<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-31" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-31"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur, Belgium</organization>
      <address>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Serhii Nikolaichuk">
      <organization>The Capital Index, Austin, Texas</organization>
      <address>
        <email>nikolaichuk.s.f@gmail.com</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="13"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 232?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader intra-handshake (aka early) attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 236?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 874?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA829yXLrSLIouNdXwDLtvjrSFTiPpzo7kyIpkpKoidR47BkP
CARJiBgoDBxUmdd607v+gbbutl4+6x/o1d3Vpr/jfkm7ewAgwAESTp2TVfXe
zUyBgIeHh4dP4e4hiuKBozoa+yz81DEcSxInkqHYE2nKhE/SVBKakqWtDoWa
4zDbkRzVNIS6adiqwiymCG3J0keuJnyq3zfFXCZXEvP5UrUsmCOhft/rCeVU
UQB4gs3mzJI0wXQmzIKfmja+4s4ExxTYcsZkB4DRF9lMKgM/yKauGuPDnw6k
4dBi8x3YxWP004EsOWxsWqvPgmqMzIMDxZQNSYd5KpY0ckQ1Ck4cSaom5rMH
tjvUVdsGqM5qBm93mv1TQfhZkDTbBCxUQ2EzBv8wnJ+OhZ+YojqmpUoa/tGp
ncC/TAv+67Z/+tOB4epDZn0+UACTzwcy4MgM27U/CyMAxg5gUvkDAGwx6bNQ
u23WDhamNR1bpjv7LPSatf7BlK3gkfL5QBCFWkeQxjCqjX9s0kJa0wJ/ji7G
wZwZLiDwsyB4wB9a+Aef3wOMCZQWWvgTPtaBEPjKb2wp6TONpWAp8LlkyZPP
wsRxZvbndDr0YxrAAWjVmbhDoJDuTiRdlxTRtSVdEm3JUiQrvYvcP8FnmoSY
w2c+4J2fpzj0lGruBJTev6SpiaPDQAeS60xMCykJgwoCcIjGueGnrjegcIcD
Cj0a8Cd6y7TGkqG+EV0/C/07oWExG5b+WGgxS5eMFb3FOMWCiQ8I8xTH/DfH
FRX+VUphP+0Y/16V5AmzNWkuNNwhW03NXYPXTYs9MGnOIkPiV9JvCv8M12LX
AGdMMsSuZKlMOJPkV5c5uwa4M1TYorbqrHBnXkq6ax0LJ0wbq64eGfMFwekI
LvXCwf3mGvh6arhzfj3TGA9N4cTdNWoPVms8kVSh5UqGUDOAs0cmkJZ2dZ/J
E8PUzPEKpp86Fi4cBf5Zn6iGFMFoqLlMMccGjPnbGJ/to0R9wozxUjWENow2
3oVPZ729I0NIroUbzHp/jLZkLpgh4Kx/2IQnsOpGNpcpZoqFQjw659IKZLgl
qzDuTnwWqiNPItCn8EmK8U9+s+n3lDzZBbxhCefuUNWklVCb6MwRzv/+n3//
H3//z+mukRrXE1UTrpYwXSXEbZGhFSs1dWV3+ptJr0maqxtqCuDsZCxmTVRV
uFSnpiap8sTdOWx/woS6NFMd0D64ustjoebajgqbuA9CzI6Mb6xhpezUKJ60
zZRQTwndlPCgahrT7Xf46Vi4ZKj9NJRPkVHZXJJTemrBwfw2s0zHNFL6zt3U
lUA36aqmSgbsKUsdA3Mo6q6hr9sd8arbbNUiY80mqqmzsZSyXMNRdRY/xa46
BbU9EW5ckK0rg4l1U9NUY+dU25I9qWumNIVJy6T0e445GjFNuJCGNj4EVpYM
SYnyss6H+G0Cn8v4+T5cOiBwhZ48sUx550I3u52LTk24RurJpnaMI6YiQzlM
0n9jRLyZ91ZKAtodGHwHzkFJCpu6NYVa5DPB2WMn0RubFtAhEAQWRyTDB4Uq
/AyGiGe1gJ3Sv+jxWZB1IJy5BhPw82M+lGSNmbNWt4vFIgUSiKESHsMHKYM5
6Zk71FSZpp8uZCq5bDVbyQ02sEPkBlHcBhHM8MeBagx8zAaAGeEQqEz6nwjY
g+kC7H6X8pRk9Jf7lK+/os/PRPjGUzx7yCtabGb+GTTWVjE09mwMtGg+ZMMQ
Tj+QUtHJetCjQ9Ee+Ixv8gce9epm3ex5RiEng6DawtzVDNhqQ42h1W0xFNvw
jiRP4TdVAjscpkeGOJtNmE72On4KVqjtgd/BlfKcoYBOAw63TAah/auq/LJh
gArrNciVhC4yMa0D/NC8u2/wV7OlQqUSN8vmZadX+6fMk7lzJcUM1Qa96Frm
DP+Vpr/TG/jHTbXV7tVAgMqmLdY6UW7//hMJ830uH0UklvVdDYDOVVNjjmWn
ZUQ3bTPZxQ2WlpS5aoO/w+w0zWY+Go9Ffb5civp4XN6/F+7WQAWiALgzmxTJ
bZKEvyaoO30dn0rohOigXbkBtUU0m5ErJ4JLN0RFCY6OT0EwMFAYgX7qNx4F
lCAjFXzTmeRMwsTLlsBeGIPF8P2pV5gt8+LiJbcUl8vCP0i9/HegngwKVpJl
NnOE5hzcaUNmAph/E8FQQZ0yfeasyL0F19xBECi1LachORJKXbBthFq3AZ7r
vdi7vP5TCWmVgA1nhYr4krMW30bIpjJmGnCL2FsBfXQ7Ss9bpptOxM9GXgNn
Hqml7tqh4aknmDfz0LBXOGtcPNvZP/HJy1gWX+TiXBwtypP9E/cnJ3iT2zfp
jT3YYriVcKlnJlgaMKygmMZfHEFhDpMdQdI04CFpzIASQ7CpHRcp8+dMXc+9
jsWFtZyLk0q1kmjqGFsRfTkB1qCzEjkrb645OTaeuFCNrahLOAKF0qRuGiPc
No4KgriGwRpVxj3ojRzZDFlQ9EaMMYImK8psMEpTKnNGpGPxQVq3x0AVyUkv
8+xmefpyc3p2ITOJlbTC4HL8aOh24yn9YbOEaHltqXMJyC5asFbaBuv7Pwq3
NRGFhjyBZQc/mgm6qTBBURXBMB0BxWtkfzBfhMDOQNmA33riOEyJvNCDLcQw
UvYhLvHRSXNc9zPIS+l1LhbysDesQjW3nyA+wC1ijM09hGiZuNzTz/9qFBmb
+6lRfhktxGLe0sXZZPIt1GDmPEoOmIkmzZkI6meuWo4raTsIIjPLAb2KsVhb
WDCLccqYLpDmB1FhG6/9VJkVRzNxXC2M4R969Zuoou+liq4a6r8cSRCpGEVa
fdXBLHkBsyQnl76BHpYjR+kBAhN2qShrKsaud5AjMLy45QG65tU1kTQ/nCpR
1PYTpfhqyeK8Ui6I+nK+/DaiiIq0R5jsDuV/0Lxt8CiaafhqKkyY0o8mzAxN
1+ICxOxoUoyxX2MJ48juj6BM/6rev7r7p5BlPK68ivpoMgHzxJI/RJZOQ6xb
qq3C08ZVJ5XNpLLZQjGdL5eruUwllS9XivlKOfzirpAJmR4YBqE30GKJWCR1
U5+BgWaAK32KAS+wUQxJW+Gr5mhv0OTSnAe0Kr4bOKnX62LILEpTbFsT7RmT
RVURZcLsW2Im8EvXBI0vjaToD/0U2JgWPrTYCHAPUTBTTfeuU7lMtpyiZYZf
