<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-12" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-12"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="August" day="25"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 115?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 119?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- peforms a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs and finders</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, and Haowen Song) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings below and the <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail#community-service">archives</eref>. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <table>
          <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
          <thead>
            <tr>
              <th align="left">Event/Host</th>
              <th align="left">Venue</th>
              <th align="left">Date(s)</th>
              <th align="left">Evidence</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
              <td align="left">Prague, Czechia</td>
              <td align="left">5-7 Oct, 2026</td>
              <td align="left">slides, video</td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
              <td align="left">Singapore</td>
              <td align="left">28 Sept-2 Oct, 2026</td>
              <td align="left">slides, video</td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
              <td align="left">Rome, Italy</td>
              <td align="left">14-18 Sept, 2026</td>
              <td align="left">slides</td>
            </tr>
            <tr>
              <td align="left">IETF RATS Interim meeting</td>
              <td align="left">Virtual</td>
              <td align="left">TBA Sept, 2026</td>
              <td align="left">slides, video</td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
              <td align="left">Grenoble, France</td>
              <td align="left">2-4 September, 2026</td>
              <td align="left">
                <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, slides, video</td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
              <td align="left">Virtual</td>
              <td align="left">24 Aug, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
            </tr>
            <tr>
              <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">21 July, 2026</td>
              <td align="left">
                <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
            </tr>
            <tr>
              <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">21 July, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">20 July, 2026</td>
              <td align="left">
                <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
            </tr>
            <tr>
              <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">20 July, 2026</td>
              <td align="left">
                <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
            </tr>
            <tr>
              <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">19 July, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">19 July, 2026</td>
              <td align="left">
                <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
            </tr>
            <tr>
              <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
              <td align="left">Vienna, Austria</td>
              <td align="left">19 July, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
              <td align="left">Dresden</td>
              <td align="left">26 June, 2026</td>
              <td align="left">
                <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://output-dd.de/">Output 2026</eref></td>
              <td align="left">Dresden</td>
