| Internet-Draft | ZTDS Protocol | September 2026 |
| Sibiryakov | Expires 27 March 2027 | [Page] |
This document specifies the Zero-Trust Data Sanitization (ZTDS) protocol, an architectural framework and execution standard designed to eliminate personally identifiable information (PII), protected health information (PHI), payment card data, and corporate credentials from unstructured text payloads prior to ingestion by remote Large Language Models (LLMs) and autonomous AI agents.¶
ZTDS enforces strict in-memory execution within volatile Random Access Memory (RAM), ephemeral surrogate tokenization, tab-isolated session mapping, and mathematically verifiable zero network egress of raw identifying data. Reversible mapping is executed strictly on the client or private host boundary, precluding intermediate cloud proxy interception, prompt injection exfiltration, and persistent vector database poisoning.¶
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.¶
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."¶
This Internet-Draft will expire on 27 March 2027.¶
Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved.¶
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License.¶
The rapid deployment of frontier generative artificial intelligence (AI), Retrieval-Augmented Generation (RAG) architectures, and autonomous multi-agent systems has exposed a fundamental security paradigm failure. Millions of enterprise users, developers, and autonomous software agents continuously transmit unstructured natural language prompts, source code repositories, clinical summaries, and financial ledgers to remote foundation model inference endpoints.¶
Legacy enterprise data loss prevention (DLP) systems rely on intermediary cloud proxies or central inspection gateways. When applied to modern generative AI workloads, this architecture introduces four critical vulnerabilities:¶
ZTDS replaces network-boundary inspection with a host-native, client-boundary sanitization topology [ZENODO-ZTDS]. All entity detection, de-identification, and surrogate replacement occur within volatile memory on the originating client device before any TCP/IP socket serialization.¶
Traditional Cloud DLP Architecture: +--------+ WAN Cleartext +-----------+ WAN Cleartext +-------+ | Client | --------------> | Cloud DLP | --------------> | Cloud | | Device | <-------------- | Proxy | <-------------- | LLM | +--------+ (Risk/Latency) +-----------+ (Audit Friction)+-------+ ZTDS Zero-Trust Endpoint Architecture: +-----------------------------------+ | Client Host Execution Perimeter | | +-----------+ +-------------+ | Sanitized WAN +-------+ | | Cleartext | --> | In-Memory | | ---------------> | Cloud | | | Payload S | | Engine T(S) | | <--------------- | LLM | | +-----------+ +-------------+ | Surrogate WAN +-------+ | ^ | | | | Local Inverse v | | [Volatile Session Map R in RAM] | +-----------------------------------+
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.¶
[NAME_1]", "[EMAIL_2]") that preserves grammatical structure and semantic roles for downstream language models.¶
Let an input text prompt or agent payload P be a finite sequence of tokens partitioned into non-sensitive tokens U and sensitive tokens S:¶
P = U UNION S, where U INTERSECT S = EMPTYSET¶
Where S = {s_1, s_2, ..., s_k} represents discrete identifying entity substrings matching statutory, medical, financial, or organizational classification taxonomy.¶
Under the ZTDS protocol:¶
Any implementation claiming conformance with the ZTDS standard MUST satisfy four non-negotiable invariants:¶
Under no operational circumstances SHALL cleartext sensitive entities S or session mapping pairs R be committed to non-volatile secondary storage. This prohibition explicitly bans:¶
In browser runtimes, session mapping state MUST be tab-isolated (scoped strictly to the execution context of the originating browsing context) to prevent cross-session or cross-tab side-channel memory leaks.¶
To prevent human perceptual latency and avoid pipeline stall conditions in real-time autonomous multi-agent loops, the sanitization transformation T MUST execute with deterministic bounded latency:¶
The sanitization engine MUST be completely self-contained. All pattern compilation, regular expression matching, checksum verification (e.g., Luhn algorithm for payment cards), and surrogate substitution MUST operate with zero external network connectivity.¶
Conformance is verified using the Airplane Mode Audit: the host device MUST successfully perform complete entity detection, substitution, and inverse reconstruction while all network interfaces (Ethernet, Wi-Fi, cellular, and loopback sockets to remote hosts) are disabled.¶
When distributed agent swarms or collaborative enterprise workflows require transferring session maps across host boundaries, the session map R MUST NOT be transmitted in cleartext. Serialization MUST enforce authenticated encryption with associated data (AEAD) using XChaCha20-Poly1305 with a 192-bit cryptographic nonce and key derivation via Argon2id [RFC9106]. The intermediary relay server MUST act exclusively as an opaque blind store with zero computational ability to derive the key or decrypt cleartext entities.¶
The ZTDS operational lifecycle progresses through six sequential phases executed within the local host boundary:¶
The cleartext payload P is received by the local host interface. The engine performs lexical scanning across standardized entity taxonomy classes (Section 4). To prevent catastrophic regex backtracking (ReDoS), all evaluation expressions MUST conform to linear-time deterministic finite automaton (DFA) matching semantics.¶