xdtalGjACxKauMLQdYBvxhSixSNDh43hOTqM1g7b30AW2x1d2kMkjJW4NjPU
JZlyYOCOQPaDNZCWHDlXTM8wvOexc3rBVGNiasp+StUlC1bLEB7Cb36Ajh3T
cP+//0PoqiCAwWqM/vgE87cnQgP+MYNtx6K/tiXDALnct+WJOYKJjDc+liyg
TG/CRjCxjTWamLpkA9fZNsxvA1UVdAE44bem6rzZdBRRh03ETq5PoyvV7fRv
m3+xhUu2EE4tSWcLssF6tA1hmVBF4FfChbQCdn0yXQuN7wbF323hKqI0qh8R
ArJmuoq/zUFfqRIsF63eUDPHafwuDTwG/x8cYouJtmiwhTjycRNtDzURUBPZ
cDYSNURNXAFqoqSK/GjAFvHQdu86Iw7eJGFr1zws4CWiB/j/sLkNF7ZGeN9F
KRdQy/dSvC8Ez6sNfbjhsAcR070sTTMnmsDcbRFwVscTkI7h2PSaIvIaW76r
xMjJ9V6x4C39bnHGFxwkV9gfix5rH6j+KZsX4xcbqRHnRhF9KZFhlkMYmY+9
JWYKmy+iioi8UXr3jep7b2Qz/hvABG8cl5Ekgz11kEqlDg5EURQkcMAxGnhw
gCdedCAuSKpuozKcWSa6HoKD54uwKho68OBgkuD/Eg3W/vdPCaO7h8fCl40o
6BrGxyOnACacKNJSnbY7DDF+oGSFT6hl7UNhMQHREcyNIhASZ431PAOXCyY6
MRfC0REFxI6ONtNcGE9zCQv5EVEItOgM6arK7BjAgcg9wpiYCepiNgHliaOg
6WrbR6iiLPCTmHUs2CqOuub3zdDRmEIrGmwvi726KrLv3/7mC74//oA/4vb3
H38c75xKeBBJAal3dOSC0EbsJGsF6KDVtAR6HgGyyCegdFzNsTEJRRiCpQRo
DFckSv3TJsBk11kMYvC3v3GNCuji0uFXEvo2yJl7PiOzBd4HqiKe4JKMSDrC
dwK3FQCUZ5Q4Jp7iXVvmPboIxwK4AiCtazNMlxBzqYwAAoYZNiOpBnAtU3Fl
lQd0CCELVp8tOF9NwP8RhoxhhHNqmAsNo02hyWpsDsyDSE0Z6lMwq1NC3bVA
RTva6hjfshiR6ejIWZhBCpOf5XQsmAYj8xafVlMZEROZ4Dt4l/g1eLmaykZf
9kBUjon5jY3Xy6kCn8HWJ6VUXiAxa09gJtJYAlnp0HSGlikhrTaDv/s4XUae
pdi4pgmko2h80qiyaVP4ykvWokWezXzZHuIjzi0zaUZfUzzY5hSTfTIKTKX8
L76S60wrDCoPGSIAVhDYYzAdXNP1C3yQNXNx5AC8NxwenQMEAaaJH1PQGjEF
htddA/nhG5knBV6IgJaEz5XHHr/oQG1EOOqHEGZE4Ah9QTxvhiFJDWOEkwbr
gjj+C8Xr4VUOPOTPeBJeVxVFYwcHP5NnhPiS1ty3PwXPooTN7UsbXDlgDVgm
WEma0Ruj+XyUUeDrmWlLGpDBYmMwL2lKMOfFhAxnBLaiNccl8A4FbNmckQDG
uCt6/pYDbwLZwcNPgSln6oChb2YJuJ6YDwiamm8TjxGnAFhhsmpz0Sw7Jqw7
SglcZkBcVciK9w55dNAAEqgZHaxgU9/x3A5juRtD2nQ4K/4uYRtlQ3wszTFS
i14nAIoXekl48BhP9+DHMEuOXIuI7G824IsaiCMu1YkHLRDsfE8gKr6vGOYF
Wm3fUZQDRxF+F2mM3edFtPp89ptSGv7/JgkiPmrCeRMSkanjLA2eNxqZqTdP
2Bhr+bIlWOBXeAlxxm2ApqXpjidbk/B4TGFgvcJ+n/G9rBqx5ICd+LNwBZIT
BcXBB/ahsyYfsjgPApKqxkDxBi4xPM3PLv3H8VhyQQqGEXiCipcrQ88i0RQ/
HQYMyoPfweVPCb8LJ5vDwrM7myGLwH/Vgk3wO3yRxQ/qFBj5r//lf7cJpmGi
BfQ72PC/C18QWWZl14bhNyVbpMHXYHg0YqQ9gIc0fG5j+PD8d6CR+95o5Dga
eUSD8qUxp9kkIRIZOP+9B87zgQs4cA8YkVk0f+58kciMjF/43uMX+PhFor+p
w0NOdODhn3PE1j/noygUvzcKRY5CKQaFAg6/VwHvRGgzjqUzhq6mjZ7/kA8P
3iTDzG873ZWsqWvfusoq5Z9bgvuGoUJZDvtxqZkyOvwrOFz+4fw8k6qkclGP
yzbAi3bwcKs0JlQWM3KbgbfT7kwDw87GyEMxnc2lHxhO1xJreFCIJ7IYbOjj
t2L96vK002he9ju1i1LLGxmGrtcjbnKv0/rI/A/BOJEUk8LzICte8PD3S4zU
2QlzgxppXwKRuzszZSTN2hByZwqdPKOkXIOT1JQOrxA8giODkrHBQJNZeobx
VHApAEF0eCjw4juC4gIJRBrjcM2Mpe/NjCXOjOWdzHgMm+F4zZGgL2LDBqA5
AkTL3xvRMiL6t888RPTLT1uyHgy8TcsWEfedsbUN9NMfBwf/8R//cfDAAk9c
8pUcPICJw/8Hx8Q37+AvdDLIjRiC27HWcwc79Bx9u1+3ubYX+DvYcibReQyh
ayie7Yro6aqjjteaEL9XVJucIGQ4H9VwhoDKwB28clGVwjZH54DBzodPJUdQ
HUGXVgd0XgVUgAX1E0LA4FHhTfjIMtG7WvtNIkxqBPpf+ASOJ9OE/GEwfT6p
uGlLGtjFaI2BtYA5OzAq6BvNBA5XDrhNFUpEOUbjHA1Vw3sCWkkHkGgQ8bMM
P+lHWh9RH4y4Wa6oIwpT4xRhMjhsjzuB3qcwvjdx27VYQBCQWAYICfsAqKCC
kYCWFScuKqkUscwBMg3s3hkW7wxBaeIiaCaaGDhAJEHjPSsHA2B0ZMjtk7/9
LZIchQEH23bhN3jPc2LB01bAhTj2wkg8EMK/xkhMJMQF34dcfW74dU2FabhS
V2Sa+juoGzAvD8RFnYVXF9ZIGGEMBlkE10o3laghiJNCSDDimvpxc9+xb4Yr
wcb9u0Jnxhjjr8hVMORXkBGO9FXAUw+QpBQkIHrUPVbAvG1aJMGTo8j5pxQR
Eb5I4zH6fQ77fvIoAHlI0TIMYpCE8NxTJbx3lV1z3et2wapRBqCG2grzJTEa
4M/RNby/Ut4CjnjQx0eCXE/fSt/hVhIPUCIRGXxhZRmOwEaF/O4gMnEnbT7u
9nB9gWuCElXCnRE62/yE2KPfCgMsjMOd42zHj2GMICgCM9XMBUnOhSlQrIG4
BCSCt+t9+b12xcEvABv/hHSHMIGtRqE0T0cfgP19bYLRsZs/ZyiPg28kRfHC
O1Y0+k9U81w5gWspb20/QkHF9FIGZiibAUI0XVayvQieim+B0+xFikDYW8wB
p9nbBXxcivoAoirh7wmMLcd3P99hJI+Fw6PkcFljVyc/cDFZCZHxCasgSksB
+x2TAJ57j8qgh3Z/e8zPNyeMT/PoyJ8dzCgcFX5P4wKirvGC9TMjlSl8FzSX
oDGRSYSeC9vfIiXvhU6FHnzogizs+Tn6AGEo4VYGaF8uO70+bCrHUmV7LVKM
uZKCTeakxuY8jawveq+k5bltH6bQRyVhjE6PBxa8Vqq2xLGvg6AoRmnTPJ4K
dpkoisH/AQg/SIu2GsCgSD64sgL/LRt9nPMMuwr8NxYdBG9ihWvwyH+rsH5U
9twT9IO6TFFd3ft0bX3txBdZ5oNhObTBjo5O4QP0uy3mHSwfC2141wGhgSFR
2AG+Ajs6woULkYlGxDMeG7H6GZhSBLZUUHH/gcTG3/FnIaD7Ke2TXVTdVr0+
2XYWWh4L2/WP3EjeLlsUOPwt3ewvwvcaYONk6geMsDP51hunsG8cYQd5c/QR
59bdH5FC90swd4HIfzuIrfRhD1Swr7hnLKBr/FchVDoNKg1MlDVMioG/N+eN
LNX3yPWtyxLK//zhQzBz/ieMof/wMSxH/jPGEBUpySbZzDOjbz1JvOfbtVBe
