Summary
- Revision 05 of the individual Authorization Posture Mechanism draft adds a detailed IPR section describing two pending US patent applications and possible RAND licensing; these are statements in the draft, not independent findings about the patents.
- The note points readers to formal IETF disclosures as authoritative, yet the Datatracker IPR relationship API returned zero records linked to this exact draft at the 13 September 2026 reporting cutoff. That narrow database observation cannot establish that no other filing exists or that anyone breached IETF policy.
- Daniel Kade proposes a two-record implementation-rights docket: preserve the immutable draft revision and its claims, then link it to the separately updateable disclosure record used for adoption, procurement and implementation review. This is editorial guidance, not an IETF requirement.
One revision created two records to read
The significant change in revision 05 of draft-vicente-oauth-apm is not a new authorization outcome. The 04-to-05 comparison is dominated by a new “IPR Considerations” section. It says that technology described in the document is covered, or may be covered, by two pending US patent applications; names Sanctum SecOps LLC as owner and Brian Vicente as inventor; and says licences may be available under a separate written agreement on reasonable and non-discriminatory terms.
Those are the draft's representations. They are not BTW Media findings about ownership, validity, scope, essentiality, infringement or enforceability. The applications are described as pending, so the note does not supply public application numbers. It also narrows the stated licensing posture to “Necessary Patent Claims” and lists exclusions for optional features, proprietary enhancements, non-compliant implementations, unrelated products, hosted control planes, managed services, trade secrets and claims outside the document's scope. Reciprocity, defensive suspension and remedies may apply.
Publication of the draft grants no patent licence.
The same section says that IPR disclosures filed through the IETF Datatracker are controlling and authoritative. That sentence creates the central operational problem: a reader now has an immutable revision containing a detailed notice and a separate disclosure system intended to carry the formal, updateable record.
At the reporting cutoff, the official iprdocrel API query returned HTTP 200 with total_count equal to zero and an empty object list for this exact document name. The finding is deliberately bounded. It does not prove that no disclosure exists under another document identifier, that no submission is in progress, or that Datatracker cannot lag. It is not a compliance judgment.
BCP 79 makes the separation consequential
The IETF's IPR process page and submission instructions direct participants to a formal disclosure system. BCP 79, published as RFC 8179, sets out disclosure and licensing-declaration procedures, including mechanisms for later updates or withdrawals and rules governing reliance on licensing statements. It also says specific IPR and licensing information should not be placed in RFCs or IETF Contributions; readers are to consult the online disclosure page.
That procedural architecture is why copying a paragraph out of revision 05 is not enough for an implementation-rights decision. A draft revision is excellent evidence of what the authors wrote at that moment. It is a poor substitute for a record whose identity, submitter authority, updates, withdrawals and licensing declaration can be followed over time.
The distinction should not be inflated into a verdict about whether the new section complies with BCP 79 or whether a formal disclosure was due on a particular date. Those questions require facts and authority the observed records do not supply. The IETF itself says it does not determine the validity or scope of asserted rights, and it does not decide whether particular terms satisfy a RAND commitment. A registry entry is notice and provenance, not patent adjudication.
The protocol may still matter before its status changes
The Datatracker document record showed revision 05 posted at 05:37:48 UTC on 13 September 2026. Its history and API state identify an active individual Internet-Draft with no stream, no responsible Area Director and no formal intended RFC status recorded there. The text header says “Intended status: Standards Track.” That is an author-declared destination, not proof of working-group adoption, IESG approval or publication as an RFC. The running-header change from “Network Working Group” to “Web Authorization Protocol” is likewise not institutional adoption.
The technical proposal is concrete enough to attract experimentation. APM would let an authorization server evaluate a client certificate or DPoP key, an access token and an integrity-protected device-posture statement on each privileged request. The result may be full permission, reduced scope, restriction to particular methods or full denial. The mapping from a degraded posture signal to an outcome is implementation-defined. A reduced scope is additional enforcement for the request; it does not mutate or revoke the original token.
Those distinctions matter to rights review. Mutual-TLS OAuth, DPoP, Rich Authorization Requests and OAuth authorization-server issuer identification are published specifications that provide surrounding mechanisms. Their RFC status does not transfer to APM, and implementing them does not answer whether a particular APM implementation would practise a claimed invention.
Revision 05 also retains a note that an experimental Go implementation remains private until counsel hand-off is complete. Its proposed authorization_details type is unallocated. These are useful readiness signals, not evidence of interoperable code or registry assignment.
Build an implementation-rights docket with a join
Daniel Kade proposes a two-record implementation-rights docket. The first record should freeze the technical artifact: document name, revision, publication time, exact text and XML hashes, process status, affected mechanism, relevant sections and declared implementation state. The second should track the formal rights record: Datatracker disclosure identity, submitter and authority, patent or application identifiers—or an explicit unpublished state—rights holder, licensing commitment, exclusions, reciprocity, defensive suspension, updates, withdrawals and counsel review.
A controlled join between the two records should name the technical sections potentially affected, available design alternatives, the implementation or procurement decision, responsible owner, confidence, unresolved questions and the trigger for the next review. The join must support “not yet linked” without silently converting that state into “no rights”. It must also retain superseded declarations instead of overwriting the decision history.
This is consistent with Heng Lu's Policy Mirror: preserve what an authority actually published and keep the decision layer visible. The Minimum Initial Specification argues for a small shared surface while leaving later choices local. Why BTW Media Exists supplies the newsroom discipline: report the record, its institutional weight and the uncertainty between them.
Sources
- APM Datatracker record
- APM document history
- APM Datatracker API record
- APM revision 05
- APM revision 04
- APM revision 04-to-05 diff
- Datatracker IPR relationship query for APM
- IETF intellectual-property process
- IETF IPR disclosure instructions
- RFC 8179: Intellectual Property Rights in IETF Technology
- RFC 8705: OAuth 2.0 Mutual-TLS
- RFC 9449: OAuth 2.0 DPoP
- RFC 9396: OAuth 2.0 Rich Authorization Requests
- RFC 9470: OAuth authorization-server issuer identification
- APM revision 05 XML source
- The Policy Mirror
- Minimum Initial Specification
- Why BTW Media Exists
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