Each identified entity s_i is registered and assigned an indexed synthetic surrogate m_i. Surrogate formatting adheres strictly to bracketed syntactic labels (e.g., "[NAME_1]", "[IBAN_1]"). If the identical entity string s_i recurs multiple times within the same payload, the engine MUST map all occurrences to the identical surrogate token m_i to preserve coreference resolution for downstream language models.¶
The association pair (m_i, s_i) is committed to an in-memory hash map R. The map structure is tagged with a cryptographically secure random session identifier and marked for volatile lifecycle management.¶
The sanitized payload P_sanitized = U UNION M is serialized and transmitted over TLS to the remote foundation model inference provider. Because raw identifying strings never leave the client boundary, the remote provider's logging infrastructure, fine-tuning pipelines, and prompt caching systems ingest strictly synthetic surrogate identifiers.¶
Upon receipt of the inference response P_out from the foundation model, the client runtime parses the stream for surrogate token patterns. Each occurrence of m_i is matched against local session map R and replaced with corresponding original value s_i:¶
Input Text: "Transfer $50k from Alice Smith acct 12345678" Sanitized: "Transfer $50k from <tt>[NAME_1]</tt> acct [IBAN_1]" Model Output: "Confirmation: scheduled transfer for [NAME_1]." Reconstructed: "Confirmation: scheduled transfer for Alice Smith."¶
The end user or local consumer receives complete grammatical fidelity without any cleartext exposure to the cloud model provider.¶
Upon user session termination, tab close, or explicit pipeline teardown, the host runtime MUST execute a zero-fill overwrite or release of the memory buffer hosting R. In runtimes lacking manual memory management (e.g., JavaScript engines), object references MUST be nullified immediately, and WeakMap structures SHOULD be utilized to allow instantaneous garbage collection.¶
To maintain natural language fluency and attention head alignment across diverse foundation model architectures (Transformer, SSM, MoE), surrogate tokens MUST conform to standard bracketed uppercase identifiers:¶
| Entity Classification | Canonical Token Format | Syntactic Example |
|---|---|---|
| Personal Full Name |
[NAME_N]
|
"John Doe" -> "[NAME_1]" |
| Electronic Mail Address |
[EMAIL_N]
|
"user@enterprise.org" -> "[EMAIL_1]" |
| Telephone / Mobile Number |
[PHONE_N]
|
"+1-555-0199" -> "[PHONE_1]" |
| Government / National ID / SSN |
[NAT_ID_N] / [SSN_N]
|
"123-45-6789" -> "[SSN_1]" |
| Payment Card (Luhn Validated) |
[CARD_N]
|
"4532...8812" -> "[CARD_1]" |
| International Bank Account (IBAN) |
[IBAN_N]
|
"GB29XAAA10203012345678" -> "[IBAN_1]" |
| Protected Health Identifier (PHI/MRN) |
[MRN_N] / [PATIENT_N]
|
"MRN-889104" -> "[MRN_1]" |
| API Keys and Cryptographic Secrets |
[SECRET_KEY_N]
|
"sk-live-99f...8a" -> "[SECRET_KEY_1]" |
| Network IPv4 / IPv6 / Hostname |
[IP_ADDR_N]
|
"192.168.1.104" -> "[IP_ADDR_1]" |
In enterprise agent architectures where an upstream agent creates a session map that must be de-tokenized by a downstream agent running on a distinct host node, the session map MUST be encrypted prior to transit across intermediate networks.¶
The cryptographic handoff protocol mandates the following primitives:¶
Compliance with this specification requires verifiable testing under adversarial boundary conditions:¶
The following test vector illustrates a standardized ZTDS execution sequence:¶
Vector 1.0 (Clinical / Financial Hybrid):
Input Payload:
"Patient Sarah Connor (MRN: 902-114-88, Phone: +1-555-0144) authorized
payment using Visa 4111111111111111 to Dr. Marcus Vance."
Sanitized Payload Egress:
"Patient <tt>[NAME_1]</tt> (MRN: [MRN_1], Phone: [PHONE_1]) authorized
payment using Visa <tt>[CARD_1]</tt> to Dr. [NAME_2]."
Volatile Session Map R:
{
"<tt>[NAME_1]</tt>": "Sarah Connor",
"<tt>[MRN_1]</tt>": "902-114-88",
"<tt>[PHONE_1]</tt>": "+1-555-0144",
"<tt>[CARD_1]</tt>": "4111111111111111",
"<tt>[NAME_2]</tt>": "Marcus Vance"
}
Inference Response Inbound:
"Billing confirmed for <tt>[NAME_1]</tt> under clinical file [MRN_1]."
Restored Client Display:
"Billing confirmed for Sarah Connor under clinical file 902-114-88."
¶
This document has no IANA actions.¶
This entire document specifies security and privacy architecture. In conformance with BCP 72 [RFC3552], the following threat scenarios are analyzed:¶
Adversaries executing indirect prompt injection attacks against LLMs attempt to manipulate model context into revealing private user records. Under ZTDS, because raw PII never enters the model context window, prompt injection attacks cannot exfiltrate original credentials; the attacker can at most observe synthetic surrogate labels.¶
If an adversary achieves root-level compromise of the client operating system, they may inspect volatile memory buffers. To mitigate this, compliant implementations SHOULD use memory locking (e.g., mlock on POSIX systems) to prevent volatile memory from being paged to unencrypted swap disks, and explicitly zero memory buffers upon deallocation.¶
If an input prompt naturally contains text matching the surrogate regex syntax (e.g., a software tutorial discussing "[NAME_1]"), the engine MUST escape or disambiguate literal brackets using namespace prefixes to prevent accidental de-tokenization collision.¶
In accordance with [RFC6973], ZTDS provides deterministic technical and organizational measures (TOMs) satisfying global privacy statutes:¶