              <td align="left">25 June, 2026</td>
              <td align="left">
                <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
              <td align="left">San Francisco, USA</td>
              <td align="left">23-24 June, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
              <td align="left">Virtual</td>
              <td align="left">30 April, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
            </tr>
            <tr>
              <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
              <td align="left">Montreal, Canada (virtual)</td>
              <td align="left">17 April, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
              <td align="left">Virtual</td>
              <td align="left">16 April, 2026</td>
              <td align="left">
                <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
              <td align="left">Karlsruhe, Germany</td>
              <td align="left">16-17 April, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
              <td align="left">Luz-Saint-Sauveur, France</td>
              <td align="left">24-26 Mar, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
            </tr>
            <tr>
              <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
              <td align="left">Shenzhen, China (virtual)</td>
              <td align="left">19 Mar, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
            </tr>
            <tr>
              <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
              <td align="left">Shenzhen, China (virtual)</td>
              <td align="left">17 Mar, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
            </tr>
            <tr>
              <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
              <td align="left">Shenzhen, China (virtual)</td>
              <td align="left">16 Mar, 2026</td>
              <td align="left">
                <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
            </tr>
            <tr>
              <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
              <td align="left">Shenzhen, China (virtual)</td>
              <td align="left">16 Mar, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
            </tr>
            <tr>
              <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
              <td align="left">Shenzhen, China (virtual)</td>
              <td align="left">15 Mar, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
              <td align="left">Shenzhen, China (virtual)</td>
              <td align="left">14-15 Mar, 2026</td>
              <td align="left">
                <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
              <td align="left">Virtual</td>
              <td align="left">10 Feb, 2026</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
              <td align="left">Virtual</td>
              <td align="left">9 Feb, 2026</td>
              <td align="left">
                <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
              <td align="left">Brussels, Belgium</td>
              <td align="left">31 Jan-1 Feb, 2026</td>
              <td align="left">
                <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
              <td align="left">Virtual</td>
              <td align="left">27 Jan, 2026</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
              <td align="left">Virtual</td>
              <td align="left">13 Jan, 2026</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
              <td align="left">Virtual</td>
              <td align="left">16 Dec, 2025</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
            </tr>
            <tr>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