y8QkopjH6T3hCBbCJ4o340tYuEi1vaRQTEvhuso7wANrDKX4z+DUWWDicO+C
LCKHP8DMYg2VJ3p6YLJxT6XH5BTMKIuQ9hrB3KSHFwvea+tzAdADJ2xlooWN
lgU/JqJ5aAwmOKZDka8YWGmef0XT2O+yEGv80KEPeBdgQmF6Ip08SzPfk0Mb
BRYbw/9obeJHWFwtKDyNB4OWITyA9AxPu2YrHl9A8xheA4NTkxw0ycJ2IFU+
0Xwx2wRjZRQ6s8Dg9QLd9MKQaeiOg50FHif4WuAewPPw7BUTzWLs1IDj81YH
x1RaGCpwwWne15vnuCpAFTCA6DwZfxqplr5Ah4+mCI7zTHQNFVjbM/g4kpLQ
r58IXgYnOaIa2+iUMfNmuf7OCtwS9I1AqfduL1s+7kz5K6LgRyGP12uH4yEB
PjXrh412U/CCZcJc0lzGwTqrGfKmFtCfz8c2Rw7NhXE7j4ITNqWT0AlrKCXn
vrsOyQhjgOsIVz1cQtlazRxzbEkzcLZFTR1ayBQWIAXkwcwN0h/gZ/ITLt20
gNw+nb/eNq+vbvuDRq1f+8rLbjCQsj695yPx0yvZtGYmx52S9IgX1THulzCj
8HoPwc/k4IfPmPRngfnsbC/kX4n5GawgTwcAsqnKukqKKqdcNK8dSuyGpfVd
RiJwMBDHIUhXC3E2MySy2UJcSA44bAtGVVdsKWtA3TkPMTE77CjCrHkgReGH
6Hxtgan5md3Xi+b5J84Jh1/De9EGpDSFu0bAZoy6nABa6BJIto2+hKLKDjme
/KyOEWk3NqksuTanmcJGWCcEhr83t2NBxmiVQp/TPhQxz0Ro3J60eArIMX7E
vcw1r8HbPulp8uB5AVzMo4lKAT95qSiWcvD/oqF0SVd4YZGR9oPEdpqfNjpi
kL47dAErByMRuiLaQ7GcKRapa8ihH9GkSJlp4AZkgInhYkAHlsXi+XwgwlzN
k9CfBWk04t1sUFQ8g79V9AMpJkUXkN4AyLUwoGW7I49eWrAdvB3JJQezKBjx
9bbRazYbXwV+ksklBTG7BYNpK2JxicJRtkvJSF54MHCLkfNJ05C7B7BRAHvc
A5iKvWuR2B8dQhIpVOg3wpN5PwgSxOu386+5e6kwHTaJY1FlA48EKkzSRD4x
Aw9fgKlc3TtexU1DZd0ojxd+wIPOIXkSyl/X/OBbjlSDBlOcoOi7gme93sVf
bOGrKOIOo5FgZZnyi6XIM/er8OmL95KQTxXBJO1c9vq1i4uUruyMYJnwsm1r
wb/ptMf7QyQI6TWEw0M/eIgzgR2wXiagHfz3be0S/ptk9DVSFBGDVZu5IJhV
DTYzkQpIHMSMMc4ljX2H3plwLpiAdcIlsCcvaKWACRll9/m6zldwoZ3JHfQL
cyFeUJi5K81mXmwRyc3Nds/YODhVxxjCzcUaE6Et0W82RWlsgOEAzOGvnEjx
7AM/G5HSBtAzlQRYY/6jwLOyNkJRJGN0aWZ7ZwNeNiNyK8gPOj43KVnAT5MG
cbEu30XhH9bNG4cXFDKA+aVgdoz/wBNMwRRcA/ng/36PjPSxT2B4ccf/hN2P
4/73TZ/A8EdH1366YpeH8o+OABbMWySFoPnkDEyOfbP3Zh58htSI/YgPX68H
NhuM7MGqX98J7Qfh34n+wIcuwPv3jVT7EZoylksiN/wJF1tpXIRP3IA4XBte
/y7cduG35r1/cAH2BsfjxjVJAVOBJscEySDcNGOWGwYS0mQRhHH7dN8NDbl7
1lH7yJ95CDqd1woNsjiFT/3G4bvMJFxjrA/TlQCfTQMs/lPC6ZI5lA1uY2jQ
p4APMzDb/p3kiW+reSYf0Gk/OvGfIrL8jQ102r1uun8dIc3vPPGXbWzWncT4
+Ks0GlnEtfOvoeF+jxyJowSFySBHeJzS5OVzG+Oi6Z++B8uKlK/vurxLfN8i
j4z/4InwNEaMiVrrjg47oX7LJ+vhL/rh8X8HBUFn5bB98UtMiHuHpN/ySci3
3lBDvrAXvExT7utui3uQIBtyHX3mvpcc6OdjoFG7MPyAfgCbA+Wun819v+Bw
LQL0gA7haFN6bqCf+BbVVRHjMGx+RxUdj1b7WiwdXprfhVvXsNMazM3mh7S/
7uQbob+abYmX3W/eBqYWjcSN3r3q56PK5OM6Z9+bhAIKhWYdvc8o0h0uIIyw
WNqa2WXMr5EXr3ppX/J4dhdnv9/XzvDu8eMl6e9Ci4RXYJJ+Ewq1c/+diBpa
f3rqaRO/ZjcdaFZcz4kK+9uSJ3jeEQRAAgPdH6QLdri1EgECut2+TPtdCGlg
f7i2Z1qmAy0G/o2EmfGbcwq+hOmkzxunwpqsEf98/UXdYn4MgZOu55Pud4Ga
hvgucsz/MBkxHDgOTGCvaoJkTVi0XASbb6NCFHf17igPCpFrcOZgyfWdlMND
L8pKINcYf9nklb9gd4QubPWDn4UGldbA6/eRBIYGT25AGdlXdUwdYDylhufq
1dZVCfyQEKhW813Je56rgJKkSWd7REAWPn2BnzA9RTVUQmmdVsH8tApKzzC9
vAeAkCkLVzJ4Iug9c96MooAYBC9nCzAvOfRyuG2hF2b5gq1S125VfAcLWAI7
XRoPX5eZx6fKw5PVzneXhflVxciJ7vn4KY1pWrxLBo1aolG/eNTCpBPXkAnP
kM/Phil/RBwM/qYivUwuV86WwK0vpCPVmOtuMCnL5jV9DmM8HQ1DKPIKsAhT
IVcWTtkwhE+Qybeuw9g+/xK+HB0F55S/CO1Oq42dzHjRx+HR0X9HyF6LpjDs
++auw671SHFwiz7c0hZcaqMVAoOnXTsPvb4R/pc1H0WXJ6aJB9bfSDaz0440
5nl8GLan9MgsLUFQFE6JA/TRLuJ8AOMqFTV+K75jcz+uxVRWHJvZVK4Eg20h
PTa/EeFsZgvj+pYl9G0Jl1hQoVEewpeYXmMfSpDdhJ2euZqWLlZoG5c3Z3C/
Hm3HZCg6+40z8va/gryZixk2UdoMpdrgivLqVBu9DtixG9C3Moy3hMKOE98Y
Bij4e2yLZd8XO7nt/Vu/7fQ79dqFB78KO8tjML8xV6IR8v/gCMmpldsi19aA
/ODZp1the9RgS26Ntn26/IGlCfUeSTYInS3/yAH4yfKPHUH/wSPwU+V/fIRA
JmxX5oGX6GkTtMV0c87NvNn+PKvfhcI/MtrY/H4jxVKOn5V/gHilf2QQfqoe
HaXbbHTuut44pVQ+Zpy13R5YzdG037DtGraapQ1zmadAXXr1pWiN8iwqg+d3
kzGFKYiSsVqfJazA6QYz1ETUvYrV8Bl35OSdsie/PjBpin2Ovx7z/260v9Lx
1NcTSWlyDfY1dXSE8QJw1kxNifguFO4wbTxJTrHUsQezR8nhBJWm5j0A0Hym
mgZMYyp+ZMX2ixYl3s2fUrmad1531IMmVtkzycAO26YBfskX+uGdivyJqbMZ
uH2HRKRook6YAbaNRJpDcNUD5bwHKwOzDfXl8Yv5AF0Mh2AKANCcvucZuPfR
fPv9/WuEC9VBHw64Yp2vNgdFYcsmZhL88f3TDaO+HDfOg2S4L/5oH4a5mTfn
eXBfFuDSOtKMDltCfk3oKTjqoBODR1jXw51kxOjTFwrhR09B8bBI49aTV0YE
T9MudgULehiJMsMjpXTYr0rTh8E5qRj+jR+5ZjNiriJmMlnvuBTZ9Uut2/ge
p7D5TCETgF0PjKSjcrJLzM8mmvWbzQ16gRMXphVV/WxQagtI41ExFyEzWtFS
kqyTG6mYajroyFQqVkqFQgrM90wun6Faoj+R5gWkeSZMcyx+LFI8dsFn0nMk
jbkh9l7KkuhnEK+v0bD5a/6/B7w1EbguHp3WB+vFQjFT/XhXEO8DhFHgOYBe
0isidwISdXpa6/XfQ2+IL46wAWjwXwNTmmLv/F04lrLVci4JjvjBIWKY28RQ
