A small workshop needs curation. A deployment discussion may also need people who possess evidence but did not see the call, cannot prepare a paper or cannot travel. The governance point is narrower: the final evidence base is not a census of deployers, and admission is not peer review of every factual or technical claim.
The report should therefore describe the selection perimeter. It can publish counts for papers, statements of interest, direct invitations, accepted attendees, non-attending contributors, remote participants and declined or withdrawn submissions without ranking people or exposing confidential applications. It can also explain which sectors and deployment environments were actively sought, and which remained thin or absent.
That receipt would not make the room representative of the Internet. It would let readers know what kind of sample produced the observations.
Public, unattributed and protected evidence are different states
The call expects accepted position papers to be public, while allowing an author to request that a paper be withheld or its material used without attribution. Discussions may use the Chatham House Rule. There will be no public recordings or minutes. Collaborative notes are expected to remain available as a public reference, except for portions covered by that rule.
These choices can improve the evidence. An operator may be able to explain a hardware limit, certificate migration failure or procurement constraint only if a customer, product or incident cannot be identified. Requiring every fact to arrive with a public corporate name could select for evidence that is safe to market rather than evidence that is important to understand.
But confidentiality changes what a later reader can verify. A public paper can be inspected and cited. Unattributed material can inform a finding but cannot carry the same provenance. A protected discussion may expose a real pattern while leaving outsiders unable to test its scope. Collaborative notes may be public yet incomplete by design.
The answer is not to discard protected evidence. It is to preserve its state. A conclusion supported by three public deployment papers is different from one supported by a single protected intervention. Both may belong in the report. They should not look identical.
The report needs an evidence-to-claim ledger
For each material observation, blocker or open question, the final report could carry a compact provenance record. It would identify the evidence class: public paper, public note, presentation, invited intervention, protected discussion or external source. It would record how the source entered the process: submitted paper, statement of interest, Program Committee invitation or contribution without attendance.
The record would then state whether the evidence is public, withheld, unattributed or protected; whether it is single-source, independently corroborated, contested or unresolved; and what uncertainty or counter-evidence remains. Finally, it would point to the exact report claim and label the authority of that claim: participant view, workshop observation, organizers' synthesis, IAB advice, proposed follow-up question or later IETF work.
This is Daniel Kade's proposed reporting design, not a requirement the IAB has adopted. It can be implemented as an appendix or a table rather than burdening every paragraph. Sensitive details need not be revealed. A protected source can be described as, for example, one deployment class in a regulated environment, corroborated by a public paper, with identifying facts withheld.
The crucial field is authority status. An observation may be widely shared by attendees without becoming IETF consensus. Organizers may synthesize a pattern without making it an IAB position. The IAB may later offer advice without choosing the text or outcome of an IETF working group. A follow-up proposal may open a process without predetermining it.
IAB authority is real, but bounded
RFC 2850 gives the IAB responsibility for architectural oversight and long-range planning. It specifically permits invitational workshops for in-depth review of architectural issues. The resulting report may advise the IETF community and the IESG.
That charter matters in both directions. The workshop is not an informal private meeting with no institutional consequence. An IAB Stream report can shape attention, frame questions and influence which work appears urgent. But the charter describes advice, not a substitute standards process.
Recent precedent shows how that distinction can be written. RFC 9969, the report from the IAB's AI-CONTROL workshop, says that recorded views belong to participants and do not necessarily represent the IAB. It also says the report follows presentations and discussion notes without attempting to capture consensus. Its appendix records public papers, withheld identities and Chatham House treatment.
The post-quantum workshop need not copy that report mechanically. It should preserve the same type discipline. A workshop report is an Informational artifact about a selected inquiry. If a later working group evaluates a proposal, its own charter, adoption, issue resolution, implementation evidence and consensus record remain the relevant authority chain.
Heng Lu's distinction between stakeholder and principal provides the commissioning discipline here. Participation can contribute evidence, expertise, warning, objection and technical judgment. It becomes dangerous when presence is inflated into authority over absent parties. Applied to this workshop, the lesson is not to distrust experts. It is to keep expert evidence legible without turning admission into representation.
Sources
- IAB — Call for Papers: IAB Workshop on Accelerating the Deployment of Post-Quantum Authentication
- IETF — Post-Quantum Authentication: Up Next
- RFC 2850 — Charter of the Internet Architecture Board
- RFC 8980 — Report from the IAB COVID-19 Network Impacts Workshop 2020
- RFC 9969 — Report from the IAB Workshop on AI-CONTROL
- Heng Lu — The Multi-Stakeholder Mirage
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