              <td align="left">Virtual</td>
              <td align="left">2 Dec, 2025</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 606?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-authors of paper <xref target="Intra-handshake.fail"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8192XLjSJLgu74ClmUzk9IKJMGbOVZbTVHiIYm6SJ1pYywQ
CJIQcVA4eKizxuZl3/YH1mzX9nFtf2Cf5q3/ZL5k3T0AEKBISMjJ7O62maoS
CHh4eHj4Fe4eoijuuZqrsy/Cp47p2rI4kU3VmchTJnyWp7JwItv6al+ouy5z
XNnVLFNoWKajqcxmqtCWbWPk6cLnxt2JmM/ly2KhUK5VBGskNO56PaGSKQkA
T3DYnNmyLljuhNnw04mDr3gzwbUEtpwxxQVg9EUtU4XnimVo5nj/0548HNps
vgW5ZIQ+7Smyy8aWvfoiaObI2ttTLcWUDZimassjV9Ti4MSRrOmilN9zvKGh
OQ5AdVczeLtz0m8Kwi+CrDsWYKGZKpsx+IfpfjoUPjFVcy1bk3X8o1M/gn9Z
NvzXTb/5ac/0jCGzv+ypgMmXPQVwZKbjOV8E1/bYHsypsAdwbSZ/Eeo3J/W9
hWVPx7blzb4IvZN6f2/KVvBI/bIniEK9I8hjGNTBPzZJIa9JgT/Hl2JvzkwP
xv9FEHzg9y38g0/vHsYEQgst/AkfG0AHfOVPbCkbM51lYCXwuWwrky/CxHVn
zpdsNvJjFsABaM2deEMgkOFNZMOQVdFzZEMWHdlWZTu7jdqf4DNdRszhswDw
1s8zHHpGs7YCyu5e0czENWCgPdlzJ5aNlIRBBQEYROfM8KnrDyjc4oBCjwb8
RG9Z9lg2tVei6xehfysc28yBlT8UWsw2ZHNFbzFOsXDiA8I8wzH/k+uJKv8q
o7JPW8bvWeZ4aAlH3rYxezCb8UTWhJYnm0LdhJUfWTA0MX2fKRPT0q3xCvg/
cyicuyr8szHRTDmG2FD3mGqNTRjzT2N8hqu2DZXGhJnjpWYKbRhtvA2fzpr7
Y0PIno0MaL8/Rlu2FswUcNY/bcITeS6bUj5XypWKxWR0OrCMQk+Z2JYy3YbP
Sbdz3qkLV7blWoqlHwI+SiY2mMtk40/M0HRNnvlvZWQNWM7keM9h6wmbOzaD
vPmF4OyQvfTGplTd/yK0tfFEJGGquSvc6SDdfFEIwq9/3uOzIJEjnHomE/Dz
Qz6UbI+Zu97Ei8UiA+vGcGuP4YOMydzszBvqmkLTzxZz1bxUk6r5wQZ2iNwg
jtsghhn+ONDMQYDZADAjHMKNSP8TAXuQh92McJvxt178l7uMcOwN2WpqxZ+f
ivDNqay8eMzdQV7RZjPrr0FjfZVAY19yoZz8kGQknH4ipeKT9aHHh6I98AXf
5A986jWshtXzVQ0ng6A5wtzTTVDsQ52hJreZLq/wHVmZwm+aDLodpkfKnc0m
zCAbAD8F3eb44LdwpTJnGUAiCzjcMAV04G+a+uuGWhPWa5AvC11kYloH+OHk
9u6YvyqVi9Vq0ixPLjq9+t9knsybqxlmao6cYZ5tzfBfWfo7u4F/0lRb7V5d
bIDUccR6J87tP34iUb7PF+KIJLK+pwPQuWbpzLWdrILoZh2meLjBsrI61xww
opiTpdnMR+OxaMyXS9EYjyu798LtGqhAFAAjKaDIiTpmOnMcsbeCyRtOnDI3
zLDcmNmElAHTTGEzV9tGmujM697Yc9wPzZv5aDgrnDXudMfdPfHJ81gRn5XS
XBwtKpPdEw8mJ/iTg1/RXhSDpQVd5K5I/Nnu5sRxTnV/uTXzjSUZNapB8aJh
PdJQ3YOJK9TRANUUtEX9kaNkkSQQM2aCKESFiRwDKjGjMXdEOxwfZA1nDFSR
3eyywK6Xzefr5um5wmRW1ouDi/GDaTjHj9kPCsU9LbAYfM17LDZszdHgvePL
TkbKZSSpWMoWKpVaPlfNFCrVUqFaib64TXEQCVAZ0BtIuRhlGpYx81ywo78I
TRwcaGXK+gpfBS9nl+q4sOYMPQSkWeld9dFoNMTI8mRplrrogO8kaqqoEGbf
ozngl64FHC2P5PgP/Qzwuo0PbTYC3CMUzNWyvatMPidVMrQLOuJxZmQ5DqAm
4kqKDL1GMbLDvnzoLTFX3HzR1Z34G+V336i994aUC96AjfjKcRmB1AM5kclk
9vZEURTkoUOScG+vP2HcaRRkzXBQNoClN4fFF1y0SMFa0gWVucDetNxf44rq
Xz6n1Gz75DB/3VACazAfVxz7h8JiooGMJukG85E5u67RZjgNU2GI98RaCAcH
ZI8cHGz3LoURTRLYf4ak0RR2CCDAnj9YAKNanivMJsD1CFlWFBBRB8hbNgNG
tw8FR8ORUA5qpgcctymAQbygugF7ymYvngbe/OG7CMmq6sBLnmkyHE+2VzAA
uqZL2K4HMDwuHhi5oIEc9LWFIYg+2IrDleDyX8j8Ff78523G4R9/0Frgm7Lt
asQiO14lqQHvA20QNyZaIxG+E+E7gW9VAOXLBNdCVwKcijswMUeHggcelS3U
Z7ICH+QzOQEscGY6jEQwwLUt1VM0LtcPCSNwcWAqDCgP0zGthY6aJjIrnYEL
5CImUzaxdADv+GxtaKqqsz1w6XEWCJjCBjvnP0MSmUi8YH0EeQYYAa64E2hO
r4yG1XaHJXDHzCxH1p1DwG4MUogUGHDdYsIoJAT/WNECIScBERGgo1gzYk1U
b4IyAVrCm0AT03IzQtO2DMAqUKfCDCaJgSQQ/IeCZdKHCAUsF9ieiuZwBlZc
y3aQ3fA3BZDVUBoLQw3+yxwLBuwNcAAdA4SlZWx57kSx3I4hrhAFuvi7hG0/
xkP4GD5PZqU0bEFjgu0Gv/tPYL3rsDP4bjBgCWFvHBwIMxnohAMH6i66xrSK
ga5TQl0Hv4s0QMIK8xlucjr8HzjjoPfRqOITjqnZHzJLkwcVYzP15wkMD9xh
wzOQKnykdYAPf50xRBm5G3Wm5Y0nb+bgs5HKHG1sCtYMZ0tkSaIGbLBfhEsQ
e3ONLVCFACCuQ2LE9sdCvtVGvttNk9wcPYFRHaJU8DgZL3oV9QBYAaof5aBn
MTchCGSAOtz7BmZKRvgmHG0OC89uHYY8Af9VDzn7G3wh4QcNXYNp/se//Q+H
YJoWCv9vwtcuaMp/Qlt9rdFkLWPAUzJzCFEFmMOxPFth2ZmtzVGcAk4o4AEF
MVRfImg3l9FK7yNopAGzpTXg7/K+s67NGFqrZtYHuE+zym/MKkrWYHbiGo38
j0Yjz9EoIBoUlMfAuUUCJzZw4UcPXOADF3HgHnA0s2n+PFJE4jU2fvFHj1/k
45eI/pYBDznRYWv8kqfd8kshjkLpR6NQ4iiUE1Ao4vCbrhm6CeT1bUVo06Q3
GEMnwskOdWvIhwdHhuH5gpMFb3vqOTeeusoEriTYtGDYKooSNW4zM3W0/89g
hfoucdz+dExH1FwbzP3ymHBYzEQEB0yd9Wa6JatOFt2RrJTP3jOcpy3W0Wlz
UbPC5uvjt2Lj8qLZOT656Hfq5+WWPySM2WjEXMhep/WRie+DPJBVkKwgTmCf
P8NQwtcEKbYV5gYZsoFEI+N/ZikRCVH+0exR5uxR2coeh8Ceh2seARWY6N2A
SgwRrfxoRCuI6J+/cMf2109vhDqYZ1qoRbmiQ8QDU3VtwXz6Y2/vX//1X/fu