Um5r3TWooQTGv44y0vsvHPv378jmWS/ZAKso838iubJJyZUlFKsbKJ5KQxBr
U6a8h+LIf3H9X/FMl818AEN4GPpgJ4a7DrKjkP/Exvo4y5gMZp4zHjKLNjUl
zwqbb2vKSEBSDjSlFmhK/6hEXkMMjl+wDm+tyI+OKEecohZ78wAwdCuvEz02
W5djyolO4wor5niDsqCVI16mss5d2ok5xfl5giiWuQUl/qGWEAuGZWwOTNLg
DXojDUvIMMKGPJRVf3Dg5ZZt1XGgxaOtUVsf88xMx7c8kmaBftpsScC7idBs
1ibt4ef3Khlo4I9XLnwiWlq6n4s1Z5qJRTyHXk1DZfODPaUO8XAqqbIQVwRR
3C6CqAqfikIs0I0CiXJkFzTXN4QlXIgY6gvejvCa1Mws8C50LKdeYbKUqhNz
wxpwo/KYWHqkYn4UXsFCGYX0U4pb+5SY6WAfmvCYxIShsFMnen55cFCzw2lT
sYm1hH9shxHYLg5m7nptgNasvEmurdpei4VqzIAtxVAp9vetvv68S/7xmW17
F++FRxHPZIX9u5qME07fGqA7OOiMhJXp8mYwPHlxRH4ml9Wx1VQbSXQziiwL
2J7etQX0owTb5AJ2wZNM5QmTp15/ou3C2a26WZVniMFjr2Kx5gUn0l1eAw0c
t8WS/USsQx2MQ9HjaLOtoyM/HIK1ZdY67nF0hJGPfc3LOAf+Szcr+PynBM+R
mmEaEln82Oz/9MtWB4n4GxTWjJ7keOr4e+7Yv8J0dHVMwg5YIj4CxpvowRxB
4eHMg6CUF7MDAoQPYHKpzEdOm9ZUSB7zPY5yNO+J4CHlTyt+UjQP1eKfjM3N
OeRBtfuHSO8dRe2YyIfiyt9hElGt5t+5JfTCbY3sg9pubRRk+Ua6IPHAVqy8
PMKc2KMNbYWYfpxBSbK803qjCq8J9kof4qUXu7pY/PUjB0dHR8HRERJ55LAg
FLmFwr6y5hAaOJ9PpEJFTHKeMUOkwNahZzNLXjXvrqYbn0xLHaPpgroCDWg0
ocRMgQcYqZjC5qn/QEsxUzo8wNarNUxtoo5oDy0qL1ZldYZNEmcmhikUwcRE
Zk9nYesFrqmGoPeSSAy/4F4iO56v5qaMIsDr9gChN/fe5bH1FQWF85RizSwk
ijxKAQAKHpqWBVtHQhFwyD+j0CU/JAxy6HGp7NEqRdShtnJRwth+8j3eWrcK
Opvt7GeBhTXBnSleOQje5ud4BSNYd+W1avDb6E38xojovvCodHy/OZpIyLWB
JeG41yitlgOyYPlM3srQ8+X82ns+6aMjReVFBsDFfpkT7xMANs6eQnqfdny4
o6O7PU1IcRDVsZk2CrcAxFoLZhnBLtloevve7qQxUfGRBR9ecjXay5Fe3N0f
NR4xkH5+vw/Kq7exOUKjvVHU/+nreLn6eshzh8DJjP46ZM4CLSR53XeDN0fB
bgrtQPz5fWIwD+nT14ljyz5EKk1bJyphg9vgKx0nNGb2QT4l1NZdZzagSbHQ
Qt1qsCG0dHBwzbc69jbwCg/jawUQptdomPygoJnvNV8QauZbx9xJjQ/Twi14
uI7pB9tS+AN7xfhnMxRk8JqUSJh51e/57estvyQDmZnXs+2PjqSoqUUYAZhN
M3RJi4SL2uPL1vMWtZU9xBWK+SrUiG69jn2P8udI+VbuEFfmYzDC6xeFkj/c
tSb5RGvSRdF7y7sAo2qshVuv7Oqa6TX6jaa87uiCGtvAaEuBbzS6EDfb6E2Y
NrODfko8wS/r44fvY/Jb0CVm3bJw13e58Hcd3jQjpnmT16DpvQ5E1JRpXee3
bq8RKnmio6RrXxrF/u/3dSch4efsce64cFyKPswfF48xEHO9PWsMqHwWxfgR
IoN5b/v/Efwbmz9khc9xrEpSDr74r//rf/OA/df/+b9G/wOh5N6BMpUnG1D4
f0Wh5N+F8lXYA8X7j0gaOh7/c96nJNCNvVROZYnfvcKo4kc3FknPoGcLdUjx
4lfBRotvsxlqrrn+1m/VvfvoMK4D5w/rvpk+/KHQNXOccpbOx3t8/rD+nuGJ
/gDokYnu7iL6wzqIhqf2A6BHphbbp/SH9SgNz/AHQI/M8L1OqD+sC2p4kj8A
emSS7/Za/VHdNdM/tHdndJIf6uH5w9pzhmf6A6BHZlpJha0IGNbv8v79xvUh
8mn9QPihie04Pgrp+p8p7h2EnmBxT7kitklj7/uR3xrc7J/6gREwIR8w1q2R
rRgTyyT78DioXf9C/rEYDQAtZ1Lo1AKdLqxdmzJrXUChmHJ636fpw2PvDt+o
5RoydyN3NdjuGHxEx3P7wclHR3SyGlqq33ERXa9PcnQTxBrBfieZnT8ffrSZ
n3fQtcv15+1jFCXmZpP3kAzb6NiV1VitPfwhM9hIjR5Y/7MXNYUc5t1AED1h
OjpaX5vgeRUYU8fV3FrGMGPQG+9Ny2/t6n2E3LN5WDlcUTwlFKP0ztR5F5j1
1S2R3g4bUd/vwBNbN2aQCx0JQBIR6VyK4pzUcUXhhPgIAmKmEMHhXXS9+BOP
3PmLBH+YFtODXIVo5JZCeqkPip+L2nmTi5+eqmOhFU4JZo5Nk2UYjt7cTXLh
iwYLLlrSh7kSH4neR+nDj6KILghh+H64ffv+xu0AMp6zS8aUYquco/xqDFrW
dZ3G+7F55OUdN3of8czaIwIeOvG0sUfTSlCwR6plurZ/uxOgiewf5LseY+dj
vMFhnaIyUccTqhrFTAEllEv7LSk8wifeVnQj3/WPPw55j41Q58ejo3XvRxAJ
2P2R0noo24T6P2IH5pY69xqCIp78AhDZSwQJ0pg2UT3Gs2hQFtQ+VznwouUs
lNHBM9xhR2Lg3btLKE4gd+96/QPXGvOEGTwijhe7Xvvo95iQKmtz9E9+pu3/
uG67Fm25yW84wnyYT17duZ+QEeqIiScEWGHuNbiJmRZKXNW7qYc3oaItiLdM
+QLBUu2ph2xHkMZed1iGUQlqcOXOUBrb4Rh0uAVxbWM0vwN7cOuZNCRFZ3DY
5HOt70bzui9h5x5SYMFXXlcoLybGXl0S9nQ6N8Ym6YafzO11dgFkV3SuBxwH
WzPyDhe33k2HmIQduikohJV/Jc2xt6n9m2CAnbyrXGxfyksaT74J+hnjYZSh
8IZfzGs6cxyME+RJcHQoeQj7qMnrJkRDWjdLBUowhVv3/tc6k/BsBIQOh47V
t7xCjUqHg4Ch1yLA57DIIQi8TKctsqd4/aZz1LubenDxrgL4G/M3pB969Y8J
dt4j7gdjAwr4bcH81kopoRecSEVP1jcbfw3xqIHXa0tcglGjIt5EzVtRkiwg
ivjyScSZ6w5WoevNKSPQCHg6oBbPjGIjv92X15yPAtH9gC95KQi3w/umqWHo
H7srbfX4D+yOYHNE7o7DfAFugKwVncoYtcq3sCaZMV/PUWPmdLUCqqaYP/Rv
BdhQm+um3PyunGgfeD9vJnQ6B0jzY8cvI3WJMt+7q5k6u/t/+B2q48PLH0oj
2XnZbshLwk4hUhpwOeQHeCbFzGHZsK8aNVfgbbKR0pbDUyABJxSKI6ARbd9o
W+13YuL+NkDYKaKP5Rk7LDhtXITOdfAmBWRGIBwyLHZvn3idwXjb8OBslMAS
++CuDRWhr298g621bkb4r7cCHqnxDB+rmqIbay0TvE6a29jSCkaaeR4H8iB0
mwWVhWwbU4d4EwI/KeM87XFBsIHkQAWgUKN7tPgtmDyJINrpLbI8uNAAQPfv
R5Anpioz78oJdK00sExC0i6Q4zvmiIt2zI2TwByJcuCC8OSJl56CePfarksT
r7f17Wa/e8G/HIfs3qNkfnH5YoA5e90753kga4M1dXC6xRufDw7+Z9LWwbKg
dZ5N5Y8jGzCAEaqaaqgg4ZnYZpqmA2siX/n3OI6w3QSqPaahcofnmqbOsB0c
yOM5o1sC15YUcLzXfdRrToi1WYx6RyIS6Ne6RsS/5fFhLKIMbpjbEMnWZuk4