WegMyYE2gwcwcfg/8CID4wz+AsueW9JDcAfWCm1vi0Kjb3crMQ/VAMLae2Nq
o2kdQddUfcsT0TM0VxuvVR5+r2pgwc3p4DBENRpG0ZiTES491Jmw8cAcmTPY
i/Cp7AqaKxjyag+sD7DEBRjDCUJHYMpo8CZ8ZFuAKNjLQUhdhEmNQNELn8FC
Z7pQ2A+nzyeVNG1ZB6sW7SwwC4B8OCpoAN2CvanucWspErJC3w8mBjTwn4Ce
MAAk2joKaTHy0WYuvhH4gXsjblSr2mjE0GyCT2AyOGzP4oYI/xTG9yfueDYL
CQKiBBwx19kDKmhgDaDRxImLaiNDLLOHTAP6fYaHtkNQY7gIuoW2BA4Qi2K9
Z86gn+6ggc0NkT//ORYPRXfMcTz4Dd5zOf7grargAASeMXcN+dfwedwTh+8j
59jcputaKtNxpS7J6Ax2UDdkXh4viJv64M2C5TZCrxRZBNfKsNS4xYeTQkgw
4pr6SXPfsm/A/3Nw/67QFTHH+CtyFQz5O8gIV/4dzGJbBlsLMPd9rIbPCoAB
1+2Cb2kh5zfJdRS+yuMxem0u+3HyKAS5TxEBeOSQhPAdSjW6d9Vtc93pPsGq
wVo7oIdBjWBIG3A0gjl6pv9Xxl/AEfeOAyTIcQzM8S1OIfEARVvJBItqsWig
KC7kt8e6iDtp83GHhusLXBOUqDLujEiw/jNij14nDLAw97eO8zbMBWPgN76v
oevWgiTnwsJzfpNzCUgEf9cH8nvtSIMDAMb8EekOYQJbjWIO3gwFt7oHFvGV
BdbADpcf5XH4jayqsI5cSkWR5FTznTSBayl/bT9CQdVitP/RrZojhPiJhkxu
Fjrb+Ba4w4CmL+xt5oI77O8CPi6s7nvzAYm/fahDYei5CIsDPDiACWv4HRA0
GpF6T7cBop75DDYWMCBTkd+Eho1pJg76YijeMHYIJkKTUCaHSxRF+v+9b9tE
2Ddha47DoXCnoc/t6PI8ODrkZsopk00RzE2NBQeHAge9EV78obA3BfcPhrx5
ILR7BPqqf1Tf+TuJyiBrI2ZO4UhOlpKb8KURXyE0lX4BrW0DD3P1QSzv8gcG
PsBVR1UOe5Kroh5TMuBtSMgtiaFJerHov7YO6QDfwJjHFJQGiHcxnXrM9S3q
7b5moDZj3MrjDl19HVE0KFABWqUOCokOBe+4+kRePKFN8E04xqhEnAvRYtJM
jYLNa03PAk1PFoPlq2KAkKsIl4p7SOcgRP4NFBCD8GWpCPNSIi9HU0R8Jf8V
s7bWuir55MmWXSdbHg9flrmHx+r9o90udJfF+WXVzIve2fgxi54DP92iUcs0
6lefWmgHgVIhPCOuFhtmghFxMPgb3apyLp+vSOVcqVTMRr2yyPloxib3b5x1
GeOuCwZAlBVgEaVCviI02TCCT+DucbfcmcBavd1UwteDg16Q2PCr0O602pj/
QPZNdf/g4F8Qsn+wG4UNAmeLYFmPlAS3FMAtv4FLh+8RMChftoqZ74T/dc1H
8eWJGC9XSF48n0W/FtxsjJ3LYPxkXXnMg0/wozjPZaoZiZYg+IDrMvpoG3E+
gHGNkke+F9+xtRvXUkYSx5aUyZdhsDdIj63vRFjKvcEYPf64x/idzrnKFJ1U
89eEDIUPRVE2YWdnnq5nS1XaxpXNGdytR9syGQxAW985I3//q8ib+YRhU1ly
ZP3hivJDXlD/Au7YDehvwlBvhMIWfZjAAMVgj22w7Fr1haom7r5FBX5U1cgb
OgZ15MHBBdOCsyCydNBm43+hBEJTUjbxLIenICor8OFAdluItGBxu0tZZwLH
FCxZwb/fM3nalp3J74f8v4/bv1PC7u9HsnrCl/33DNhofTyMwnMzIZLvy61z
cEcOBS3DMoc+zB45+QSVpuY/ANB8puDTjC1LFZjuq1P/6Ejm6bhk4Z3c+olI
eyd4oguWjHBrwrr/kyN8pR/eOf2dWAabyWPwpZBIEZzBh4gu/VvJSnMIM7Up
dhGuDMw2kjAUHLegQQr2LBhaDtCcvuee1F08brI7SUI4B28YtC5wBXLQL2CM
i8oceNFRLLAWBOCFkBEBgaGMHiCM9RUo0QdfzLU1JSIKTCAI0MPNjK15FrEV
/VeyCHQ/sxfZbpwruUb7xucNQiwY7cMwo+ZOxOz5utDAq5BnZKBFjIHI0+wI
dokTPsLAqYBHLITR569g6TE9HrHV8BEXOX6cFp5mPSfLzDCVSFTgObOzUWMk
Sx+K4SvR35AHSiBUxHxVzOUkypL20w7q3eP4+LKh8lwmMxscyjhZfirnhtCz
Q5CxGLzOwuuiMxQLuWIuBLseGElHgfoL9LOJZv2Tkw16geUTpRWd72xQ6g2Q
4wfVWkR0j6pnZMUg20u1tGyY9lMuVcvFYgZ0Xi5fyFFM+K9I8yLSPBelOR4r
gRkrnFsLPpOeK+vMi7D3UpFFX/1F8uAd/lrw74HngExYgr736RQkoZTEUrGU
q308CcX/AGEUMzl0gsD59AyO3BFI1Gmz3uu/h94QXxxhtlv4XwNLnurAYttw
LEu1Sj4NjvjBPmKY38RQVm/q3TWooQwa00AZ6f8Xjv3tB7K5VOIriedThb8i
uaS05JIIxdoGik15CGJtytT3UBwFL67/K5nppNwHMISHkQ+2YrjN+Y1D/ivm
sO8LO0IsFdrF+H3MLNrUlDxTYf5WUypRTamEmlIPNSVaSBQpW0P0o4X8PGWt
yA8OABkwYtDU3xk7wMAmVkj5ZxmbWcIYUTNoXGHFXH9QtKmsIG3KDTMTtmPu
IAPxyAweV4RJGJHEnAXD4wgXJmnybFR8CKzhkElKhhEmj1G12N5e07P9gG08
PQMtHn2N2jrKObPcwPLAiAySIynw9nkzUWRtu+5THoRvLYSmCegfKvDiZwQn
zqZRAJ9gLds3TBp1KScO/A+BP5bij/P0uJqphDzkvxllK/8tsMY3H5Vjkoce
rlnwZF1d9wEqbE5d8PkOD9BsjEyDDW/gqfBKwPMKg1gICMBNt0NinJGGQU/Z
wXwZjLXiTxluUyMM+AxsYj6QzTA/hpY64hF14keQe3t1YBLwdN2NFX5zVGmz
SMgcFk38aekmX7aJAWT2bUb2e6414vn2uD45f54wSB3fOfzRaKdLeNiWD7+e
yHf4pES5v+ekgy9/lcAGruDBQRBwODgAsoQRHx6i+vITgmF4ps+Ptn2/iqLQ
qQNLiKxmc2THVkpEPx4F+1HY7nVGwsrySNjIC/wnQjZXvm5PPNuJyatDYUaI
C1jA4jkCTlpwLK6QF5QhISgTpkxpebcdmL85L0djgutBY1OmBiWMQi+aa+js
Eq1BCmA8NZEHLxLneDCT3cnBhihGpD4ueEhwv5MmU4PXBGdlDC0Mwm/JOPnn
j0TUDg7CmBoYTPLIZWG46Q0Ku44gI2jgfD6TfgDPTxVnzBQpeLHv20Wyfx64
LUHms2VrY1ScuL5oJKGmFnNFHkRCxsXMDR35w4Ln5f09rNOoYzYH5R7ft+iA
UlO0GWZ+zyx0RVXB8tyQzzBNgnPXEHg1jSYIDsdlstX4am7qHgK8PsqPvLmz
OOnNVxT4K9CxP7ORKMooAwAoQGTZNuxmoMAff+zzz9x1Um14DIxL5YxWGaIO
JXDHCYOFEFSZgEXAqzC/eGvuCWZTYNWE5nKTlixfsLtcYS7rHu37IK0iSFjn
p8u+icojj8k53jSRiPkKS8Jxr5uCX8mER2gy2Ptk8fj2enBOzid9cKBqNugv
Hc+X4TlFnfmZPsilHYfeAe34cAcHtztKKHAQzXWYPoom2yuY8Gqb4S7ZqKN5