P3pZ56ITd+0gEkrvB95G0fGYCFSgoXKzntN3x2fe9Y9bUiw4EtWC1p3+CTfe
GKNyQzIQhoJi0t7yAxjq+h5YwCdg0egFIsEq8evheP9G2zsGXzcfJSoY6CMB
wf3sgujP6KPMPK8T0PJYIYXFUbJGlwbzTjCKb0H61++BgzJ2raCnHqi/9VH+
QehUPzaL2WLBRX5OcN/BxqehFsX8LK6y1btY0LktZhNvg43A9NlEstW3cB5S
aA9TzmzkTgjqMwrW5pif05LwdLk8w5sxcKHsCLp07yCf99pciZYG3lLy0cH6
52jaj9d3NnJpIg9B7CRWCs+n8WW6oMdL0whVp+C3zd7Vbafeo5Jawu3nzUrK
g+A0M76zY+iawu2bomkjBd20OA0xn0RmwZWFmxcmcWS6wW1LPh7vdZiMxWNt
hXmn3gF4P8PZ2y8HtT33dO6l9977Ki/4fZU8YQK8QEmooxgE4zbIVcHbz4PC
U7QA6TXAcsRNcskrMccuM2PmBy18Lb0nbxtNTcxejho2pBd4iMLS3/GtU5RI
jXLklo1VTJCJlj6RA8B/4Fn9fqEav9y+nM4U0uG4hBjEJWyReqSJgT8qqrY4
tMwpM8hABxUm6tJKBDEnsiWMkC7mSqVMsXQIGH06k2aSAet8KHw50YCT2pJz
CRTsm9NVqPPHEH+CvYzETTn4W9rLW7XT2Wy1mi0SMJ/mmmSMXUx7AqhtCmYZ
ZlgtT4JnNNdI1vVCskXsK408JTqmOGQ0Cw3v8uMTBUGIl2iuRNWBqRoYqyVV
DlJsYirwNdhsIvwfovQFk3bwOECRI4UI3gM7hclVjBckjP2nCRFKq0q2VK0U
s+VSIf+r+ks2k8mUy6VSLp+rEJG/hHs0BblXSOZQkybmt7y2eH+mMArRtEqv
1M4zIdOHHmNdsqXTYgYKPN5HLcRhqHTgZ/QBGTbhpJ9p1jNXs1k6iDWNNGkh
rq1WUTXE3VwXCeUFnhjh0oAdvPKneUvVN+EAJ/zoM7dXmoN4rEs1o9MTI4Qg
vcGRnKgOrA22DYAlFCmrXpRUTo1eHbsyakp0i9nyAh/ScENLZaO9G8qikOTO
KdJWQpEhjpALSRVxstHImaxw40qG4+rhzWOO7RT1CECbCpc35U7TmazovSp2
DBmXaC05RFScIoaoxCljMxHn6vWKhjmv9qyJzSnj3SFFXIrxZNGmxVTHhkNf
0lUAZAPTpr11QS5KxiFWz3useSENN0jn/QJyO2W5aRQD6WK5UCwUU7PJjMC0
GHA4QqHpglCJQvCfUllnLEupzHLhD77U4MaAqOCI1rF7LEmqnmqEYuZYC2bI
LAU+ppSSjTSyOIlNMVMWQWxyhQWsrI5seelUq0XgrGxK4eW+uGpIpcJQfYvG
4fEJl0+YWIwF7GAViyPwuyQR1mKGMgCkK16ZLIlgpu5ZlQ0id/q98D2aVKTu
AH0Duqq2rTHFxBouTRUNyZ7Av6a0QSfMnrorV3RX0ttc1TEuO49skA062fqb
ooeFnu2k6Bnf+mmpkjO1ajWzSV9MTQ8LJ0SSP6MPCU1O1XQhDYIum8nlAmqG
4KgjZoxDMZ8UPeBlPemKezdaZa67+muTL4I7HkuGa0sb4/qPOc4whX3sg+LA
1Jg4Ux15gkqQqwvcBpScTBoQ/5I10wVyLUxxBR6wjZEsT4WgZztSo+jsb4I1
w3fgjXTwLh3QhJzInbKMH8HiGPbMVJ1wiwCbLo90OZm9qySxurqaK1aztUwR
OPqkLhYz2aJ4Uss3xJNsvlA+yRcbpUqBIGrSfClEF4+WDZ+nJq7PyukNqcrP
ofGcE7QcyFERK3pFTO7frwH4DMyJuyEq4AnfNelsplCslIrVfGGQzeUymUIm
y42Oa3QFaDcQcorqRFp2BM9SqsWZbZ8SiGp+EKnVUSmXy4q5kiyJ5Vw1L1YZ
q4rFYrE8zMuZYWVU2diOF2r3Wri/vlwPr4EjO59xy8Tfk1GDwFc6Xm9Cjgou
sydMQMOlFDbfUHr4iPjXTk87pWvz8u16SR+AUgDihqhIf6coyiKpKRBmhIO/
SkA7EUNBUc2IONhcbVA19l697RmL6FfT6C0sRmChRVSGqTGW+DM3bWMdBN22
/Oury6zVL1F+pu/RNklpoe+jbWZk1ZI1+J0ep6PRr58D+ARJBpwsDYzgsKkY
ekgrkitkKuXNLJSIpsZjGxGjl+vuHVg4YqCFLBlgvsG7VvAbNxKNFxDtgWm2
0U+CfqTmDtiYcovqYnAR0GG4NC4kdr0nZNcRDO9MIYI2WJYomxCqd3jAbZm6
5EZjWjJ/ANTgwACZuU8BWuAJ8yGsNdwIRJIBpAxpTe8JKWRFxfyTdKm8IcBl
WzGihkwKH9E3C6YuVWNQyOXLpWw1l8YmBGPTWg2y+Uy1BPbvenQTVLNDix0i
S+ih36BlF79yxuaSyWNeOqwjTPuuNVXtCWDqX80ANoga0iCRxzTMRBpirxcs
N1ZBeER30R4cVBmk4Ju0UkfiVNLUlWnxtZGmw7CVTX9y7y1kcalGSOmAVgIe
pDsnghWWFPBWZGFb5fIfRC4PWXoBlgF4v2DejUAHEjiwmdHjYuCOSgwIA9NA
CUDHBvQ3KNyxBXAkuqiGGveIYwZ+QLpULVWzhXKRb4BO19UcFVyhcI257j3j
ys4TdsyAbScHVeV0kRY4evwaVt+AvF3LqrUnTue2FDoMTl3Xr61zdyIlisfc
PV/HH/2QIl1nzJ3qLhhGEkYJpWmUfqi/YEgjsBzstM7fnUnTwT4bGo/yt1xq
jLjPUZSUC+VqIVss5suVfAk4P1MqiK9ircCX8tZULHVsCicW0Mh8FxvLGtKL
A7CtuMjyj+64JKegAPKMYYpIHlDMVLtEWBQrOdCq+VKpBOgUc+JjplbkWJzg
mdy1BS7fZjukHTgM4WXQZPSyWCgUs4VsbmBynsU+DA7ZR/tMrjU2hWo5W8lV
C+D6FgoZcTFS875ralqwZOD5AlFHLAYhMJhseifNU+ACqqfB5k5zFuNuxuov
tnDS6xwcrP88ZQpx2RUeg/LCyp1u96cTjCrZku4Io7//pyX00Ky2JgwzRgys
qwt/ZvOw15S3Y9tgPqEuWeByCG1Vc/DuJKAJXfpq2wIYdlNmYwoGDw0Crsfw
lab8q4WAPvP8k3o9mmrmFVh6LWKCBt88QwKUBYgbTQgJOS8RBP8RuSAII+AU
scboOCxLaJv7iQZ+P/AD3u+cGl4zR04d82AhJi1QD5ugTcJwJdTr3oCAN+Xa
UJBud486fhi32RbHOyZg3v0C65oP7PVSp/gij1zw028EzTN6gsd7w6bBBcsz
BnYGD3F4t2cnih5T7la6c9s/DSRopMTVi78Gb3lJdSEe9Rr8ULHKcLXRTdAv
ig1qXr0XeXgekfZ/QRMsxcts/ZhvGA8adjdsL6AawsHLTfJAq5aAN0SEz+r9
C/m4x8YlDxJtx/HSrkh3BE2/+JIfovBDCmQguuXq09ERXeSGhtjRUfR9PLvy
UtpiAuSHvDnGx9qsY35i+qR8mm28DKwXu9LJnI/zq/osfyvNMo+smf5ov/Z3
AR0mREpq3leVu1PTqd28tQ1lmsu/nsiLk35espMhFQcoKVL59jzTzNqjR3u+
OnG0Um38VHkRe+22ukiGVBygpEgVL85KatWem7oxma2u2w/X7KVbHnX1x5tk
SMUBSorU/eDptXX3lB81F9LpYrEa1aoNezJrMyeTDKk4QEmROjsdyAu93W4O
rbPBQ/G+tGoy5+HBUNVCMqTiACVF6npQf+qv5HHmvFWWh+eSe1oTp/fjx9yL
mQypOEBJkXo+ezl7nD0tnotG/V5/GzwUTs9Lj+pp8ykhpeIAJUWqYJv5i2X7
6uqx3csujPnENdnDw5jV29NkSMUBSorUTelMl4uVeUbOao37vPvSecrUHgfm
qFVLhlQcoKRIGYUuK95c1+eLyVJunhnKA7tegUcqmwl5Kg5QUqSG7Pbt8nK+
6Kqj6e3o7Hq0ZHLLbM/6jYQSPQ5QAqTkEfx1V3xqK9Ws9vSivtb7TvXkeXXf
uDxld7Puh5F6F1Bi3XdaNwsn3dtG725lzC+rtZszybl+MR6lcULdFwMoKVKL
4eDJrnaflapbNbu5k6lYcebl0fyxlRCpOEBJkTLnlZFYlp/Pz4u3z2JXf5FL
ncl970Q8TSgS4gAlRSrn3rlSI9tYjV8uG91Cqz8Qrafhoq+eJUQqDlBSpGYn
+ao0vMzeWO3CoNbvDprlynx53XeXCZGKA5RY9y3P68tum4m9mnpbdSdXV5pm
nRf0u1pCNRMHKClS/ezSnd2dLF6fmie9dr3/OO61H58d5fWtkgypOEBJkZrc
Lgql08VYv1fU6uj1Wc+NXs6HmjHoJFQzcYCSInXXKq+ag6mm3/aWl6tc+7E0
enNPTaPx8nHh+S6gxLtvMmMdTWGno2bJrL6WLqr3UyeTqdXPE1IqDlBSpMZy
Tn3JzIcmm/QG4jybEXuXtraUnusJzeE4QImF51VBr41ei+2z55nTaFxaPUMp
vzWUx2xCRo8DlBSpR/dMHqyaZ9f1bsd9kue5q275sWGOb+t3yZCKA5TYnrpv
a8bwtNOciPL1Deu6jfur12Xxaf6Q0MWKA5QUqeX9Xb5efr27MsayOiufFJ6v
it2zu371MaFCjgOUFKnsuC5fL8TypTlr3L69nbzV8sppZ2zmbxMaeXGAkiLl
VCRz+HaSLxe0B/Xizbq3rm6fytPW0yrh8sUBSoqUnr9bnZQeL27elpIrs5fm
wKxcG4Ws2+skQyoOUGI59dp+lYfD87k0MFtN8aXZeHZzhfx4JCZUyHGAErtY
jcrNSfbh/kJ0zEtz3rrJ9aelhq6zZkI1EwcoKVLzx8vcTB09F1uPcj27vFj0
Rhd1404+vUsYNIsDlBSpbuv0UTWGleJjT7qYvr6cNCf6yXO9fC0n5Kk4QEmR
erGr953C9Ull9aRPxrmrofR8kpVyudFFQp6KA5QUqczt29Xt2+PgXtGeinc3
g+5DV18+a4b1klBOxQFKitRDvtvOnoCzNtSzD3fXy9aNOpE6cvatn9BGjwOU
2J4aSK2Vpp+2zQv99bJ8ciI/3Ztt0bpM7M3EAEqKVLn31HNPKvlz3aq+1ofZ
++xptWBUH/L5hFZCHKDEPNV7GI1zT5fN2pVzdlN+tkfZpVa4EmtXCaMucYAS
K2R9dLkQh4vKua2cDbWCLV1Uq6dvBZXJCRVyDKDE0eGVOmpV3q6L0sK0hoNe
9vK2etq8az4+JI0OxwBKilT9aTHvlotvJavfUXK1/PPz/PlMby+v1IT2VByg
BEi5Ix3+zFWXp8+PxXrB7LWms+fa/LE/KD9dPOTuP75+70NKSis3214+PVTl
s9H9TM3XR9XXTIlNFrOnVkLtFwcoKVK91qCWyWRLknjeNR5r05bTvVua02f9
JSGrxwFKfGS0KItXD7l67d7KiDcnb9Uyq3WXJwOjm1AlxwFK7Lgbq6EsjeY3
uYbYmdyN+ve5XOXh5vRyktBHjgOUFClLv79kp8MXaZkrafmsUZypTruzvLqZ
JlQ0cYCSItUYT86UVn5lD69Pz7s3rCK/vYmO3Om+JpRUcYASU+r5QpJVJbcw
mo50tugN1U5n5OT7mdOEPBUHKClSg2nz5KpxafcfXsaSMiwuDe2lUlLmEzmh
RRUHKClSr9f5x3qmK1mnp7V8rzs8mT08nDnLWv0yIaPHAUqK1HT6cjNRC6v5
2UCtLZ6s60VWtk4noi4m5Kk4QIn9mZOpcu6cv/Wdwmk1ez+zRucdQxnr/VxC
4yUOUFKk2q47qJ262exJ31KW5/lOZaIvci8vs0pCxz0OUPKwmaGay+nJYHDz
3JlPTo2iIT2UXjqPbwnthDhASZFSH+x6vaZVnp7F2VW/VrbVy7uWPdLUdkJK
xQFKipTYbl3f3Rbrc/f+Qb6qjfNlubdcmLW+npDR4wAlRerCuHhqloetmyu9
vrx/fC3ZjnrlnC/kbEI5FQcoMU8Nhp2zyZVyUnjJjjOG/La8fl6cPjp1M2ko
NgZQ4jOHVeH1/ubspnVbyYlDe3ozuGt1SirTsk8JzxxiACW2p87y9uDp1BhV
OzeVcn+ek7OvhVG+tDxPyOhxgBInljycd5+esk+tbDOn9gbt1U3BauhXdqOV
MC8oDlBiK+E8azR6bFEb3l8MFuxqVq1MjadneVxKyOhxgBKHOF7ct8yo81Jx
Xp5M+U5Xn58f5d5icdpOSKk4QIkdhyf1vnD+fGnlMhYr3Uxb+uqhl59dOyyh
lRAHKHEKztN4qWfVoVOaFZSL8vI0+3SpaJnH3iyhNxMHKClSpYvz8dUsl3u6
Xbb6T0NRFU+Warf11n1IGMuLA5RYJJht+fzaebwYndw91Z/Ny6xhXJVY9lRM
yOhxgBLncPRWw3ZVnRiXL5fl3osymTwNHp3lpOskXL44QEmRUgatilW+6LZe
aoXiyTVbPi/ska7XnLOEEj0OUOJYgvgmVUqDp7OMPVucPJ4s+vc3bwv1qm4l
jOXFAUqcmVDodJV5fVnRes1zq66edV6Gs5P6rVVIaOTFAUpsT9WuqqvTM3Ok
3WcXjcVCnhSKiv461VcJbfQ4QIlt9MzFa3t0Itk3ulaqPonVZ21gvIzsZiXh
7osDlFgkTK5a2tNKHqwMR5/3M6AklpqiLaRlwiOjOECJrYTh4qIqK1pppF5n
5ietca13d9fQpetVQiMvDlDibBeHLdrDbuv85ObqvJGzX61x3zJm9atpwlhC
HKDE8Sm781Iyy4tRYfI4cOsXxWy/3p+Li9NlQpEQByixRC/JlUbp+qRxyzLL
QqP2+tjNO4XmtVxIKtFjACVO67JOivny2cTJTZsX9/We1b+dOiBhykkTdeMA
JUXq9to4fxrd1RuD7u0iPzFqmczbuFQprFoJd18coMQ5HN32IGNfXNwVu2xq
No23h/Mzo3OmS72E4cU4QEmRap3Va/msPq6xiTY+vb51B6t2LZvRzq8T7r44
QEmRqo7EXPase16ys9eKbA5L+rWZKVmXCz2hixUHKClSldfXQeu0n69mO81h
6/n55s556l5dPlbvEsYS4gAdei2psE3gjYuVy3TjbYc6LlrOsTACwNS6WHj1
fw7dZmtJqs1LwTYv/oMPqFmPRdeaY9M+7B5GlToP2Ixsd6d2r0n7J15XLvx7
bO98r7mvnax7u/fVrwfYKBwLybBppmq41Owx3KrT9ivuqFMdNvmgpqvYZw57
tNd7NZGdXJ/+8Qf80e30b5tiPYAU7nCIfSixaaeKHadD12Btdug/OqJZ77sB
WHhxgfwjlSm/CncBHtSEDKtWHVXfbrY8XDfUwpovk7r7h96xsIOToOrUm8th
WNdLt3LCRAzG+/E24V3qDE0FgX0Y5TPdB/Ul6K290UMlzIPAO2lV8Xqme9dX
AEeKfHnneLUvLFqmQBXq2DWMKvBLYu4w5fOJVyPoX0OAXShpGsA/6tigLuA2
p5+1o3+538B8s4P5J6pvBtjYkt6QVz61vFYfTDn8le4YULyO+EdHvCMJLxPk
463Hp4Z0dFkoLgJ2JXR1qnjk/UQ3YWMvXmzi90OJWEjlUgUiYxt4L+hEjB0m
adG9skTahIAzkMZgWnAThGrMTW3uXwaxdaflr4T93/6GvTlva7x9PA5DF4NK
AtGKGmBHGmELY8Y7t2EbCX6fvHDd6TR4qWG93bkewB+/conUclUFuwkJfbZ0
UGoEt5phc3SkZ8w8UsIpiEV8AD8rJt4Z7tc+qsZBtOnhdivY4123sh5vX8KK
s6ZuyipsGcKKV35Sf2kcOTRPv/+BV26Ln/iVowf+TY2xWAubWO+5nn0bKRmG
5fev8rvSQ820k9EpMv3cDpLk+fAn/LpUPrh3l22EgewPzPRgY9ytm6mPt37B