b3fSmGjQkP0YXXJMwfDs0LynF7dXdyQjBtIvyM05x1QrBxMZjttCjBbC59/H
y9Xv+yB+MePE2fh1yNwF5i4o6xwZnsiEmQ/tUPwFOV2YCfv594nrKAFE3MPM
VOzVLEgHXAtNAyc0Zs5eISPU1xliG9BAMidAi2SWYU2ZvLd3xbe6w1hwhpxP
PENGmH7tEmmMXkDHK74gKHU+N2DvgbVCw7RwC+6v47bhthT+wLyuIP5OjqSf
UAR0van3e0EdnB2pSnJXM3KBdnrAGUpAiSIAszkJqpYwXo2L2uPL1vMXtSXt
4wolfBVJ416vY9+n/BlSvpXfx5X5GIzo+sWhFPa3rUkh1Zp0UfTe8BomVI31
aJrUtvoUv2QJ14asBnWbs/ROHspbBR4zWDOAx0YS+oTpMyfMfeT5jVKAH76P
WQFhRte6jmDbd/nodx2edpOQaOknU76XLUgJlEJQqhZJ0AFf1TN4YQcdF1wF
0ijxf9/WWX/CL9Jh/rB4WI4/LByWDtGnv3o7a/Tbv4hi8gixwfy3g/8I/41p
QZLwJYlVScrBF//xv/67D+w//ud/i/8HQsm/A2WqTDag8P+KQym8C+V3YQcU
/z8i0Qvifb9+D0MRm3upkpGI35vaGKMVpY9uLJKeAStjTl8YJgk3WnLtS6Ti
Zf1tUGi4/XgosSzmZ9WuZH9qZUxWt8YZd+l+vELmp1XHRCf6E6DHJrq9Buen
1d9Ep/YToMemlljl89MqfKIz/AnQYzN8r47op9UQRSf5E6DHJvlupdLPqoTJ
/tQ6m/gkP1Rv89NKaaIz/QnQYzOtZqJWBAwb1FP/uHEDiHxaPxF+ZGJbTiki
uv4XOggIQ0+wuE2uiB3S2Lt+JDVPbfv8wAiYkPdYLa+TrTjbneFN9uEhRggm
6LR85X3l4gGg5UyOhCTR6cIuEVNmrzNLVUvJ7vo0u39Igb1NyzVi7vajfQkc
bww+ouu7/eDkoyM6WQ1tTV3X1AuflfgmSDSCsa5iJw32P5p4z0NFW11/stbB
uk7oy/AeklEbHSuozNXawx8yk420+KHk33pRM8hhfq1/PCp8cLBuUOB7FTB9
Ws03yxhlDHrjvWkFZVj+R8g9dSy6MmBLwAxc3hIC4ymRGKV/bsrrzdZNKPzC
k61R3x/AEzajipO4SxkPQBIRqbMFxTmxCobicvLH6mnEXDGGw7vo+vEnHrkL
Fgn+sGxmhOfR8cgthfQyHxQ/5/WzEy5+epqBGeg4JZg5FjgqMBy9uZ3kwlcd
W1ja8oe5Eh+J/kfZ/Y+iiC4IYfh+uP1t87C3AWQ85ZXNKcVWOUcFaaq0rOsE
1vdj88jLW/p0HfDsyQMCvt4ZiBsDGaNiPZNteU7QbQbQRPYPcxoPsUoR2yqs
0xAm2niCaQh0Tq1G8iW/J01D+IyuqR+yXuc0/vEHLglWP7a0uV8ihOPythqK
nwmwbjq4MfQhngeB8KfSNXXPj35jTwrQHihUeNAHdxgG0vHvdwRs97bX3/Ps
MU94MDCDJFGM+qWb7zEVtQjL0z/3EvuzJOFGwXwDMz9UMC8oD1WmDjJUg+5X
74YNcSlE1g87GvFEZG4h9C1Lx6CkhxGDzUrhUCKGCMb68whfA9G43oIaY1Rw
a2MZCWPBDvQo9a9WhU1QKuwHtcUbG3pd2sdba8SrSXluT+zcAJDmByJfR9oS
uRHI5wNSteAPed3KLe3R9Yf6iUXsNxAVopwFXPb50YJF0TwGQtRzBGxd7Bfb
IaVtlyfgAE7IViOgEW65jeK8d6J1wSkFws4QfWxfDLPwHGQRiThjPTYyDRAO
O1JjDSi2tCIpRMWH4akNgaX8A23oReuGcIN5pn/2E1aZ/x2ugE9qPF3EnPpD
JA3PnIedgtMOUAcDnW3BllYwVjF2GIaNIzXxlJT8VszvYz01j+Fznva5INxA
iuXpapALRNXXfr8wfry5tk+czeXJ8FY5RlBlrUwsDcQ4L1xHo08HTc7XnhqP
hdWtW+aIi3bIxWwoWOMcuCA8eUKSb6C829fnwsLefYFGDwrO/u44ZPseJUXC
5YsJivaqd8ZPqNeqNMPldow3vuzt/VdsbLheFrQbpEzhMLYBQxiRnP1jbTTS
mNhmuo6tlpGvBL/KY4QVgiD0NKarDlZhwDvaDBtMgjyeM+oU5jdL4odzn08a
+8ftE78DAlYGMEVG2b7gtrdnxixvHrkCflt3oNoQyfZmtQ8PCq8zIYm7thAJ
pff9RENB5PpMNATbX+MGB6fvls+4SfRWioWHNX7EfLY+e8O+ExqvCQ2FIShI
2luBa6WtO+YBPiGLxtsQhKvEu0k5RCbHP6DzsG7ZDeliovUGBA/OPeM/o/U0
8+1hQMtnhQym5is6dUjERTBklVJTwYkL2nOB6TT2+Ox99bc+ZNyLnDcmVfYj
6KDRF/X54t0Y459G6mD5KUH1TYGsgIuOiBBvg43AjNlEdrTXaIZEZA9TBk6s
shwZzQbjdsxPkEh4elyeYX09LpQTQ5f6kvF5r82VeGHKDaVF7K1/jick8KyJ
eFM17hxtJVYGT87wZWrz4R8gR3Kj8duT3uVNp9Gjgi7C7ZfNOp698Jwl6Wgl
1tXsbVtM2khBR02fhnjSrbCww9lm2xWOTDfs2RLgkXye/Q4eayvMP48LwfOF
CU919uqxBh4foPfOfnbnvJ8dP8plqiYLDRSDYL2Gp+gmW6zLntACpNcAyxGj
TnUYHEAOw8LgMQvcqUBL78gC8w3mDcOG9AJ3nmzjHS8hQxm0KEdu2FjDo/t4
4j21VuA/8GTaoEwCuSmbq2RzxWzUYxJDj8kRqQeVGJ6oiZojDm1rykwy0EGF
iYa8EkHMiWwJI2RL+XI5VyrvA0afT+WZbMI67wtfj3TgpLbsXgAF+9Z0FSnW
HOJPsJeRuBkXf8v6GZJOVpJqNalEwAKa6+A6epiQAVDb5GabVlQtT8JnNNdY
MuZCBkfPmxFPia4lDhnNQsceXXyiIAix595K1MBVd0yMIpEqByk2sVT4Gmw2
Ef4fUfqK6QQYqFSVWCKt/8DJYNoHv3uDjYOnKRHKaqpUrlVLUqVcLPym/Srl
crlKpVzOF/JVIvLXaFl9mBWCZI7U1WMjGdhxuP5UUh9FIZ7w5Rd6+CZkdt9n
rAu2dFvMRIHX4fopUgYGSgd+RiePYQ8i+plmPfN0h2VDr3mkywtxbbWKmilu
57pYkCH0xAiXY9jBq2CaN5SVHg29wI8Bc/sp64jHulAoPj0xRgjSGxzJiebC
2mDRKiyhSHncoqxxavQaeBmLrsa3mKMs8CENN7Q1Ntq5oWwKlmydIm0lFBni
CLmQVBEnG42ck4RrTzZdz4huHmvsZKhCFW0qXN6MN83mJNF/VeyYCi5R5MIV
VJyiAr+KU8ZmIs4VMDA0h8GcVzvWxOGU8TvREJdipEt0aDG1senSl6iIuQ1M
m/bGA7kom/tYu+mz5rk83CCd/wvI7YztZVEMZEuVYqlYyswmMwLD73EBKDRd
ECpxCMFTKipKZCmN2R78wZca3BgQFRxRvJ2ES6qeZkaieVgjYSosAz6mnFHM
LLI4iU0xVxFBbHKFBaysjRxl6dZqJeAsKaPyYjNcNaRScai9xiOE+ITLJ0x5
xPJJsIrFEfhdsghrMUMZANIVW6rKIpipO1Zlg8idPpB5o0TSBfqGdNUcR2eq
haUTuiaasjOBf01pg06YM/VWnuit5Ne5ZmCEaR7bIBt0coxX1YgKPcfN0DO+
9bNyNW/ptVpuk76YNBsVTogkf0YfEpqcqtliFgSdlMvnQ2pG4GgjZo4jMZ8M
PeDZ/tmqdzta5a66xssJXwRvPJZNz5E3xg0ec5xhCrvYB8WBpTNxprnKBJUg