q563nzJzvvuxvuux5ch7HouKtO8XR3Zx5lgrHGq4gLcBY383XOZ1CfEBFcaG
Gi54TDMDvYTtFRW86J6qyy3dL/zdqsHdXXT7Xp9foYuF1mqoGH+BTYKHfrNi
k7cqx2rgmYW9mrAvSJpuWOalu7xSOnpzad3rwepdcH2A12X67aj9PuIkH6lt
KmKNes7X/fs13ydpKgl0j8jhRvvGE7yckvrQ26Gu7SB0DAULhdf1xdGe88N1
V1/4TaPuAFxo8M7tIOd4ibwPKCh0pvs8Y5p626bm8gawAthN3ApywSjD1rgm
tvKdmF5zS83E3oW8wd7WFaFUHI1WhqZOGV37sHEpKKKJMzXxqmsPCEx0ffuG
124dG9NyW4dJNjbSHTIhKH8frqI3sARdNFMgYcGiA2nLgErzSHcQqrTHltew
WPGTgHdgBHk1BJ7xv0dWRmGHvSe8Nr/AUoipX3HuN9k+XvecpfYE/sh4xRHe
eoCtAgyaHto+dEOwO3S0nY1WhSYsvkwdCKIcCnr9k5piKd65GIxUaotAm0rC
u169gnOuAkNs5O/ZY3ji1avTVRE4H2rQwYv9u951XWCkgaoWenRd1zFY2JYq
6bAFQXxJI+lY6LumDlZIzbXgj3sV976tSXOh4Q7ZamoeC2fYJQk/Y8KZJIP1
DdZ4zzTGQ1M4cY+F+oQZ4yUg13YltDXakrnA5h4m/nEurSShackq8AyObdvY
21uVDGyJoo4nKP45sTvYwronTyxTnh4SDzKPbmEZJalcGL3bgXUGv/LGD9SL
lXpZB0znWUB+699vlGL+tUXBPRbYfl21OV/uaxzrtT+YefcsxFzNErS88URh
+Cs+CsoMIANqeY8LPZ+CRvc7lG914/VbOpAf5b+LqOEMLWmmKt4dHCniUW+O
dAOrQv2rgw0e2jHrDhb+3S0poQ/SUTVgxd4Ckvv3K4HAV6jBOUGnneh39AmG
2qlxfDjUg2KNH0IAhW7hfVgKyVCLYWtiyZHWV6LTI5sMlPXq8S+9IfEtvPMS
LxkOupzj1FwdO5r7j6mNC4xON8j65iBeeIuNv9b3sd3vXv7aupPE/VqqNlA5
2Ad903Mz7MBfDd3vE7rQCNeQ2iEDP5INtSYnkoFEgNeILI4XQ20tQiKeNNXm
BWC7roc6/uCtW8ext4SBYLbRIVbn3PlDOy3o1syooY1/g4JBnpKFjWQCjkHW
A98I19ABCtDN8NjIER/6cGgN7XdEZr1eF8I39/Q6LS6bfKspJYRuIkbyfcJO
/2w5kdAnxov9VFq3Q7qGyeJXzvBLitYPvOvKiPrcrfLf8f+EN6gnCXEp6VT0
X0jxTjdX7f07tYg+/iVca3nCrZGQJB25Ftkd3hbbsGA4hth6zDMx0cb0pxQ0
2w5N+w+8SRlVuZNuozXxO7gDhouXATdgBT/ZeOFksHnwtksRdPbef8LvXy5U
w13CCrg6avVwDx50kEING2dyCi+wAKOR/pXOZeh6y2tLGruwdepv2PNYgidF
sSxcyaDPEAD8bWsYxzkWEC2TD9qqFVptIVvAywo0ZmBb/C7nyairPJYK4wn5
ynxM/EKc8S9o9B58Is3QlvpdyFXAcJ05Yu690cNNgEJdQYFh7dTYNMdeLzZF
TYH+AzknZVOqk2a2aamyTW2icOhbMPWPhY4Dohr+yhbELB9/Y2Qaki6Iu631
e2BDwkZTdX8L4gKqluPCZkIYuwCEUcc23xJwqSH8Jny57Vz1hZ6rw07bnAo9
BJlgOqLJOyIGaLdgcfHmvGPh1JL4PdJ8WIYMEIz9xTFneNXQyjBnoIlCfUNN
JJNqgMGTGlnp3Gxmjq3cqN87d+1bc5y/fRxe3/yKlt3PBGLdH9LXaqh5Iv0A
pXCbTaZMTJnf1Pr9ZpgTd87R7+//PlzeA3KGPT8te8+lrYfHwhe+ZFEm9k0t
bKxFPR1DPanShWy+WqnkM6WB73QNah6dBuZo4EUPlEH/ojcAOq0fNBvtq/ph
hK8bqJgD3+0BL97o4S1XuvCp0XvoHe7bWxi7Hdj0Zpq3svZ7oqF3xq+LaWnm
EJgUHECVaIrirwV01mFLkORtgx0A2/kTbe29Qx1GGD5XAL09Xq/Ht1CvWKoW
y8VBGy/N6XmX5gw2jISBagxOyXcatDqngwbD6N4AphCl7647STe1Li4ykXyN
pWtncgs2TL2Zpp5ysYWsnKaISPquZuQrWYWpkih1L/WXVnvSfV2aspxty6vT
8tS+0CTGztloeVUY9uo5vX39tri+uX5qsZxiPN+m3kYae6rrugOyyRxc9vi+
iLRgq3WEa25R9TAc4YlRlA8kdLLhXROJPnoSKJ31ts29ygwDvJUaaF2LBHku
K5y5eLOKvz5oiH30cALAItnAmGJ22lTGymCpT15uHtXbgXTxpLw69/PGGTst
fOu2yVSLhVy2OvBvch7ctgZhwgyC3nR8ocd0Icyg1uE0pPuMfwiRNuey87LR
MFwMIQIszU7zT0V4yLnP72C7vi8GZSfdkytmMqmZMtrBjivTddzUkKVPh8X2
2ySrz7LNX51fCtlK1ROr/pxJneDdVvAfs9lKaINhHKKDOlXXCDMjgvPEV0T0
XwhjD3UyYeogedYqDGb1wsLC92Mj/rzR7puuBi0XxQ23ErvHIXUQt39kUpv7
LWCrH7fttmj2zfvuvnpy/nw2aLSmz9eKZrycSHdspbmT4evNP2nftU3n9rT+
XeiUrW7S6ftsvYnpWCOZujtLYra492oOsFq8Jp2Rux8ymdhN2Wg/3Kovy3Pb
hE2Zz1WKuzYlceE7hAm41U4T1gHzfpRaf/ZO/E6r449OC6TsGmzj7pZ3VqR1
+7qyGp3muLmAFcnmC5lDz2a/bv1L86nKZmOPSzM7iZ6MDuPK68DNVuePb1NU
F4VMweNMNCTtiTmLEiDcJ9s2JHniiAqIDuypr7A0cNTYAhvZu8BCMmwV3tjX
fTxbLOI+AGI3OAihh3esgpl5iZ3LN2z/90dnfBP4wECklmAJ8NbJYAk21MKP
mRCR78p18GbZ6BxMeigqCsLewLUYxnUL1ciXtHGnDrZyxtsavFM1bIYe17sf
5HJUqElcSIsSWL38qDHtIb9H9e30yXh0AJtNu8sR3R5F8U7k5X2NrQkMjBW6
gHq4Es5gGcDTwHgE+fiSwT05vDDpWLjr1ZBKeRG8hyih8Kh8s93zO9osWymC
C1EZ9DDeB26c+ka/bLpeu6kRRJXrQah8K4oRnrkcfOH5QsDwdewwL1xKFOha
E/g0oF90OrIhj/CShKgflc8ItZmlajEi5kO0KFQL1dzgFnkJp4+8hK7TRmPe
QS3WHdp2g/LO5Hli36riyfPZhdh6fTEWrbdJWTWGmuOed7TZ/ctrV3uYlR5u
lW7/uVR6rszEytOLJLGr0XDymKqb7dLTiTuVzl0pM546eJTB8wNUHTHRZ0Im
8zlX/pzJ0EKBk4c3NaJOo7tl6fbI3/ywE5HKz4LZIVs2g04Svo8bBt8XgzBD
F6/jBaf3WKhLhqRIwqc5XxD8MVuOrMi3LUgumy+VsplBH0/F0dLyXh80DRjK
NDCUOOjfNgdXM2YMei44iXEC/tyqmstZdqQYGVR0mUoe3+ZXNO6jQHBZtGRt
UUH0NJTIQfgi4xL2Z2+lw2ZUMcBvoMkn9DEUZPsHFb50N0ehjvHwWs+EnbYR
6DFtcW4SLnS3VxqsM3i2sQGypU1y7wjt7IFEC8pDOLuslNBnXDamRyreUsWv
virQvzOFbGnA8f+3XObfcpXsv+Wqe9yzj6DBCXnd7Iv1q0veqzz7WcgWMVzK
L4gQmv4FEd7VnHjuhDzt3di+Hm8E7iNzUmMV9QWG7Q3YMLDv0LIoYjR1940T
BJDfY2bwhLzfhXPJ0mzLnYDI9W4EINKL34XZUfoUMzmK04AXsS8IhhT9Njmf