Vxe4DShtkjQg/qXolgfkWljiCjxgByNZvgpBz3akxdHZ3bdghu/AG9nwXQod
R5zIrbKMHw7hGM7M0txogapDLeg8Tma/IR3W9tXypZpUz5WAo48aYiknlcSj
euFYPJIKxcpRoXRcrhYJoi7Pl0J88WjZ8Hlm4gWsnN2QqvyEDE9gQMuBHBWx
nkzEtOPdGoDPwJp4G6ICnvBdk5VyxVK1XKoVigMpn8/lijmJGx1X6ArQbiDk
VM2NFYyHzzKazZltlxKIa34QqbVROZ+XxHxZkcVKvlYQa4zVxFKpVBkWlNyw
OqpubMdzrXsl3F1drIfXwZGdz7hlEuzJuEEQKB2/nQxHBZfZFyag4TIqm28o
PXxE/Otkp53ylXXxerWkD0ApAHEjVKS/MxRlkbUMCDPCIVgloJ2IoaC4ZkQc
HK42qBZwp972jUX0q2n0FqZJs8giqsPMGAtMmZd1MEObuqj+9uIxe/VrnJ/p
e7RNMnrk+3iTA0WzFR1+p8fZePTrlxA+QVIAJ1sHIzhqKkYe0orki7lq5c3V
ZVFNvQBbR8To5bp2HKPgJlrIsgnmG7xrh79xI9F8BtEemmYb1cz0I5UWYy+h
N1QXw25TBGsEm98EpCP6yX9Cqk/V8Aw6W65siErFUc24yZDBR/TNgmlLzRwU
84VKWarls8F1fAOpkKuVwdJcazILlKBLZI1IgMjDoBB/G2dwFuIywGcT8PCn
XKn0PXuqORPAFJwdFe0Y0PaaHLXpI49pmIk8xJp+LEzTYJvG+XUHDpoC8uZV
XmkjcSrr2sqyuUUnT4dRe5b+5H5SxLbRzIh4B/kPq63puucEps5XWQW/QBHe
Kjf+g8glD8suQAeDnwmG1Ai0DYED6xR9GwaOn8yAMDAN3GsUoKe/QbWNbYAj
Y7tHhxo0iGMGFne2XCvXpGKlxFmt0/V0VwOnI1pEafjPuFrxxQozgcGVsGwS
b2sDd3Sft00MTLWbtVRY+7wKdrmjIF3wWkR4rM/vY2VKh9wRXkf6guAdtR/l
7msXTBAZ43HyNE4/1BQwpBnqaCdr8Hdn8nSwy1rF47w3zivGtue4aSvFSq0o
lUqFSrVQBs7PlYvii1gv8qW8sVRbG1vCkQ00st7FxraH9OIArBguHII2rVxm
kvuNPGNaIpIHVCDVLxAWpWoe9FehXC4DOqW8+JCrlzgWR3j6dWWDc7XZ9mIL
DkN4GXQGvSwWiyWpKOUHFudZrAR2yRLZZdyssSnWKlI1XyuCk1ks5sTFSCsE
TqBlw5KBjwlEHbEEhMA0ceidLE+DCameBes2y1nMv5jxnxzhqNfZ21v/2WQq
cdkl5ubz4qqtDu7nI4zfOLLhCqO//Lst9NCAtScMT41NrK2JfubwANOUt93Z
YD6hIdtg3AttTXcPsWmRRykgWCsLJtSUOXgeyoNwgOshfKWrf2/Bli/8zLrR
iKeb+EVWfisACjzz1kaUYK2BtYl3GqyFnH94jP8ImzdhkApjzRQbxjg0LEtk
m4e3UGDYa8pWe7COst8NkLlK5pCH5TBPhHoV8Dgez3dpNPwBAW+bjTBehrkm
W3sR8WOvzfYHfkAeS3vwqq913jeW+jcoksdjBPycGUFjv16FhY93BijDhqgz
BhqdBxP8brep4rSUv5HFi2ZDCRorc/MjneFbfmJNhEfdyM04w9VG16jw4o2g
7i24QocC4Yh08AsaO/5dKUF0NYoHDbsdth+6jODg5zP4oDVbsBZm7FScIyDz
kjJf8lAP67cHOdtiyjE0gwIsflzBjwOQgQCDhfD54IAtFd3D1IaDg/j78P0B
VXkeBOkt+7zXQIqbzo4qTen4eWA/O9VO7mxcWDVmhRt5lntgJ9mPNq58F9B+
SqTkk7uaetu03Pr1a9tUp/nCy5GyOOoXZCcdUkmA0iJVaM9zJ5IzenDmqyNX
L9fHj9Vnsddua4t0SCUBSotU6fy0rNWcuWWYk9nqqn1/xZ67lVHXeLhOh1QS
oLRI3Q0eX1q3j4XRyUJuLharUb127Exmbebm0iGVBCgtUqfNgbIw2u2ToX06
uC/dlVcnzL2/NzWtmA6pJEBpkboaNB77K2WcO2tVlOGZ7DXr4vRu/JB/ttIh
lQQoLVJPp8+nD7PHxVPJbNwZr4P7YvOs/KA1Tx5TUioJUFqkio5VOF+2Ly8f
2j1pYc4nnsXu78es0Z6mQyoJUFqkrsunhlKqznOKpB/fFbznzmOu/jCwRq16
OqSSAKVFyix2Wen6qjFfTJbKyamp3rOrFXifipWSp5IApUVqyG5eLy7mi642
mt6MTq9GS6a0rPasf5xSoicBSoGUMoK/bkuPbbUm6Y/P2kuj79aOnlZ3xxdN
djvrfhipdwGl1n3NhlU86t4c925X5vyiVr8+ld2rZ/NBHqfUfQmA0iK1GA4e
nVr3Sa15NaubP5qKVXdeGc0fWimRSgKUFilrXh2JFeXp7Kx08yR2jWel3Jnc
9Y7EZkqRkAQoLVJ579aTj6Xj1fj54rhbbPUHov04XPS105RIJQFKi9TsqFCT
hxfStd0uDur97uCkUp0vr/reMiVSSYBS677lWWPZbTOxV9duat7k8lLX7bOi
cVtPqWaSAKVFqi8tvdnt0eLl8eSo1270H8a99sOTq768VtMhlQQoLVKTm0Wx
3FyMjTtVq41enoz86PlsqJuDTko1kwQoLVK3rcrqZDDVjZve8mKVbz+UR69e
0zKPnz8uPN8FlHr3TWaso6usOTopW7WX8nntburmcvXGWUpKJQFKi9RYyWvP
ufnQYpPeQJxLObF34ehL+amR0hxOApRaeF4WjfropdQ+fZq5x8cXds9UK6/H
6oOUktGTAKVF6sE7VQark9OrRrfjPSrz/GW38nBsjW8at+mQSgKU2p66a+vm
sNk5mYjK1TXresd3ly/L0uP8PqWLlQQoLVLLu9tCo/Jye2mOFW1WOSo+XZa6
p7f92kNKhZwEKC1S0rihXC3EyoU1O755fT16rRfUZmdsFW5SGnlJgNIi5VZl
a/h6VKgU9Xvt/NW+sy9vHivT1uMq5fIlAUqLlFG4XR2VH86vX5eyp7Dnk4FV
vTKLktfrpEMqCVBqOfXSflGGw7O5PLBaJ+LzyfGTly8WxiMxpUJOApTaxTqu
Xh9J93fnomtdWPPWdb4/LR8bBjtJqWaSAKVFav5wkZ9po6dS60FpSMvzRW90
3jBvleZtyqBZEqC0SHVbzQfNHFZLDz35fPryfHQyMY6eGpUrJSVPJQFKi9Sz
U7vrFK+OqqtHYzLOXw7lpyNJzudH5yl5KglQWqRyN6+XN68PgztVfyzdXg+6
911j+aSb9nNKOZUEKC1S94VuWzoCZ21oSPe3V8vWtTaRO4r02k9poycBSm1P
DeTWSjeabevceLmoHB0pj3dWW7QvUnszCYDSIlXpPfa8o2rhzLBrL42hdCc1
a0Wzdl8opLQSkgCl5qne/Wicf7w4qV+6p9eVJ2ckLfXipVi/TBl1SQKUWiEb
o4uFOFxUzxz1dKgXHfm8Vmu+FjWmpFTICYBSR4dX2qhVfb0qyQvLHg560sVN
rXlye/JwnzY6nAAoLVKNx8W8Wym9lu1+R83XC09P86dTo7281FLaU0mAUiDl
jQz4M19bNp8eSo2i1WtNZ0/1+UN/UHk8v8/ffXz93oeUllae1F4+3teU09Hd
TCs0RrWXXJlNFrPHVkrtlwQoLVK91qCey0llWTzrmg/1acvt3i6t6ZPxnJLV
kwClPjJaVMTL+3yjfmfnxOuj11qF1bvLo4HZTamSkwCldtzN1VCRR/Pr/LHY