K+cr70GnENumLgAJCEw7QDvQW5lWv3vKw8efhZphIA/6DqB37PnQEn7iY8Ev
dG0S8r7P7D+tcR87+ohiyimbbwobNQaxh2dy/Ir3PP7CaAUu3Dexh8eZ8E93
zlwrHOMsiED8rmT9o1qgmC9ni8m0AHeTT2/DBnPxXYO5yEP4E2a8wf/hoTde
9BARo9V3JvSO5VzcZTmDRzey/KvvfJMp3jbujM7Hw6ty4cIpgOgsZYqFnVGk
j035E4387tTLP2TqFFfaDsnHT3/yWAYLsTm9LKOLVCqXvNlj5EPfinx8l4X/
xzk5ky+UC/lyfn+kwo9JXNTOm382/t+2ehqa8t51bDuPU+j05J3VPHsbXcyG
xkTL1DAEkc2W94Rmvgshij+EEJEYjUeQIK1hnYHG/9rvCcUT6sq5MsuX5li1
ke3zxazvEfv0+bZYTXEjVhNLvoK4RcFvi9sUQ3Gb7+0tfkN0Z9+6bkR3EmEa
v5qlXK1YeW1nq90OrGYuV874Xt12gkJIP68vooT3xKjSC1ugGeGUDWP4PARo
9/GhB963qm08cxxisNcIkcrPP6P0M559xjW1p6hb4AiQRZrL8vOBv24RBBmU
iDLkx9wLyZEnv85/UZXXxTAzOdUm9n/DjItfri/00fTuTM5X3e7k2b5s6bOl
+NoQ3bp5s+qOtc7sv6EbUcra4W2x65T7g1yh8q+4c2FJDqilbNq/pg//jpK8
+g7Fk4+1xZK73vKEDnHm2np47zBmfHf7VMoq9+o1RRlBNR0KcSGWkAFv2grT
10fRNuYRuxpL09z2hFZAsChsDgJRxxPcL6dXvUazu+FabQJG6p6Aq2kzzT4W
Tpg2RgfudyGfFc4kQ8xukHvbw9qLKfejW+3W6Uk30FUOkHmX4NiE4iWdEKmp
TsXeBYlDSedKoPNz3CnLZbKDUsatsoyxZ3Xoz9TmgK5SymWLOwZJSfNsasGG
+vcUHLkyUvefLji4kQRGEZEumyvvkR4BQ19nCs7Fmdxbjrq/flxcFPKF7yp1
8/8SxPOIls2/RzS5Z9WfL1dmeTBOQDQK1XxPqpWEBpOJasX3qLYBKJ2YTif8
DJuscH6GjdQqZnPZ0nvUWgy61kuXtVfXlQTUKla/K7FyH6fVd+YwiuoFZZse
1TK596iWLUmtZ9F8VpUkPJar5sge+ttnwVEdjf3yUzgH10/4ZOtc3Eh2a4L8
15/+OOCJjjUvLzNIcwzyNuENXrwJe9uVrNU6CTfITuV1Ll4+879Eui3VK/A6
KMwv9iueqIRzI53etLzaB56yavJCW0HCEjIDS1eAVyeYz2R7+UxbdKbb+2Yz
LOnE0qKZhQWekWx0HIQqIKQRC7LxVQuLXC37M63Az9xi2+O6HB4Igih8oQjH
Q2jffKAkeZlnN8vTl5vTswuZSaykFQaX40dDtxtPPliyEj8OFk2vdGk8fF1m
Hp8qD09WO99dFuZXFSMnuufjACzeO/lxqGg3VLTVa3tSXZUHF/PSMKs+TmZ3
r0/WLNPN+EApPPBxqOijp/vm3NHKi/H8bXH20M91cs8LY2J2roynm4CytdrH
ySpJ4/TLyfP9tPy06i1m0unrSqmNlg/5/PTy+TqY/zUaZLwuJlKkg3Lgo2PN
fBhipNAnrZSKD9dSPfMwfL5dLPsnsmb0p6NyT6cbDHB4yvXIkXvIc7a/OBOL
SUr2o0NLawBpd/hWdh/rtig+vbm9h9Xj5aWtP4wGTu8G0xJhA3jQc98Cfdme
vNSqhdEbU0pXl5359e140e+LD7d6zadlo9etJyKcotty+qaek5SO/DRdqn3N
UJuyXB6Pp5XSSS1YpB1Bg3jA63DBdcc6y10Nbl7ly7ua0e0Yg/tJLtfRH7qy
Dz2c//P9c4YCwXG7JTisiOC4O+3etj4n5gDe2vn54TzjdrvV3JWy0K6H48eT
+U1t1pix4reuvQf3dnJbNrNt62E5ajVG49uz7m2peHsybTQ9tCmGnRRpujDt
crhsdxbV9mA56z0Nx6OrgVHW7jun7MH+Rpw/cA8bZ9TO5e2HJQnYYulB5aKZ
v3Wzy8dsaTJunS2sVbd/u7g1pdp6hcFs2XeK7fmYdA7NN37UyNq17LiR8Ab6
PXDG6ZCqTVPieDqbLecy5Ww+v498iWB6186m8+CBENL9Wv2bEAWLf41gNZ/L
Vr8dwRCsXCZTqlSKmWABrurX0R2GlaH8exbaaPBacK4E8/GmGZqQKc9ESdNS
dNpo83HhI9H/KDKZcraEfrIHJZcYCoXnButDIkxD4nOr4kXYa9D57wa6UMlX
MDJLS+BBL3w36MVcoZQvwqJ0RgKY2FQsFionxiK3uQT6DncdHoOQ3qOuEmCz
egXM3FjlxXy8LMirZSNj7FiY8fInjWEPEhqBSlwxwcRSh7z6+CDyl29o83Ij
rOtcMOQtRtGeD7smm8FUnHQCz2bX54dUwSd0ape1rdrcfqRsHG/wNkz+Ji+N
xMreAyxMGoLCQyg12a/No7gPeAoGlSkx5ZefRuA2MXAmou/wJhVYgWYwLOGU
LCyRxjrmVbTOtMPvulb9BjNhP2LEc0uwHpMxBZEh5sICUZeCkbhwI1ejYlad
ykO9Wv6timfvBnRezarwZhkzLEEh89wvX0/5tPFq2akbis1rLH3XC2vvbN4J
hZ96CXSj+frCdSzDC9WnC3bojm4LiAHEwUIPe/OO7s9U8LlQ7YlX3WiRCwI+
jFckRz4Gk1Uu3z3OWxfSep6GGjg1XoUllhTazrox0Al4/xbS8RRbvGCDHmCp
lXCO/CEJV6ohwbOGJdlT0/vXXJXhUVeyprAtbl1lBX/dsiGbShPhCqiimNYI
HvXNoQq8dO1qGjDZ0dGue8SPjvZeMM6nTxsVa/P5BLEmECchmyLnCpwVLd1e
OEQIXMW5pLnkgcrhLUs02K76ptGpvcwY6OC18pACnmY7iK3CrhpPHGTANUty
n3DCtBk+90vrTWMvuoRP01Jl7GoBLKoh+c/ciQnrY9l//3+MLdJvFLnjklou
1pxrkiFPYCqwpA5wq3BuMZ1ZuDIvEuY0toGh+Peg+YT+xNRtE8E/gT8MczpT
JeKHa/DwNeFSnZqGCXsKntRBLK6EB1Xj79cM01jp2MopXMHndz+wcIwGLJwp
dMECgs3mMdCZOTGEa4u5f/+/AQfHsTm0E5D+wHhtSWPYjohR74GeI7lDnIhf
io+9b9a198L2/xDNSLF+QIYL1ySkFQs2BaCkEU3OXfDipZVQm+gg78///p9/
/x9//88p/BCu1ScMZhMVU6UmusrGNLX5ShGuppJK5IZ5InTUNxLsvQfTVAAA
PGr9/f+1EBKDZVH4MoAY6UkOvn8mTd0hX0ms+XTMhT1V12tzikXOwBMTWg5g
XhB9DXc8JsANNgSRbmpsRbuMLBrsEWKpIOr4BmuI/K+P7ioSaLxVFrWZsFbr
TbaGFRIxMXtrmz1DTRh+zDbz1QON3zEN14F1noCVx6Tdm10k7gecTnmsaccW
bGOPI1vo2/LEHDFDxaV/kiy0rCdsNKIFvZBcXqJ7AYpqCLyOHNxSLVWZgODv
AoorSSfGBAqCfYOWCiynQ3x/ZhoSdRtpmytkERSqsOKg0oUTCTYByVCLjUCl
0KLy//RWdFfd9JYqENbZv7xIHHWibiqMmsdwJZfL4H9jvCabynt5gSpvIxca
M7CkKPpH3SYke2MIv7WH35cmUDjnwNMT4L0VzPUE5jeW5pKxS2pdgrDQhXNz
yFRYZJx+i2G4DbTGwUHP079k79l+PSQGzo4F9IKPscCdhwZ5eilvBuOzJ89o
5i0kiES+RYEVIwSKFHtKqAm7q97XoKhviQ3mHSzAP6F24OcZGNa/ZMto4e1s
g4LIjbB7Ak2ZZwgGLZNCGc3Cp58azHXwdJB0jTxxjbE9Bgmgeun3qZ8OD/5/
bwqzvao3AQA=

-->

</rfc>