mdyO+nf5fPX+unkxSekjJwFKi5Rt3F2w5vBZXubLekEySzPNbXeWl9fTlIom
CVBapI7Hk1O1VVg5w6vmWfeaVZXXV9FVOt2XlJIqCVBqSj2dy4qm5hfmiSuf
LnpDrdMZuYV+rpmSp5IApUVqMD05ujy+cPr3z2NZHZaWpv5cLavziZLSokoC
lBapl6vCQyPXle1ms17odYdHs/v7U3dZb1ykZPQkQGmRmk6frydacTU/HWj1
xaN9tZAUuzkRDTElTyUBSu3PHE3VM/fste8WmzXpbmaPzjqmOjb6+ZTGSxKg
tEi1PW9Qb3qSdNS31eVZoVOdGIv88/OsmtJxTwKUPmxmatZyejQYXD915pOm
WTLl+/Jz5+E1pZ2QBCgtUtq902jU9erjkzi77NcrjnZx23JGutZOSakkQGmR
Etutq9ubUmPu3d0rl/VxoaL0lgur3jdSMnoSoLRInZvnjyeVYev60mgs7x5e
yo6rXbpnC0VKKaeSAKXmqcGwczq5VI+Kz9I4Zyqvy6unRfPBbVhpQ7EJgFKf
OayKL3fXp9etm2peHDrT68Ftq1PWmC49pjxzSACU2p46LTiDx6Y5qnWuq5X+
PK9IL8VRobw8S8noSYBSJ5bcn3UfH6XHlnSS13qD9uq6aB8bl85xK2VeUBKg
1FbCmWQe99iiPrw7HyzY5axWnZqPT8q4nJLRkwClDnE8e6+5Uee56j4/Wsqt
oT09PSi9xaLZTkmpJECpHYdH7a549nRh53M2K19PW8bqvleYXbkspZWQBCh1
Cs7jeGlI2tAtz4rqeWXZlB4vVD330Jul9GaSAKVFqnx+Nr6c5fOPN8tW/3Eo
auLRUuu2Xrv3KWN5SYD2/XJ7bIFy7WFFI1281KFuMrZ7KIwAMDWYEl6Cn3lu
JyWz2rLm8OTbzesW4AMqRLbpwjBsSIKdEShf8h4bLWzvj+e3xvvMa2aE/5LY
sRAbxWlqcJXZR3vm+V/9Ru3ZMHUXGwJppkeNbKJtiJwgx5m6cGABIzWUwh4a
zqGALYbglYODSDvxzU6HBwc0j4ODHXg9e0DQkcbU34TbALJ/X5zJRLw4N/Y6
tgkcrsv/MW/Woi6JkXdsrDcXNIM6CbgMayPodpOGhR0Z6ZUTeJdanVFSNd4E
/4X6an+lnGnMZt6o+IxyFXBDVlP93nN+G1DgMZEv2BzvJ4JlyBWpygd7HFCZ
U1nM72eClffzrIN2jtgzh6YBHKGNTeqm5nD62Vv6wAWN4DY7wX2mGhGAja39
8I5gn1p+YSJT93+jXo2q31nw4IDXT/JUaz7eenxqn0GXruAiYA8Vz6Cscd79
aBM2dg7DliM/lYjFTD5TJDK2gfeCkhDqh0OL7qd207YCnIE0pn8BMjZj0cy5
pc+Dpppv7gb5zQdLPdhkgWizwrdt4CFq6iVjX/wx430lsMiN3wInXHU6xzw9
u9HuXA3gj98oTz1S7IO30WAVP9J4nb6+R0nZkWIfP1V9BjsUm2ioeDkSVTbY
RpB0/ib/e3vC93vdnPj9glqkEGSBraCGQUsq6lnOM9FnNlbkYk0av5CWp43z
LP34zRkNv9NOeHkdQAyajgXd4oivqDkOYo3yIZCCH5IYMOARXoggYHUg3lpC
LYiIAMxUsd/iOp89dtkLlxvhFdl0c5vPKNQ6bH2PVQAoTKynOyQS2rU5lu7x
1j4CaA2uAzxQSYf80mzYMZbftgSvrqLiNBvZdssdfiRjdW3KqDXhxkUUiCbO
1MLrlXwgMNF1x0e/kR62HOKSnskOtkgaMiEstxiu4l0/w/4oGeEE24qxJQgP
B1VepBqNKjuwmRksUPIk4B0YQVkNgU+C75F9sXYAa538Bk7ARojp5pWWh+tu
QlQOE4yMbXUNzcHNYJs0PdQTdCuNN3T1rS10hBNYfIUqXuJcCTLwM7/GnAjh
zagMhzYSXlke9O3k4iLCRsE+xRaOfn2EMAQ+xvlQQRgvLun6LaJBoYFYE3rU
IvoQ7Atbkw3YdqDx5JF8KPQ9ywCJXfds+ONOw/3u6PJcOPaGbDW1DoVTrH/F
z5hwKitge4At0rPM8dASjrxDoTFh5ngJyLU9OajmacvWAgvK4K194ifm0yAq
Y2SNC5N3++SsrxGljjnUcSxkIF/yR66U+x4pFLS93XbH2872Pn7pjN9RM6kV
6PpWNy7Kol+tL/r0b7z0Ocq3jmj0oI/cm55JQTkQWYTBu4gaztCWZxrWNPny
aj1HusFDpS5j4WaNXugaVj9RE1as9Bb6IOk0E1bsNSR50J8XBLZKbegIOu2q
oBo0HGqrxgjgUP3SGj+EYONd72xOZVkIBhtIya68vlKLHvnX1ArxL/0h8S28
MwEvqQl70eHUPAP7zgWPqQQQRqcbSAJNjhemYHn2up/33fblr/ubNPIGSIFj
FPTOXt/yzSsntLwj/WQjDXFxDalpFfAjtXJdkxPJQNvZLxdP4kV5jUxEXJPW
2Wwgva298OEHuzYfJnaZRt6RgxsNJzJdDYb9MvCh45fJ0SI478ivLZeK0sCh
2ZIRIlfR4Pw/Y0NFtpzIaMxjZ3eNCL9PfXtt3iKX15YFjTa/+jbg9ts/P95k
/5dQaol+ISXvR076EO02UprTzVX6wP2ISM6gafNafnBLIiI5R/7VzP6W2rA+
eDNkLFPHrs5730jDutk2Kvlvwh0zPbwX5hhsyM8O3j0Q7gO8+EAEVbrzn3g9
+Dm4bEtYC7qK2YmWYmKpZKRDxkzJYMdQsN/oX9l8jm46uLLlsQe7oPGKTaZk
eFISK8KlAmoGAcDfjo7O5aGAaFl80Fa92GoLUhG7Q+qMbkPuMrwXfhy39sdy
cTwhc5+PiV+IM/4FjQ6e51ieoYnzTchXwYacuWL+vdGjtaCRNizAuk5mbFlj
vyRf1TLAFCCyZCmjuVnmWLamOFQtjEPfgNV9KHRckLp43XRRlPj4GyPTkNQr
nO5w65jgRWoGrDBNFxdQs12PbrHuH9W3QYjhftO57As9z4CNtok/PYQ9bbmi
5RDRQlxbsKLYOf1QaGJFPFFLLNJgDNc9HPFr0GPwfbjUGAMUIewi29mx2/YP
t83hGHVBaO7fY0fOngsqwRA+H/fue/u7eAADHwOH3szyHldBCfe+4HcB/drS
rSEQE3wGjSaKO7AFkzdg6bhxA6oH2O4zseDOofZjC5MvgqoYr4nE5xT/NrCN
sIqaGnhECpCzRalQKtdKldIA7x0XgwtyBxt6aaCZgyaZ3oNWpzk4ZuhID2AK
A//qP3XQP+8Ntl2jsCnogfJfieRrLD0nl1+wYebVsoyMh71llCx5r9nbulmo
SirTZFHuXhjPrfak+7K0FEVqK6tmZeqc6zJjZ2y0vCwOe4280b56XVxdXz22
WF41n24yryOdPTYMw4U9ZA0uevzSlVjFeL0jXHEl3kMP1t/uwp+Er7Q5pCgr
xxx9f6dkJZ+X7zRmmmDs1kFP2CRw8pJw6mHL1WB9UPd/NLIHYJFsoL+Zk7XU
sTpYGpPn6wftZiCfP6ov7t38+JQ1i8jL37PwuVqpmJdqg+DymcFNaxAlzCAs
pecLPaZOsYN6h9OQrmD5KUTanMvW+xGicDFKAbB0J8s/FeEh5z7/8hVx3UgW
DUW62kPM5TIzdbSFHVfgvXuZIcs2h6X260QyZtLJb+6vRala41MP5yxgO0ls
eg3/MZuthDbYYhE6aFNtjTAzYzhj00kZNLZJ/4UwdlAnF6UOkqcdfBlcbp52
xF82+oDRbQaVkrhhgaABgtRB3P4zk9rcbyFb/bxt94Zm373v7mpHZ0+ng+PW
9OlK1c3nI/mWrXRvMny5/hvtu7bl3jQbP4ROUm2TTj9m600s1x4pInYekkWp
tLNnp6mKfk+RWFPIXC5xUx6372+05+WZY8GmLOSrpW2bkrjwHcKE3OpkCeuQ
eT9Krb/2TvxBqxOMTgukbhtso6nrOyvSunlZ2cedk/HJAlZEKhRz+75tedX6
u+ZTjc3GPpfmthI9HR3G1ZeBJ9XmD69TVBfFXNHnTDQknYk1ixMg2tbLMWVl
4ooqiA5stqcyvFRtbIPh6ne2lE1Hgzd2NUuTSiXcB0DsYw5C6Cka+UoXdK15
3CB/f3TGN0EADERqGZYAr6MIl2BDLfycCRH5Lj0Xnm7MwaKHoqoi7A1cS1Fc
36Aa+5I27tTFzlPYxtHvAY+925Ka+oFcjgs1mQtpUQarl4JHTtZHfofq2+oo
cS8We2N5yxG1laYQG/Lyrj5cBAbG+ry+T2G4Ek5hGcDTQL+ZfFHZ5O4VdlI+
FG57daRSQQTvIU4oPJXa7E71jjaTqiVwIaqDHoaYwLfSXumXgTWKuQbbqREG
MhthdPaNtx2duRJ+4ftCwPANbIgnXMgUmlkTuBnSLz4dxVRG2D0x7kcVckJ9
Zmt6goj5EC2KtWItP7hBXsLpIy+h67TRMWpQT3SH3rpBBXfyNHFuNPHo6fRc
bL08m4vW66SimUPd9c46+uzu+aWr38/K9zdqt/9ULj9VZ2L18VmW2eVoOHnI
NKx2+fHIm8pnnpwbT12MnvMjRc1ATIyZkMt9yVe+5HL8qudOE69wQJ1Gl87Q
tRJ/CsIjRKrgwHmLbNkMjsj4Pm4YfF8Mff8u3tMDTu+h0JBNWZWFz3O+IPij
VImtyPctSF4qlMtSbtDHZl9oafmvD05MGMoyMZo16N+cDC5nzBz0PHASkwT8
mV2zljNppJo5VHS5agHf5nc37KJAeIuUbL+hguhrKJGDCETGBezP3sqAzahh
TNlEk0/oWzMMFPiR2kC6W6NIgzt4rWfBTtuIvliOOLcIF2r6nQXrDJ5tbACp
vEnuLfGWHZBoQXlcZZuVEvmMy8bsSMP21bwndpH+nStK5QHH/x/yuX/IV6V/
yNd2uGcfQYMT8uqkLzYuL3hrNemLIJUwrMf7WQonQT9L/84OPOpAnp7zCOd6
vBG4j8zNjDXUFxhoNmHDwL5Dy6KEUb/tDTIJIG9wbvJslm/CmWzrju1NQOT6
DQyJ9OIPYXaUPqVcnuI04EXU/VOXN5L48HvlfL5SqL4HfQAy7o0uAAkITDtA
O9BfmVa/2+Rhzi9C3TSRBwMH0D9pu28Jn/hY8Av1U0beD5j9UySw7hojin1m
HL4pHNQYxB6+yfEbXgDxK6MVOPdexR6eoME/vTnz7GjgsSgC8buy/Z/VAqVC
RSql0wLcTW7eRA3m0rsGM794ujdh5iv8P56ZYl/KmBitvTOhdyzn0jbLGTy6
kR30xA9MpmTbuDM6Gw8vK8Vztwiis5wrFbdGkT425c808rtTr/yUqVNcKezl
HJxtvjP9yUMFLMST6UUFXaRypezPHiMfxpvIxw9Z+P88J+cKxUqxUCnsjlQE
MQm6D/WvjP/3rR7do+r3aQ/Xzhqtu0EzFVsvJ6/m6evofDY0J3qujiEISars
CM38EEKUfgohYjEanyDhSfo6aYn/tdsTSibUpXtpVS6sseYg2xdKUuARB/T5
vlhNaSNWk0i+oviGgt8XtylF4jY/2lv8jujOrnXdiO6kwjR5Ncv5eqn60pZq
3Q6sZj5fyQVe3dsj9a0H3xuXHm5YoDmhyYYJfP7uCboPPrCqHTwIHGKw14yQ
KkhfouwlnrzENbWvqFvgCJBFmpf4+cA/vyEIMigRZciPYxeyq0x+m/+qqS+L
YW7S1CfOP2KOwK9X58ZoenuqFGped/LkXLSM2VJ8ORa9hnW96o71zuwf0Y0o
S050W2w7jf0gV2j8K+5c2LILaknKOvymsSz+HSd57R2Kpx/rDUtue8sXOsSZ
a+vhvcOY8e3NY1lS77QrijKCatoXkkIsEQPeclRmrM+HHUw99XSWpbntCK2A
YFHZHASigSe4X5uXveOT7oZrtQkYqXsErqbDdOdQOGL6GB24b0JBEk5lU5Q2
yP3Ww9qJKfejW+1W86gb6ioXyLxNcGxC8ZMjiNSUEu5sg8ShZPNl0Pl57pTl
c9KgnPNqLGfuWB36M7M5oKeW81JpyyAZeS5lFmxo/EjBka8gdf/mgoMbSWAU
EemkfGWH9AgZ+ipXdM9Pld5y1P3t4+KiWCj+UKlb+Lsgnk80qfAe0ZSe3Xi6
WFmVwTgF0ShU8yOpVhaOmUJUK71Htc2bflPT6YifYQ/W96gitUpSXiq/R63F
oGs/d1l7dVVNQa1S7YcSK/9xWv1gDqOoXljz5FMtl3+PalJZbj2J1pOmpuGx
fC1P9tCfvwiu5urs10/RtM8gRZGt0z9jCZUpUi4//YFZpUKnflF/k/vdj5Ui
4I0EpsXf5Om6mDm+hxl2Q9h1CKWuBPmipBgAe5Py7Zj666cR0JXBaPF3eAHJ
5i3FmCe/iuc+d3jvfo1F7kIO5jXiwWfMEWZMRWQoBQqTlj2yVoK73jHB2qCU
Zb8+5E1GfXjFMmZYq7yQZYaJY5iMG5ZHZALa+LUSVJnk35YerA1dv8arkrhb
LPA7vsMLJDCzNFL/IDiROwf4zSX+5cAbdw58oSTkheZM/IxbuisE83b9RE4q
iWGKJkevrF8nd49oKjzBGwsGgqxfLIRy3HXZXQ92wEo4Q3aQhUvwhODZsS07
U8v/11xT9vYODrZdYHFwsPPqXY49FaJg6QbHD9NOEQfFEiPMSqTffYfveiJ4
JTzxNB7p2NrQC65sFrfUCsDDt8UChBVVcI3xvnlgFmTAkFXZFhriTaPjiYt8
teY0nnw3YfoMnwcVGdbum6oJyRNbU7AACjhPRzKfehMLL1J3/vJ/TfgTMJ16
jnDjqSv+V7Q2Ap6AlQgb8whEAUzVxaVzgQmFM7xuxYY/+88ynmW2gU/49y7e
xz2xDMdC8I+eiXM61WRzDH9eyXOmCxfa1DIt2CrwpCE7bCXcazp/v25a5srA
+sdohmlQNGPjGMewoJbQ1XQZ9hAxCkzKmph4n5D3l/8NOLiuw6Ed2RpobXDd
dYYVf4xKVnqu7A1xIkEFB5abrcs1hLf/QzRjNR4hGc49XPIzD6SivBLqYLO6
wtlf/v0v/+cv/z6FHzp433xPmdiWMqURZxMNj0QmhsbGNJX5ShUup7JG5DWJ
geooyWXgvHvLUgEAPGr95f/ZCAnsEEySR7KDNOjJLjGcPPWGfOUwB9m1Fs5U
W69FE/PngQcmRH7gYJBgx3TvIiLAhiCZLZ2taLcFF97wG8r5RlvfV55id8Xu
G1/vtcjd5x/aYG/ZMVKr83O2VSDlafyOZXousNpE1hUmb9/cInE74NTkyaRb
tlwbyx8doQ9OkjVipoZL/yjbaKZM2GhEC3ouezxl/Bz0zRB4Gzm2pdmaOgH5
3QUUV7JBjAgUdIGRgKKwnC7x+akFihqL0trWClkEHt3gNWK2KhzJwPQOrq7N
RqAZaFH5f/orui1F/41EF9an/Lx8IbwOh4pmSVflc/jfeH2RlCn4538ar7WO
jMlVbFDdQYVM4ZVqwRBBBVhQshjqjTPg6Qnw3grmegTzG8tz2dwmpS5AOBjC
mTVkGiwyTr/F0DgB7bG+7o2qDJ0g7xlDGocC1lUcYukFL/Lgx8j+Vec+e/LM
BV6dRCQKDAPMDCNQpJ8zQl3YXo+xBkXlbY7wFe/V+hvkCP0yk8fsV6myD0bH
1mo5RA7va+ZT5ieBYTVtJHNB+PzpmHkuRgFItygTD8xfvCtL89NsMp/29/4/
mMdlaujhAAA=

-->

</rfc>
